From bc6ab6b52e34ef7320fd5ef906d4836cc0a2fb0d Mon Sep 17 00:00:00 2001
From: curben-bot <3048979-curben-bot@users.noreply.gitlab.com>
Date: Fri, 26 Mar 2021 00:12:46 +0000
Subject: [PATCH] Filter updated: Fri, 26 Mar 2021 00:12:45 UTC

---
 urlhaus-filter-ag-online.txt         |  1328 ++-
 urlhaus-filter-ag.txt                |   619 +-
 urlhaus-filter-agh-online.txt        |  1234 +--
 urlhaus-filter-agh.txt               |   588 +-
 urlhaus-filter-bind-online.conf      |   119 +-
 urlhaus-filter-bind.conf             |    68 +-
 urlhaus-filter-dnsmasq-online.conf   |   119 +-
 urlhaus-filter-dnsmasq.conf          |    68 +-
 urlhaus-filter-domains-online.txt    |  1234 +--
 urlhaus-filter-domains.txt           |   588 +-
 urlhaus-filter-hosts-online.txt      |   119 +-
 urlhaus-filter-hosts.txt             |    68 +-
 urlhaus-filter-online.tpl            |   119 +-
 urlhaus-filter-online.txt            |  1328 ++-
 urlhaus-filter-snort2-online.rules   | 11404 ++++++++++++-------------
 urlhaus-filter-snort3-online.rules   | 11404 ++++++++++++-------------
 urlhaus-filter-suricata-online.rules | 11404 ++++++++++++-------------
 urlhaus-filter-unbound-online.conf   |   119 +-
 urlhaus-filter-unbound.conf          |    68 +-
 urlhaus-filter-vivaldi-online.txt    |  1328 ++-
 urlhaus-filter-vivaldi.txt           |   619 +-
 urlhaus-filter.tpl                   |    68 +-
 urlhaus-filter.txt                   |   619 +-
 23 files changed, 23824 insertions(+), 20808 deletions(-)

diff --git a/urlhaus-filter-ag-online.txt b/urlhaus-filter-ag-online.txt
index 1820922d..ae728920 100644
--- a/urlhaus-filter-ag-online.txt
+++ b/urlhaus-filter-ag-online.txt
@@ -1,5 +1,5 @@
 ! Title: Online Malicious URL Blocklist (AdGuard)
-! Updated: Thu, 25 Mar 2021 12:12:40 UTC
+! Updated: Fri, 26 Mar 2021 00:12:29 UTC
 ! Expires: 1 day (update frequency)
 ! Homepage: https://gitlab.com/curben/urlhaus-filter
 ! License: https://gitlab.com/curben/urlhaus-filter#license
@@ -12,7 +12,6 @@
 ||1.192.180.19$all
 ||1.222.140.251$all
 ||1.222.196.60$all
-||1.24.132.118$all
 ||1.245.4.163$all
 ||1.246.222.107$all
 ||1.246.222.109$all
@@ -22,8 +21,10 @@
 ||1.246.222.153$all
 ||1.246.222.16$all
 ||1.246.222.165$all
+||1.246.222.228$all
 ||1.246.222.232$all
 ||1.246.222.234$all
+||1.246.222.237$all
 ||1.246.222.245$all
 ||1.246.222.249$all
 ||1.246.222.38$all
@@ -34,7 +35,6 @@
 ||1.246.222.69$all
 ||1.246.222.8$all
 ||1.246.222.80$all
-||1.246.222.9$all
 ||1.246.222.98$all
 ||1.246.223.10$all
 ||1.246.223.103$all
@@ -66,23 +66,19 @@
 ||1.250.159.41$all
 ||1.252.102.28$all
 ||1.254.250.52$all
+||1.58.223.96$all
 ||1.60.77.53$all
-||1.62.195.101$all
 ||1.65.166.225$all
 ||1.82.104.89$all
-||1.85.84.38$all
 ||100.12.184.63$all
 ||100.2.131.143$all
 ||100.8.77.4$all
 ||1008691.com$all
 ||101.108.130.108$all
-||101.108.131.202$all
-||101.108.133.231$all
 ||101.16.183.179$all
 ||101.16.98.170$all
 ||101.229.85.127$all
 ||101.255.36.154$all
-||101.28.102.38$all
 ||101.28.105.132$all
 ||101.28.106.134$all
 ||101.28.145.2$all
@@ -93,45 +89,49 @@
 ||101.75.157.99$all
 ||102.130.115.14$all
 ||102.141.240.139$all
-||103.106.29.148$all
 ||103.107.113.22$all
 ||103.113.99.79$all
 ||103.124.104.118$all
 ||103.125.218.107$all
 ||103.136.82.50$all
-||103.139.89.205$all
 ||103.141.138.12$all
 ||103.144.36.20$all
 ||103.145.13.24$all
 ||103.146.174.208$all
 ||103.156.221.66$all
 ||103.16.145.25$all
+||103.161.232.16$all
+||103.207.0.134$all
 ||103.217.215.21$all
 ||103.224.200.40$all
 ||103.233.64.182$all
-||103.235.165.183$all
 ||103.238.228.3$all
 ||103.238.228.4$all
 ||103.240.249.121$all
+||103.4.117.26$all
 ||103.70.160.51$all
 ||103.79.112.254$all
+||103.82.144.197$all
 ||103.82.145.111$all
+||103.82.98.151$all
 ||103.82.98.170$all
-||103.84.240.130$all
 ||103.84.240.228$all
-||103.91.245.11$all
 ||103.91.245.12$all
+||103.91.245.16$all
 ||103.91.245.17$all
 ||103.91.245.19$all
 ||103.91.245.20$all
+||103.91.245.27$all
 ||103.91.245.3$all
+||103.91.245.30$all
 ||103.91.245.36$all
+||103.91.245.41$all
 ||103.91.245.46$all
 ||103.91.245.47$all
 ||103.91.245.54$all
 ||103.92.25.90$all
 ||103.92.25.95$all
-||104.168.44.57$all
+||104.168.98.105$all
 ||104.184.75.123$all
 ||104.33.52.85$all
 ||104.61.86.37$all
@@ -140,6 +140,7 @@
 ||106.104.193.155$all
 ||106.113.145.32$all
 ||106.113.177.60$all
+||106.4.138.95$all
 ||107.172.134.48$all
 ||107.172.193.132$all
 ||107.172.249.148$all
@@ -158,8 +159,8 @@
 ||109.124.90.229$all
 ||109.233.196.232$all
 ||109.235.7.228$all
-||109.248.58.238$all
 ||109.86.85.253$all
+||109.88.185.119$all
 ||109.95.200.102$all
 ||109.95.200.230$all
 ||109.96.127.90$all
@@ -174,6 +175,7 @@
 ||110.228.195.46$all
 ||110.241.119.168$all
 ||110.241.23.107$all
+||110.247.151.4$all
 ||110.248.124.254$all
 ||110.248.224.19$all
 ||110.248.251.194$all
@@ -183,22 +185,25 @@
 ||110.253.51.112$all
 ||110.255.101.184$all
 ||110.255.167.147$all
-||110.35.145.127$all
 ||110.35.208.21$all
 ||110.35.209.175$all
-||110.35.221.77$all
 ||110.35.223.92$all
+||110.35.225.24$all
+||110.35.233.147$all
 ||110.35.235.57$all
+||110.35.249.21$all
 ||110.35.4.2$all
-||110.82.195.88$all
 ||110fss.net$all
-||111.118.124.223$all
+||111.118.111.207$all
 ||111.118.41.173$all
 ||111.118.88.61$all
+||111.119.245.114$all
 ||111.125.67.125$all
 ||111.160.112.142$all
 ||111.162.224.14$all
 ||111.163.50.120$all
+||111.165.21.195$all
+||111.165.28.234$all
 ||111.17.186.194$all
 ||111.170.84.182$all
 ||111.170.86.133$all
@@ -212,6 +217,7 @@
 ||111.185.230.136$all
 ||111.185.27.9$all
 ||111.185.48.248$all
+||111.38.103.114$all
 ||111.38.103.122$all
 ||111.38.103.13$all
 ||111.38.103.66$all
@@ -234,16 +240,16 @@
 ||111.61.52.53$all
 ||111.73.99.162$all
 ||111.91.185.131$all
+||111.92.63.24$all
 ||111.93.169.90$all
 ||112.105.117.227$all
 ||112.111.100.236$all
 ||112.111.108.184$all
 ||112.111.31.175$all
 ||112.122.36.108$all
-||112.123.109.156$all
 ||112.123.200.47$all
-||112.123.61.115$all
 ||112.132.134.106$all
+||112.159.108.96$all
 ||112.170.124.75$all
 ||112.170.233.9$all
 ||112.186.210.211$all
@@ -299,10 +305,10 @@
 ||112.242.2.247$all
 ||112.243.115.183$all
 ||112.245.12.89$all
-||112.245.246.253$all
 ||112.245.5.141$all
 ||112.245.8.24$all
 ||112.246.162.50$all
+||112.246.180.49$all
 ||112.247.100.14$all
 ||112.247.121.39$all
 ||112.247.14.135$all
@@ -310,6 +316,7 @@
 ||112.247.191.118$all
 ||112.247.214.146$all
 ||112.247.240.226$all
+||112.247.248.76$all
 ||112.247.81.173$all
 ||112.247.82.122$all
 ||112.247.89.81$all
@@ -318,8 +325,10 @@
 ||112.248.44.153$all
 ||112.249.109.217$all
 ||112.249.118.157$all
+||112.249.206.69$all
 ||112.249.26.129$all
 ||112.249.41.142$all
+||112.249.79.98$all
 ||112.250.102.173$all
 ||112.250.57.99$all
 ||112.251.17.5$all
@@ -332,6 +341,7 @@
 ||112.252.237.109$all
 ||112.252.239.103$all
 ||112.252.245.249$all
+||112.252.46.212$all
 ||112.254.208.123$all
 ||112.255.38.10$all
 ||112.255.52.179$all
@@ -346,6 +356,7 @@
 ||112.27.124.119$all
 ||112.27.124.120$all
 ||112.27.124.122$all
+||112.27.124.124$all
 ||112.27.124.127$all
 ||112.27.124.128$all
 ||112.27.124.130$all
@@ -361,7 +372,6 @@
 ||112.27.124.146$all
 ||112.27.124.149$all
 ||112.27.124.150$all
-||112.27.124.151$all
 ||112.27.124.155$all
 ||112.27.124.158$all
 ||112.27.124.160$all
@@ -450,12 +460,10 @@
 ||112.72.153.37$all
 ||112.72.162.159$all
 ||112.72.162.49$all
-||112.72.162.53$all
 ||112.72.175.147$all
 ||112.72.176.112$all
 ||112.72.176.84$all
 ||112.72.226.202$all
-||112.72.231.35$all
 ||112.78.45.158$all
 ||112.80.118.16$all
 ||112.80.127.91$all
@@ -472,18 +480,17 @@
 ||112.82.227.41$all
 ||112.82.228.175$all
 ||112.86.133.125$all
-||112.86.23.41$all
 ||112.86.253.238$all
 ||112.9.140.247$all
 ||112.93.29.211$all
 ||112.95.22.17$all
 ||112.95.23.121$all
 ||113.103.10.209$all
+||113.104.237.52$all
 ||113.105.71.239$all
-||113.11.95.254$all
-||113.110.247.207$all
 ||113.116.121.167$all
 ||113.116.149.83$all
+||113.116.150.147$all
 ||113.116.246.109$all
 ||113.116.48.217$all
 ||113.118.195.247$all
@@ -492,11 +499,11 @@
 ||113.161.58.249$all
 ||113.172.250.35$all
 ||113.179.129.99$all
-||113.188.76.31$all
 ||113.194.133.9$all
 ||113.194.135.154$all
 ||113.195.163.26$all
 ||113.195.166.46$all
+||113.201.24.26$all
 ||113.224.225.172$all
 ||113.226.42.250$all
 ||113.227.128.9$all
@@ -506,31 +513,28 @@
 ||113.231.93.142$all
 ||113.232.141.23$all
 ||113.232.211.182$all
+||113.234.224.130$all
 ||113.235.116.209$all
 ||113.237.129.7$all
-||113.245.218.18$all
+||113.253.144.141$all
 ||113.254.169.251$all
 ||113.3.153.57$all
 ||113.3.155.199$all
 ||113.59.133.16$all
-||113.59.136.39$all
-||113.59.144.42$all
 ||113.59.154.21$all
-||113.59.191.47$all
 ||113.61.204.205$all
+||113.81.112.35$all
 ||113.86.204.13$all
 ||113.87.175.112$all
-||113.87.32.93$all
+||113.87.248.177$all
+||113.88.100.120$all
 ||113.88.208.189$all
 ||113.88.232.36$all
+||113.88.242.0$all
 ||113.88.38.232$all
-||113.89.41.33$all
+||113.89.245.13$all
 ||113.89.41.51$all
-||113.92.156.196$all
-||113.93.225.12$all
 ||114.199.204.37$all
-||114.199.253.235$all
-||114.223.122.19$all
 ||114.226.100.56$all
 ||114.227.156.119$all
 ||114.228.205.101$all
@@ -539,53 +543,62 @@
 ||114.229.52.14$all
 ||114.235.115.236$all
 ||114.235.42.152$all
-||114.30.54.64$all
 ||114.79.161.94$all
 ||114.79.172.42$all
 ||115.165.216.112$all
+||115.171.239.28$all
 ||115.193.130.126$all
+||115.201.38.185$all
 ||115.208.101.195$all
+||115.213.187.251$all
 ||115.223.159.80$all
 ||115.23.88.135$all
 ||115.42.47.36$all
+||115.45.178.12$all
 ||115.48.130.181$all
+||115.48.130.187$all
+||115.48.135.151$all
 ||115.48.141.239$all
 ||115.48.198.142$all
-||115.48.215.189$all
+||115.48.200.115$all
 ||115.48.22.130$all
 ||115.48.228.176$all
 ||115.48.9.246$all
 ||115.49.100.124$all
-||115.49.18.53$all
-||115.49.216.150$all
+||115.49.152.10$all
+||115.49.242.100$all
 ||115.49.60.231$all
+||115.49.80.117$all
+||115.49.96.88$all
 ||115.50.1.143$all
 ||115.50.158.223$all
 ||115.50.2.251$all
-||115.50.219.100$all
-||115.50.22.86$all
+||115.50.202.11$all
 ||115.50.220.156$all
-||115.50.224.175$all
-||115.50.230.43$all
-||115.50.232.149$all
 ||115.50.239.222$all
-||115.50.3.25$all
-||115.50.56.198$all
-||115.50.8.131$all
+||115.50.240.230$all
+||115.50.61.247$all
+||115.50.64.182$all
 ||115.50.81.194$all
 ||115.51.104.85$all
+||115.51.107.18$all
 ||115.51.123.216$all
 ||115.51.93.76$all
 ||115.52.112.200$all
+||115.52.17.196$all
 ||115.52.19.250$all
 ||115.52.200.245$all
+||115.52.201.231$all
 ||115.52.21.5$all
-||115.54.192.172$all
-||115.54.222.126$all
+||115.52.22.162$all
+||115.54.160.25$all
+||115.54.212.227$all
 ||115.54.236.22$all
+||115.54.240.173$all
 ||115.54.241.122$all
+||115.54.70.108$all
 ||115.54.73.162$all
-||115.55.105.163$all
+||115.54.73.50$all
 ||115.55.144.146$all
 ||115.55.144.222$all
 ||115.55.144.42$all
@@ -593,58 +606,70 @@
 ||115.55.149.30$all
 ||115.55.178.67$all
 ||115.55.198.209$all
+||115.55.211.41$all
 ||115.55.211.86$all
+||115.55.3.36$all
 ||115.55.42.200$all
 ||115.55.53.51$all
 ||115.56.134.116$all
 ||115.56.134.220$all
+||115.56.136.144$all
 ||115.56.139.122$all
 ||115.56.142.251$all
 ||115.56.143.241$all
 ||115.56.148.22$all
+||115.56.154.147$all
 ||115.56.155.72$all
 ||115.56.156.185$all
+||115.56.156.54$all
 ||115.56.162.173$all
-||115.56.178.107$all
+||115.56.177.202$all
 ||115.56.188.24$all
 ||115.56.31.54$all
-||115.56.67.22$all
 ||115.56.86.251$all
 ||115.56.87.42$all
 ||115.56.98.205$all
 ||115.58.111.222$all
 ||115.58.119.171$all
+||115.58.132.199$all
 ||115.58.134.143$all
 ||115.58.141.177$all
+||115.58.167.90$all
+||115.58.20.186$all
 ||115.58.83.233$all
 ||115.58.88.163$all
 ||115.58.93.151$all
 ||115.59.197.123$all
 ||115.59.198.165$all
+||115.59.198.200$all
 ||115.59.210.228$all
+||115.59.215.96$all
 ||115.59.235.229$all
 ||115.59.253.202$all
-||115.59.26.134$all
 ||115.59.63.220$all
+||115.59.95.247$all
+||115.60.201.176$all
 ||115.61.107.203$all
-||115.61.111.142$all
+||115.61.118.201$all
 ||115.61.119.187$all
 ||115.61.119.198$all
 ||115.61.119.77$all
 ||115.61.125.184$all
-||115.61.137.47$all
 ||115.61.180.193$all
 ||115.61.182.138$all
 ||115.61.185.246$all
 ||115.61.97.190$all
+||115.61.97.55$all
+||115.62.152.207$all
 ||115.62.26.39$all
-||115.62.60.206$all
 ||115.63.135.206$all
+||115.63.140.242$all
 ||115.63.4.244$all
 ||115.63.56.176$all
 ||115.73.3.11$all
 ||115.74.217.2$all
 ||115.75.217.79$all
+||115.78.133.146$all
 ||115.92.174.231$all
 ||116.124.219.2$all
 ||116.127.207.224$all
@@ -655,18 +680,20 @@
 ||116.211.100.26$all
 ||116.212.142.215$all
 ||116.24.153.40$all
-||116.72.201.93$all
-||116.75.192.140$all
+||116.72.202.126$all
+||116.72.202.87$all
+||116.72.203.143$all
+||116.74.84.65$all
+||116.75.194.14$all
 ||116.76.114.71$all
 ||116.88.65.131$all
 ||117.11.234.35$all
-||117.11.95.179$all
 ||117.15.201.1$all
-||117.192.224.243$all
-||117.192.225.29$all
-||117.192.226.96$all
-||117.194.162.116$all
-||117.194.163.237$all
+||117.156.69.22$all
+||117.194.160.84$all
+||117.194.161.143$all
+||117.194.162.121$all
+||117.196.48.216$all
 ||117.20.204.138$all
 ||117.20.204.5$all
 ||117.20.210.52$all
@@ -676,39 +703,25 @@
 ||117.200.76.54$all
 ||117.200.76.60$all
 ||117.201.128.152$all
-||117.202.66.23$all
-||117.202.67.181$all
-||117.202.67.218$all
-||117.202.68.75$all
-||117.213.41.18$all
-||117.213.42.147$all
-||117.213.42.226$all
-||117.213.44.184$all
-||117.213.45.119$all
-||117.213.45.150$all
-||117.213.45.204$all
-||117.213.46.124$all
-||117.213.46.243$all
-||117.215.213.155$all
-||117.215.215.188$all
-||117.222.160.86$all
-||117.222.165.221$all
-||117.222.166.6$all
-||117.222.169.193$all
-||117.222.170.122$all
-||117.222.175.220$all
+||117.202.66.177$all
+||117.202.68.94$all
+||117.208.133.121$all
+||117.222.161.68$all
+||117.222.162.144$all
+||117.222.163.150$all
+||117.222.165.31$all
+||117.222.170.189$all
+||117.222.171.68$all
+||117.222.172.97$all
 ||117.241.66.200$all
 ||117.241.67.68$all
-||117.242.211.217$all
-||117.247.204.33$all
-||117.247.206.195$all
-||117.248.60.21$all
-||117.251.56.191$all
-||117.251.56.244$all
-||117.251.56.64$all
-||117.251.56.73$all
+||117.242.210.69$all
+||117.242.211.111$all
+||117.242.211.98$all
+||117.251.56.135$all
+||117.251.59.242$all
 ||117.251.60.161$all
-||117.251.63.211$all
+||117.251.60.69$all
 ||117.26.110.17$all
 ||117.26.235.164$all
 ||117.27.10.73$all
@@ -716,8 +729,11 @@
 ||117.63.195.140$all
 ||117.63.252.82$all
 ||117.63.53.15$all
+||117.63.56.81$all
+||117.86.105.110$all
 ||117.87.170.32$all
 ||117.90.78.120$all
+||117.91.240.50$all
 ||117.93.115.242$all
 ||117.93.79.40$all
 ||118.176.104.35$all
@@ -734,19 +750,20 @@
 ||118.232.88.146$all
 ||118.232.96.150$all
 ||118.232.96.6$all
-||118.233.165.213$all
 ||118.233.221.162$all
+||118.233.63.194$all
 ||118.233.65.93$all
 ||118.249.136.112$all
 ||118.250.51.192$all
-||118.38.189.207$all
 ||118.42.125.246$all
 ||118.43.180.33$all
 ||118.68.245.69$all
+||118.75.120.136$all
+||118.75.240.239$all
 ||118.75.50.253$all
 ||118.75.70.70$all
 ||118.79.125.92$all
-||118.79.143.45$all
+||118.79.164.102$all
 ||118.79.218.157$all
 ||118.79.50.203$all
 ||118.79.58.82$all
@@ -762,7 +779,7 @@
 ||119.112.22.58$all
 ||119.118.251.73$all
 ||119.119.52.202$all
-||119.123.219.137$all
+||119.123.175.133$all
 ||119.14.143.145$all
 ||119.147.213.57$all
 ||119.162.109.111$all
@@ -774,6 +791,7 @@
 ||119.165.107.93$all
 ||119.165.163.220$all
 ||119.165.174.63$all
+||119.165.208.73$all
 ||119.165.241.222$all
 ||119.165.27.77$all
 ||119.165.68.145$all
@@ -793,6 +811,7 @@
 ||119.179.170.212$all
 ||119.179.27.213$all
 ||119.179.43.1$all
+||119.179.44.141$all
 ||119.179.75.8$all
 ||119.18.38.144$all
 ||119.180.101.151$all
@@ -803,6 +822,7 @@
 ||119.180.231.79$all
 ||119.180.33.161$all
 ||119.180.80.69$all
+||119.180.9.35$all
 ||119.180.94.80$all
 ||119.181.124.203$all
 ||119.181.43.18$all
@@ -829,6 +849,7 @@
 ||119.191.215.221$all
 ||119.191.253.206$all
 ||119.204.30.144$all
+||119.250.129.231$all
 ||119.250.218.177$all
 ||119.251.105.221$all
 ||119.251.12.85$all
@@ -836,12 +857,12 @@
 ||119.56.131.155$all
 ||119.56.143.46$all
 ||119.56.143.71$all
+||119.56.144.75$all
 ||119.56.148.115$all
 ||119.56.155.57$all
+||119.56.166.36$all
 ||119.56.172.28$all
-||119.56.175.41$all
 ||119.56.206.43$all
-||119.56.220.170$all
 ||119.96.37.55$all
 ||119.96.70.116$all
 ||119.99.188.187$all
@@ -856,6 +877,7 @@
 ||12.207.39.227$all
 ||120.12.144.232$all
 ||120.12.153.54$all
+||120.12.212.5$all
 ||120.142.222.22$all
 ||120.150.213.110$all
 ||120.151.248.134$all
@@ -900,20 +922,19 @@
 ||120.43.54.218$all
 ||120.50.66.60$all
 ||120.50.93.115$all
-||120.59.245.212$all
 ||120.6.141.142$all
 ||120.6.8.11$all
 ||120.69.113.208$all
 ||120.69.131.51$all
 ||120.7.90.104$all
 ||120.85.165.141$all
-||120.85.169.138$all
+||120.85.173.137$all
 ||120.85.174.165$all
 ||120.85.174.175$all
-||120.85.186.112$all
+||120.85.174.39$all
+||120.85.199.222$all
+||120.85.212.45$all
 ||120.85.237.129$all
-||120.85.239.77$all
-||120.86.84.72$all
 ||120.9.32.51$all
 ||121.100.114.164$all
 ||121.100.96.8$all
@@ -941,6 +962,7 @@
 ||121.24.116.173$all
 ||121.25.101.86$all
 ||121.254.43.215$all
+||121.34.150.32$all
 ||121.61.101.93$all
 ||121.61.102.1$all
 ||121.61.107.189$all
@@ -950,6 +972,8 @@
 ||122.100.150.204$all
 ||122.137.52.122$all
 ||122.160.147.53$all
+||122.188.86.225$all
+||122.190.19.204$all
 ||122.192.190.203$all
 ||122.194.191.57$all
 ||122.199.72.23$all
@@ -957,19 +981,18 @@
 ||122.199.83.86$all
 ||122.202.37.85$all
 ||122.202.41.23$all
-||122.252.241.170$all
 ||122.252.250.22$all
 ||122.254.183.207$all
 ||122.254.29.37$all
 ||122.254.33.214$all
 ||123.0.240.58$all
 ||123.10.128.46$all
+||123.10.131.225$all
 ||123.10.140.225$all
-||123.10.210.87$all
+||123.10.209.95$all
 ||123.10.36.124$all
 ||123.10.41.32$all
-||123.11.1.232$all
-||123.11.74.72$all
+||123.10.83.136$all
 ||123.110.124.238$all
 ||123.110.124.244$all
 ||123.110.170.237$all
@@ -977,13 +1000,15 @@
 ||123.110.19.248$all
 ||123.110.200.98$all
 ||123.110.238.188$all
-||123.12.238.89$all
+||123.12.229.243$all
 ||123.12.3.58$all
+||123.12.36.185$all
 ||123.128.128.205$all
 ||123.128.133.91$all
 ||123.129.84.36$all
 ||123.129.88.123$all
-||123.130.169.45$all
+||123.13.101.56$all
+||123.13.30.75$all
 ||123.130.208.52$all
 ||123.130.23.110$all
 ||123.130.37.182$all
@@ -1000,9 +1025,9 @@
 ||123.135.71.150$all
 ||123.14.101.111$all
 ||123.14.150.79$all
+||123.14.205.23$all
 ||123.14.217.22$all
 ||123.14.235.65$all
-||123.14.248.97$all
 ||123.14.76.38$all
 ||123.14.88.195$all
 ||123.152.42.4$all
@@ -1013,6 +1038,7 @@
 ||123.159.137.101$all
 ||123.159.31.110$all
 ||123.159.8.100$all
+||123.183.123.41$all
 ||123.191.173.88$all
 ||123.192.101.163$all
 ||123.192.194.233$all
@@ -1033,7 +1059,6 @@
 ||123.234.116.110$all
 ||123.234.184.57$all
 ||123.234.246.103$all
-||123.235.107.135$all
 ||123.240.103.89$all
 ||123.240.181.57$all
 ||123.240.79.61$all
@@ -1041,39 +1066,42 @@
 ||123.241.184.124$all
 ||123.27.44.219$all
 ||123.28.217.23$all
+||123.4.180.137$all
+||123.4.185.137$all
 ||123.4.193.171$all
 ||123.4.44.217$all
 ||123.4.85.76$all
-||123.4.88.225$all
 ||123.4.92.3$all
 ||123.5.123.162$all
-||123.5.13.128$all
 ||123.5.178.213$all
+||123.5.188.181$all
+||123.5.22.220$all
 ||123.5.27.66$all
-||123.8.253.37$all
+||123.8.183.194$all
 ||123.8.254.172$all
 ||123.8.40.20$all
 ||123.8.41.63$all
 ||123.8.62.165$all
-||123.9.110.119$all
 ||123.9.243.93$all
-||123.9.245.134$all
 ||124.105.105.222$all
 ||124.129.162.169$all
 ||124.129.221.150$all
 ||124.129.76.230$all
 ||124.130.167.20$all
+||124.130.40.31$all
 ||124.131.104.82$all
 ||124.131.130.95$all
 ||124.131.136.75$all
 ||124.131.151.135$all
 ||124.131.21.39$all
+||124.131.26.243$all
 ||124.131.26.78$all
 ||124.131.54.33$all
 ||124.131.70.49$all
 ||124.131.72.208$all
 ||124.132.110.150$all
 ||124.135.34.49$all
+||124.153.136.175$all
 ||124.153.236.6$all
 ||124.160.126.238$all
 ||124.163.138.104$all
@@ -1093,9 +1121,11 @@
 ||124.6.0.4$all
 ||124.7.254.85$all
 ||124.80.46.73$all
-||124.92.132.207$all
 ||124.92.148.218$all
+||124.95.17.41$all
 ||125.106.125.119$all
+||125.106.252.96$all
+||125.126.69.95$all
 ||125.128.28.161$all
 ||125.142.93.34$all
 ||125.168.10.234$all
@@ -1103,79 +1133,82 @@
 ||125.40.1.127$all
 ||125.40.107.252$all
 ||125.40.113.66$all
+||125.40.136.25$all
 ||125.40.150.131$all
 ||125.40.16.231$all
 ||125.40.163.112$all
+||125.40.237.130$all
 ||125.40.65.120$all
 ||125.40.73.6$all
 ||125.40.74.153$all
 ||125.40.75.22$all
-||125.41.0.209$all
 ||125.41.106.180$all
 ||125.41.138.208$all
 ||125.41.189.235$all
 ||125.41.191.183$all
 ||125.41.196.151$all
-||125.41.2.58$all
+||125.41.200.189$all
 ||125.41.204.126$all
 ||125.41.205.197$all
-||125.41.245.135$all
 ||125.41.6.192$all
 ||125.41.7.204$all
 ||125.41.80.153$all
 ||125.41.86.72$all
 ||125.41.96.53$all
-||125.41.97.22$all
 ||125.42.124.114$all
+||125.42.125.103$all
 ||125.42.234.197$all
 ||125.42.96.17$all
-||125.42.96.209$all
 ||125.42.98.24$all
+||125.43.105.157$all
 ||125.43.106.162$all
 ||125.43.112.123$all
 ||125.43.126.184$all
+||125.43.130.232$all
 ||125.43.136.23$all
 ||125.43.177.48$all
+||125.43.21.157$all
 ||125.43.26.36$all
 ||125.43.34.132$all
-||125.43.5.247$all
 ||125.43.53.9$all
-||125.43.93.164$all
+||125.43.73.19$all
 ||125.44.168.169$all
+||125.44.212.107$all
 ||125.44.213.216$all
-||125.44.248.76$all
-||125.44.29.38$all
+||125.44.230.191$all
 ||125.44.30.143$all
-||125.44.42.12$all
-||125.44.61.172$all
+||125.44.31.79$all
 ||125.44.8.227$all
+||125.45.57.249$all
 ||125.45.65.166$all
+||125.45.90.158$all
+||125.46.138.117$all
 ||125.46.184.28$all
-||125.46.203.85$all
 ||125.46.206.206$all
 ||125.47.193.134$all
 ||125.47.200.11$all
-||125.47.207.239$all
 ||125.47.209.166$all
 ||125.47.244.201$all
-||125.47.29.173$all
+||125.47.252.106$all
+||125.47.254.44$all
+||125.47.28.217$all
 ||125.47.36.171$all
 ||125.47.45.218$all
 ||125.47.71.30$all
 ||125.47.90.82$all
 ||125.47.91.51$all
+||125.99.220.202$all
 ||128.116.133.92$all
 ||130.255.159.133$all
 ||134.195.139.4$all
-||134.236.252.28$all
 ||138.99.204.224$all
 ||139.159.226.180$all
 ||139.170.173.198$all
 ||139.170.174.162$all
+||139.170.228.166$all
 ||139.216.102.151$all
 ||139.227.46.137$all
 ||14.102.17.222$all
-||14.102.97.204$all
 ||14.136.80.242$all
 ||14.138.109.129$all
 ||14.138.109.26$all
@@ -1191,16 +1224,21 @@
 ||14.46.25.17$all
 ||14.46.98.241$all
 ||14.55.29.2$all
+||140.237.30.113$all
+||140.237.5.43$all
 ||142.11.216.5$all
 ||142.177.56.127$all
 ||146.71.79.230$all
 ||148.69.108.177$all
-||149.255.15.121$all
+||149.20.176.179$all
 ||149.255.15.180$all
 ||149.255.15.182$all
+||149.255.15.191$all
+||149.255.15.235$all
 ||149.255.15.87$all
-||149.3.36.210$all
+||149.3.85.55$all
 ||150.116.207.99$all
+||150.129.105.61$all
 ||151.177.163.87$all
 ||151.33.230.191$all
 ||151.51.158.195$all
@@ -1213,10 +1251,12 @@
 ||153.34.135.92$all
 ||153.34.23.76$all
 ||153.34.29.28$all
-||153.34.52.74$all
+||153.35.111.46$all
 ||153.35.27.49$all
 ||153.36.126.35$all
 ||154.126.178.16$all
+||154.91.1.27$all
+||157.122.105.142$all
 ||158.101.165.14$all
 ||158.174.213.128$all
 ||158.51.125.115$all
@@ -1226,12 +1266,16 @@
 ||162.191.249.195$all
 ||162.194.28.60$all
 ||162.209.98.174$all
-||162.212.203.250$all
+||163.125.183.111$all
 ||163.125.195.108$all
-||163.125.200.233$all
+||163.125.200.72$all
 ||163.125.200.73$all
-||163.125.203.85$all
-||163.125.223.16$all
+||163.125.202.174$all
+||163.125.202.74$all
+||163.125.203.179$all
+||163.125.207.125$all
+||163.125.250.202$all
+||163.125.68.29$all
 ||163.53.206.228$all
 ||165.90.16.5$all
 ||170.78.39.3$all
@@ -1245,30 +1289,31 @@
 ||171.120.125.147$all
 ||171.121.6.162$all
 ||171.123.189.154$all
-||171.125.114.254$all
 ||171.125.30.233$all
 ||171.125.30.93$all
 ||171.125.64.223$all
+||171.125.65.22$all
 ||171.126.109.145$all
 ||171.34.112.42$all
+||171.34.114.181$all
 ||171.34.179.178$all
 ||171.35.161.234$all
 ||171.35.162.156$all
 ||171.35.173.151$all
 ||171.35.174.198$all
+||171.36.42.154$all
 ||171.38.219.189$all
 ||171.44.254.4$all
 ||172.105.36.168$all
 ||172.114.244.127$all
 ||172.245.5.185$all
-||172.93.176.137$all
+||172.245.5.190$all
 ||173.167.85.89$all
 ||173.169.46.85$all
 ||173.19.58.108$all
 ||173.220.222.227$all
 ||173.233.85.171$all
 ||173.235.209.70$all
-||173.237.254.251$all
 ||173.25.113.8$all
 ||173.52.95.134$all
 ||173.52.97.25$all
@@ -1281,12 +1326,11 @@
 ||174.84.148.29$all
 ||174.96.30.156$all
 ||175.10.147.167$all
-||175.10.48.233$all
-||175.11.212.203$all
-||175.11.96.155$all
+||175.11.193.66$all
 ||175.115.241.87$all
 ||175.117.66.74$all
 ||175.145.200.216$all
+||175.146.17.227$all
 ||175.153.144.2$all
 ||175.162.69.13$all
 ||175.169.172.216$all
@@ -1303,17 +1347,20 @@
 ||176.111.174.63$all
 ||176.111.174.66$all
 ||176.111.174.67$all
+||176.113.161.101$all
 ||176.113.161.104$all
 ||176.113.161.113$all
 ||176.113.161.120$all
 ||176.113.161.128$all
 ||176.113.161.138$all
 ||176.113.161.59$all
+||176.113.161.60$all
 ||176.113.161.65$all
 ||176.113.161.66$all
 ||176.113.161.84$all
 ||176.113.161.88$all
 ||176.113.161.91$all
+||176.113.161.93$all
 ||176.113.174.139$all
 ||176.12.117.70$all
 ||176.123.4.115$all
@@ -1321,6 +1368,7 @@
 ||176.123.7.127$all
 ||176.123.9.243$all
 ||176.124.7.225$all
+||176.221.251.147$all
 ||176.240.40.142$all
 ||176.240.84.106$all
 ||176.32.151.180$all
@@ -1329,90 +1377,103 @@
 ||177.54.82.154$all
 ||177.86.235.143$all
 ||178.124.182.187$all
-||178.136.195.90$all
-||178.141.210.251$all
+||178.134.185.112$all
+||178.141.161.129$all
 ||178.141.25.82$all
 ||178.141.57.166$all
 ||178.150.174.65$all
 ||178.165.122.141$all
 ||178.175.0.140$all
-||178.175.1.109$all
+||178.175.0.232$all
 ||178.175.1.247$all
 ||178.175.1.250$all
+||178.175.1.252$all
 ||178.175.1.80$all
 ||178.175.10.108$all
 ||178.175.10.156$all
 ||178.175.10.26$all
+||178.175.10.34$all
+||178.175.10.42$all
 ||178.175.100.129$all
 ||178.175.100.180$all
 ||178.175.100.190$all
 ||178.175.100.223$all
 ||178.175.100.4$all
+||178.175.100.87$all
 ||178.175.101.110$all
+||178.175.101.207$all
 ||178.175.102.134$all
 ||178.175.102.136$all
 ||178.175.102.152$all
+||178.175.102.221$all
 ||178.175.102.228$all
-||178.175.102.232$all
 ||178.175.102.245$all
-||178.175.102.81$all
 ||178.175.103.172$all
+||178.175.103.195$all
 ||178.175.103.91$all
+||178.175.104.106$all
+||178.175.104.110$all
 ||178.175.104.120$all
 ||178.175.104.128$all
 ||178.175.104.153$all
+||178.175.104.155$all
 ||178.175.104.16$all
-||178.175.104.161$all
 ||178.175.104.169$all
 ||178.175.104.183$all
 ||178.175.104.206$all
-||178.175.104.220$all
 ||178.175.104.49$all
+||178.175.104.64$all
 ||178.175.104.80$all
 ||178.175.105.111$all
+||178.175.105.125$all
 ||178.175.105.146$all
+||178.175.105.177$all
 ||178.175.105.217$all
 ||178.175.105.245$all
 ||178.175.105.247$all
 ||178.175.105.27$all
+||178.175.105.28$all
 ||178.175.105.49$all
-||178.175.105.85$all
+||178.175.105.94$all
 ||178.175.106.118$all
 ||178.175.106.18$all
 ||178.175.106.193$all
 ||178.175.106.219$all
+||178.175.106.253$all
 ||178.175.106.37$all
-||178.175.106.63$all
 ||178.175.106.77$all
 ||178.175.106.87$all
 ||178.175.107.0$all
 ||178.175.107.133$all
+||178.175.107.245$all
 ||178.175.107.83$all
+||178.175.107.86$all
 ||178.175.108.116$all
 ||178.175.108.145$all
 ||178.175.108.148$all
-||178.175.108.16$all
 ||178.175.108.179$all
-||178.175.108.18$all
+||178.175.108.232$all
 ||178.175.108.67$all
 ||178.175.108.87$all
+||178.175.108.94$all
 ||178.175.109.1$all
+||178.175.109.127$all
+||178.175.109.193$all
+||178.175.109.37$all
 ||178.175.109.77$all
+||178.175.109.78$all
 ||178.175.11.176$all
 ||178.175.11.184$all
 ||178.175.11.204$all
 ||178.175.11.57$all
 ||178.175.110.150$all
 ||178.175.110.155$all
-||178.175.110.173$all
 ||178.175.110.214$all
 ||178.175.110.221$all
-||178.175.110.43$all
 ||178.175.110.90$all
 ||178.175.110.97$all
 ||178.175.111.105$all
 ||178.175.111.157$all
-||178.175.111.16$all
 ||178.175.111.190$all
 ||178.175.111.206$all
 ||178.175.111.36$all
@@ -1420,20 +1481,20 @@
 ||178.175.112.159$all
 ||178.175.112.26$all
 ||178.175.112.4$all
-||178.175.113.130$all
-||178.175.113.150$all
+||178.175.112.79$all
+||178.175.113.0$all
 ||178.175.113.171$all
 ||178.175.113.174$all
 ||178.175.113.35$all
+||178.175.113.64$all
 ||178.175.113.85$all
 ||178.175.114.107$all
-||178.175.114.211$all
 ||178.175.114.215$all
 ||178.175.114.234$all
 ||178.175.114.238$all
 ||178.175.114.241$all
+||178.175.114.247$all
 ||178.175.114.254$all
-||178.175.114.27$all
 ||178.175.114.5$all
 ||178.175.114.55$all
 ||178.175.114.63$all
@@ -1441,14 +1502,19 @@
 ||178.175.114.90$all
 ||178.175.114.99$all
 ||178.175.115.1$all
+||178.175.115.12$all
 ||178.175.115.13$all
 ||178.175.115.142$all
 ||178.175.115.143$all
 ||178.175.115.19$all
+||178.175.115.206$all
+||178.175.115.208$all
 ||178.175.115.221$all
-||178.175.115.222$all
 ||178.175.115.242$all
 ||178.175.115.35$all
+||178.175.115.40$all
+||178.175.116.15$all
+||178.175.116.236$all
 ||178.175.116.48$all
 ||178.175.116.64$all
 ||178.175.116.87$all
@@ -1456,123 +1522,124 @@
 ||178.175.117.32$all
 ||178.175.117.51$all
 ||178.175.117.63$all
-||178.175.117.90$all
+||178.175.117.84$all
 ||178.175.118.112$all
+||178.175.118.139$all
 ||178.175.118.192$all
 ||178.175.118.225$all
-||178.175.118.34$all
 ||178.175.118.60$all
 ||178.175.119.205$all
 ||178.175.119.209$all
+||178.175.119.26$all
 ||178.175.119.86$all
 ||178.175.119.88$all
-||178.175.12.179$all
+||178.175.12.114$all
 ||178.175.12.252$all
 ||178.175.12.53$all
 ||178.175.12.97$all
 ||178.175.120.133$all
 ||178.175.120.184$all
+||178.175.120.196$all
 ||178.175.120.203$all
 ||178.175.120.251$all
 ||178.175.121.123$all
 ||178.175.121.155$all
 ||178.175.121.55$all
 ||178.175.121.62$all
+||178.175.121.63$all
 ||178.175.121.68$all
 ||178.175.121.99$all
-||178.175.122.144$all
 ||178.175.122.172$all
 ||178.175.122.245$all
+||178.175.122.26$all
 ||178.175.122.28$all
 ||178.175.123.113$all
 ||178.175.123.2$all
 ||178.175.123.20$all
-||178.175.123.223$all
+||178.175.123.30$all
 ||178.175.123.56$all
 ||178.175.123.60$all
 ||178.175.124.109$all
 ||178.175.124.122$all
 ||178.175.124.131$all
 ||178.175.124.141$all
-||178.175.124.157$all
-||178.175.124.175$all
 ||178.175.124.211$all
-||178.175.124.233$all
 ||178.175.124.4$all
 ||178.175.124.79$all
 ||178.175.124.89$all
-||178.175.124.9$all
 ||178.175.125.118$all
 ||178.175.125.14$all
-||178.175.125.143$all
 ||178.175.125.153$all
 ||178.175.125.156$all
 ||178.175.125.174$all
 ||178.175.125.219$all
 ||178.175.125.39$all
-||178.175.125.54$all
-||178.175.126.101$all
+||178.175.126.124$all
 ||178.175.126.131$all
 ||178.175.126.141$all
 ||178.175.126.167$all
 ||178.175.126.220$all
 ||178.175.126.222$all
 ||178.175.126.237$all
-||178.175.126.80$all
 ||178.175.126.83$all
+||178.175.127.10$all
 ||178.175.127.109$all
 ||178.175.127.116$all
+||178.175.127.129$all
 ||178.175.127.142$all
 ||178.175.127.15$all
 ||178.175.127.182$all
-||178.175.127.212$all
 ||178.175.127.230$all
 ||178.175.127.231$all
 ||178.175.127.236$all
+||178.175.127.238$all
 ||178.175.127.63$all
 ||178.175.127.75$all
+||178.175.13.237$all
 ||178.175.14.106$all
 ||178.175.14.185$all
 ||178.175.14.246$all
-||178.175.14.28$all
 ||178.175.14.60$all
 ||178.175.15.17$all
 ||178.175.15.217$all
+||178.175.15.232$all
+||178.175.15.246$all
 ||178.175.15.252$all
 ||178.175.15.35$all
+||178.175.15.44$all
 ||178.175.15.45$all
 ||178.175.15.85$all
 ||178.175.16.1$all
 ||178.175.16.108$all
-||178.175.16.121$all
+||178.175.16.114$all
 ||178.175.16.17$all
 ||178.175.16.179$all
+||178.175.16.193$all
 ||178.175.16.208$all
+||178.175.16.73$all
 ||178.175.16.97$all
 ||178.175.17.176$all
 ||178.175.17.245$all
 ||178.175.18.238$all
-||178.175.18.6$all
+||178.175.18.27$all
 ||178.175.18.93$all
 ||178.175.19.144$all
 ||178.175.19.150$all
 ||178.175.19.163$all
 ||178.175.19.174$all
+||178.175.19.229$all
 ||178.175.19.242$all
 ||178.175.19.44$all
 ||178.175.19.47$all
 ||178.175.2.110$all
 ||178.175.2.237$all
-||178.175.2.245$all
 ||178.175.2.41$all
 ||178.175.2.5$all
-||178.175.2.80$all
 ||178.175.20.117$all
 ||178.175.20.145$all
 ||178.175.20.170$all
 ||178.175.20.21$all
 ||178.175.20.225$all
-||178.175.20.227$all
 ||178.175.20.237$all
 ||178.175.20.238$all
 ||178.175.20.24$all
@@ -1581,19 +1648,21 @@
 ||178.175.21.149$all
 ||178.175.21.184$all
 ||178.175.21.238$all
-||178.175.21.58$all
 ||178.175.21.76$all
+||178.175.22.207$all
+||178.175.22.248$all
+||178.175.23.102$all
 ||178.175.23.156$all
 ||178.175.23.250$all
+||178.175.23.6$all
 ||178.175.24.13$all
 ||178.175.24.138$all
 ||178.175.24.15$all
 ||178.175.24.171$all
 ||178.175.24.227$all
-||178.175.24.239$all
-||178.175.24.251$all
+||178.175.24.230$all
 ||178.175.25.117$all
-||178.175.25.156$all
+||178.175.25.169$all
 ||178.175.25.244$all
 ||178.175.25.28$all
 ||178.175.25.56$all
@@ -1601,17 +1670,16 @@
 ||178.175.25.77$all
 ||178.175.26.134$all
 ||178.175.26.164$all
-||178.175.26.168$all
+||178.175.26.165$all
+||178.175.26.215$all
 ||178.175.26.219$all
 ||178.175.26.224$all
 ||178.175.26.246$all
-||178.175.26.38$all
-||178.175.26.69$all
+||178.175.26.34$all
 ||178.175.27.122$all
 ||178.175.27.138$all
 ||178.175.27.14$all
 ||178.175.27.167$all
-||178.175.27.169$all
 ||178.175.27.179$all
 ||178.175.27.199$all
 ||178.175.27.202$all
@@ -1619,69 +1687,66 @@
 ||178.175.27.225$all
 ||178.175.27.233$all
 ||178.175.27.239$all
-||178.175.27.241$all
+||178.175.27.32$all
+||178.175.27.48$all
 ||178.175.27.68$all
 ||178.175.27.69$all
 ||178.175.27.84$all
-||178.175.28.118$all
 ||178.175.28.124$all
-||178.175.28.128$all
-||178.175.28.167$all
 ||178.175.28.168$all
+||178.175.28.75$all
 ||178.175.28.8$all
+||178.175.29.12$all
 ||178.175.29.16$all
 ||178.175.29.173$all
 ||178.175.29.174$all
-||178.175.29.184$all
 ||178.175.29.207$all
 ||178.175.3.116$all
+||178.175.3.123$all
 ||178.175.3.130$all
 ||178.175.3.172$all
 ||178.175.3.190$all
+||178.175.3.194$all
 ||178.175.3.196$all
 ||178.175.3.214$all
 ||178.175.3.56$all
 ||178.175.3.81$all
 ||178.175.30.0$all
-||178.175.30.213$all
-||178.175.30.255$all
 ||178.175.30.77$all
 ||178.175.31.211$all
 ||178.175.31.232$all
 ||178.175.31.249$all
 ||178.175.31.251$all
 ||178.175.32.0$all
-||178.175.32.105$all
-||178.175.32.141$all
 ||178.175.32.172$all
-||178.175.32.196$all
 ||178.175.32.198$all
 ||178.175.32.208$all
 ||178.175.32.211$all
+||178.175.32.229$all
 ||178.175.32.243$all
-||178.175.32.32$all
+||178.175.32.255$all
 ||178.175.32.42$all
 ||178.175.32.89$all
 ||178.175.33.112$all
-||178.175.33.118$all
-||178.175.33.151$all
 ||178.175.33.155$all
 ||178.175.33.161$all
 ||178.175.33.162$all
 ||178.175.33.170$all
+||178.175.33.173$all
 ||178.175.33.174$all
 ||178.175.33.181$all
 ||178.175.33.2$all
+||178.175.33.205$all
 ||178.175.33.216$all
 ||178.175.33.234$all
 ||178.175.33.236$all
-||178.175.33.239$all
 ||178.175.33.26$all
+||178.175.34.219$all
+||178.175.34.5$all
+||178.175.34.56$all
 ||178.175.34.96$all
-||178.175.35.160$all
 ||178.175.35.21$all
 ||178.175.35.215$all
-||178.175.35.253$all
 ||178.175.35.38$all
 ||178.175.35.83$all
 ||178.175.35.89$all
@@ -1690,37 +1755,39 @@
 ||178.175.36.102$all
 ||178.175.36.112$all
 ||178.175.36.12$all
-||178.175.36.16$all
+||178.175.36.127$all
+||178.175.36.176$all
+||178.175.36.19$all
 ||178.175.36.199$all
-||178.175.36.200$all
 ||178.175.36.218$all
 ||178.175.36.22$all
 ||178.175.36.223$all
 ||178.175.36.33$all
-||178.175.36.88$all
+||178.175.36.78$all
 ||178.175.37.121$all
 ||178.175.37.135$all
 ||178.175.37.159$all
 ||178.175.37.6$all
 ||178.175.38.1$all
-||178.175.38.126$all
 ||178.175.38.132$all
-||178.175.38.148$all
 ||178.175.38.162$all
 ||178.175.38.165$all
 ||178.175.38.191$all
-||178.175.38.7$all
+||178.175.38.200$all
+||178.175.38.53$all
 ||178.175.38.98$all
 ||178.175.39.167$all
+||178.175.39.176$all
 ||178.175.39.245$all
+||178.175.39.61$all
+||178.175.4.219$all
 ||178.175.4.222$all
 ||178.175.4.42$all
-||178.175.4.58$all
 ||178.175.4.95$all
 ||178.175.40.1$all
+||178.175.40.145$all
 ||178.175.40.151$all
 ||178.175.40.166$all
-||178.175.40.191$all
 ||178.175.40.199$all
 ||178.175.40.226$all
 ||178.175.40.41$all
@@ -1728,10 +1795,10 @@
 ||178.175.40.67$all
 ||178.175.40.70$all
 ||178.175.40.71$all
-||178.175.40.73$all
 ||178.175.40.82$all
 ||178.175.41.165$all
 ||178.175.41.178$all
+||178.175.41.200$all
 ||178.175.41.203$all
 ||178.175.41.210$all
 ||178.175.41.216$all
@@ -1748,74 +1815,81 @@
 ||178.175.43.121$all
 ||178.175.43.125$all
 ||178.175.43.147$all
-||178.175.43.17$all
-||178.175.43.176$all
-||178.175.43.22$all
+||178.175.43.16$all
 ||178.175.43.33$all
-||178.175.43.44$all
-||178.175.43.47$all
+||178.175.43.34$all
+||178.175.44.0$all
 ||178.175.44.134$all
 ||178.175.44.143$all
 ||178.175.44.155$all
+||178.175.44.197$all
+||178.175.44.209$all
 ||178.175.44.218$all
+||178.175.44.219$all
 ||178.175.44.22$all
 ||178.175.44.241$all
+||178.175.44.70$all
 ||178.175.44.89$all
 ||178.175.44.90$all
+||178.175.44.95$all
 ||178.175.45.205$all
 ||178.175.45.221$all
 ||178.175.45.224$all
 ||178.175.45.230$all
+||178.175.46.119$all
+||178.175.46.132$all
+||178.175.46.151$all
 ||178.175.46.187$all
 ||178.175.47.141$all
 ||178.175.47.151$all
 ||178.175.48.121$all
 ||178.175.48.195$all
 ||178.175.48.243$all
+||178.175.48.76$all
+||178.175.49.100$all
 ||178.175.49.107$all
+||178.175.49.129$all
+||178.175.49.138$all
+||178.175.49.188$all
 ||178.175.49.247$all
 ||178.175.49.3$all
-||178.175.49.98$all
-||178.175.5.16$all
 ||178.175.5.247$all
 ||178.175.5.251$all
 ||178.175.5.70$all
 ||178.175.50.131$all
 ||178.175.50.177$all
+||178.175.50.196$all
 ||178.175.50.201$all
 ||178.175.50.218$all
 ||178.175.50.236$all
 ||178.175.50.237$all
-||178.175.50.47$all
-||178.175.51.150$all
 ||178.175.51.197$all
 ||178.175.51.202$all
 ||178.175.51.223$all
-||178.175.51.37$all
 ||178.175.51.66$all
 ||178.175.52.149$all
 ||178.175.52.161$all
-||178.175.52.79$all
 ||178.175.53.103$all
-||178.175.53.15$all
 ||178.175.53.186$all
 ||178.175.53.20$all
+||178.175.53.228$all
 ||178.175.53.4$all
 ||178.175.53.5$all
 ||178.175.53.79$all
 ||178.175.54.105$all
 ||178.175.54.205$all
 ||178.175.54.214$all
+||178.175.54.35$all
 ||178.175.54.72$all
 ||178.175.55.101$all
-||178.175.55.111$all
 ||178.175.55.163$all
-||178.175.55.204$all
+||178.175.55.170$all
 ||178.175.55.216$all
+||178.175.55.248$all
 ||178.175.55.29$all
 ||178.175.55.41$all
 ||178.175.55.77$all
-||178.175.55.86$all
+||178.175.55.85$all
 ||178.175.56.103$all
 ||178.175.56.196$all
 ||178.175.56.33$all
@@ -1824,10 +1898,8 @@
 ||178.175.57.141$all
 ||178.175.57.178$all
 ||178.175.57.192$all
-||178.175.57.7$all
-||178.175.58.117$all
 ||178.175.58.141$all
-||178.175.58.223$all
+||178.175.58.42$all
 ||178.175.59.142$all
 ||178.175.59.161$all
 ||178.175.59.229$all
@@ -1837,37 +1909,40 @@
 ||178.175.59.91$all
 ||178.175.6.134$all
 ||178.175.6.151$all
-||178.175.6.154$all
 ||178.175.6.162$all
-||178.175.6.171$all
-||178.175.60.154$all
+||178.175.6.72$all
 ||178.175.60.181$all
-||178.175.60.32$all
-||178.175.60.99$all
-||178.175.61.151$all
+||178.175.60.209$all
+||178.175.61.117$all
 ||178.175.61.156$all
 ||178.175.61.219$all
 ||178.175.61.229$all
 ||178.175.61.234$all
 ||178.175.61.253$all
 ||178.175.61.40$all
-||178.175.61.96$all
+||178.175.61.42$all
+||178.175.61.82$all
 ||178.175.62.110$all
 ||178.175.62.115$all
+||178.175.62.168$all
+||178.175.62.216$all
 ||178.175.62.43$all
-||178.175.63.185$all
+||178.175.62.44$all
+||178.175.62.70$all
+||178.175.63.194$all
 ||178.175.63.21$all
 ||178.175.63.218$all
 ||178.175.64.116$all
 ||178.175.64.12$all
 ||178.175.64.142$all
 ||178.175.64.158$all
+||178.175.64.219$all
 ||178.175.64.30$all
 ||178.175.64.66$all
 ||178.175.65.115$all
-||178.175.65.136$all
 ||178.175.65.171$all
 ||178.175.65.223$all
+||178.175.65.44$all
 ||178.175.65.70$all
 ||178.175.65.95$all
 ||178.175.65.96$all
@@ -1878,17 +1953,15 @@
 ||178.175.66.199$all
 ||178.175.66.211$all
 ||178.175.66.228$all
-||178.175.66.237$all
 ||178.175.66.93$all
 ||178.175.67.0$all
 ||178.175.67.184$all
-||178.175.67.185$all
 ||178.175.67.201$all
 ||178.175.67.254$all
-||178.175.67.31$all
+||178.175.67.83$all
+||178.175.68.1$all
 ||178.175.68.109$all
 ||178.175.68.126$all
-||178.175.68.166$all
 ||178.175.68.170$all
 ||178.175.68.227$all
 ||178.175.68.232$all
@@ -1897,12 +1970,14 @@
 ||178.175.68.66$all
 ||178.175.68.83$all
 ||178.175.69.111$all
+||178.175.69.112$all
 ||178.175.69.119$all
 ||178.175.69.128$all
 ||178.175.69.138$all
+||178.175.69.148$all
 ||178.175.69.149$all
+||178.175.69.173$all
 ||178.175.69.188$all
-||178.175.69.205$all
 ||178.175.69.77$all
 ||178.175.7.163$all
 ||178.175.70.119$all
@@ -1916,64 +1991,57 @@
 ||178.175.71.148$all
 ||178.175.71.153$all
 ||178.175.71.185$all
-||178.175.71.196$all
 ||178.175.71.22$all
+||178.175.71.240$all
 ||178.175.71.55$all
 ||178.175.71.63$all
+||178.175.71.64$all
 ||178.175.71.84$all
-||178.175.71.89$all
-||178.175.72.113$all
 ||178.175.72.13$all
 ||178.175.72.164$all
-||178.175.72.173$all
 ||178.175.72.196$all
 ||178.175.72.222$all
-||178.175.72.47$all
-||178.175.72.75$all
-||178.175.72.91$all
-||178.175.72.98$all
-||178.175.73.220$all
+||178.175.73.211$all
+||178.175.73.71$all
 ||178.175.74.182$all
 ||178.175.74.48$all
-||178.175.75.135$all
+||178.175.74.77$all
 ||178.175.75.181$all
 ||178.175.75.19$all
 ||178.175.75.209$all
-||178.175.75.249$all
-||178.175.75.54$all
 ||178.175.75.84$all
 ||178.175.75.87$all
 ||178.175.76.109$all
+||178.175.76.121$all
 ||178.175.76.167$all
 ||178.175.76.187$all
 ||178.175.76.214$all
 ||178.175.76.215$all
 ||178.175.76.217$all
 ||178.175.76.24$all
-||178.175.77.132$all
-||178.175.77.145$all
 ||178.175.77.46$all
 ||178.175.77.47$all
 ||178.175.77.95$all
 ||178.175.78.106$all
-||178.175.78.202$all
+||178.175.78.118$all
 ||178.175.78.233$all
 ||178.175.78.46$all
 ||178.175.78.76$all
+||178.175.78.97$all
 ||178.175.79.156$all
 ||178.175.79.227$all
-||178.175.79.24$all
 ||178.175.79.247$all
 ||178.175.79.45$all
 ||178.175.79.77$all
 ||178.175.8.100$all
-||178.175.8.165$all
 ||178.175.8.199$all
-||178.175.8.205$all
 ||178.175.8.217$all
 ||178.175.8.254$all
+||178.175.8.97$all
+||178.175.80.100$all
+||178.175.80.136$all
 ||178.175.80.237$all
-||178.175.80.244$all
+||178.175.80.41$all
 ||178.175.80.79$all
 ||178.175.80.86$all
 ||178.175.81.1$all
@@ -1982,43 +2050,47 @@
 ||178.175.81.152$all
 ||178.175.81.17$all
 ||178.175.81.194$all
-||178.175.81.216$all
 ||178.175.81.226$all
 ||178.175.81.244$all
+||178.175.81.32$all
 ||178.175.81.50$all
-||178.175.81.82$all
+||178.175.81.8$all
+||178.175.82.120$all
 ||178.175.82.61$all
 ||178.175.83.147$all
 ||178.175.83.196$all
+||178.175.83.247$all
 ||178.175.84.102$all
 ||178.175.84.109$all
 ||178.175.84.148$all
+||178.175.84.158$all
 ||178.175.84.159$all
 ||178.175.84.215$all
 ||178.175.84.42$all
 ||178.175.85.153$all
-||178.175.85.165$all
 ||178.175.85.183$all
 ||178.175.85.190$all
-||178.175.85.229$all
+||178.175.85.23$all
+||178.175.85.81$all
 ||178.175.85.87$all
-||178.175.85.9$all
 ||178.175.86.119$all
-||178.175.86.218$all
-||178.175.87.107$all
+||178.175.86.159$all
+||178.175.86.166$all
+||178.175.87.108$all
 ||178.175.87.123$all
 ||178.175.87.162$all
 ||178.175.87.253$all
-||178.175.87.90$all
 ||178.175.88.180$all
 ||178.175.88.181$all
-||178.175.88.78$all
 ||178.175.89.130$all
-||178.175.89.19$all
+||178.175.89.157$all
+||178.175.89.160$all
+||178.175.89.169$all
 ||178.175.89.37$all
-||178.175.89.51$all
-||178.175.9.178$all
+||178.175.9.106$all
+||178.175.9.139$all
 ||178.175.9.183$all
+||178.175.9.210$all
 ||178.175.9.215$all
 ||178.175.9.217$all
 ||178.175.9.245$all
@@ -2026,8 +2098,8 @@
 ||178.175.9.80$all
 ||178.175.9.84$all
 ||178.175.9.95$all
-||178.175.90.115$all
-||178.175.90.160$all
+||178.175.90.104$all
+||178.175.90.122$all
 ||178.175.90.178$all
 ||178.175.90.187$all
 ||178.175.90.21$all
@@ -2038,72 +2110,73 @@
 ||178.175.91.165$all
 ||178.175.91.172$all
 ||178.175.91.191$all
+||178.175.91.223$all
+||178.175.91.230$all
 ||178.175.91.253$all
-||178.175.91.47$all
 ||178.175.91.58$all
-||178.175.91.71$all
 ||178.175.91.96$all
 ||178.175.92.132$all
 ||178.175.92.186$all
 ||178.175.92.201$all
 ||178.175.92.208$all
 ||178.175.92.215$all
-||178.175.92.224$all
 ||178.175.92.231$all
 ||178.175.92.248$all
 ||178.175.92.45$all
 ||178.175.93.143$all
+||178.175.93.148$all
 ||178.175.93.150$all
 ||178.175.93.155$all
+||178.175.93.171$all
 ||178.175.93.198$all
+||178.175.93.224$all
 ||178.175.93.225$all
-||178.175.93.245$all
 ||178.175.93.31$all
+||178.175.93.34$all
 ||178.175.93.4$all
 ||178.175.93.45$all
 ||178.175.93.6$all
+||178.175.93.90$all
 ||178.175.94.116$all
-||178.175.94.184$all
 ||178.175.94.195$all
 ||178.175.94.238$all
+||178.175.94.248$all
 ||178.175.94.40$all
+||178.175.95.111$all
+||178.175.95.132$all
 ||178.175.95.147$all
 ||178.175.95.227$all
+||178.175.95.237$all
 ||178.175.95.244$all
-||178.175.95.249$all
 ||178.175.95.4$all
+||178.175.95.7$all
 ||178.175.95.89$all
-||178.175.95.99$all
 ||178.175.96.13$all
-||178.175.96.180$all
 ||178.175.96.195$all
-||178.175.96.24$all
 ||178.175.96.6$all
-||178.175.97.111$all
-||178.175.97.181$all
-||178.175.97.243$all
-||178.175.98.140$all
+||178.175.97.1$all
+||178.175.97.128$all
+||178.175.97.135$all
+||178.175.97.162$all
+||178.175.97.17$all
+||178.175.97.208$all
 ||178.175.98.228$all
 ||178.175.98.254$all
 ||178.175.98.50$all
 ||178.175.98.68$all
-||178.175.99.108$all
 ||178.175.99.123$all
 ||178.175.99.130$all
 ||178.175.99.22$all
 ||178.175.99.45$all
-||178.175.99.75$all
 ||178.175.99.8$all
 ||178.175.99.91$all
 ||178.19.183.14$all
-||178.205.101.33$all
 ||178.21.164.68$all
 ||178.217.8.194$all
 ||178.22.117.102$all
 ||178.222.252.130$all
 ||178.34.183.30$all
 ||178.92.246.246$all
-||178.93.112.88$all
 ||178.95.115.33$all
 ||179.159.58.134$all
 ||179.4.187.39$all
@@ -2116,7 +2189,6 @@
 ||180.116.203.220$all
 ||180.120.149.106$all
 ||180.122.13.227$all
-||180.125.155.69$all
 ||180.125.44.194$all
 ||180.157.66.204$all
 ||180.175.93.52$all
@@ -2137,7 +2209,6 @@
 ||181.112.218.238$all
 ||181.112.218.6$all
 ||181.143.60.163$all
-||181.174.63.114$all
 ||181.193.107.10$all
 ||181.199.170.210$all
 ||181.199.170.222$all
@@ -2154,79 +2225,86 @@
 ||182.112.52.131$all
 ||182.113.0.79$all
 ||182.113.222.154$all
+||182.113.233.129$all
 ||182.113.24.21$all
 ||182.114.106.207$all
-||182.114.122.228$all
 ||182.114.202.186$all
-||182.114.31.65$all
-||182.114.50.124$all
-||182.114.50.93$all
 ||182.114.64.27$all
-||182.114.70.177$all
-||182.114.93.165$all
-||182.114.94.255$all
 ||182.116.101.82$all
-||182.116.104.125$all
+||182.116.103.81$all
+||182.116.108.180$all
+||182.116.108.244$all
 ||182.116.110.31$all
-||182.116.44.70$all
-||182.116.49.171$all
+||182.116.119.129$all
 ||182.116.60.73$all
 ||182.116.61.252$all
 ||182.116.65.157$all
 ||182.116.65.245$all
 ||182.116.68.40$all
 ||182.116.69.37$all
-||182.116.69.47$all
 ||182.116.94.196$all
+||182.116.99.150$all
 ||182.116.99.17$all
 ||182.117.155.204$all
 ||182.117.25.120$all
 ||182.117.26.235$all
-||182.117.27.150$all
+||182.117.29.220$all
 ||182.117.29.74$all
 ||182.117.43.27$all
 ||182.118.140.117$all
 ||182.119.100.228$all
+||182.119.13.141$all
 ||182.119.14.252$all
 ||182.119.166.208$all
+||182.119.196.182$all
 ||182.119.211.69$all
 ||182.119.220.48$all
-||182.119.227.82$all
-||182.119.229.96$all
 ||182.119.236.21$all
+||182.119.49.17$all
 ||182.119.50.155$all
+||182.119.7.54$all
 ||182.119.81.33$all
 ||182.120.10.21$all
 ||182.120.16.22$all
 ||182.120.16.46$all
 ||182.120.37.251$all
 ||182.120.43.0$all
+||182.120.86.248$all
 ||182.121.101.100$all
 ||182.121.109.190$all
+||182.121.12.128$all
 ||182.121.125.170$all
 ||182.121.129.232$all
-||182.121.131.69$all
 ||182.121.133.200$all
-||182.121.135.160$all
+||182.121.133.46$all
+||182.121.134.73$all
 ||182.121.148.236$all
 ||182.121.157.221$all
-||182.121.200.151$all
+||182.121.165.217$all
+||182.121.205.118$all
 ||182.121.206.132$all
 ||182.121.219.239$all
 ||182.121.233.191$all
 ||182.121.249.26$all
-||182.121.68.100$all
+||182.121.50.111$all
+||182.121.78.29$all
 ||182.121.81.241$all
 ||182.121.92.113$all
 ||182.121.93.174$all
 ||182.121.98.21$all
 ||182.122.170.19$all
+||182.122.202.37$all
 ||182.122.220.203$all
 ||182.122.229.102$all
 ||182.122.245.2$all
+||182.122.246.187$all
 ||182.122.249.24$all
+||182.122.251.141$all
+||182.124.134.80$all
+||182.124.15.108$all
+||182.124.166.57$all
 ||182.124.188.23$all
-||182.124.53.111$all
+||182.124.95.139$all
 ||182.126.113.127$all
 ||182.126.117.41$all
 ||182.126.124.47$all
@@ -2236,22 +2314,27 @@
 ||182.126.139.66$all
 ||182.126.140.30$all
 ||182.126.178.187$all
+||182.126.181.121$all
+||182.126.241.7$all
+||182.126.52.233$all
 ||182.126.82.29$all
 ||182.126.83.79$all
-||182.126.87.58$all
+||182.126.87.207$all
 ||182.126.95.209$all
 ||182.127.155.157$all
 ||182.127.166.232$all
 ||182.127.210.107$all
 ||182.127.6.12$all
+||182.127.70.195$all
 ||182.127.78.61$all
-||182.127.87.72$all
 ||182.127.91.161$all
+||182.127.96.120$all
 ||182.172.36.164$all
-||182.207.219.164$all
 ||182.233.0.252$all
 ||182.235.252.31$all
 ||182.53.197.62$all
+||182.58.160.0$all
+||182.59.227.125$all
 ||182.88.235.221$all
 ||183.105.104.83$all
 ||183.105.225.154$all
@@ -2264,7 +2347,9 @@
 ||183.188.151.225$all
 ||183.188.180.116$all
 ||183.188.180.68$all
-||183.188.76.196$all
+||183.188.188.186$all
+||183.191.162.120$all
+||183.83.105.21$all
 ||183.83.14.35$all
 ||183.83.15.116$all
 ||183.83.23.138$all
@@ -2273,6 +2358,7 @@
 ||183.95.147.102$all
 ||183.97.22.14$all
 ||184.164.185.41$all
+||184.175.115.10$all
 ||184.74.149.230$all
 ||185.106.209.68$all
 ||185.107.3.8$all
@@ -2293,50 +2379,47 @@
 ||185.68.230.207$all
 ||185.81.157.186$all
 ||185.82.217.185$all
-||185.82.217.213$all
 ||185.82.219.160$all
 ||185.82.219.161$all
 ||185.82.219.219$all
-||185.82.219.80$all
 ||185.90.166.56$all
 ||186.151.144.85$all
 ||186.179.219.164$all
 ||186.179.243.112$all
 ||186.179.243.77$all
+||186.179.243.91$all
 ||186.179.253.150$all
 ||186.225.120.173$all
 ||186.227.148.107$all
+||186.232.44.86$all
 ||186.28.60.184$all
-||186.4.125.48$all
+||186.33.112.28$all
 ||186.73.188.132$all
 ||187.12.10.98$all
 ||187.188.124.229$all
 ||187.212.200.162$all
-||187.56.88.170$all
-||187.75.218.102$all
 ||188.10.21.14$all
 ||188.10.231.246$all
+||188.113.102.18$all
 ||188.113.81.17$all
-||188.127.224.149$all
 ||188.127.224.61$all
+||188.127.227.173$all
 ||188.127.227.99$all
-||188.127.230.133$all
 ||188.127.231.226$all
 ||188.127.231.55$all
 ||188.127.235.232$all
-||188.127.235.70$all
+||188.127.235.244$all
 ||188.127.235.71$all
+||188.127.237.152$all
 ||188.127.254.114$all
 ||188.13.179.87$all
 ||188.138.200.32$all
 ||188.152.41.141$all
 ||188.169.178.50$all
-||188.169.199.59$all
 ||188.169.30.30$all
 ||188.169.36.163$all
 ||188.242.167.159$all
 ||188.242.242.144$all
-||188.81.100.83$all
 ||188.83.202.25$all
 ||188.93.233.223$all
 ||189.222.157.241$all
@@ -2355,14 +2438,12 @@
 ||190.130.15.212$all
 ||190.130.20.14$all
 ||190.141.117.41$all
-||190.147.16.184$all
 ||190.159.240.9$all
 ||190.187.55.150$all
 ||190.210.214.130$all
 ||190.213.177.39$all
 ||190.213.226.63$all
 ||190.213.49.207$all
-||190.214.24.194$all
 ||190.216.140.123$all
 ||190.35.225.36$all
 ||190.65.206.162$all
@@ -2376,13 +2457,17 @@
 ||192.227.185.106$all
 ||192.227.209.27$all
 ||192.227.228.67$all
+||192.3.152.166$all
 ||192.3.73.205$all
 ||192.99.240.77$all
+||193.142.146.25$all
 ||193.228.135.144$all
 ||193.91.131.237$all
+||194.15.36.167$all
+||194.15.36.202$all
 ||194.152.35.139$all
 ||194.38.20.199$all
-||195.123.208.140$all
+||194.87.139.10$all
 ||195.123.213.154$all
 ||195.139.126.51$all
 ||195.228.231.218$all
@@ -2395,12 +2480,14 @@
 ||197.159.2.106$all
 ||197.50.27.115$all
 ||198.23.133.218$all
+||198.23.207.121$all
+||198.23.213.57$all
 ||198.23.251.105$all
 ||198.46.201.76$all
 ||198.46.202.7$all
 ||1am.co.nz$all
 ||2.229.89.119$all
-||2.37.203.65$all
+||2.249.161.188$all
 ||2.45.111.158$all
 ||2.45.4.24$all
 ||2.55.125.182$all
@@ -2419,27 +2506,26 @@
 ||201.184.163.170$all
 ||201.184.248.190$all
 ||201.187.102.73$all
-||201.193.17.190$all
+||201.200.254.86$all
 ||201.203.221.20$all
+||201.208.139.84$all
 ||201.215.84.97$all
 ||201.218.97.142$all
 ||202.107.233.41$all
 ||202.111.131.91$all
-||202.150.176.100$all
 ||202.164.150.115$all
 ||202.166.217.54$all
+||202.169.234.22$all
 ||202.169.234.47$all
 ||202.169.234.52$all
 ||202.169.234.56$all
-||202.178.113.26$all
+||202.169.234.9$all
 ||202.29.95.12$all
 ||202.4.124.58$all
 ||202.51.176.114$all
 ||202.51.191.174$all
 ||202.74.236.9$all
 ||203.109.201.243$all
-||203.130.69.205$all
-||203.170.105.156$all
 ||203.170.115.82$all
 ||203.189.156.107$all
 ||203.202.248.237$all
@@ -2454,28 +2540,25 @@
 ||203.82.36.34$all
 ||203.93.6.28$all
 ||204.195.116.171$all
-||205.185.115.74$all
 ||205.185.123.217$all
+||206.248.137.132$all
 ||206.47.41.166$all
 ||207.200.247.187$all
 ||207.44.28.234$all
 ||207.5.32.6$all
 ||208.163.58.18$all
-||209.133.223.130$all
 ||209.141.39.50$all
 ||209.141.40.190$all
-||209.141.40.31$all
 ||209.145.60.38$all
+||210.102.196.200$all
 ||210.124.149.19$all
 ||210.216.152.122$all
 ||210.216.153.142$all
-||210.57.234.131$all
 ||210.57.237.70$all
+||210.57.245.109$all
 ||210.68.242.114$all
 ||210.96.116.236$all
-||211.116.220.37$all
 ||211.172.11.169$all
-||211.179.243.103$all
 ||211.187.132.204$all
 ||211.187.75.220$all
 ||211.204.215.157$all
@@ -2487,8 +2570,8 @@
 ||211.238.83.238$all
 ||211.247.113.49$all
 ||211.247.5.96$all
-||211.32.122.110$all
 ||211.36.174.137$all
+||211.41.197.30$all
 ||211.47.102.51$all
 ||211.51.174.149$all
 ||212.122.86.105$all
@@ -2502,24 +2585,22 @@
 ||213.14.173.117$all
 ||213.149.182.113$all
 ||213.149.190.193$all
+||213.163.104.10$all
 ||213.163.104.12$all
 ||213.163.104.20$all
 ||213.163.104.99$all
 ||213.163.113.100$all
 ||213.163.113.199$all
 ||213.163.113.225$all
-||213.163.113.226$all
-||213.163.113.237$all
 ||213.163.113.51$all
 ||213.163.113.79$all
-||213.163.114.107$all
-||213.163.114.36$all
+||213.163.114.80$all
 ||213.163.115.11$all
 ||213.163.115.15$all
 ||213.163.115.26$all
+||213.163.115.33$all
 ||213.163.115.71$all
-||213.163.116.149$all
-||213.163.116.160$all
+||213.163.116.132$all
 ||213.163.116.164$all
 ||213.163.116.203$all
 ||213.163.116.249$all
@@ -2533,10 +2614,8 @@
 ||213.163.126.131$all
 ||213.163.126.243$all
 ||213.163.126.60$all
-||213.163.126.61$all
 ||213.163.126.7$all
-||213.163.126.96$all
-||213.163.127.178$all
+||213.163.126.71$all
 ||213.163.127.217$all
 ||213.163.127.46$all
 ||213.189.178.163$all
@@ -2544,8 +2623,6 @@
 ||213.249.156.189$all
 ||213.27.8.6$all
 ||213.80.44.17$all
-||213.87.87.173$all
-||213.92.254.214$all
 ||213.92.254.52$all
 ||213.92.255.36$all
 ||213.92.255.84$all
@@ -2557,10 +2634,9 @@
 ||216.36.12.98$all
 ||217.11.75.162$all
 ||217.127.133.214$all
-||218.104.175.64$all
+||218.103.180.199$all
 ||218.215.243.65$all
 ||218.238.246.3$all
-||218.255.226.166$all
 ||218.28.160.174$all
 ||218.35.207.119$all
 ||218.35.227.133$all
@@ -2569,38 +2645,45 @@
 ||218.48.135.50$all
 ||218.56.93.129$all
 ||218.57.53.55$all
-||218.58.3.119$all
-||218.58.3.38$all
 ||218.59.116.203$all
 ||218.72.198.15$all
-||218.72.248.42$all
 ||218.79.103.159$all
 ||219.154.104.209$all
 ||219.154.119.145$all
+||219.154.141.222$all
 ||219.154.182.197$all
 ||219.155.102.14$all
+||219.155.12.221$all
 ||219.155.14.17$all
+||219.155.170.22$all
+||219.155.208.188$all
 ||219.155.24.246$all
+||219.155.241.135$all
 ||219.155.26.37$all
-||219.155.28.41$all
 ||219.155.31.15$all
 ||219.155.31.67$all
+||219.155.37.97$all
 ||219.155.9.202$all
-||219.155.97.226$all
+||219.156.103.248$all
 ||219.156.21.73$all
-||219.157.139.165$all
+||219.156.23.29$all
+||219.156.60.224$all
+||219.156.9.32$all
 ||219.157.146.200$all
 ||219.157.150.91$all
 ||219.157.162.205$all
 ||219.157.17.8$all
-||219.157.177.232$all
 ||219.157.178.201$all
 ||219.157.183.29$all
 ||219.157.202.66$all
-||219.157.215.242$all
+||219.157.220.170$all
 ||219.157.221.133$all
+||219.157.223.245$all
+||219.157.244.33$all
 ||219.157.32.244$all
-||219.157.64.251$all
+||219.157.50.211$all
+||219.157.54.158$all
+||219.157.56.46$all
 ||219.241.6.180$all
 ||219.68.1.148$all
 ||219.68.1.84$all
@@ -2618,34 +2701,34 @@
 ||220.173.160.53$all
 ||220.200.22.163$all
 ||220.71.239.115$all
+||220.90.159.188$all
 ||221.0.16.221$all
 ||221.1.162.82$all
 ||221.124.78.15$all
 ||221.14.122.127$all
 ||221.14.182.157$all
 ||221.14.46.33$all
+||221.14.58.5$all
 ||221.14.58.84$all
-||221.15.124.188$all
+||221.15.147.220$all
 ||221.15.153.17$all
-||221.15.160.67$all
-||221.15.194.218$all
-||221.15.199.35$all
 ||221.15.218.173$all
 ||221.15.234.159$all
 ||221.15.234.175$all
+||221.15.237.107$all
 ||221.15.54.237$all
+||221.15.7.202$all
 ||221.157.191.178$all
 ||221.160.136.213$all
 ||221.160.177.104$all
 ||221.160.177.107$all
 ||221.160.177.224$all
 ||221.196.12.96$all
-||221.208.4.71$all
 ||221.214.130.147$all
-||221.214.146.73$all
 ||221.214.162.109$all
 ||221.214.224.184$all
 ||221.215.116.167$all
+||221.215.172.207$all
 ||221.215.184.31$all
 ||221.215.237.220$all
 ||221.215.239.162$all
@@ -2660,6 +2743,7 @@
 ||221.3.34.43$all
 ||221.3.43.223$all
 ||221.3.68.16$all
+||221.5.30.118$all
 ||222.108.17.64$all
 ||222.119.65.145$all
 ||222.132.125.138$all
@@ -2669,13 +2753,10 @@
 ||222.135.113.41$all
 ||222.135.219.29$all
 ||222.135.26.161$all
-||222.136.21.126$all
-||222.136.218.233$all
 ||222.136.231.197$all
 ||222.136.49.252$all
 ||222.137.101.251$all
 ||222.137.113.184$all
-||222.137.120.3$all
 ||222.137.121.127$all
 ||222.137.136.241$all
 ||222.137.137.5$all
@@ -2687,18 +2768,26 @@
 ||222.137.172.250$all
 ||222.137.175.242$all
 ||222.137.186.150$all
+||222.137.22.79$all
+||222.137.220.94$all
 ||222.137.221.128$all
+||222.137.49.4$all
 ||222.137.5.150$all
 ||222.137.72.146$all
-||222.137.8.96$all
 ||222.137.81.67$all
+||222.137.83.53$all
 ||222.138.137.188$all
 ||222.138.143.84$all
+||222.138.189.88$all
 ||222.138.203.22$all
+||222.138.215.161$all
 ||222.138.232.159$all
+||222.138.232.84$all
+||222.138.49.93$all
 ||222.138.96.79$all
+||222.139.16.229$all
 ||222.139.59.63$all
-||222.140.10.235$all
+||222.140.112.150$all
 ||222.140.117.221$all
 ||222.140.161.11$all
 ||222.140.163.112$all
@@ -2706,27 +2795,26 @@
 ||222.140.209.222$all
 ||222.140.219.212$all
 ||222.140.39.66$all
-||222.141.120.17$all
-||222.141.147.104$all
 ||222.141.150.38$all
+||222.141.165.180$all
+||222.141.244.231$all
 ||222.141.40.136$all
-||222.141.40.2$all
 ||222.141.41.155$all
+||222.141.44.36$all
 ||222.141.45.153$all
-||222.141.45.255$all
 ||222.141.60.251$all
+||222.141.73.249$all
 ||222.141.85.128$all
 ||222.142.162.164$all
 ||222.142.192.66$all
 ||222.142.209.7$all
 ||222.142.65.30$all
-||222.184.129.122$all
+||222.179.215.189$all
 ||222.185.116.233$all
-||222.186.20.19$all
 ||222.187.9.178$all
 ||222.211.72.66$all
+||222.214.54.208$all
 ||222.218.220.219$all
-||222.236.85.220$all
 ||222.238.230.7$all
 ||222.239.83.232$all
 ||222.248.64.253$all
@@ -2736,21 +2824,17 @@
 ||222.99.171.192$all
 ||223.166.117.210$all
 ||223.167.118.17$all
-||223.175.121.249$all
 ||223.212.225.68$all
 ||223.212.234.84$all
 ||223.212.252.180$all
 ||223.212.5.29$all
-||223.212.57.78$all
 ||223.212.73.175$all
-||223.213.164.81$all
 ||23.125.186.135$all
 ||23.126.120.25$all
 ||23.228.143.58$all
 ||23.24.213.121$all
 ||23.243.149.13$all
 ||23.243.21.167$all
-||23.81.246.58$all
 ||23.95.89.21$all
 ||24.103.74.180$all
 ||24.11.141.134$all
@@ -2777,6 +2861,7 @@
 ||27.105.106.201$all
 ||27.105.152.107$all
 ||27.116.84.57$all
+||27.12.234.4$all
 ||27.12.245.238$all
 ||27.13.83.77$all
 ||27.14.211.219$all
@@ -2792,7 +2877,6 @@
 ||27.193.217.210$all
 ||27.194.149.142$all
 ||27.194.158.229$all
-||27.194.166.45$all
 ||27.194.192.66$all
 ||27.194.210.20$all
 ||27.194.224.96$all
@@ -2844,14 +2928,15 @@
 ||27.208.166.13$all
 ||27.208.201.212$all
 ||27.208.247.130$all
+||27.208.25.59$all
 ||27.208.34.2$all
 ||27.208.92.64$all
 ||27.209.160.222$all
 ||27.209.231.15$all
 ||27.209.60.21$all
-||27.21.159.174$all
 ||27.210.107.125$all
 ||27.210.127.11$all
+||27.210.146.61$all
 ||27.210.172.245$all
 ||27.210.234.28$all
 ||27.210.236.134$all
@@ -2860,6 +2945,8 @@
 ||27.213.104.201$all
 ||27.213.109.105$all
 ||27.213.109.58$all
+||27.213.145.221$all
+||27.213.167.175$all
 ||27.213.175.208$all
 ||27.213.220.5$all
 ||27.213.255.202$all
@@ -2874,6 +2961,7 @@
 ||27.215.38.166$all
 ||27.215.71.243$all
 ||27.215.98.242$all
+||27.216.131.66$all
 ||27.216.144.66$all
 ||27.216.193.217$all
 ||27.216.197.193$all
@@ -2900,7 +2988,6 @@
 ||27.219.184.94$all
 ||27.219.192.223$all
 ||27.219.83.244$all
-||27.220.243.172$all
 ||27.220.40.189$all
 ||27.220.85.168$all
 ||27.221.239.223$all
@@ -2912,25 +2999,27 @@
 ||27.223.242.164$all
 ||27.223.44.106$all
 ||27.24.28.134$all
-||27.35.127.129$all
 ||27.35.129.198$all
 ||27.35.154.13$all
+||27.35.16.145$all
 ||27.35.2.30$all
 ||27.35.212.124$all
 ||27.35.58.5$all
-||27.36.143.238$all
-||27.41.159.216$all
-||27.41.36.15$all
-||27.41.38.79$all
-||27.46.45.90$all
-||27.5.38.169$all
-||27.5.41.251$all
-||27.5.42.169$all
-||27.6.196.172$all
+||27.41.153.66$all
+||27.41.154.31$all
+||27.43.82.210$all
+||27.46.45.248$all
+||27.46.47.74$all
+||27.5.16.243$all
+||27.5.26.105$all
+||27.5.26.4$all
+||27.5.27.1$all
+||27.5.35.127$all
 ||31.0.98.131$all
 ||31.11.51.57$all
 ||31.13.23.180$all
 ||31.154.234.3$all
+||31.163.191.11$all
 ||31.168.124.130$all
 ||31.168.179.83$all
 ||31.168.184.59$all
@@ -2949,8 +3038,10 @@
 ||31.204.174.180$all
 ||31.210.20.138$all
 ||31.210.20.177$all
+||31.210.20.227$all
 ||31.28.7.159$all
 ||31.30.119.23$all
+||31.62.255.3$all
 ||32.208.157.193$all
 ||32792.prolocksmithwinterpark.com$all
 ||35.184.169.169$all
@@ -2962,8 +3053,6 @@
 ||36.251.19.88$all
 ||36.251.51.244$all
 ||36.255.90.219$all
-||36.32.203.118$all
-||36.32.25.158$all
 ||36.33.128.60$all
 ||36.33.160.167$all
 ||36.36.243.67$all
@@ -2973,7 +3062,6 @@
 ||36.66.139.36$all
 ||36.67.152.161$all
 ||36.89.18.133$all
-||36.91.89.187$all
 ||36.96.187.93$all
 ||360.lcy2zzx.pw$all
 ||360down7.miiyun.cn$all
@@ -3011,8 +3099,8 @@
 ||39.72.67.64$all
 ||39.73.10.198$all
 ||39.73.163.231$all
-||39.73.183.14$all
 ||39.73.203.225$all
+||39.73.44.17$all
 ||39.74.104.228$all
 ||39.74.21.201$all
 ||39.74.28.89$all
@@ -3038,7 +3126,6 @@
 ||39.79.91.244$all
 ||39.79.93.171$all
 ||39.80.127.214$all
-||39.80.188.238$all
 ||39.80.191.137$all
 ||39.80.205.255$all
 ||39.80.24.54$all
@@ -3055,8 +3142,10 @@
 ||39.84.34.217$all
 ||39.84.95.200$all
 ||39.85.54.191$all
+||39.85.54.4$all
 ||39.86.129.233$all
 ||39.86.13.0$all
+||39.86.151.49$all
 ||39.86.170.209$all
 ||39.86.184.164$all
 ||39.86.211.20$all
@@ -3067,6 +3156,7 @@
 ||39.86.76.9$all
 ||39.86.78.228$all
 ||39.87.63.58$all
+||39.87.90.210$all
 ||39.87.93.109$all
 ||39.88.141.172$all
 ||39.88.155.96$all
@@ -3087,95 +3177,100 @@
 ||41.219.185.171$all
 ||41.230.31.58$all
 ||41.72.203.82$all
-||41.76.157.2$all
+||41.86.18.133$all
 ||41.86.18.147$all
 ||41.86.18.148$all
+||41.86.18.165$all
 ||41.86.18.200$all
 ||41.86.18.71$all
-||41.86.21.35$all
-||41.86.21.40$all
+||41.86.21.28$all
+||41.86.21.5$all
+||41.86.21.62$all
 ||41.86.5.103$all
-||41.86.5.104$all
-||41.86.5.198$all
-||41.86.5.237$all
 ||42.176.112.72$all
 ||42.202.101.147$all
+||42.224.122.39$all
 ||42.224.128.210$all
 ||42.224.168.142$all
 ||42.224.168.97$all
-||42.224.170.140$all
+||42.224.176.214$all
 ||42.224.179.49$all
-||42.224.181.121$all
-||42.224.183.11$all
 ||42.224.209.156$all
 ||42.224.212.124$all
 ||42.224.218.16$all
 ||42.224.233.247$all
 ||42.224.235.4$all
+||42.224.249.8$all
 ||42.224.37.186$all
 ||42.224.37.44$all
 ||42.224.43.25$all
 ||42.224.64.34$all
-||42.224.66.246$all
 ||42.224.70.213$all
 ||42.224.76.168$all
 ||42.224.76.198$all
 ||42.224.8.136$all
+||42.224.90.17$all
 ||42.224.91.8$all
-||42.225.24.101$all
 ||42.225.240.244$all
 ||42.225.250.39$all
-||42.226.76.62$all
+||42.225.33.31$all
+||42.226.89.25$all
 ||42.227.179.209$all
-||42.227.204.4$all
 ||42.227.66.88$all
 ||42.228.198.102$all
 ||42.228.60.114$all
 ||42.228.65.201$all
 ||42.228.70.126$all
 ||42.228.70.231$all
+||42.228.75.7$all
 ||42.228.76.135$all
 ||42.230.100.114$all
+||42.230.174.125$all
+||42.230.219.243$all
 ||42.230.228.78$all
-||42.230.57.145$all
 ||42.230.66.255$all
 ||42.230.82.44$all
 ||42.230.88.107$all
 ||42.230.93.169$all
+||42.231.223.215$all
+||42.231.244.80$all
 ||42.231.66.174$all
+||42.231.95.195$all
 ||42.232.102.163$all
 ||42.232.170.117$all
 ||42.232.226.16$all
+||42.233.90.183$all
+||42.234.105.6$all
+||42.234.162.44$all
 ||42.234.166.242$all
-||42.234.180.136$all
 ||42.234.255.20$all
 ||42.235.124.55$all
-||42.235.160.215$all
 ||42.235.169.85$all
 ||42.235.23.163$all
 ||42.235.66.249$all
-||42.235.83.180$all
+||42.235.90.32$all
+||42.235.92.111$all
 ||42.236.148.201$all
 ||42.236.212.174$all
 ||42.236.212.83$all
 ||42.236.215.63$all
 ||42.236.236.179$all
+||42.237.45.223$all
 ||42.237.54.162$all
-||42.238.175.61$all
+||42.238.175.32$all
 ||42.238.191.210$all
 ||42.238.241.239$all
 ||42.238.59.222$all
 ||42.239.192.128$all
-||42.239.207.166$all
-||42.239.42.135$all
 ||42.242.200.90$all
 ||42.52.180.36$all
 ||42.56.15.227$all
 ||42.61.99.155$all
+||42.82.217.241$all
 ||42.84.14.5$all
 ||43.230.156.44$all
-||43.230.207.204$all
 ||43.241.106.183$all
+||43.241.106.234$all
 ||43.252.8.94$all
 ||45.112.203.218$all
 ||45.130.138.66$all
@@ -3187,16 +3282,20 @@
 ||45.14.149.204$all
 ||45.14.149.244$all
 ||45.14.149.66$all
-||45.141.84.182$all
 ||45.141.84.184$all
+||45.144.225.142$all
+||45.144.225.213$all
 ||45.144.225.65$all
 ||45.148.10.47$all
 ||45.15.143.158$all
 ||45.164.140.133$all
-||45.165.215.19$all
 ||45.176.108.116$all
 ||45.176.108.248$all
+||45.176.110.99$all
+||45.176.111.154$all
 ||45.176.111.16$all
+||45.176.111.202$all
+||45.176.111.84$all
 ||45.178.101.22$all
 ||45.201.165.164$all
 ||45.22.209.58$all
@@ -3210,10 +3309,8 @@
 ||46.172.75.231$all
 ||46.175.184.121$all
 ||46.182.173.246$all
-||46.182.173.247$all
 ||46.20.63.218$all
 ||46.201.214.64$all
-||46.201.38.162$all
 ||46.21.153.231$all
 ||46.214.27.4$all
 ||46.24.130.254$all
@@ -3245,7 +3342,6 @@
 ||49.68.221.252$all
 ||49.68.249.121$all
 ||49.70.15.16$all
-||49.70.2.100$all
 ||5.181.135.114$all
 ||5.2.70.50$all
 ||5.53.146.179$all
@@ -3255,6 +3351,7 @@
 ||50.252.47.29$all
 ||51.171.146.13$all
 ||51.222.56.159$all
+||54.180.158.181$all
 ||54.253.194.14$all
 ||54.36.114.136$all
 ||54.36.180.122$all
@@ -3267,9 +3364,10 @@
 ||58.142.166.120$all
 ||58.142.200.124$all
 ||58.143.142.142$all
+||58.143.189.75$all
 ||58.18.103.109$all
+||58.19.249.50$all
 ||58.217.171.157$all
-||58.218.67.253$all
 ||58.22.212.107$all
 ||58.226.129.29$all
 ||58.229.194.122$all
@@ -3280,44 +3378,36 @@
 ||58.240.147.97$all
 ||58.241.57.237$all
 ||58.241.78.55$all
-||58.248.112.16$all
-||58.248.116.2$all
 ||58.248.117.188$all
-||58.248.140.132$all
-||58.248.142.137$all
-||58.248.142.174$all
+||58.248.143.173$all
+||58.248.144.97$all
 ||58.248.149.117$all
-||58.248.150.204$all
-||58.248.150.244$all
-||58.248.153.194$all
+||58.248.149.226$all
 ||58.248.154.55$all
 ||58.248.154.66$all
 ||58.248.76.206$all
 ||58.248.79.25$all
-||58.249.15.148$all
 ||58.249.18.244$all
-||58.249.22.210$all
-||58.249.72.121$all
+||58.249.74.104$all
 ||58.249.74.124$all
 ||58.249.74.248$all
 ||58.249.77.227$all
-||58.249.79.134$all
+||58.249.78.155$all
 ||58.249.80.23$all
+||58.249.80.46$all
 ||58.249.86.85$all
-||58.249.88.207$all
-||58.252.177.212$all
+||58.249.87.248$all
+||58.249.89.210$all
+||58.249.90.206$all
+||58.249.90.86$all
+||58.252.176.107$all
 ||58.252.177.66$all
-||58.252.178.167$all
-||58.252.178.55$all
-||58.253.14.46$all
-||58.255.140.156$all
 ||58.255.43.163$all
 ||58.48.154.143$all
 ||58.50.178.137$all
 ||58.50.221.148$all
 ||58.72.165.153$all
 ||58.72.165.39$all
-||58.76.151.51$all
 ||58.97.201.45$all
 ||58.97.206.33$all
 ||59.0.211.161$all
@@ -3325,48 +3415,18 @@
 ||59.151.202.3$all
 ||59.151.214.4$all
 ||59.151.237.51$all
-||59.151.246.125$all
 ||59.29.133.229$all
 ||59.30.12.254$all
+||59.32.97.190$all
 ||59.58.104.244$all
 ||59.58.117.226$all
 ||59.7.124.148$all
 ||59.8.35.22$all
-||59.89.243.76$all
-||59.92.176.136$all
-||59.92.178.202$all
-||59.92.18.175$all
-||59.92.182.177$all
-||59.92.216.255$all
-||59.93.17.196$all
-||59.93.17.204$all
-||59.93.17.72$all
-||59.93.19.11$all
-||59.93.23.154$all
-||59.93.23.215$all
-||59.93.23.23$all
-||59.93.23.7$all
-||59.94.180.237$all
-||59.96.36.131$all
-||59.96.36.137$all
-||59.96.39.91$all
-||59.97.168.110$all
-||59.97.170.16$all
-||59.97.175.101$all
-||59.97.175.96$all
-||59.97.193.118$all
-||59.99.137.46$all
-||59.99.138.222$all
-||59.99.139.252$all
-||59.99.139.66$all
-||59.99.141.103$all
-||59.99.141.219$all
-||59.99.142.43$all
-||59.99.188.93$all
-||59.99.41.26$all
-||59.99.43.225$all
-||59.99.46.7$all
-||59.99.47.64$all
+||59.92.182.72$all
+||59.92.218.77$all
+||59.92.219.28$all
+||59.97.174.85$all
+||59.99.47.93$all
 ||60.13.61.12$all
 ||60.14.48.221$all
 ||60.162.122.36$all
@@ -3405,24 +3465,24 @@
 ||60.220.22.89$all
 ||60.25.115.48$all
 ||60.25.76.224$all
-||60.253.15.104$all
-||60.253.39.88$all
+||60.253.4.72$all
 ||60.253.42.72$all
-||60.253.44.99$all
 ||60.253.51.127$all
 ||60.253.60.174$all
+||60.253.8.36$all
 ||60.253.8.81$all
+||60.254.49.59$all
 ||60.7.10.121$all
 ||60.7.136.8$all
 ||60.7.202.153$all
+||60.7.8.43$all
 ||60.7.99.254$all
 ||61.102.243.124$all
+||61.109.164.140$all
+||61.141.124.123$all
 ||61.162.169.210$all
 ||61.162.55.42$all
-||61.163.129.97$all
 ||61.164.96.98$all
-||61.167.211.218$all
-||61.168.139.87$all
 ||61.179.171.60$all
 ||61.179.91.194$all
 ||61.179.91.230$all
@@ -3432,37 +3492,42 @@
 ||61.213.118.28$all
 ||61.247.224.66$all
 ||61.253.94.230$all
-||61.3.126.128$all
-||61.3.144.90$all
-||61.3.147.175$all
+||61.3.124.3$all
+||61.3.124.51$all
 ||61.47.220.169$all
 ||61.52.102.61$all
 ||61.52.103.144$all
 ||61.52.11.87$all
+||61.52.135.192$all
 ||61.52.157.4$all
 ||61.52.159.231$all
 ||61.52.195.226$all
 ||61.52.212.191$all
+||61.52.212.250$all
 ||61.52.243.169$all
 ||61.52.247.208$all
-||61.52.30.49$all
 ||61.52.35.86$all
+||61.52.39.119$all
 ||61.52.43.174$all
 ||61.52.48.112$all
+||61.52.5.217$all
+||61.52.63.119$all
+||61.52.76.72$all
 ||61.52.9.166$all
-||61.52.97.134$all
 ||61.52.99.183$all
 ||61.53.100.87$all
-||61.53.121.19$all
+||61.53.123.162$all
+||61.53.125.182$all
 ||61.53.251.243$all
 ||61.53.62.169$all
 ||61.53.73.171$all
-||61.53.74.27$all
 ||61.53.81.18$all
 ||61.53.83.14$all
-||61.53.86.195$all
 ||61.54.172.248$all
-||61.54.41.143$all
+||61.54.240.20$all
+||61.54.58.190$all
+||61.54.58.20$all
+||61.54.61.18$all
 ||61.54.64.104$all
 ||61.54.77.175$all
 ||61.56.180.67$all
@@ -3485,6 +3550,7 @@
 ||62.141.73.58$all
 ||62.219.131.205$all
 ||62.219.143.46$all
+||62.219.155.61$all
 ||62.219.227.31$all
 ||62.31.126.33$all
 ||62.38.149.66$all
@@ -3496,16 +3562,13 @@
 ||65.125.128.196$all
 ||65.21.58.252$all
 ||65.26.155.131$all
-||65.35.61.255$all
 ||66.153.233.87$all
-||66.207.93.46$all
 ||66.229.214.115$all
 ||66.57.55.210$all
 ||66.74.7.197$all
 ||66.91.21.31$all
 ||66.97.181.196$all
 ||66.97.181.213$all
-||67.221.107.75$all
 ||67.245.151.203$all
 ||67.3.169.223$all
 ||67.8.138.101$all
@@ -3544,7 +3607,7 @@
 ||70.33.144.248$all
 ||70.93.129.118$all
 ||71.127.148.69$all
-||71.146.190.91$all
+||71.19.150.93$all
 ||71.204.63.239$all
 ||71.29.48.164$all
 ||71.34.191.213$all
@@ -3569,7 +3632,6 @@
 ||74.199.84.77$all
 ||74.75.165.81$all
 ||75.127.141.52$all
-||75.176.213.114$all
 ||75.82.36.220$all
 ||75.83.102.27$all
 ||75.99.213.61$all
@@ -3581,11 +3643,13 @@
 ||76.84.134.33$all
 ||76.95.12.137$all
 ||77.237.25.210$all
+||77.45.183.39$all
 ||77.71.50.153$all
 ||77.71.52.220$all
 ||77.79.191.32$all
 ||77.89.203.238$all
 ||78.179.225.254$all
+||78.186.155.18$all
 ||78.187.141.144$all
 ||78.187.240.125$all
 ||78.187.41.200$all
@@ -3603,7 +3667,6 @@
 ||79.170.31.56$all
 ||79.175.42.244$all
 ||79.21.84.63$all
-||79.22.176.145$all
 ||79.7.170.58$all
 ||79.79.58.94$all
 ||79.8.70.162$all
@@ -3619,7 +3682,6 @@
 ||81.198.7.22$all
 ||81.213.111.60$all
 ||81.213.141.184$all
-||81.213.166.175$all
 ||81.215.199.29$all
 ||81.218.187.113$all
 ||81.218.195.216$all
@@ -3663,7 +3725,7 @@
 ||84.210.219.208$all
 ||84.210.219.213$all
 ||84.212.219.127$all
-||84.214.103.73$all
+||84.224.162.170$all
 ||84.228.50.118$all
 ||84.228.95.204$all
 ||84.238.24.35$all
@@ -3680,12 +3742,12 @@
 ||85.105.208.25$all
 ||85.105.224.141$all
 ||85.105.241.2$all
+||85.105.9.152$all
 ||85.214.149.236$all
 ||85.64.181.50$all
 ||85.74.215.180$all
 ||85.97.130.227$all
 ||85.97.195.129$all
-||85.98.40.5$all
 ||86.35.43.220$all
 ||87.121.98.51$all
 ||87.61.89.40$all
@@ -3700,7 +3762,6 @@
 ||88.250.204.12$all
 ||88.250.226.26$all
 ||88.250.254.90$all
-||88.37.171.141$all
 ||89.122.183.130$all
 ||89.136.197.170$all
 ||89.29.213.33$all
@@ -3721,11 +3782,10 @@
 ||91.244.169.139$all
 ||91.92.16.244$all
 ||91.98.4.181$all
-||92.113.192.30$all
-||92.113.195.115$all
 ||92.114.191.82$all
 ||92.241.78.114$all
 ||92.27.246.202$all
+||92.54.237.237$all
 ||92.85.18.138$all
 ||93.171.157.73$all
 ||93.21.224.154$all
@@ -3750,7 +3810,6 @@
 ||95.170.201.34$all
 ||95.181.155.112$all
 ||95.214.52.64$all
-||95.53.229.84$all
 ||95.54.11.179$all
 ||95.60.146.134$all
 ||95.60.6.114$all
@@ -3771,7 +3830,6 @@
 ||98.30.24.54$all
 ||99.150.245.203$all
 ||99.33.195.164$all
-||99centsdigitals.com$all
 ||abcd.bg$all
 ||abclicks.in$all
 ||abissnet.net$all
@@ -3779,11 +3837,12 @@
 ||absoftechworld.com$all
 ||absupplies.co.uk$all
 ||abyssos.eu$all
+||academyshademani.com$all
 ||acbick.com$all
 ||accounts.thesmarttechhub.com$all
 ||aceeprc.com.aceeprc.com$all
 ||acellr.co.uk$all
-||aclassapart.in$all
+||aciabogados.com$all
 ||acteon.com.ar$all
 ||activateyourdiscount.com$all
 ||activecost.com.au$all
@@ -3801,6 +3860,7 @@
 ||agenciadigitalwdys.com$all
 ||agenciatabletshouse.com.br$all
 ||agenda.gmelloinformatica.com.br$all
+||agenmovie.xyz$all
 ||agentt.ac.ug$all
 ||agile8studio.com$all
 ||agmcarpetcare.co.uk$all
@@ -3808,12 +3868,10 @@
 ||ajpharmaholding.com$all
 ||ajstudiollc.com$all
 ||aktyd05.top$all
-||akwer03.top/downfiles/file.exe$all
 ||al-wahd.com$all
 ||alasdemariposas.org$all
 ||alemelektronik.com$all
 ||alena1971.es$all
-||alertlauncher.fr$all
 ||alexdubai.com.aldiabsteel.com$all
 ||alka.institute$all
 ||allforcreative.com.au$all
@@ -3825,6 +3883,7 @@
 ||amarteargentina.com.ar$all
 ||amenyan.zouri.jp$all
 ||amos524.org$all
+||ams.alvinasschools.org.ng$all
 ||amumufree.weebly.com/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe$all
 ||analogx.com/files/proxyi.exe$all
 ||anantam.net.in$all
@@ -3846,10 +3905,9 @@
 ||aplicativoparasindicato.com.br$all
 ||apoolcondo.com$all
 ||app.adsensearticle.com$all
-||app.explicitsurveys.co.uk$all
 ||app.prerana.info$all
 ||apps.saintsoporte.com$all
-||aras.iuc.ac$all
+||aqv.news$all
 ||areyoulivingwell.com$all
 ||arsapetrolab.com$all
 ||artedibujoyarquitectura.com$all
@@ -3868,11 +3926,12 @@
 ||ayamallah.com$all
 ||azmeasurement.com$all
 ||azraktours.com$all
-||b2b.toptanakaryakit.com.tr$all
 ||backgrounds.pk$all
 ||backup.agewsage.com$all
 ||badeggdesign.com$all
+||balealgodon.mx$all
 ||bangkok-orchids.com$all
+||barcionstw.eastus.cloudapp.azure.com$all
 ||bary.sz4h.com$all
 ||basma.com.kw$all
 ||bausch.kr-atlas.monaxikoslykos@zytrox.tk$all
@@ -3881,7 +3940,6 @@
 ||bcmt.elin.co.za$all
 ||bcrg.co.za$all
 ||bearcatpumps.com.cn$all
-||beatyamerican.com$all
 ||beautincollagen.rs$all
 ||bekape.co.id$all
 ||bespokeweddings.ie$all
@@ -3889,6 +3947,8 @@
 ||betone.co.kr$all
 ||betycopaints.com$all
 ||beveragesmiami.solucioneslink.com$all
+||bhavaniengineering.com$all
+||bigbag.wootraining.certificacion.cl$all
 ||bilbosaquet.ug$all
 ||bilhen.co.za$all
 ||billing.rahitechnosoft.com$all
@@ -3976,11 +4036,10 @@
 ||bitbucket.org/teaserex/tease/downloads/macro_xmprohiq27.bin$all
 ||blog.callensaxen.com$all
 ||blog.oyinblogs.com$all
-||blog.takbelit.com$all
 ||bmlifestyle.co.uk$all
+||bnrbook.com$all
 ||bnrnews.id$all
 ||bodenstein.co.za$all
-||bolnicaloznica.rs$all
 ||booksearch.com$all
 ||bounces.mi-fs.com$all
 ||bpo.correct.go.th$all
@@ -3994,23 +4053,21 @@
 ||brightstarshop.com$all
 ||browardinsurancemiami.solucioneslink.com$all
 ||bt2.elin.co.za$all
-||btdapi.robotake.com$all
 ||bucrinsuranlceonlines.com$all
 ||buenavista.co$all
-||buigiaphat.com.vn$all
 ||bullseyemedia.in$all
 ||busandvanrentalmalaysia.com$all
 ||buscascolegios.diit.cl$all
 ||business.softberg.ro$all
 ||buyingmusiconline.com$all
-||buypropertyfast.com$all
 ||bwsr.eu$all
 ||c.oooooooooo.ga$all
 ||c0140529.ferozo.com$all
+||caballo.com.au$all
 ||cacapavaonline.sdserver144.com.br$all
+||calgaryautorepairservice.com$all
 ||callbury.in$all
 ||camminachetipassa.it$all
-||campusvirtual.cepsanjuanbosco.net.pe$all
 ||cancer.educandome.co$all
 ||capitalgroup-kw.com$all
 ||capitalnewsagency.com$all
@@ -4027,12 +4084,10 @@
 ||cdn.discordapp.com/attachments/816070119281131570/816070273254162442/all.txt$all
 ||cdn.discordapp.com/attachments/823355293043261515/823692323514482788/inquiry_-_rfq_hmg_u66_sw5558_pdf.iso$all
 ||cec.asso.ac-amiens.fr$all
-||cellas.sk$all
 ||cendekiabinaaksara.com$all
 ||cespol-bote.com.mx$all
 ||cfs5.tistory.com$all
 ||ch.rmu.ac.th$all
-||changematterscounselling.com$all
 ||chardhamdodham.com$all
 ||cheacrilnsurances.com$all
 ||chealablilitycarinsurances.com$all
@@ -4040,7 +4095,6 @@
 ||childselect.com$all
 ||chinhdropfile.myvnc.com$all
 ||chinhdropfile80.myvnc.com$all
-||chipmania.it$all
 ||chiptune.com/razor/rzr-winner_intro.zip$all
 ||cible-energy.com$all
 ||cifeer.net$all
@@ -4048,10 +4102,10 @@
 ||cityglobalgospel.com$all
 ||civi.istmejia.com$all
 ||cleanbydesignllc.com$all
-||clim34000.fr$all
 ||cloud.fc.co.mz$all
 ||cloudme.com/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz$all
 ||cloudme.com/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar$all
+||clurbgolf.com$all
 ||codeload.github.com/meteoradminz/hidden-tear/zip/master$all
 ||codsambal.com$all
 ||colfincas.com/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/$all
@@ -4075,7 +4129,6 @@
 ||crecerco.com$all
 ||crittersbythebay.com$all
 ||crm.notariavieitoyvelamazan.com$all
-||crmmanivela.net$all
 ||crscorretordeimoveis.com.br$all
 ||cse-engineer.com$all
 ||csnserver.com$all
@@ -4090,7 +4143,6 @@
 ||czas.dbstrony.pl$all
 ||czsl.91756.cn$all
 ||d.powerofwish.com$all
-||d.ttr3p.com/kr.bin$all
 ||d9.99ddd.com$all
 ||da.alibuf.com$all
 ||damagedessentialtelecommunications.testmail4.repl.co$all
@@ -4124,7 +4176,6 @@
 ||detorre.es$all
 ||dev-interestingtech.pantheonsite.io$all
 ||dev.sebpo.net$all
-||dezcom.com$all
 ||dfcf.91756.cn$all
 ||dfsfcsfcdsfsdvcfsvcscv.com$all
 ||diamantenegro.mi-fs.com$all
@@ -4147,7 +4198,6 @@
 ||doncedyhall.com$all
 ||donghobinhminh.com$all
 ||dongphuctop.com$all
-||donwnloasecury.ath.cx$all
 ||dosame.com$all
 ||dosman.pl$all
 ||dovberger.com$all
@@ -4155,6 +4205,9 @@
 ||down.pcclear.com$all
 ||down.posti-fi-fsa.top$all
 ||down.posti-fi-fwa.top$all
+||down.posti-fi-ij.top$all
+||down.posti-fi-in.top$all
+||down.posti-fi-iz.top$all
 ||down.udashi.com$all
 ||down.webbora.com$all
 ||down1.arpun.com$all
@@ -4172,85 +4225,31 @@
 ||drive.google.com.it-barcelona.com/frm0reseen/prntscrnofamzorderid.jpg.exe$all
 ||drive.google.com/uc?export=download&id=0byfg0_4xbjgnwvuyev9ltuh4rmm$all
 ||drive.google.com/uc?export=download&id=13vodfxml9fg8kcnexuafh64dzmnqv8ch$all
-||drive.google.com/uc?export=download&id=14l8sj2dqo04ozum88tvuy74yfcwk5fnf$all
-||drive.google.com/uc?export=download&id=15bd1dksg4pkrxehoczi7e0uok4vblz4e$all
 ||drive.google.com/uc?export=download&id=167imxqgc8ehepa1gisxa6q6ifcjxceox$all
-||drive.google.com/uc?export=download&id=17xvn-rlhei5n9f6unuqqb_wh84u4w5cx$all
-||drive.google.com/uc?export=download&id=1_vz7veeec-juwt23g9d9wjuid2kusew7$all
 ||drive.google.com/uc?export=download&id=1a-herfdxr6xamxeabcdao0mqw9bimrig$all
 ||drive.google.com/uc?export=download&id=1aphk_vq7gtn368zxpd5bg5rv8nk0bnhn$all
-||drive.google.com/uc?export=download&id=1aqhdbelnscyjygigfopt7x_oafaqgwg1$all
-||drive.google.com/uc?export=download&id=1cf8d3ljsfn3toddczqtkkbhrd5g00cjg$all
 ||drive.google.com/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben$all
-||drive.google.com/uc?export=download&id=1cynoc3t9rp-xvso3jcmx_prwppp8u-dv$all
-||drive.google.com/uc?export=download&id=1d8fykmpewc_4yurihjh_cdehkdp_nuik$all
-||drive.google.com/uc?export=download&id=1dgcin9vevl9f63cbhbkmc_gpa2b0zlrh$all
-||drive.google.com/uc?export=download&id=1do7c-fjuscbueu0un2dbxe3-pnwdufb_$all
 ||drive.google.com/uc?export=download&id=1eqnvgn0qkunp7t6crk8oj7_e7rh5qxwi$all
-||drive.google.com/uc?export=download&id=1f3kxfcvbpaaexgnchpvmyoxkcdmickjj$all
-||drive.google.com/uc?export=download&id=1gsmk1t_yigh7jablxkuhbmmh93vwgikb$all
-||drive.google.com/uc?export=download&id=1hmud67vsl-shqddzpxniqmyj92iynyis$all
-||drive.google.com/uc?export=download&id=1ik-x4_bsr5dbocs9j1ryg1ybw75fqu8t$all
 ||drive.google.com/uc?export=download&id=1in-rhdrss2qsjqj8xffb1hbwi9znp4je$all
 ||drive.google.com/uc?export=download&id=1iwc-lf99neesk6mvvo2al4futbmyoiev$all
 ||drive.google.com/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr$all
-||drive.google.com/uc?export=download&id=1jgykopezccdq3q5qprmkl1zdl1auymkq$all
-||drive.google.com/uc?export=download&id=1lplk8rixxuboakkmut_qgzn92bkoulna$all
-||drive.google.com/uc?export=download&id=1mug8m5o6kl_bx68x8cuxmzhn0gxnc7ki$all
 ||drive.google.com/uc?export=download&id=1n8o4hbvi7o9ks9jqhofny7okposfaz4y$all
-||drive.google.com/uc?export=download&id=1nindqtjvyyzz-qk-hqa9gls5ccwhys-e$all
 ||drive.google.com/uc?export=download&id=1nio_cdsggt4zv1kdrpubrfpd0pzsyffd$all
-||drive.google.com/uc?export=download&id=1nsyqwodoi1t9-i29arbxwe7fkafjydsz$all
-||drive.google.com/uc?export=download&id=1nwctbvlr_1bewpvgdbmuhnny-zi6kp1l$all
-||drive.google.com/uc?export=download&id=1o2dcrdwgu91moicmterbx9avcl9cavy1$all
-||drive.google.com/uc?export=download&id=1o4lh97cmfnztr_hkocnwiucy5l6oskpy$all
 ||drive.google.com/uc?export=download&id=1oabvvnazifkxktvt-izbcdqpb7dm6nrw$all
-||drive.google.com/uc?export=download&id=1oys1nkexzsuci6pfghowlbpwaw-_btxk$all
 ||drive.google.com/uc?export=download&id=1prxtn1juykhcr_9ilw-vtirv5anyeoej$all
-||drive.google.com/uc?export=download&id=1pzywywxrwl2plk82nuodgvmcckpzrufb$all
-||drive.google.com/uc?export=download&id=1q0uxhnzfs4j91rxz5x45iov8tjkomsgr$all
-||drive.google.com/uc?export=download&id=1q9vzzhu-n9cu8ixdginpzaxxgvb1lrjv$all
-||drive.google.com/uc?export=download&id=1qk8_jouqbnrfkky7x1aqunudfyl6fjii$all
-||drive.google.com/uc?export=download&id=1qxv3i0dwy_cdx2bm1lqx6ef0qjwmhbpk$all
-||drive.google.com/uc?export=download&id=1qzmi4jvter0_cwexcp4grjhxvr7lep5k$all
-||drive.google.com/uc?export=download&id=1r-kstukxtxjqxlwypgd764dw-puj_7fz$all
-||drive.google.com/uc?export=download&id=1r-zn6o95qzworq8e4fhz637bfuoxayby$all
-||drive.google.com/uc?export=download&id=1rcykjynwhlc487sn1vwcsmjse_ctlrox$all
-||drive.google.com/uc?export=download&id=1rdxnm_kxegbwlojlucu4qiff7kyax3oi$all
-||drive.google.com/uc?export=download&id=1s9tu6akdxquy7cezquljtb2yarci99ab$all
-||drive.google.com/uc?export=download&id=1serasql3bw7nc-sllzyrishnhodmefyf$all
-||drive.google.com/uc?export=download&id=1shuxviwx167elbuz8mfcjc2bk99zzov_$all
-||drive.google.com/uc?export=download&id=1sjzynfvpwdcwsr1p3w_q8-6ktsqiwadx$all
-||drive.google.com/uc?export=download&id=1sogqqdapgyioillf7u62widsprhw3cjh$all
 ||drive.google.com/uc?export=download&id=1t1bd_itjnhsmozdl9was0gouehujm1fn$all
-||drive.google.com/uc?export=download&id=1tfra7fzrjl2vdj73hcmcru5ynuqmz61g$all
 ||drive.google.com/uc?export=download&id=1tsmbsikhechaqedk6nktlfzasus_tghw$all
-||drive.google.com/uc?export=download&id=1ur9qebooqc-mjcdzn9wcbavocumdlosm$all
 ||drive.google.com/uc?export=download&id=1uvtmu3-hcryp3rskqnpkiodcjuchtz55$all
-||drive.google.com/uc?export=download&id=1v4ima0sfnmboxmyoklp4g0_uehaj22x2$all
 ||drive.google.com/uc?export=download&id=1vevblftithattyguwyjot1p0wptg7l5t$all
-||drive.google.com/uc?export=download&id=1vl9gje5llm7ja3dadct9okr6bzbmijc3$all
-||drive.google.com/uc?export=download&id=1vvvujegfrgey39w6y3ybwpptl1guwf8a$all
-||drive.google.com/uc?export=download&id=1ws2ptumptku-imi9sv_k5g4fhsx30gnl$all
-||drive.google.com/uc?export=download&id=1wtxdbb1fm9ozinx09a63-o-tn4ssgzpw$all
-||drive.google.com/uc?export=download&id=1xbeqbw67xz4iqpu8dgmdrlkpa6kzotes$all
-||drive.google.com/uc?export=download&id=1xdpxbb9gifdrugqxmg2_06xygbfq-x2k$all
 ||drive.google.com/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e$all
-||drive.google.com/uc?export=download&id=1xu9wvl5ktadwfxd94dicuej6y_j6kf8-$all
 ||drive.google.com/uc?export=download&id=1yawygcfjs9inzoiwagqfcn3utaywxmwi$all
-||drive.google.com/uc?export=download&id=1ycggxvacywdkt3jvqbpxpz9cyjcwvl_c$all
 ||drive.google.com/uc?export=download&id=1yhflwpk3yeyrdhlhanctlind-5j24iwv$all
-||drive.google.com/uc?export=download&id=1ys9rupdqvnhvrngizxfzstzcos0dlx-u$all
-||drive.google.com/uc?export=download&id=1z6wmqtnaa-jtpm5bqkb3ebi_btjcvmat$all
 ||drive.google.com/uc?export=download&id=1zbclvhabervgfryoyqklo4_oe6icd8sr$all
-||drive.google.com/uc?export=download&id=1zor7cinphnazfkldkthucb2h8jthlh9d$all
-||drive.google.com/uc?export=download&id=1zsghzos5foggoqxq6w12xeqvanhccdyk$all
 ||drive.google.com/uc?id=148pt6v0nlg8yoim7w6in7dpixkzaacbg&export=download&authuser=0$all
 ||drohnen.ensenanzainteligente.com$all
 ||drools-moved.46999.n3.nabble.com$all
 ||drpamelageorge.com/wp-includes/1zilg/$all
 ||drpamelageorge.com/wp-includes/qcgfmfvh/$all
-||drrohanfonseca.com$all
 ||drsha.innovativesolutions.mobi$all
 ||dsenterprize.co.za$all
 ||dsspainting.com$all
@@ -4265,19 +4264,15 @@
 ||e.sldov.ru$all
 ||ebruyatkin.com$all
 ||econews.treegle.org$all
-||edelweissdecoration.com$all
 ||efficientegroup.com$all
 ||elliot.newreadermedia.net$all
-||emaids.co.za$all
 ||en.baoend.com$all
 ||enc-tech.com$all
 ||endurotanzania.co.tz$all
-||enkonooh.com$all
 ||ennovate.elin.co.za$all
 ||enriquecendocomconsorcio.com.br$all
 ||envios.petpienso.cl$all
 ||equimination.ee$all
-||es.paymelist.com$all
 ||escola.probommar.org.br$all
 ||esnconsultants.com$all
 ||essentia.org.br$all
@@ -4298,7 +4293,6 @@
 ||f1sol.com$all
 ||familydentist.site$all
 ||farmaciasdrogaminas.com.br$all
-||farmnatural.in$all
 ||faveraprojects.com$all
 ||fc.co.mz$all
 ||felicienne.nl$all
@@ -4308,8 +4302,8 @@
 ||files.constantcontact.com/ee304de9001/7e533e73-e272-4a44-9d9e-138cab64bf19.docx$all
 ||files.martellexpress.us$all
 ||files6.uludagbilisim.com$all
-||filmotainment.com$all
 ||final.makkahkmcc.com$all
+||fineartgallerym.com$all
 ||fkd.derpcity.ru$all
 ||flintspin.com$all
 ||flyingbuddhadesign.com$all
@@ -4317,20 +4311,17 @@
 ||fms.buladde.or.ug$all
 ||foothills.com.br$all
 ||footweardirect.elin.co.za$all
-||formestore.evencsoft.co$all
 ||forum.mdb.nu$all
 ||fotoobjetivo.com$all
 ||foundationrepairhoustontx.net$all
 ||foxeps.com.br$all
 ||freecnetdownload.com$all
-||freedombookshop.tickme.lk$all
 ||freisites.com.br$all
 ||ftp.n3twork30cm.ml$all
 ||fullelectronica.com.ar$all
 ||funletters.net$all
 ||fusionfiresolutions.com$all
 ||futuregraphics.com.ar$all
-||gahanassociates.com$all
 ||gametwogame.com$all
 ||garayvidalabogados.com$all
 ||garciadogshow.com$all
@@ -4338,7 +4329,6 @@
 ||garenanow4.myvnc.com$all
 ||gbbulls.co.uk$all
 ||gcpc.co.id.chronoscurtain.com$all
-||gcrcorporation.com$all
 ||generaldeviales.com$all
 ||gfmodd1.webselffiles01.com$all
 ||gfold1.webselffiles01.com$all
@@ -4346,6 +4336,8 @@
 ||ghislain.dartois.pagesperso-orange.fr$all
 ||giadungg7.com$all
 ||giddos.ga$all
+||gilliem.com$all
+||girotexuniformes.com$all
 ||gist.githubusercontent.com/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe$all
 ||giteletropical.com$all
 ||globaltask.ar$all
@@ -4361,10 +4353,12 @@
 ||goldcupmortgage.com$all
 ||golden-memories-funerals.yourpageserver.com$all
 ||goldmen.in$all
+||gorecycle.fahadjutt.com$all
 ||gracejukes.com$all
 ||grupoinmare.com$all
 ||gruposelt.000webhostapp.com$all
 ||gs.monerorx.com$all
+||guide-to-cell-phones.com$all
 ||gulfac-house.com$all
 ||gvpcdpgc.edu.in$all
 ||habbotips.free.fr$all
@@ -4390,6 +4384,7 @@
 ||hmpmall.co.kr$all
 ||hoagietesting10.com$all
 ||hoayeuthuong-my.sharepoint.com$all
+||holmesprpmgmt.com$all
 ||homefindersolutions.com$all
 ||hongluosi.com$all
 ||hookedupboatclub.com$all
@@ -4403,7 +4398,6 @@
 ||hsmwebapp.com$all
 ||htownbars.com$all
 ||hubtech.co.za$all
-||huequito.evencsoft.co$all
 ||hunggiang.vn$all
 ||husamiyahschool.com$all
 ||ia801802.us.archive.org/19/items/startup_20210219/startup.txt$all
@@ -4417,6 +4411,7 @@
 ||iesanjosemonitos.edu.co$all
 ||ikexpert.com$all
 ||ilrafrica.com$all
+||images.jermiau.com$all
 ||imbueautoworx.co.za$all
 ||imperiumtherapy.co.za$all
 ||in-tune2016.com$all
@@ -4433,6 +4428,7 @@
 ||inovations.searchkero.com$all
 ||inrajahmundry.co.in$all
 ||insignificantfinecore.testmail4.repl.co$all
+||instantindialoan.com$all
 ||instvisionmexico.edu.mx$all
 ||intellectsmart.in$all
 ||intersel-idf.org$all
@@ -4443,6 +4439,7 @@
 ||iremart.es$all
 ||iris101.co.uk$all
 ||iscamenabe.com$all
+||ismf.com.ng$all
 ||iso-dubai.net$all
 ||israrulhaq.me$all
 ||isrorg.com$all
@@ -4464,7 +4461,6 @@
 ||jiaoyuzixun.cn$all
 ||jing-da.com.tw$all
 ||jktnet.xyz$all
-||jmcomputacion.com.ar$all
 ||jmtc.91756.cn$all
 ||jnanbharati.com$all
 ||jobs.thebeessolution.com$all
@@ -4476,12 +4472,11 @@
 ||josegene.com$all
 ||josuarochoa.com$all
 ||jpwoodfordco.com$all
-||julietlaser.site$all
 ||jumpmanualjacobhiller.com$all
-||jumpnjamchicago.com$all
 ||jupiter.toxsl.in$all
 ||jurgensen.newreadermedia.net$all
 ||justinscott.com.au$all
+||justlficante.mediafire.com/file/jl01o54yy09qrzg/fac215.tgz/file$all
 ||kaizenjanitorial.com$all
 ||kalawatihomes.com$all
 ||kalpataru-elitus-mulund.thakkers.in$all
@@ -4503,6 +4498,7 @@
 ||kumaralok.in$all
 ||kwanfromhongkong.com$all
 ||kz.sldov.ru$all
+||lab18.it$all
 ||lacasadelosalebrijes.com$all
 ||ladylabonde.com$all
 ||lameguard.ru$all
@@ -4549,6 +4545,7 @@
 ||lp.difusodesign.com$all
 ||lp.juancamilogarciareyes.com$all
 ||lp.tecnimasdecolombia.com.co$all
+||ltc.typoten.com$all
 ||luckybrownie.com$all
 ||luminouspneuma.com$all
 ||luxomodels.com$all
@@ -4557,15 +4554,15 @@
 ||madicon.co.za$all
 ||magianegramagiablancayamarres.com$all
 ||mail.bs-eiendomme.co.za$all
+||mail.golimoapp.com$all
 ||mail.jeffsono.org$all
 ||maksi.feb.unib.ac.id$all
 ||malaya.tv$all
 ||malwarecoding.github.io$all
 ||managed.oss-cn-beijing.aliyuncs.com$all
+||managemysalon.in$all
 ||manantialesdelnorte.uy$all
-||manivelasst.com$all
 ||marcapinyo.ru$all
-||marcusthepoet.com$all
 ||mario-sunjic.com$all
 ||mariobrown.net$all
 ||mariotessarollo.com$all
@@ -4574,7 +4571,6 @@
 ||marksidfgs.ug$all
 ||masjidhabeebiyarazviya.mysunni.com$all
 ||materialescantu.com$all
-||matinal-nominal.pt$all
 ||matruchhaya.co.in$all
 ||mattysplayground.com$all
 ||maxtox.com.pk$all
@@ -4586,6 +4582,7 @@
 ||mediamaster.co.za$all
 ||medianews.ge$all
 ||medistaffconsulting.com$all
+||meditreat.itwebservice.in$all
 ||meeweb.com$all
 ||megamart.afnan-amc.com$all
 ||merbay.ru$all
@@ -4607,7 +4604,6 @@
 ||mingguanwms.com$all
 ||minpic.de/k/big5/1giof6/$all
 ||minuevavida.org$all
-||mirror.mypage.sk$all
 ||mis.nbcc.ac.th$all
 ||misterson.com$all
 ||mixr.at$all
@@ -4615,12 +4611,15 @@
 ||mktf.mx$all
 ||mmogollon.com.mx$all
 ||mncarteam.com$all
+||mobile.illumetechnology.com$all
 ||modelhouseturkey.com$all
 ||modernmanna.org$all
 ||monetization.business$all
 ||moninediy.com$all
 ||mopai.sg$all
+||morrobaydrugandgift.com/wp-contentbak/t9m/$all
 ||motorcomunicacion.com$all
+||msacontabil.com.br$all
 ||mtspsmjeli.sch.id$all
 ||muzimbiti.xigubo.co.mz$all
 ||mxpiqw.am.files.1drv.com$all
@@ -4658,8 +4657,8 @@
 ||nicolas.ug$all
 ||nidhi.iexist.in$all
 ||nikanpolimer.ir$all
+||nilehouse.co.ug$all
 ||nilinkeji.com$all
-||nisacooks.com$all
 ||njtiledesigncenter.com$all
 ||nobius.org$all
 ||nocalnoodle.elin.co.za$all
@@ -4678,11 +4677,14 @@
 ||oakleyandfriends.co.uk$all
 ||obseques-conseils.com$all
 ||ocean.tecnasulstore.com.br$all
+||ohe.ie$all
 ||ohsewgorgeous.co.uk$all
+||oknoplastik.sk$all
 ||oldschoolvalue.s3.amazonaws.com/spreadsheets/osv_stock_valuation-sample-dummy.exe$all
 ||oleholeh.memangbeda.website$all
 ||olirecords.mixture.ltd$all
 ||olooom.com$all
+||omaia.org$all
 ||omaromatic.com$all
 ||omega.az$all
 ||oms.pappai.com$all
@@ -4694,6 +4696,7 @@
 ||onedrive.live.com/download?&resid=b4c15a27928f663b!229&authkey=aiarm61fwmd_npe$all
 ||onedrive.live.com/download?&resid=b4c15a27928f663b!230&authkey=ancu1eabetiubzg$all
 ||onedrive.live.com/download?&resid=b4c15a27928f663b!231&authkey=ai9h3sk_luxran0$all
+||onedrive.live.com/download?&resid=c127f9e0fb7cbbea!214&authkey=aat73nvghhjdr9g$all
 ||onedrive.live.com/download?authkey=!aase4ma0-vo_cls&cid=4df11eda676a355f&resid=4df11eda676a355f!140$all
 ||onedrive.live.com/download?authkey=!akd6uxvljtlvpxu&cid=4df11eda676a355f&resid=4df11eda676a355f!130$all
 ||onedrive.live.com/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135$all
@@ -4712,14 +4715,13 @@
 ||onedrive.live.com/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw$all
 ||onedrive.live.com/download?cid=03286724f74117f9&resid=3286724f74117f9!1179&authkey=acr-_rvrgp39kk4$all
 ||onedrive.live.com/download?cid=03286724f74117f9&resid=3286724f74117f9%211179&authkey=acr-_rvrgp39kk4$all
-||onedrive.live.com/download?cid=032ce380af7ab389&resid=32ce380af7ab389!210&authkey=akcynbtc0h3ui7e$all
-||onedrive.live.com/download?cid=032ce380af7ab389&resid=32ce380af7ab389%21210&authkey=akcynbtc0h3ui7e$all
 ||onedrive.live.com/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48$all
 ||onedrive.live.com/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq$all
 ||onedrive.live.com/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg$all
 ||onedrive.live.com/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw$all
 ||onedrive.live.com/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq$all
 ||onedrive.live.com/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!273&authkey=ae2m69e5nu3rrea$all
+||onedrive.live.com/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!274&authkey=acqg0akutoxdpgo$all
 ||onedrive.live.com/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21273&authkey=ae2m69e5nu3rrea$all
 ||onedrive.live.com/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21274&authkey=acqg0akutoxdpgo$all
 ||onedrive.live.com/download?cid=0e26b39babdbf63c&resid=e26b39babdbf63c%21137&authkey=anshbgxg1_qa2h4$all
@@ -4731,8 +4733,10 @@
 ||onedrive.live.com/download?cid=115bffdddaa40942&resid=115bffdddaa40942%21540&authkey=aamhnqgfdtdsoxk$all
 ||onedrive.live.com/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a$all
 ||onedrive.live.com/download?cid=13b301f1cb48f8cd&resid=13b301f1cb48f8cd%21106&authkey=aiae3olcs4lulz4$all
+||onedrive.live.com/download?cid=14f52af71b98dbc5&resid=14f52af71b98dbc5%212449&authkey=anfs_n5cs1noojo$all
 ||onedrive.live.com/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte$all
 ||onedrive.live.com/download?cid=165468846f076ee7&resid=165468846f076ee7%21118&authkey=antash3ig98aqte$all
+||onedrive.live.com/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f%21286&authkey=almwisomhv3c0zc$all
 ||onedrive.live.com/download?cid=174a158b69387a7e&resid=174a158b69387a7e!348&authkey=ahnjoxa4ufoxa54$all
 ||onedrive.live.com/download?cid=174a158b69387a7e&resid=174a158b69387a7e%21348&authkey=ahnjoxa4ufoxa54$all
 ||onedrive.live.com/download?cid=18418adacefed6e2&resid=18418adacefed6e2!126&authkey=ad4yflrisq6d82g$all
@@ -4748,10 +4752,6 @@
 ||onedrive.live.com/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg$all
 ||onedrive.live.com/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4$all
 ||onedrive.live.com/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c$all
-||onedrive.live.com/download?cid=2184cd6093fdd997&resid=2184cd6093fdd997!136&authkey=agsnq9l7ncf4p-w$all
-||onedrive.live.com/download?cid=2184cd6093fdd997&resid=2184cd6093fdd997!137&authkey=aawcijw8fv4m-8g$all
-||onedrive.live.com/download?cid=2184cd6093fdd997&resid=2184cd6093fdd997%21136&authkey=agsnq9l7ncf4p-w$all
-||onedrive.live.com/download?cid=2184cd6093fdd997&resid=2184cd6093fdd997%21137&authkey=aawcijw8fv4m-8g$all
 ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!123&authkey=am1rcmkppbht8v0$all
 ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!124&authkey=am5sltharf-j_cc$all
 ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!125&authkey=acgvgbbuowodg4c$all
@@ -4784,6 +4784,8 @@
 ||onedrive.live.com/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21115&authkey=aglznnsx71tbe9e$all
 ||onedrive.live.com/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37!183&authkey=akon9i9zzhusiuk$all
 ||onedrive.live.com/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37%21183&authkey=akon9i9zzhusiuk$all
+||onedrive.live.com/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6!161&authkey=aovldmsenzzpjrw$all
+||onedrive.live.com/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6%21161&authkey=aovldmsenzzpjrw$all
 ||onedrive.live.com/download?cid=2f01a497b687285e&resid=2f01a497b687285e!734&authkey=aiumuxtp3phppy4$all
 ||onedrive.live.com/download?cid=2f01a497b687285e&resid=2f01a497b687285e%21734&authkey=aiumuxtp3phppy4$all
 ||onedrive.live.com/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!116&authkey=!abwledjhfsqwap4$all
@@ -4806,8 +4808,6 @@
 ||onedrive.live.com/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0$all
 ||onedrive.live.com/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa$all
 ||onedrive.live.com/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa$all
-||onedrive.live.com/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c!139&authkey=ap4bbakgkikau-a$all
-||onedrive.live.com/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c%21139&authkey=ap4bbakgkikau-a$all
 ||onedrive.live.com/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!198&authkey=acyz0gbpl6bp9mo$all
 ||onedrive.live.com/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!199&authkey=admaszabh84m8ou$all
 ||onedrive.live.com/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e%21198&authkey=acyz0gbpl6bp9mo$all
@@ -4817,21 +4817,6 @@
 ||onedrive.live.com/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21152&authkey=am09sv26njxzyn0$all
 ||onedrive.live.com/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21153&authkey=ajs0jkoeqkqjrze$all
 ||onedrive.live.com/download?cid=3a1715e2cb964f25&resid=3a1715e2cb964f25%213713&authkey=aortxmfnibnoqkk$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237!963&authkey=aewqwrtr9szefem$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237!965&authkey=aaayllvoxl-rbdi$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237!966&authkey=apsg26pur_hpk6k$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237!971&authkey=amfm0a4mjjup0o8$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237!973&authkey=acfwvefa0v7myb4$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237!975&authkey=ajreyx8ik2l5uxm$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237!976&authkey=alpmp7w4cfupsvu$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237!977&authkey=adju1b_cnsxdxni$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21965&authkey=aaayllvoxl-rbdi$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21966&authkey=apsg26pur_hpk6k$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21971&authkey=amfm0a4mjjup0o8$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21975&authkey=ajreyx8ik2l5uxm$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21976&authkey=alpmp7w4cfupsvu$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21977&authkey=adju1b_cnsxdxni$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21978&authkey=agg7tntwzgctq7s$all
 ||onedrive.live.com/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21432&authkey=aa_npsupyqb2kge$all
 ||onedrive.live.com/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21435&authkey=admsjhgpkbtcqzs$all
 ||onedrive.live.com/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog$all
@@ -4998,6 +4983,7 @@
 ||onedrive.live.com/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w$all
 ||onedrive.live.com/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta$all
 ||onedrive.live.com/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21117&authkey=aivf1ddcvvu22em$all
+||onedrive.live.com/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb!211&authkey=anxavz-oaf9pv_c$all
 ||onedrive.live.com/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21210&authkey=agpl0pgvft8faaa$all
 ||onedrive.live.com/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21211&authkey=anxavz-oaf9pv_c$all
 ||onedrive.live.com/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto$all
@@ -5038,7 +5024,6 @@
 ||onedrive.live.com/download?cid=8ca507baa15fdb5c&resid=8ca507baa15fdb5c!213&authkey=acyrjlhflcrypae$all
 ||onedrive.live.com/download?cid=8ffd8cbd6540c065&resid=8ffd8cbd6540c065!822&authkey=acfj7bbrmktj1i0$all
 ||onedrive.live.com/download?cid=907247dc330a3f33&resid=907247dc330a3f33!243&authkey=aeiqd4ihuqopwm8$all
-||onedrive.live.com/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21276&authkey=afig5wsljtdc33s$all
 ||onedrive.live.com/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my$all
 ||onedrive.live.com/download?cid=914146ba02b70d25&resid=914146ba02b70d25!130&authkey=ais_g9dqoddonsc$all
 ||onedrive.live.com/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby$all
@@ -5081,7 +5066,6 @@
 ||onedrive.live.com/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8$all
 ||onedrive.live.com/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq$all
 ||onedrive.live.com/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq$all
-||onedrive.live.com/download?cid=9fb622acb27482ef&resid=9fb622acb27482ef%211197&authkey=aeacibxy2zlyxro$all
 ||onedrive.live.com/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o$all
 ||onedrive.live.com/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4$all
 ||onedrive.live.com/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi$all
@@ -5098,7 +5082,6 @@
 ||onedrive.live.com/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21!6053&authkey=agfh0ahstj7rrki$all
 ||onedrive.live.com/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21%216053&authkey=agfh0ahstj7rrki$all
 ||onedrive.live.com/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fi$all
-||onedrive.live.com/download?cid=a76c2c9b2bbef5ec&resid=a76c2c9b2bbef5ec%21141&authkey=akcfuxzfafd_c9c$all
 ||onedrive.live.com/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21414&authkey=akf9uwwkitvhrvc$all
 ||onedrive.live.com/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21415&authkey=ag_5kthuezprnoy$all
 ||onedrive.live.com/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21416&authkey=airlma-pycgfkyc$all
@@ -5202,12 +5185,14 @@
 ||onedrive.live.com/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211030&authkey=aeqnasuksxccax4$all
 ||onedrive.live.com/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211031&authkey=acxtarrhbwrqt20$all
 ||onedrive.live.com/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211032&authkey=aemitbkn-vma9yk$all
+||onedrive.live.com/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211033&authkey=abiydifgst6musa$all
 ||onedrive.live.com/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211035&authkey=ahd_ichsrf8ok_u$all
 ||onedrive.live.com/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!191&authkey=ajl2uegqunsgc3q$all
 ||onedrive.live.com/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!192&authkey=acd_hx4bka3z0nw$all
 ||onedrive.live.com/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21191&authkey=ajl2uegqunsgc3q$all
 ||onedrive.live.com/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21192&authkey=acd_hx4bka3z0nw$all
 ||onedrive.live.com/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy$all
+||onedrive.live.com/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21107&authkey=alo4lep7wht05na$all
 ||onedrive.live.com/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21109&authkey=adnbm6mekgzvvh8$all
 ||onedrive.live.com/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!141&authkey=alya4infudqs53o$all
 ||onedrive.live.com/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!142&authkey=aiemnxi-s-5vrz0$all
@@ -5242,8 +5227,6 @@
 ||onedrive.live.com/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21350&authkey=ao-vuexoihzj7da$all
 ||onedrive.live.com/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2!142&authkey=ais88uad5aom6qu$all
 ||onedrive.live.com/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2%21142&authkey=ais88uad5aom6qu$all
-||onedrive.live.com/download?cid=e86539a3497e46a2&resid=e86539a3497e46a2!120&authkey=amd6o5flalahjsy$all
-||onedrive.live.com/download?cid=e86539a3497e46a2&resid=e86539a3497e46a2%21120&authkey=amd6o5flalahjsy$all
 ||onedrive.live.com/download?cid=e97110434470423e&resid=e97110434470423e%21113&authkey=afowclex54if0g0$all
 ||onedrive.live.com/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw$all
 ||onedrive.live.com/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw$all
@@ -5296,6 +5279,7 @@
 ||onedrive.live.com/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta$all
 ||online.creedglobal.in$all
 ||onlinestatis.bar$all
+||ont.proman.id$all
 ||open.warehousesaas.co.uk$all
 ||opolis.io$all
 ||optimus.com.sg$all
@@ -5303,6 +5287,8 @@
 ||order.bizpeed.com$all
 ||orientgatewayltd.com$all
 ||orion445.com$all
+||oserve.pk$all
+||otolithenrichment.fahadjutt.com$all
 ||ottimade.com$all
 ||ourteam.searchkero.com$all
 ||ozemag.com$all
@@ -5325,6 +5311,7 @@
 ||paths.elin.co.za$all
 ||paulmercier.biz$all
 ||payerrealty.com$all
+||payments.atifsiddiqui.me$all
 ||pcsoori.com$all
 ||pd.oceaniarp.net$all
 ||perpus.onlineman7-jombang.sch.id$all
@@ -5339,6 +5326,7 @@
 ||pierreconsulting.info/wp-admin/llc/mwcacs65xienqdp/$all
 ||pink99.com$all
 ||pioneiraagronegocio.com.br/bayesian-forecasting-amj5e/s5hqmf6/$all
+||pizzabarletta.com.br$all
 ||plasfan.ind.br$all
 ||pmglance.startwriteup.com$all
 ||pokojewewladyslawowie.pl$all
@@ -5348,17 +5336,15 @@
 ||posmicrosystems.com$all
 ||poulman.panagiotopoulos-tours.gr$all
 ||ppdb.smk-ciptaskill.sch.id$all
-||pptvideotemplates.com$all
 ||prestasicash.com.ar$all
 ||prestigehomeautomation.net$all
 ||prishaartcreations.com$all
 ||procrossover.ru/wp-content/uploads/2020/10/skoda22.jpg$all
 ||procrossover.ru/wp-content/uploads/2020/10/skodaqq.jpg$all
 ||production.sparshims.com$all
-||productprecise.com$all
-||prof-dr-ahmedalmoatasem.com$all
 ||programaoperadoronline.com.br$all
 ||project.exquitec.com$all
+||promolyko.com$all
 ||promotoradescomplica.com.br$all
 ||promoversdubai.com$all
 ||propertiq.elin.co.za$all
@@ -5371,7 +5357,7 @@
 ||pujashoppe.in$all
 ||punchdialogues.com$all
 ||punjabdevelopersassociation.com.pk$all
-||purefoe.top$all
+||pvcprinting.co.uk$all
 ||qadir.tickfa.ir$all
 ||qatarglobalconsulting.com$all
 ||qjbutterflyevents.co.za/wp-admin/zzcoiatsr5wujrwagsgbnm2wkjxldvgu/$all
@@ -5401,7 +5387,6 @@
 ||raw.githubusercontent.com/tennc/webshell/master/other/small_shell.txt$all
 ||rc.ixiaoyang.cn$all
 ||readymmade.com$all
-||realtheprocess.co$all
 ||redchillicrackers.com$all
 ||reifenquick.de$all
 ||relaxindulge.co.nz$all
@@ -5452,7 +5437,6 @@
 ||sarakem.cl$all
 ||sasystemsuk.com$all
 ||savasaachi.systems$all
-||savingchintu.com$all
 ||scarfaceindustries.com$all
 ||scglobal.co.th$all
 ||schalke04rss.de$all
@@ -5460,10 +5444,8 @@
 ||schoolbustracker.softgig.co.ke$all
 ||sec-doc-w.com$all
 ||secure-doc-reader.com$all
-||sefp-boispro.fr$all
 ||segalsmetals.elin.co.za$all
 ||sellmyphonela.com$all
-||selltechtoday.com$all
 ||senbiaojita.com$all
 ||sendspace.com/pro/dl/q05z91$all
 ||sentierodelviandante.ml$all
@@ -5481,7 +5463,6 @@
 ||shivakunwar.com.np$all
 ||shoblasaathitrust.org$all
 ||shooka-co.com$all
-||shop.clarostudio.ro$all
 ||shop.goldspot.agency$all
 ||shopsofe.com$all
 ||shribharatvatika.com/ey4lpx8rx.zip$all
@@ -5494,11 +5475,11 @@
 ||simoneporzi.it$all
 ||simplithy.co.uk$all
 ||sindicato1ucm.cl$all
+||sindpol.tiejuris.com.br$all
 ||sinergidwireka.com$all
 ||sipahielektrik.com$all
 ||siperb.in$all
 ||sistelligent.com$all
-||site.sjc.co.ke$all
 ||sites.google.com/site/stormqk/dn/stormagent.apk?attredirects=0$all
 ||skkksolo.beweiretail.com$all
 ||skyflyfares.com$all
@@ -5509,7 +5490,6 @@
 ||smokeandgrowrichtour.com$all
 ||smokesolutionindia.com$all
 ||sobethuacademy.com$all
-||soft.110route.com$all
 ||soft.officelabo.net$all
 ||sohs.conceptechs.info$all
 ||solar.amazingtribe.lk$all
@@ -5518,11 +5498,11 @@
 ||somir.com.mx$all
 ||soralapps.com$all
 ||sorteio.orgaostalita.com.br$all
+||sosgsm.fr$all
 ||sota-france.fr$all
 ||sowingminerals.cl$all
 ||space.proactint.org$all
 ||spaceframe.mobi.space-frame.co.za$all
-||specfloors.net$all
 ||special-key.cf$all
 ||spent.com.pl$all
 ||spetsesyachtcharter.gr$all
@@ -5564,6 +5544,7 @@
 ||support-4-free.com$all
 ||support.clz.kr$all
 ||supportit.online$all
+||surestdysbonescagexc.dns.army$all
 ||sw.yourpageserver.com$all
 ||sweaty.dk$all
 ||sweet-diet.com$all
@@ -5589,12 +5570,12 @@
 ||tc.snpsresidential.com$all
 ||tcy.198424.com$all
 ||tdsp.yngw518.com$all
-||tech332.synology.me$all
 ||techgms.com$all
 ||technogreen.crmmanivela.com$all
 ||technohub.searchkero.com$all
 ||technologydistilled.com/a-nurse-ss8d9/z/$all
 ||tecnicaencolectores.com.mx$all
+||tecnologyschool.com$all
 ||teduae.com$all
 ||teleargentina.com$all
 ||telescopelms.com$all
@@ -5602,9 +5583,9 @@
 ||temptmag.com$all
 ||tennisafrica.com$all
 ||tentandoserfitness.000webhostapp.com$all
-||tepresto.net.pe$all
 ||test.adventser.com$all
 ||test.letraele.es$all
+||test.typoten.com$all
 ||test.wanepghana.org$all
 ||test1.asistencia247.com$all
 ||test1.milenial.id$all
@@ -5617,9 +5598,7 @@
 ||teteaffiche.stephanebillon.com$all
 ||tewoerd.eu$all
 ||textile.softberg.ro$all
-||texts.bfftexts.com$all
 ||texturesbyvinita.com$all
-||tharringtonsponsorship.com$all
 ||thecleaningladiespdx.com$all
 ||thecreativecafe.co.uk$all
 ||thefuturelife.in$all
@@ -5627,12 +5606,11 @@
 ||thehouseofpragya.com$all
 ||thekassia.co.uk$all
 ||thelaunchpadteam.com$all
-||thelekhak.com$all
 ||thelogicalgroup.co.uk$all
 ||thesummitpc.net$all
 ||theurbantutors.com$all
+||thewwpc.com$all
 ||thosewebbs.com$all
-||thriveink.com$all
 ||tianangdep.com$all
 ||tickfood.tickme.lk$all
 ||tickjobs.tickme.lk$all
@@ -5667,7 +5645,6 @@
 ||tulli.info$all
 ||tupperware.michaelroberge.ca$all
 ||turanggaresources.com$all
-||tushartyagiji.digitalswagger.in$all
 ||uat.indianfilmzone.com$all
 ||ublretailerdemo.cstdevs.com$all
 ||udesk.searchkero.com$all
@@ -5677,7 +5654,6 @@
 ||unicorpbrunei.com$all
 ||uniengrisb.com$all
 ||unisoftcc.com$all
-||unitedpestsolutionstx.com$all
 ||unyazitelecom.com$all
 ||upcbpta.com$all
 ||urbane.dezinetimes.com$all
@@ -5705,6 +5681,7 @@
 ||vivationdesign.com$all
 ||viveirodoiscorregos.com.br$all
 ||vksales.com$all
+||vladimirinternational.com$all
 ||vniel.co.kr/gnuboard/data/scan/amowvegfrt9ja/$all
 ||vniel.co.kr/gnuboard/data/scan/fu6jvxzzs46uqlp7l/$all
 ||vokasi.ub.ac.id$all
@@ -5713,11 +5690,11 @@
 ||vstsample.com$all
 ||vtube.fadlymotivator.com$all
 ||vvsskmodinationalschool.com$all
-||wahrewah.nl$all
 ||wanepliberia.org$all
 ||wanepniger.org$all
 ||weareactum.com$all
 ||web.eng.ubu.ac.th$all
+||web.geetle.ga$all
 ||web.geomegasoft.net$all
 ||web.mit.edu/kolya/.f/root/net.mit.edu/net/user/chris/winnt/mit_agenda2a.doc$all
 ||web.mit.edu/kolya/.f/root/net.mit.edu/sipb/user/kolya/afs/root.afs/net/user/chris/winnt/mit_agenda2a.doc$all
@@ -5738,14 +5715,13 @@
 ||whcms.yourpageserver.com$all
 ||whiteglovetailgate.com$all
 ||whiteresponse.com$all
+||whynt.xyz$all
 ||wi522012.ferozo.com$all
 ||wikalen.co.za$all
 ||wikileaks.org/syria-files/attach/222/222051_instruction.zip$all
 ||wildnights.co.uk$all
 ||wildtrust.mediadevstaging.com$all
 ||wimbamusica.com$all
-||windcomtechnologies.com$all
-||winnercircle.it$all
 ||wishesconcierge.com$all
 ||woezon.agency$all
 ||wolfgang-brodte.de$all
@@ -5761,7 +5737,6 @@
 ||xia.beihaixue.com$all
 ||xixaoclothing.com$all
 ||xk.996is.com$all
-||xmp.myracingaccounts.com$all
 ||xn--80akinnkiib6h.xn--90ais$all
 ||xn--polimerbizmimarlk-rvc.com$all
 ||ybom.urbanolab.com$all
@@ -5773,5 +5748,6 @@
 ||yskadvisors.com$all
 ||yummyyogaudaipur.com$all
 ||yzkzixun.com$all
+||zakra.tecnasulstore.com.br$all
 ||zytrox.tk$all
 ||zz.690tx.com$all
diff --git a/urlhaus-filter-ag.txt b/urlhaus-filter-ag.txt
index 5c12b4f3..f42a0f0f 100644
--- a/urlhaus-filter-ag.txt
+++ b/urlhaus-filter-ag.txt
@@ -1,5 +1,5 @@
 ! Title: Malicious URL Blocklist (AdGuard)
-! Updated: Thu, 25 Mar 2021 12:12:40 UTC
+! Updated: Fri, 26 Mar 2021 00:12:29 UTC
 ! Expires: 1 day (update frequency)
 ! Homepage: https://gitlab.com/curben/urlhaus-filter
 ! License: https://gitlab.com/curben/urlhaus-filter#license
@@ -1024,6 +1024,7 @@
 ||1.58.206.122$all
 ||1.58.206.199$all
 ||1.58.220.198$all
+||1.58.223.96$all
 ||1.58.50.67$all
 ||1.59.181.177$all
 ||1.59.249.83$all
@@ -3600,6 +3601,7 @@
 ||103.217.116.166$all
 ||103.217.116.245$all
 ||103.217.117.108$all
+||103.217.117.134$all
 ||103.217.119.74$all
 ||103.217.119.75$all
 ||103.217.119.76$all
@@ -3670,6 +3672,7 @@
 ||103.217.121.228$all
 ||103.217.121.23$all
 ||103.217.121.231$all
+||103.217.121.234$all
 ||103.217.121.237$all
 ||103.217.121.238$all
 ||103.217.121.239$all
@@ -3735,6 +3738,7 @@
 ||103.217.123.2$all
 ||103.217.123.200$all
 ||103.217.123.204$all
+||103.217.123.210$all
 ||103.217.123.213$all
 ||103.217.123.216$all
 ||103.217.123.218$all
@@ -5207,6 +5211,7 @@
 ||103.78.183.4$all
 ||103.78.183.40$all
 ||103.78.21.238$all
+||103.78.22.157$all
 ||103.78.22.177$all
 ||103.78.22.207$all
 ||103.78.22.219$all
@@ -6684,6 +6689,7 @@
 ||104.168.151.198$all
 ||104.168.152.230$all
 ||104.168.157.45$all
+||104.168.158.127$all
 ||104.168.158.148$all
 ||104.168.158.248$all
 ||104.168.158.38$all
@@ -6778,6 +6784,7 @@
 ||104.168.96.11$all
 ||104.168.96.168$all
 ||104.168.96.194$all
+||104.168.98.105$all
 ||104.168.98.206$all
 ||104.168.99.220$all
 ||104.168.99.30$all
@@ -8390,6 +8397,7 @@
 ||106.36.159.125$all
 ||106.36.4.112$all
 ||106.37.121.250$all
+||106.4.138.95$all
 ||106.4.140.29$all
 ||106.4.209.123$all
 ||106.4.241.59$all
@@ -10194,6 +10202,7 @@
 ||110.244.46.196$all
 ||110.244.48.104$all
 ||110.244.51.22$all
+||110.247.151.4$all
 ||110.247.16.153$all
 ||110.247.16.64$all
 ||110.247.180.69$all
@@ -10818,6 +10827,7 @@
 ||111.165.186.127$all
 ||111.165.202.37$all
 ||111.165.207.179$all
+||111.165.21.195$all
 ||111.165.210.227$all
 ||111.165.210.249$all
 ||111.165.214.179$all
@@ -10850,6 +10860,7 @@
 ||111.165.255.240$all
 ||111.165.26.73$all
 ||111.165.27.112$all
+||111.165.28.234$all
 ||111.165.31.62$all
 ||111.165.33.132$all
 ||111.165.33.210$all
@@ -16985,6 +16996,7 @@
 ||112.246.18.70$all
 ||112.246.18.84$all
 ||112.246.18.99$all
+||112.246.180.49$all
 ||112.246.181.139$all
 ||112.246.184.252$all
 ||112.246.184.97$all
@@ -17235,6 +17247,7 @@
 ||112.247.247.234$all
 ||112.247.248.114$all
 ||112.247.248.14$all
+||112.247.248.76$all
 ||112.247.249.198$all
 ||112.247.249.82$all
 ||112.247.250.193$all
@@ -17922,6 +17935,7 @@
 ||112.249.205.67$all
 ||112.249.206.105$all
 ||112.249.206.52$all
+||112.249.206.69$all
 ||112.249.206.8$all
 ||112.249.207.154$all
 ||112.249.207.198$all
@@ -18285,6 +18299,7 @@
 ||112.249.78.69$all
 ||112.249.79.230$all
 ||112.249.79.88$all
+||112.249.79.98$all
 ||112.249.80.217$all
 ||112.249.80.53$all
 ||112.249.80.69$all
@@ -18567,6 +18582,7 @@
 ||112.252.41.80$all
 ||112.252.42.128$all
 ||112.252.43.218$all
+||112.252.46.212$all
 ||112.252.59.78$all
 ||112.252.66.17$all
 ||112.252.66.55$all
@@ -20164,6 +20180,7 @@
 ||112.93.7.60$all
 ||112.93.89.37$all
 ||112.94.188.182$all
+||112.94.188.230$all
 ||112.94.189.107$all
 ||112.95.12.157$all
 ||112.95.13.15$all
@@ -20529,6 +20546,7 @@
 ||113.104.237.236$all
 ||113.104.237.34$all
 ||113.104.237.36$all
+||113.104.237.52$all
 ||113.104.237.72$all
 ||113.104.237.74$all
 ||113.104.237.83$all
@@ -21250,6 +21268,7 @@
 ||113.116.150.101$all
 ||113.116.150.110$all
 ||113.116.150.144$all
+||113.116.150.147$all
 ||113.116.150.161$all
 ||113.116.150.176$all
 ||113.116.150.180$all
@@ -22455,6 +22474,7 @@
 ||113.118.13.222$all
 ||113.118.13.226$all
 ||113.118.13.26$all
+||113.118.13.29$all
 ||113.118.13.44$all
 ||113.118.13.47$all
 ||113.118.13.50$all
@@ -23961,6 +23981,7 @@
 ||113.201.24.202$all
 ||113.201.24.206$all
 ||113.201.24.24$all
+||113.201.24.26$all
 ||113.201.24.30$all
 ||113.201.24.4$all
 ||113.201.24.5$all
@@ -24402,6 +24423,7 @@
 ||113.234.185.255$all
 ||113.234.195.226$all
 ||113.234.197.125$all
+||113.234.224.130$all
 ||113.234.224.160$all
 ||113.234.231.172$all
 ||113.234.231.202$all
@@ -25301,6 +25323,7 @@
 ||113.81.112.13$all
 ||113.81.112.159$all
 ||113.81.112.228$all
+||113.81.112.35$all
 ||113.81.112.66$all
 ||113.81.112.72$all
 ||113.81.113.119$all
@@ -25822,6 +25845,7 @@
 ||113.87.248.159$all
 ||113.87.248.162$all
 ||113.87.248.163$all
+||113.87.248.177$all
 ||113.87.248.181$all
 ||113.87.248.206$all
 ||113.87.248.28$all
@@ -26008,6 +26032,7 @@
 ||113.88.1.69$all
 ||113.88.100.105$all
 ||113.88.100.117$all
+||113.88.100.120$all
 ||113.88.100.130$all
 ||113.88.100.160$all
 ||113.88.100.172$all
@@ -26633,6 +26658,7 @@
 ||113.88.241.9$all
 ||113.88.241.92$all
 ||113.88.241.98$all
+||113.88.242.0$all
 ||113.88.242.1$all
 ||113.88.242.10$all
 ||113.88.242.116$all
@@ -26961,6 +26987,7 @@
 ||113.89.244.91$all
 ||113.89.244.93$all
 ||113.89.245.118$all
+||113.89.245.13$all
 ||113.89.245.132$all
 ||113.89.245.144$all
 ||113.89.245.174$all
@@ -29689,6 +29716,7 @@
 ||115.171.238.92$all
 ||115.171.239.20$all
 ||115.171.239.25$all
+||115.171.239.28$all
 ||115.171.90.159$all
 ||115.171.91.155$all
 ||115.171.91.195$all
@@ -29860,6 +29888,7 @@
 ||115.201.37.74$all
 ||115.201.37.84$all
 ||115.201.37.88$all
+||115.201.38.185$all
 ||115.201.40.156$all
 ||115.201.40.65$all
 ||115.201.40.66$all
@@ -29933,6 +29962,7 @@
 ||115.202.187.124$all
 ||115.202.187.242$all
 ||115.202.187.61$all
+||115.202.188.84$all
 ||115.202.210.224$all
 ||115.202.210.228$all
 ||115.202.214.217$all
@@ -30261,6 +30291,7 @@
 ||115.213.176.80$all
 ||115.213.186.121$all
 ||115.213.186.152$all
+||115.213.187.251$all
 ||115.213.188.167$all
 ||115.213.198.25$all
 ||115.213.199.79$all
@@ -30754,6 +30785,7 @@
 ||115.48.130.177$all
 ||115.48.130.181$all
 ||115.48.130.184$all
+||115.48.130.187$all
 ||115.48.130.193$all
 ||115.48.130.196$all
 ||115.48.130.197$all
@@ -30917,6 +30949,7 @@
 ||115.48.135.123$all
 ||115.48.135.126$all
 ||115.48.135.150$all
+||115.48.135.151$all
 ||115.48.135.152$all
 ||115.48.135.154$all
 ||115.48.135.155$all
@@ -32471,6 +32504,7 @@
 ||115.48.200.103$all
 ||115.48.200.104$all
 ||115.48.200.114$all
+||115.48.200.115$all
 ||115.48.200.124$all
 ||115.48.200.126$all
 ||115.48.200.134$all
@@ -33718,6 +33752,7 @@
 ||115.49.113.126$all
 ||115.49.113.59$all
 ||115.49.116.148$all
+||115.49.116.237$all
 ||115.49.118.13$all
 ||115.49.12.164$all
 ||115.49.12.26$all
@@ -33835,6 +33870,7 @@
 ||115.49.150.203$all
 ||115.49.150.86$all
 ||115.49.151.207$all
+||115.49.152.10$all
 ||115.49.152.116$all
 ||115.49.152.140$all
 ||115.49.152.89$all
@@ -34329,6 +34365,7 @@
 ||115.49.241.61$all
 ||115.49.241.87$all
 ||115.49.241.94$all
+||115.49.242.100$all
 ||115.49.242.17$all
 ||115.49.242.79$all
 ||115.49.242.91$all
@@ -35161,6 +35198,7 @@
 ||115.49.79.87$all
 ||115.49.79.98$all
 ||115.49.8.244$all
+||115.49.80.117$all
 ||115.49.80.149$all
 ||115.49.80.161$all
 ||115.49.80.74$all
@@ -37026,6 +37064,7 @@
 ||115.50.201.85$all
 ||115.50.201.87$all
 ||115.50.201.91$all
+||115.50.202.11$all
 ||115.50.202.13$all
 ||115.50.202.131$all
 ||115.50.202.157$all
@@ -38460,6 +38499,7 @@
 ||115.50.240.216$all
 ||115.50.240.220$all
 ||115.50.240.228$all
+||115.50.240.230$all
 ||115.50.240.237$all
 ||115.50.240.252$all
 ||115.50.240.27$all
@@ -39876,6 +39916,7 @@
 ||115.50.61.228$all
 ||115.50.61.23$all
 ||115.50.61.233$all
+||115.50.61.247$all
 ||115.50.61.25$all
 ||115.50.61.252$all
 ||115.50.61.254$all
@@ -40008,6 +40049,7 @@
 ||115.50.64.177$all
 ||115.50.64.178$all
 ||115.50.64.179$all
+||115.50.64.182$all
 ||115.50.64.189$all
 ||115.50.64.212$all
 ||115.50.64.229$all
@@ -41127,6 +41169,7 @@
 ||115.51.107.156$all
 ||115.51.107.163$all
 ||115.51.107.164$all
+||115.51.107.18$all
 ||115.51.107.183$all
 ||115.51.107.193$all
 ||115.51.107.195$all
@@ -42444,6 +42487,7 @@
 ||115.52.20.97$all
 ||115.52.200.245$all
 ||115.52.201.220$all
+||115.52.201.231$all
 ||115.52.201.254$all
 ||115.52.202.73$all
 ||115.52.204.80$all
@@ -42487,6 +42531,7 @@
 ||115.52.22.140$all
 ||115.52.22.145$all
 ||115.52.22.149$all
+||115.52.22.162$all
 ||115.52.22.166$all
 ||115.52.22.177$all
 ||115.52.22.19$all
@@ -42743,6 +42788,7 @@
 ||115.52.35.151$all
 ||115.52.35.6$all
 ||115.52.36.27$all
+||115.52.37.164$all
 ||115.52.38.110$all
 ||115.52.38.132$all
 ||115.52.38.182$all
@@ -43947,6 +43993,7 @@
 ||115.54.159.16$all
 ||115.54.159.206$all
 ||115.54.159.33$all
+||115.54.160.25$all
 ||115.54.168.18$all
 ||115.54.168.190$all
 ||115.54.168.237$all
@@ -44733,6 +44780,7 @@
 ||115.54.212.205$all
 ||115.54.212.207$all
 ||115.54.212.22$all
+||115.54.212.227$all
 ||115.54.212.233$all
 ||115.54.212.239$all
 ||115.54.212.249$all
@@ -45046,6 +45094,7 @@
 ||115.54.240.128$all
 ||115.54.240.166$all
 ||115.54.240.170$all
+||115.54.240.173$all
 ||115.54.240.195$all
 ||115.54.240.197$all
 ||115.54.240.198$all
@@ -45221,6 +45270,7 @@
 ||115.54.69.60$all
 ||115.54.69.89$all
 ||115.54.69.9$all
+||115.54.70.108$all
 ||115.54.70.139$all
 ||115.54.70.150$all
 ||115.54.70.161$all
@@ -45267,6 +45317,7 @@
 ||115.54.73.254$all
 ||115.54.73.37$all
 ||115.54.73.42$all
+||115.54.73.50$all
 ||115.54.73.51$all
 ||115.54.74.109$all
 ||115.54.74.142$all
@@ -48108,6 +48159,7 @@
 ||115.55.211.247$all
 ||115.55.211.251$all
 ||115.55.211.4$all
+||115.55.211.41$all
 ||115.55.211.48$all
 ||115.55.211.54$all
 ||115.55.211.75$all
@@ -48510,6 +48562,7 @@
 ||115.55.3.155$all
 ||115.55.3.20$all
 ||115.55.3.204$all
+||115.55.3.36$all
 ||115.55.3.54$all
 ||115.55.30.105$all
 ||115.55.30.138$all
@@ -49826,6 +49879,7 @@
 ||115.56.136.124$all
 ||115.56.136.127$all
 ||115.56.136.141$all
+||115.56.136.144$all
 ||115.56.136.145$all
 ||115.56.136.146$all
 ||115.56.136.154$all
@@ -50716,6 +50770,7 @@
 ||115.56.154.14$all
 ||115.56.154.142$all
 ||115.56.154.145$all
+||115.56.154.147$all
 ||115.56.154.164$all
 ||115.56.154.17$all
 ||115.56.154.173$all
@@ -50833,6 +50888,7 @@
 ||115.56.156.30$all
 ||115.56.156.39$all
 ||115.56.156.53$all
+||115.56.156.54$all
 ||115.56.156.55$all
 ||115.56.156.6$all
 ||115.56.156.62$all
@@ -51163,6 +51219,7 @@
 ||115.56.177.192$all
 ||115.56.177.198$all
 ||115.56.177.2$all
+||115.56.177.202$all
 ||115.56.177.205$all
 ||115.56.177.214$all
 ||115.56.177.220$all
@@ -52963,6 +53020,7 @@
 ||115.58.132.194$all
 ||115.58.132.196$all
 ||115.58.132.197$all
+||115.58.132.199$all
 ||115.58.132.2$all
 ||115.58.132.205$all
 ||115.58.132.211$all
@@ -53608,6 +53666,7 @@
 ||115.58.167.23$all
 ||115.58.167.50$all
 ||115.58.167.78$all
+||115.58.167.90$all
 ||115.58.168.104$all
 ||115.58.168.117$all
 ||115.58.168.14$all
@@ -53747,6 +53806,7 @@
 ||115.58.20.147$all
 ||115.58.20.152$all
 ||115.58.20.180$all
+||115.58.20.186$all
 ||115.58.20.193$all
 ||115.58.20.197$all
 ||115.58.20.199$all
@@ -55040,6 +55100,7 @@
 ||115.59.198.181$all
 ||115.59.198.184$all
 ||115.59.198.194$all
+||115.59.198.200$all
 ||115.59.198.211$all
 ||115.59.198.215$all
 ||115.59.198.218$all
@@ -55591,6 +55652,7 @@
 ||115.59.215.74$all
 ||115.59.215.8$all
 ||115.59.215.95$all
+||115.59.215.96$all
 ||115.59.215.99$all
 ||115.59.216.103$all
 ||115.59.216.106$all
@@ -57073,6 +57135,7 @@
 ||115.59.90.149$all
 ||115.59.90.155$all
 ||115.59.90.182$all
+||115.59.90.197$all
 ||115.59.90.204$all
 ||115.59.90.22$all
 ||115.59.90.236$all
@@ -57195,6 +57258,7 @@
 ||115.60.201.105$all
 ||115.60.201.142$all
 ||115.60.201.144$all
+||115.60.201.176$all
 ||115.60.201.181$all
 ||115.60.201.186$all
 ||115.60.201.21$all
@@ -57842,6 +57906,7 @@
 ||115.61.118.182$all
 ||115.61.118.185$all
 ||115.61.118.189$all
+||115.61.118.201$all
 ||115.61.118.210$all
 ||115.61.118.226$all
 ||115.61.118.245$all
@@ -59521,6 +59586,7 @@
 ||115.61.97.250$all
 ||115.61.97.39$all
 ||115.61.97.46$all
+||115.61.97.55$all
 ||115.61.97.63$all
 ||115.61.97.65$all
 ||115.61.97.70$all
@@ -59753,6 +59819,7 @@
 ||115.62.152.143$all
 ||115.62.152.144$all
 ||115.62.152.206$all
+||115.62.152.207$all
 ||115.62.152.37$all
 ||115.62.152.55$all
 ||115.62.152.70$all
@@ -60267,6 +60334,7 @@
 ||115.63.130.140$all
 ||115.63.130.150$all
 ||115.63.130.161$all
+||115.63.130.162$all
 ||115.63.130.169$all
 ||115.63.130.170$all
 ||115.63.130.173$all
@@ -60567,6 +60635,7 @@
 ||115.63.140.216$all
 ||115.63.140.218$all
 ||115.63.140.236$all
+||115.63.140.242$all
 ||115.63.140.27$all
 ||115.63.140.32$all
 ||115.63.140.39$all
@@ -66910,6 +66979,7 @@
 ||115.96.87.95$all
 ||115.96.88.171$all
 ||115.96.90.226$all
+||115.96.92.151$all
 ||115.96.94.114$all
 ||115.97.102.100$all
 ||115.97.102.102$all
@@ -68386,6 +68456,7 @@
 ||115.97.142.175$all
 ||115.97.142.176$all
 ||115.97.142.178$all
+||115.97.142.18$all
 ||115.97.142.180$all
 ||115.97.142.182$all
 ||115.97.142.188$all
@@ -91411,6 +91482,7 @@
 ||116.24.152.157$all
 ||116.24.152.158$all
 ||116.24.152.164$all
+||116.24.152.217$all
 ||116.24.152.245$all
 ||116.24.152.34$all
 ||116.24.152.80$all
@@ -94037,6 +94109,7 @@
 ||116.72.202.80$all
 ||116.72.202.81$all
 ||116.72.202.83$all
+||116.72.202.87$all
 ||116.72.202.89$all
 ||116.72.202.90$all
 ||116.72.202.92$all
@@ -94078,6 +94151,7 @@
 ||116.72.203.14$all
 ||116.72.203.141$all
 ||116.72.203.142$all
+||116.72.203.143$all
 ||116.72.203.145$all
 ||116.72.203.146$all
 ||116.72.203.148$all
@@ -102334,6 +102408,7 @@
 ||116.74.83.90$all
 ||116.74.83.94$all
 ||116.74.83.98$all
+||116.74.84.65$all
 ||116.74.85.1$all
 ||116.74.85.131$all
 ||116.74.87.107$all
@@ -105658,6 +105733,7 @@
 ||116.75.194.137$all
 ||116.75.194.138$all
 ||116.75.194.139$all
+||116.75.194.14$all
 ||116.75.194.140$all
 ||116.75.194.141$all
 ||116.75.194.143$all
@@ -107852,6 +107928,7 @@
 ||116.75.214.51$all
 ||116.75.214.52$all
 ||116.75.214.53$all
+||116.75.214.56$all
 ||116.75.214.58$all
 ||116.75.214.59$all
 ||116.75.214.6$all
@@ -107881,6 +107958,7 @@
 ||116.75.214.96$all
 ||116.75.214.97$all
 ||116.75.214.98$all
+||116.75.214.99$all
 ||116.75.215.0$all
 ||116.75.215.1$all
 ||116.75.215.100$all
@@ -112647,6 +112725,7 @@
 ||117.194.149.247$all
 ||117.194.149.250$all
 ||117.194.149.252$all
+||117.194.149.26$all
 ||117.194.149.28$all
 ||117.194.149.33$all
 ||117.194.149.37$all
@@ -112991,6 +113070,7 @@
 ||117.194.160.8$all
 ||117.194.160.81$all
 ||117.194.160.83$all
+||117.194.160.84$all
 ||117.194.160.85$all
 ||117.194.160.87$all
 ||117.194.160.88$all
@@ -116424,6 +116504,7 @@
 ||117.202.70.224$all
 ||117.202.70.225$all
 ||117.202.70.226$all
+||117.202.70.227$all
 ||117.202.70.228$all
 ||117.202.70.229$all
 ||117.202.70.23$all
@@ -118622,6 +118703,7 @@
 ||117.213.11.106$all
 ||117.213.11.136$all
 ||117.213.11.205$all
+||117.213.11.225$all
 ||117.213.11.47$all
 ||117.213.11.50$all
 ||117.213.11.8$all
@@ -119041,6 +119123,7 @@
 ||117.213.42.153$all
 ||117.213.42.154$all
 ||117.213.42.157$all
+||117.213.42.158$all
 ||117.213.42.159$all
 ||117.213.42.16$all
 ||117.213.42.160$all
@@ -120080,6 +120163,7 @@
 ||117.213.9.58$all
 ||117.213.9.71$all
 ||117.213.9.77$all
+||117.213.9.78$all
 ||117.214.11.249$all
 ||117.214.11.8$all
 ||117.214.242.73$all
@@ -120377,6 +120461,7 @@
 ||117.215.248.208$all
 ||117.215.248.214$all
 ||117.215.248.217$all
+||117.215.248.223$all
 ||117.215.248.23$all
 ||117.215.248.237$all
 ||117.215.248.242$all
@@ -120415,6 +120500,7 @@
 ||117.215.249.20$all
 ||117.215.249.22$all
 ||117.215.249.221$all
+||117.215.249.23$all
 ||117.215.249.230$all
 ||117.215.249.240$all
 ||117.215.249.241$all
@@ -121002,6 +121088,7 @@
 ||117.222.161.65$all
 ||117.222.161.66$all
 ||117.222.161.67$all
+||117.222.161.68$all
 ||117.222.161.7$all
 ||117.222.161.70$all
 ||117.222.161.74$all
@@ -121270,6 +121357,7 @@
 ||117.222.163.148$all
 ||117.222.163.149$all
 ||117.222.163.15$all
+||117.222.163.150$all
 ||117.222.163.151$all
 ||117.222.163.153$all
 ||117.222.163.154$all
@@ -121396,6 +121484,7 @@
 ||117.222.163.59$all
 ||117.222.163.6$all
 ||117.222.163.60$all
+||117.222.163.61$all
 ||117.222.163.62$all
 ||117.222.163.63$all
 ||117.222.163.65$all
@@ -121407,6 +121496,7 @@
 ||117.222.163.70$all
 ||117.222.163.71$all
 ||117.222.163.72$all
+||117.222.163.73$all
 ||117.222.163.74$all
 ||117.222.163.77$all
 ||117.222.163.78$all
@@ -121774,6 +121864,7 @@
 ||117.222.165.28$all
 ||117.222.165.29$all
 ||117.222.165.3$all
+||117.222.165.31$all
 ||117.222.165.32$all
 ||117.222.165.33$all
 ||117.222.165.34$all
@@ -122221,6 +122312,7 @@
 ||117.222.168.114$all
 ||117.222.168.115$all
 ||117.222.168.116$all
+||117.222.168.119$all
 ||117.222.168.122$all
 ||117.222.168.123$all
 ||117.222.168.124$all
@@ -122241,6 +122333,7 @@
 ||117.222.168.181$all
 ||117.222.168.183$all
 ||117.222.168.185$all
+||117.222.168.186$all
 ||117.222.168.191$all
 ||117.222.168.194$all
 ||117.222.168.195$all
@@ -122307,6 +122400,7 @@
 ||117.222.169.112$all
 ||117.222.169.113$all
 ||117.222.169.114$all
+||117.222.169.115$all
 ||117.222.169.117$all
 ||117.222.169.12$all
 ||117.222.169.124$all
@@ -122522,6 +122616,7 @@
 ||117.222.171.192$all
 ||117.222.171.202$all
 ||117.222.171.203$all
+||117.222.171.205$all
 ||117.222.171.209$all
 ||117.222.171.217$all
 ||117.222.171.218$all
@@ -122670,6 +122765,7 @@
 ||117.222.172.9$all
 ||117.222.172.92$all
 ||117.222.172.94$all
+||117.222.172.97$all
 ||117.222.172.98$all
 ||117.222.173.10$all
 ||117.222.173.100$all
@@ -124124,6 +124220,7 @@
 ||117.242.210.65$all
 ||117.242.210.67$all
 ||117.242.210.68$all
+||117.242.210.69$all
 ||117.242.210.7$all
 ||117.242.210.70$all
 ||117.242.210.71$all
@@ -124672,6 +124769,7 @@
 ||117.247.200.169$all
 ||117.247.200.170$all
 ||117.247.200.172$all
+||117.247.200.179$all
 ||117.247.200.181$all
 ||117.247.200.182$all
 ||117.247.200.185$all
@@ -124750,6 +124848,7 @@
 ||117.247.201.156$all
 ||117.247.201.158$all
 ||117.247.201.161$all
+||117.247.201.163$all
 ||117.247.201.172$all
 ||117.247.201.175$all
 ||117.247.201.179$all
@@ -124871,6 +124970,7 @@
 ||117.247.202.31$all
 ||117.247.202.32$all
 ||117.247.202.37$all
+||117.247.202.4$all
 ||117.247.202.46$all
 ||117.247.202.48$all
 ||117.247.202.50$all
@@ -124972,6 +125072,7 @@
 ||117.247.203.3$all
 ||117.247.203.31$all
 ||117.247.203.33$all
+||117.247.203.38$all
 ||117.247.203.39$all
 ||117.247.203.40$all
 ||117.247.203.45$all
@@ -126645,6 +126746,7 @@
 ||117.251.59.232$all
 ||117.251.59.237$all
 ||117.251.59.24$all
+||117.251.59.242$all
 ||117.251.59.243$all
 ||117.251.59.244$all
 ||117.251.59.246$all
@@ -127507,6 +127609,7 @@
 ||117.63.51.128$all
 ||117.63.53.15$all
 ||117.63.53.172$all
+||117.63.56.81$all
 ||117.63.69.253$all
 ||117.63.7.177$all
 ||117.63.7.192$all
@@ -127570,6 +127673,7 @@
 ||117.85.89.213$all
 ||117.85.95.220$all
 ||117.86.1.7$all
+||117.86.105.110$all
 ||117.86.110.91$all
 ||117.86.148.199$all
 ||117.86.155.77$all
@@ -127808,6 +127912,7 @@
 ||117.91.156.66$all
 ||117.91.172.11$all
 ||117.91.172.49$all
+||117.91.240.50$all
 ||117.91.241.17$all
 ||117.92.177.76$all
 ||117.92.196.126$all
@@ -129136,6 +129241,7 @@
 ||118.75.114.227$all
 ||118.75.115.154$all
 ||118.75.119.214$all
+||118.75.120.136$all
 ||118.75.120.209$all
 ||118.75.120.229$all
 ||118.75.120.98$all
@@ -129264,6 +129370,7 @@
 ||118.75.236.238$all
 ||118.75.239.142$all
 ||118.75.240.141$all
+||118.75.240.239$all
 ||118.75.240.9$all
 ||118.75.241.204$all
 ||118.75.241.26$all
@@ -129575,6 +129682,7 @@
 ||118.79.163.61$all
 ||118.79.163.86$all
 ||118.79.163.91$all
+||118.79.164.102$all
 ||118.79.164.108$all
 ||118.79.167.240$all
 ||118.79.167.41$all
@@ -130608,6 +130716,7 @@
 ||119.123.175.124$all
 ||119.123.175.126$all
 ||119.123.175.128$all
+||119.123.175.133$all
 ||119.123.175.139$all
 ||119.123.175.144$all
 ||119.123.175.145$all
@@ -131798,6 +131907,7 @@
 ||119.165.207.118$all
 ||119.165.208.188$all
 ||119.165.208.216$all
+||119.165.208.73$all
 ||119.165.209.0$all
 ||119.165.209.121$all
 ||119.165.209.127$all
@@ -132948,6 +133058,7 @@
 ||119.179.42.247$all
 ||119.179.43.1$all
 ||119.179.43.27$all
+||119.179.44.141$all
 ||119.179.44.157$all
 ||119.179.44.192$all
 ||119.179.45.108$all
@@ -133423,6 +133534,7 @@
 ||119.180.9.183$all
 ||119.180.9.209$all
 ||119.180.9.241$all
+||119.180.9.35$all
 ||119.180.90.121$all
 ||119.180.92.176$all
 ||119.180.92.224$all
@@ -135247,6 +135359,7 @@
 ||119.250.10.222$all
 ||119.250.117.131$all
 ||119.250.119.227$all
+||119.250.129.231$all
 ||119.250.132.83$all
 ||119.250.166.153$all
 ||119.250.218.177$all
@@ -135774,6 +135887,7 @@
 ||120.12.211.237$all
 ||120.12.212.231$all
 ||120.12.212.234$all
+||120.12.212.5$all
 ||120.12.213.82$all
 ||120.12.217.158$all
 ||120.12.217.9$all
@@ -136959,6 +137073,7 @@
 ||120.57.102.243$all
 ||120.57.102.246$all
 ||120.57.102.254$all
+||120.57.102.32$all
 ||120.57.102.46$all
 ||120.57.102.5$all
 ||120.57.102.58$all
@@ -139441,6 +139556,7 @@
 ||120.82.169.73$all
 ||120.82.170.40$all
 ||120.82.170.75$all
+||120.82.217.176$all
 ||120.82.217.197$all
 ||120.82.228.185$all
 ||120.82.38.219$all
@@ -139764,6 +139880,7 @@
 ||120.85.173.121$all
 ||120.85.173.126$all
 ||120.85.173.135$all
+||120.85.173.137$all
 ||120.85.173.143$all
 ||120.85.173.145$all
 ||120.85.173.149$all
@@ -139809,6 +139926,7 @@
 ||120.85.174.24$all
 ||120.85.174.30$all
 ||120.85.174.38$all
+||120.85.174.39$all
 ||120.85.174.41$all
 ||120.85.174.42$all
 ||120.85.174.45$all
@@ -140065,6 +140183,7 @@
 ||120.85.199.184$all
 ||120.85.199.19$all
 ||120.85.199.195$all
+||120.85.199.222$all
 ||120.85.199.242$all
 ||120.85.199.247$all
 ||120.85.199.253$all
@@ -140186,6 +140305,7 @@
 ||120.85.211.82$all
 ||120.85.211.84$all
 ||120.85.211.85$all
+||120.85.212.45$all
 ||120.85.232.107$all
 ||120.85.232.64$all
 ||120.85.234.15$all
@@ -140285,6 +140405,7 @@
 ||120.85.238.80$all
 ||120.85.238.87$all
 ||120.85.238.89$all
+||120.85.238.97$all
 ||120.85.239.100$all
 ||120.85.239.11$all
 ||120.85.239.113$all
@@ -140701,6 +140822,7 @@
 ||121.154.163.88$all
 ||121.154.190.19$all
 ||121.154.190.232$all
+||121.154.190.73$all
 ||121.154.226.39$all
 ||121.154.37.14$all
 ||121.154.39.26$all
@@ -141696,6 +141818,7 @@
 ||121.34.150.234$all
 ||121.34.150.251$all
 ||121.34.150.27$all
+||121.34.150.32$all
 ||121.34.150.36$all
 ||121.34.150.43$all
 ||121.34.150.45$all
@@ -142489,6 +142612,7 @@
 ||122.188.61.157$all
 ||122.188.61.231$all
 ||122.188.61.239$all
+||122.188.86.225$all
 ||122.189.101.23$all
 ||122.189.105.132$all
 ||122.189.105.250$all
@@ -142498,6 +142622,7 @@
 ||122.189.7.14$all
 ||122.190.115.86$all
 ||122.190.19.131$all
+||122.190.19.204$all
 ||122.190.192.182$all
 ||122.190.192.92$all
 ||122.190.244.85$all
@@ -143091,6 +143216,7 @@
 ||123.10.131.179$all
 ||123.10.131.204$all
 ||123.10.131.223$all
+||123.10.131.225$all
 ||123.10.131.245$all
 ||123.10.131.251$all
 ||123.10.131.47$all
@@ -143753,6 +143879,7 @@
 ||123.10.209.61$all
 ||123.10.209.65$all
 ||123.10.209.87$all
+||123.10.209.95$all
 ||123.10.21.116$all
 ||123.10.21.172$all
 ||123.10.21.184$all
@@ -143797,6 +143924,7 @@
 ||123.10.214.114$all
 ||123.10.214.129$all
 ||123.10.214.174$all
+||123.10.214.193$all
 ||123.10.214.25$all
 ||123.10.214.60$all
 ||123.10.214.75$all
@@ -144550,6 +144678,7 @@
 ||123.10.82.119$all
 ||123.10.82.192$all
 ||123.10.82.228$all
+||123.10.83.136$all
 ||123.10.84.166$all
 ||123.10.84.18$all
 ||123.10.84.187$all
@@ -145334,6 +145463,7 @@
 ||123.11.174.47$all
 ||123.11.174.61$all
 ||123.11.175.108$all
+||123.11.175.136$all
 ||123.11.175.190$all
 ||123.11.175.197$all
 ||123.11.175.227$all
@@ -147114,6 +147244,7 @@
 ||123.12.229.211$all
 ||123.12.229.232$all
 ||123.12.229.24$all
+||123.12.229.243$all
 ||123.12.229.25$all
 ||123.12.229.252$all
 ||123.12.229.253$all
@@ -147531,6 +147662,7 @@
 ||123.12.35.198$all
 ||123.12.35.29$all
 ||123.12.36.167$all
+||123.12.36.185$all
 ||123.12.36.193$all
 ||123.12.36.3$all
 ||123.12.36.54$all
@@ -148139,6 +148271,7 @@
 ||123.13.100.254$all
 ||123.13.101.202$all
 ||123.13.101.30$all
+||123.13.101.56$all
 ||123.13.102.179$all
 ||123.13.102.204$all
 ||123.13.102.205$all
@@ -148445,6 +148578,7 @@
 ||123.13.30.167$all
 ||123.13.30.2$all
 ||123.13.30.219$all
+||123.13.30.75$all
 ||123.13.31.104$all
 ||123.13.31.144$all
 ||123.13.31.175$all
@@ -150451,6 +150585,7 @@
 ||123.14.205.198$all
 ||123.14.205.212$all
 ||123.14.205.223$all
+||123.14.205.23$all
 ||123.14.205.236$all
 ||123.14.205.241$all
 ||123.14.205.246$all
@@ -152262,6 +152397,7 @@
 ||123.183.123.153$all
 ||123.183.123.187$all
 ||123.183.123.212$all
+||123.183.123.41$all
 ||123.183.123.5$all
 ||123.183.124.131$all
 ||123.183.124.18$all
@@ -153693,6 +153829,7 @@
 ||123.4.179.75$all
 ||123.4.179.8$all
 ||123.4.179.82$all
+||123.4.180.137$all
 ||123.4.180.152$all
 ||123.4.180.156$all
 ||123.4.180.171$all
@@ -153740,6 +153877,7 @@
 ||123.4.184.8$all
 ||123.4.185.112$all
 ||123.4.185.12$all
+||123.4.185.137$all
 ||123.4.185.14$all
 ||123.4.185.168$all
 ||123.4.185.220$all
@@ -156555,6 +156693,7 @@
 ||123.5.145.23$all
 ||123.5.145.233$all
 ||123.5.145.242$all
+||123.5.145.245$all
 ||123.5.145.248$all
 ||123.5.145.42$all
 ||123.5.145.55$all
@@ -157751,6 +157890,7 @@
 ||123.5.22.110$all
 ||123.5.22.175$all
 ||123.5.22.210$all
+||123.5.22.220$all
 ||123.5.22.221$all
 ||123.5.22.238$all
 ||123.5.22.49$all
@@ -158429,6 +158569,7 @@
 ||123.8.183.124$all
 ||123.8.183.145$all
 ||123.8.183.185$all
+||123.8.183.194$all
 ||123.8.183.207$all
 ||123.8.183.31$all
 ||123.8.183.46$all
@@ -159425,6 +159566,7 @@
 ||123.9.103.190$all
 ||123.9.103.200$all
 ||123.9.103.23$all
+||123.9.103.252$all
 ||123.9.103.36$all
 ||123.9.103.53$all
 ||123.9.103.61$all
@@ -161546,6 +161688,7 @@
 ||124.130.31.18$all
 ||124.130.40.15$all
 ||124.130.40.162$all
+||124.130.40.31$all
 ||124.130.56.200$all
 ||124.130.56.42$all
 ||124.130.57.12$all
@@ -162189,6 +162332,7 @@
 ||124.131.24.86$all
 ||124.131.25.69$all
 ||124.131.26.238$all
+||124.131.26.243$all
 ||124.131.26.78$all
 ||124.131.28.172$all
 ||124.131.28.196$all
@@ -163601,6 +163745,7 @@
 ||124.94.244.153$all
 ||124.94.57.133$all
 ||124.95.16.252$all
+||124.95.17.41$all
 ||124.95.81.24$all
 ||124.com.ua$all
 ||124.cpanel.realwebsitesite.com$all
@@ -164017,6 +164162,7 @@
 ||125.126.66.6$all
 ||125.126.67.145$all
 ||125.126.69.198$all
+||125.126.69.95$all
 ||125.126.71.207$all
 ||125.126.72.174$all
 ||125.126.73.123$all
@@ -164147,6 +164293,7 @@
 ||125.160.137.80$all
 ||125.160.213.219$all
 ||125.161.14.114$all
+||125.161.70.34$all
 ||125.161.96.233$all
 ||125.162.65.174$all
 ||125.163.199.90$all
@@ -164932,6 +165079,7 @@
 ||125.40.136.22$all
 ||125.40.136.220$all
 ||125.40.136.222$all
+||125.40.136.25$all
 ||125.40.136.252$all
 ||125.40.136.253$all
 ||125.40.136.33$all
@@ -165477,6 +165625,7 @@
 ||125.40.234.169$all
 ||125.40.234.73$all
 ||125.40.235.80$all
+||125.40.237.130$all
 ||125.40.24.117$all
 ||125.40.24.134$all
 ||125.40.24.143$all
@@ -167356,6 +167505,7 @@
 ||125.41.200.172$all
 ||125.41.200.181$all
 ||125.41.200.188$all
+||125.41.200.189$all
 ||125.41.200.193$all
 ||125.41.200.203$all
 ||125.41.200.210$all
@@ -169357,6 +169507,7 @@
 ||125.42.120.98$all
 ||125.42.121.101$all
 ||125.42.121.103$all
+||125.42.121.106$all
 ||125.42.121.108$all
 ||125.42.121.109$all
 ||125.42.121.11$all
@@ -169656,6 +169807,7 @@
 ||125.42.124.88$all
 ||125.42.124.93$all
 ||125.42.124.97$all
+||125.42.125.103$all
 ||125.42.125.107$all
 ||125.42.125.110$all
 ||125.42.125.115$all
@@ -170459,6 +170611,7 @@
 ||125.42.97.100$all
 ||125.42.97.101$all
 ||125.42.97.102$all
+||125.42.97.103$all
 ||125.42.97.119$all
 ||125.42.97.122$all
 ||125.42.97.123$all
@@ -170717,6 +170870,7 @@
 ||125.43.105.129$all
 ||125.43.105.135$all
 ||125.43.105.149$all
+||125.43.105.157$all
 ||125.43.105.158$all
 ||125.43.105.168$all
 ||125.43.105.172$all
@@ -171001,6 +171155,7 @@
 ||125.43.13.92$all
 ||125.43.130.108$all
 ||125.43.130.23$all
+||125.43.130.232$all
 ||125.43.130.24$all
 ||125.43.131.111$all
 ||125.43.131.182$all
@@ -171349,6 +171504,7 @@
 ||125.43.21.146$all
 ||125.43.21.147$all
 ||125.43.21.152$all
+||125.43.21.157$all
 ||125.43.21.159$all
 ||125.43.21.161$all
 ||125.43.21.174$all
@@ -174476,6 +174632,7 @@
 ||125.44.211.83$all
 ||125.44.211.98$all
 ||125.44.212.105$all
+||125.44.212.107$all
 ||125.44.212.108$all
 ||125.44.212.109$all
 ||125.44.212.114$all
@@ -174936,6 +175093,7 @@
 ||125.44.230.125$all
 ||125.44.230.164$all
 ||125.44.230.176$all
+||125.44.230.191$all
 ||125.44.230.200$all
 ||125.44.230.226$all
 ||125.44.230.244$all
@@ -175398,6 +175556,7 @@
 ||125.44.31.61$all
 ||125.44.31.64$all
 ||125.44.31.69$all
+||125.44.31.79$all
 ||125.44.31.8$all
 ||125.44.31.82$all
 ||125.44.31.84$all
@@ -176650,6 +176809,7 @@
 ||125.45.57.231$all
 ||125.45.57.238$all
 ||125.45.57.247$all
+||125.45.57.249$all
 ||125.45.57.35$all
 ||125.45.57.46$all
 ||125.45.57.50$all
@@ -177200,6 +177360,7 @@
 ||125.45.90.131$all
 ||125.45.90.151$all
 ||125.45.90.153$all
+||125.45.90.158$all
 ||125.45.90.16$all
 ||125.45.90.184$all
 ||125.45.90.189$all
@@ -177318,6 +177479,7 @@
 ||125.46.137.54$all
 ||125.46.138.0$all
 ||125.46.138.10$all
+||125.46.138.117$all
 ||125.46.138.122$all
 ||125.46.138.149$all
 ||125.46.138.151$all
@@ -179996,6 +180158,7 @@
 ||125.47.251.96$all
 ||125.47.251.98$all
 ||125.47.252.105$all
+||125.47.252.106$all
 ||125.47.252.107$all
 ||125.47.252.109$all
 ||125.47.252.110$all
@@ -180213,6 +180376,7 @@
 ||125.47.255.94$all
 ||125.47.255.97$all
 ||125.47.28.150$all
+||125.47.28.217$all
 ||125.47.29.173$all
 ||125.47.29.191$all
 ||125.47.32.201$all
@@ -182345,10 +182509,12 @@
 ||125.99.207.92$all
 ||125.99.212.13$all
 ||125.99.220.105$all
+||125.99.220.202$all
 ||125.99.222.152$all
 ||125.99.222.245$all
 ||125.99.222.76$all
 ||125.99.223.227$all
+||125.99.223.26$all
 ||125.99.224.101$all
 ||125.99.224.102$all
 ||125.99.224.106$all
@@ -184214,6 +184380,7 @@
 ||134.209.202.202$all
 ||134.209.203.101$all
 ||134.209.203.205$all
+||134.209.203.221$all
 ||134.209.203.223$all
 ||134.209.203.70$all
 ||134.209.204.77$all
@@ -184721,6 +184888,7 @@
 ||139.170.181.68$all
 ||139.170.200.29$all
 ||139.170.206.148$all
+||139.170.228.166$all
 ||139.170.228.217$all
 ||139.170.228.55$all
 ||139.170.230.204$all
@@ -186133,6 +186301,7 @@
 ||140.237.255.239$all
 ||140.237.28.148$all
 ||140.237.29.28$all
+||140.237.30.113$all
 ||140.237.30.179$all
 ||140.237.30.188$all
 ||140.237.31.197$all
@@ -186143,6 +186312,7 @@
 ||140.237.4.82$all
 ||140.237.5.254$all
 ||140.237.5.41$all
+||140.237.5.43$all
 ||140.240.100.181$all
 ||140.240.100.94$all
 ||140.240.102.181$all
@@ -186931,6 +187101,8 @@
 ||149.255.15.121$all
 ||149.255.15.180$all
 ||149.255.15.182$all
+||149.255.15.191$all
+||149.255.15.235$all
 ||149.255.15.87$all
 ||149.255.36.133$all
 ||149.255.36.156$all
@@ -187182,6 +187354,7 @@
 ||151.226.2.198$all
 ||151.227.42.63$all
 ||151.232.180.152$all
+||151.232.249.222$all
 ||151.232.56.134$all
 ||151.233.52.223$all
 ||151.233.56.139$all
@@ -187316,6 +187489,7 @@
 ||152.173.25.125$all
 ||152.231.127.54$all
 ||152.231.25.253$all
+||152.241.13.197$all
 ||152.241.13.246$all
 ||152.241.24.181$all
 ||152.241.33.96$all
@@ -187548,6 +187722,7 @@
 ||153.34.65.168$all
 ||153.34.67.119$all
 ||153.34.86.53$all
+||153.35.111.46$all
 ||153.35.141.25$all
 ||153.35.141.60$all
 ||153.35.141.74$all
@@ -187748,6 +187923,7 @@
 ||157.119.214.172$all
 ||157.119.214.233$all
 ||157.119.215.224$all
+||157.122.105.142$all
 ||157.122.106.12$all
 ||157.230.0.237$all
 ||157.230.1.18$all
@@ -189498,6 +189674,7 @@
 ||163.125.181.187$all
 ||163.125.181.76$all
 ||163.125.181.87$all
+||163.125.183.111$all
 ||163.125.183.142$all
 ||163.125.183.180$all
 ||163.125.183.75$all
@@ -189622,6 +189799,7 @@
 ||163.125.200.6$all
 ||163.125.200.64$all
 ||163.125.200.70$all
+||163.125.200.72$all
 ||163.125.200.73$all
 ||163.125.200.75$all
 ||163.125.200.76$all
@@ -189679,6 +189857,7 @@
 ||163.125.202.158$all
 ||163.125.202.159$all
 ||163.125.202.16$all
+||163.125.202.174$all
 ||163.125.202.183$all
 ||163.125.202.186$all
 ||163.125.202.190$all
@@ -189696,6 +189875,7 @@
 ||163.125.202.4$all
 ||163.125.202.57$all
 ||163.125.202.72$all
+||163.125.202.74$all
 ||163.125.202.8$all
 ||163.125.202.83$all
 ||163.125.202.9$all
@@ -189706,6 +189886,7 @@
 ||163.125.203.146$all
 ||163.125.203.148$all
 ||163.125.203.154$all
+||163.125.203.179$all
 ||163.125.203.184$all
 ||163.125.203.198$all
 ||163.125.203.200$all
@@ -189784,6 +189965,7 @@
 ||163.125.207.0$all
 ||163.125.207.102$all
 ||163.125.207.116$all
+||163.125.207.125$all
 ||163.125.207.140$all
 ||163.125.207.143$all
 ||163.125.207.158$all
@@ -189868,6 +190050,7 @@
 ||163.125.248.230$all
 ||163.125.248.254$all
 ||163.125.250.176$all
+||163.125.250.202$all
 ||163.125.251.214$all
 ||163.125.251.225$all
 ||163.125.251.227$all
@@ -189889,6 +190072,7 @@
 ||163.125.30.28$all
 ||163.125.31.183$all
 ||163.125.34.24$all
+||163.125.37.201$all
 ||163.125.38.226$all
 ||163.125.4.131$all
 ||163.125.4.147$all
@@ -189932,6 +190116,7 @@
 ||163.125.68.229$all
 ||163.125.68.240$all
 ||163.125.68.243$all
+||163.125.68.29$all
 ||163.125.68.31$all
 ||163.125.68.65$all
 ||163.125.68.7$all
@@ -192422,6 +192607,7 @@
 ||171.125.65.115$all
 ||171.125.65.193$all
 ||171.125.65.202$all
+||171.125.65.22$all
 ||171.125.66.6$all
 ||171.125.68.45$all
 ||171.125.7.181$all
@@ -192673,6 +192859,7 @@
 ||171.34.114.167$all
 ||171.34.114.179$all
 ||171.34.114.180$all
+||171.34.114.181$all
 ||171.34.114.215$all
 ||171.34.114.217$all
 ||171.34.114.227$all
@@ -192884,6 +193071,7 @@
 ||171.36.251.189$all
 ||171.36.251.66$all
 ||171.36.41.151$all
+||171.36.42.154$all
 ||171.36.42.159$all
 ||171.36.42.3$all
 ||171.36.42.39$all
@@ -193579,6 +193767,7 @@
 ||172.245.5.120$all
 ||172.245.5.122$all
 ||172.245.5.185$all
+||172.245.5.190$all
 ||172.245.52.102$all
 ||172.245.52.122$all
 ||172.245.52.160$all
@@ -196970,6 +197159,7 @@
 ||175.11.193.118$all
 ||175.11.193.122$all
 ||175.11.193.157$all
+||175.11.193.66$all
 ||175.11.193.71$all
 ||175.11.193.82$all
 ||175.11.194.130$all
@@ -197130,6 +197320,7 @@
 ||175.145.200.51$all
 ||175.146.121.210$all
 ||175.146.16.118$all
+||175.146.17.227$all
 ||175.146.18.195$all
 ||175.146.19.126$all
 ||175.146.20.229$all
@@ -200180,6 +200371,7 @@
 ||178.141.159.159$all
 ||178.141.16.64$all
 ||178.141.160.15$all
+||178.141.161.129$all
 ||178.141.162.124$all
 ||178.141.162.211$all
 ||178.141.162.8$all
@@ -200573,8 +200765,10 @@
 ||178.175.0.225$all
 ||178.175.0.226$all
 ||178.175.0.229$all
+||178.175.0.232$all
 ||178.175.0.234$all
 ||178.175.0.236$all
+||178.175.0.239$all
 ||178.175.0.241$all
 ||178.175.0.246$all
 ||178.175.0.249$all
@@ -200644,6 +200838,7 @@
 ||178.175.1.178$all
 ||178.175.1.179$all
 ||178.175.1.186$all
+||178.175.1.187$all
 ||178.175.1.188$all
 ||178.175.1.193$all
 ||178.175.1.194$all
@@ -200663,6 +200858,7 @@
 ||178.175.1.247$all
 ||178.175.1.25$all
 ||178.175.1.250$all
+||178.175.1.252$all
 ||178.175.1.255$all
 ||178.175.1.26$all
 ||178.175.1.28$all
@@ -200738,8 +200934,10 @@
 ||178.175.10.255$all
 ||178.175.10.26$all
 ||178.175.10.28$all
+||178.175.10.34$all
 ||178.175.10.37$all
 ||178.175.10.41$all
+||178.175.10.42$all
 ||178.175.10.44$all
 ||178.175.10.46$all
 ||178.175.10.50$all
@@ -200886,6 +201084,7 @@
 ||178.175.101.203$all
 ||178.175.101.204$all
 ||178.175.101.205$all
+||178.175.101.207$all
 ||178.175.101.208$all
 ||178.175.101.209$all
 ||178.175.101.21$all
@@ -200994,6 +201193,7 @@
 ||178.175.102.216$all
 ||178.175.102.22$all
 ||178.175.102.220$all
+||178.175.102.221$all
 ||178.175.102.223$all
 ||178.175.102.225$all
 ||178.175.102.227$all
@@ -201129,6 +201329,7 @@
 ||178.175.104.104$all
 ||178.175.104.106$all
 ||178.175.104.11$all
+||178.175.104.110$all
 ||178.175.104.112$all
 ||178.175.104.114$all
 ||178.175.104.116$all
@@ -201150,6 +201351,7 @@
 ||178.175.104.152$all
 ||178.175.104.153$all
 ||178.175.104.154$all
+||178.175.104.155$all
 ||178.175.104.158$all
 ||178.175.104.16$all
 ||178.175.104.161$all
@@ -201205,6 +201407,7 @@
 ||178.175.104.54$all
 ||178.175.104.59$all
 ||178.175.104.62$all
+||178.175.104.64$all
 ||178.175.104.66$all
 ||178.175.104.69$all
 ||178.175.104.80$all
@@ -201233,6 +201436,7 @@
 ||178.175.105.121$all
 ||178.175.105.122$all
 ||178.175.105.124$all
+||178.175.105.125$all
 ||178.175.105.130$all
 ||178.175.105.131$all
 ||178.175.105.143$all
@@ -201285,6 +201489,7 @@
 ||178.175.105.255$all
 ||178.175.105.26$all
 ||178.175.105.27$all
+||178.175.105.28$all
 ||178.175.105.29$all
 ||178.175.105.3$all
 ||178.175.105.30$all
@@ -201314,6 +201519,7 @@
 ||178.175.105.90$all
 ||178.175.105.91$all
 ||178.175.105.93$all
+||178.175.105.94$all
 ||178.175.105.96$all
 ||178.175.106.100$all
 ||178.175.106.102$all
@@ -201370,6 +201576,7 @@
 ||178.175.106.219$all
 ||178.175.106.22$all
 ||178.175.106.220$all
+||178.175.106.222$all
 ||178.175.106.224$all
 ||178.175.106.226$all
 ||178.175.106.228$all
@@ -201385,6 +201592,7 @@
 ||178.175.106.25$all
 ||178.175.106.251$all
 ||178.175.106.252$all
+||178.175.106.253$all
 ||178.175.106.27$all
 ||178.175.106.28$all
 ||178.175.106.31$all
@@ -201582,6 +201790,7 @@
 ||178.175.108.227$all
 ||178.175.108.229$all
 ||178.175.108.23$all
+||178.175.108.232$all
 ||178.175.108.237$all
 ||178.175.108.239$all
 ||178.175.108.24$all
@@ -201621,6 +201830,7 @@
 ||178.175.108.88$all
 ||178.175.108.90$all
 ||178.175.108.93$all
+||178.175.108.94$all
 ||178.175.108.97$all
 ||178.175.108.98$all
 ||178.175.108.99$all
@@ -201636,6 +201846,7 @@
 ||178.175.109.121$all
 ||178.175.109.123$all
 ||178.175.109.126$all
+||178.175.109.127$all
 ||178.175.109.132$all
 ||178.175.109.134$all
 ||178.175.109.137$all
@@ -201661,6 +201872,7 @@
 ||178.175.109.19$all
 ||178.175.109.190$all
 ||178.175.109.191$all
+||178.175.109.193$all
 ||178.175.109.195$all
 ||178.175.109.196$all
 ||178.175.109.198$all
@@ -201705,6 +201917,7 @@
 ||178.175.109.71$all
 ||178.175.109.75$all
 ||178.175.109.77$all
+||178.175.109.78$all
 ||178.175.109.82$all
 ||178.175.109.83$all
 ||178.175.109.86$all
@@ -202107,6 +202320,7 @@
 ||178.175.112.90$all
 ||178.175.112.97$all
 ||178.175.112.99$all
+||178.175.113.0$all
 ||178.175.113.100$all
 ||178.175.113.106$all
 ||178.175.113.112$all
@@ -202270,6 +202484,7 @@
 ||178.175.114.242$all
 ||178.175.114.244$all
 ||178.175.114.245$all
+||178.175.114.247$all
 ||178.175.114.250$all
 ||178.175.114.251$all
 ||178.175.114.254$all
@@ -202319,6 +202534,7 @@
 ||178.175.115.112$all
 ||178.175.115.113$all
 ||178.175.115.116$all
+||178.175.115.12$all
 ||178.175.115.125$all
 ||178.175.115.126$all
 ||178.175.115.127$all
@@ -202362,6 +202578,7 @@
 ||178.175.115.20$all
 ||178.175.115.202$all
 ||178.175.115.205$all
+||178.175.115.206$all
 ||178.175.115.207$all
 ||178.175.115.208$all
 ||178.175.115.209$all
@@ -202395,6 +202612,7 @@
 ||178.175.115.37$all
 ||178.175.115.39$all
 ||178.175.115.4$all
+||178.175.115.40$all
 ||178.175.115.43$all
 ||178.175.115.45$all
 ||178.175.115.46$all
@@ -202443,6 +202661,7 @@
 ||178.175.116.143$all
 ||178.175.116.145$all
 ||178.175.116.147$all
+||178.175.116.15$all
 ||178.175.116.150$all
 ||178.175.116.152$all
 ||178.175.116.154$all
@@ -202477,6 +202696,7 @@
 ||178.175.116.226$all
 ||178.175.116.228$all
 ||178.175.116.23$all
+||178.175.116.236$all
 ||178.175.116.237$all
 ||178.175.116.238$all
 ||178.175.116.24$all
@@ -202644,6 +202864,7 @@
 ||178.175.118.133$all
 ||178.175.118.137$all
 ||178.175.118.138$all
+||178.175.118.139$all
 ||178.175.118.141$all
 ||178.175.118.143$all
 ||178.175.118.144$all
@@ -202829,6 +203050,7 @@
 ||178.175.12.109$all
 ||178.175.12.11$all
 ||178.175.12.111$all
+||178.175.12.114$all
 ||178.175.12.118$all
 ||178.175.12.12$all
 ||178.175.12.123$all
@@ -202949,6 +203171,7 @@
 ||178.175.120.189$all
 ||178.175.120.191$all
 ||178.175.120.193$all
+||178.175.120.196$all
 ||178.175.120.197$all
 ||178.175.120.20$all
 ||178.175.120.203$all
@@ -203174,6 +203397,7 @@
 ||178.175.122.246$all
 ||178.175.122.252$all
 ||178.175.122.254$all
+||178.175.122.26$all
 ||178.175.122.27$all
 ||178.175.122.28$all
 ||178.175.122.3$all
@@ -203617,6 +203841,7 @@
 ||178.175.126.93$all
 ||178.175.126.95$all
 ||178.175.126.99$all
+||178.175.127.10$all
 ||178.175.127.100$all
 ||178.175.127.102$all
 ||178.175.127.106$all
@@ -203632,6 +203857,7 @@
 ||178.175.127.120$all
 ||178.175.127.122$all
 ||178.175.127.125$all
+||178.175.127.129$all
 ||178.175.127.13$all
 ||178.175.127.130$all
 ||178.175.127.133$all
@@ -203661,6 +203887,7 @@
 ||178.175.127.185$all
 ||178.175.127.19$all
 ||178.175.127.190$all
+||178.175.127.192$all
 ||178.175.127.195$all
 ||178.175.127.197$all
 ||178.175.127.198$all
@@ -203683,6 +203910,7 @@
 ||178.175.127.231$all
 ||178.175.127.236$all
 ||178.175.127.237$all
+||178.175.127.238$all
 ||178.175.127.24$all
 ||178.175.127.240$all
 ||178.175.127.242$all
@@ -203924,6 +204152,7 @@
 ||178.175.15.225$all
 ||178.175.15.228$all
 ||178.175.15.229$all
+||178.175.15.232$all
 ||178.175.15.233$all
 ||178.175.15.236$all
 ||178.175.15.238$all
@@ -203932,6 +204161,7 @@
 ||178.175.15.241$all
 ||178.175.15.244$all
 ||178.175.15.245$all
+||178.175.15.246$all
 ||178.175.15.248$all
 ||178.175.15.25$all
 ||178.175.15.250$all
@@ -203946,6 +204176,7 @@
 ||178.175.15.35$all
 ||178.175.15.37$all
 ||178.175.15.38$all
+||178.175.15.44$all
 ||178.175.15.45$all
 ||178.175.15.47$all
 ||178.175.15.48$all
@@ -203974,10 +204205,12 @@
 ||178.175.15.97$all
 ||178.175.15.99$all
 ||178.175.16.1$all
+||178.175.16.10$all
 ||178.175.16.108$all
 ||178.175.16.110$all
 ||178.175.16.112$all
 ||178.175.16.113$all
+||178.175.16.114$all
 ||178.175.16.115$all
 ||178.175.16.118$all
 ||178.175.16.12$all
@@ -204009,6 +204242,7 @@
 ||178.175.16.181$all
 ||178.175.16.186$all
 ||178.175.16.189$all
+||178.175.16.193$all
 ||178.175.16.195$all
 ||178.175.16.196$all
 ||178.175.16.205$all
@@ -204180,6 +204414,7 @@
 ||178.175.18.249$all
 ||178.175.18.250$all
 ||178.175.18.253$all
+||178.175.18.27$all
 ||178.175.18.32$all
 ||178.175.18.42$all
 ||178.175.18.45$all
@@ -204251,6 +204486,7 @@
 ||178.175.19.224$all
 ||178.175.19.225$all
 ||178.175.19.227$all
+||178.175.19.229$all
 ||178.175.19.232$all
 ||178.175.19.236$all
 ||178.175.19.237$all
@@ -204582,6 +204818,7 @@
 ||178.175.22.188$all
 ||178.175.22.194$all
 ||178.175.22.203$all
+||178.175.22.207$all
 ||178.175.22.209$all
 ||178.175.22.210$all
 ||178.175.22.211$all
@@ -204598,6 +204835,7 @@
 ||178.175.22.237$all
 ||178.175.22.241$all
 ||178.175.22.245$all
+||178.175.22.248$all
 ||178.175.22.249$all
 ||178.175.22.255$all
 ||178.175.22.32$all
@@ -204695,6 +204933,7 @@
 ||178.175.23.55$all
 ||178.175.23.56$all
 ||178.175.23.58$all
+||178.175.23.6$all
 ||178.175.23.61$all
 ||178.175.23.69$all
 ||178.175.23.71$all
@@ -204760,6 +204999,7 @@
 ||178.175.24.222$all
 ||178.175.24.223$all
 ||178.175.24.227$all
+||178.175.24.230$all
 ||178.175.24.232$all
 ||178.175.24.238$all
 ||178.175.24.239$all
@@ -204826,6 +205066,7 @@
 ||178.175.25.164$all
 ||178.175.25.166$all
 ||178.175.25.168$all
+||178.175.25.169$all
 ||178.175.25.172$all
 ||178.175.25.173$all
 ||178.175.25.177$all
@@ -204917,6 +205158,7 @@
 ||178.175.26.161$all
 ||178.175.26.162$all
 ||178.175.26.164$all
+||178.175.26.165$all
 ||178.175.26.168$all
 ||178.175.26.169$all
 ||178.175.26.17$all
@@ -204941,6 +205183,7 @@
 ||178.175.26.207$all
 ||178.175.26.211$all
 ||178.175.26.214$all
+||178.175.26.215$all
 ||178.175.26.217$all
 ||178.175.26.218$all
 ||178.175.26.219$all
@@ -204964,6 +205207,7 @@
 ||178.175.26.3$all
 ||178.175.26.31$all
 ||178.175.26.32$all
+||178.175.26.34$all
 ||178.175.26.36$all
 ||178.175.26.38$all
 ||178.175.26.4$all
@@ -205059,12 +205303,14 @@
 ||178.175.27.25$all
 ||178.175.27.252$all
 ||178.175.27.30$all
+||178.175.27.32$all
 ||178.175.27.36$all
 ||178.175.27.38$all
 ||178.175.27.39$all
 ||178.175.27.4$all
 ||178.175.27.41$all
 ||178.175.27.47$all
+||178.175.27.48$all
 ||178.175.27.49$all
 ||178.175.27.5$all
 ||178.175.27.53$all
@@ -205168,6 +205414,7 @@
 ||178.175.28.7$all
 ||178.175.28.72$all
 ||178.175.28.74$all
+||178.175.28.75$all
 ||178.175.28.79$all
 ||178.175.28.8$all
 ||178.175.28.81$all
@@ -205185,6 +205432,7 @@
 ||178.175.29.106$all
 ||178.175.29.111$all
 ||178.175.29.114$all
+||178.175.29.12$all
 ||178.175.29.127$all
 ||178.175.29.128$all
 ||178.175.29.130$all
@@ -205296,6 +205544,7 @@
 ||178.175.3.190$all
 ||178.175.3.192$all
 ||178.175.3.193$all
+||178.175.3.194$all
 ||178.175.3.196$all
 ||178.175.3.199$all
 ||178.175.3.201$all
@@ -205380,6 +205629,7 @@
 ||178.175.30.178$all
 ||178.175.30.18$all
 ||178.175.30.180$all
+||178.175.30.181$all
 ||178.175.30.183$all
 ||178.175.30.185$all
 ||178.175.30.186$all
@@ -205573,6 +205823,7 @@
 ||178.175.32.221$all
 ||178.175.32.223$all
 ||178.175.32.227$all
+||178.175.32.229$all
 ||178.175.32.23$all
 ||178.175.32.230$all
 ||178.175.32.233$all
@@ -205601,6 +205852,7 @@
 ||178.175.32.70$all
 ||178.175.32.72$all
 ||178.175.32.77$all
+||178.175.32.83$all
 ||178.175.32.85$all
 ||178.175.32.87$all
 ||178.175.32.89$all
@@ -205637,6 +205889,7 @@
 ||178.175.33.165$all
 ||178.175.33.167$all
 ||178.175.33.170$all
+||178.175.33.173$all
 ||178.175.33.174$all
 ||178.175.33.177$all
 ||178.175.33.178$all
@@ -205649,6 +205902,7 @@
 ||178.175.33.198$all
 ||178.175.33.2$all
 ||178.175.33.202$all
+||178.175.33.205$all
 ||178.175.33.209$all
 ||178.175.33.21$all
 ||178.175.33.210$all
@@ -205735,6 +205989,7 @@
 ||178.175.34.21$all
 ||178.175.34.216$all
 ||178.175.34.217$all
+||178.175.34.219$all
 ||178.175.34.22$all
 ||178.175.34.223$all
 ||178.175.34.224$all
@@ -205763,6 +206018,7 @@
 ||178.175.34.49$all
 ||178.175.34.5$all
 ||178.175.34.53$all
+||178.175.34.56$all
 ||178.175.34.58$all
 ||178.175.34.60$all
 ||178.175.34.61$all
@@ -205909,11 +206165,13 @@
 ||178.175.36.172$all
 ||178.175.36.173$all
 ||178.175.36.174$all
+||178.175.36.176$all
 ||178.175.36.177$all
 ||178.175.36.182$all
 ||178.175.36.184$all
 ||178.175.36.187$all
 ||178.175.36.189$all
+||178.175.36.19$all
 ||178.175.36.192$all
 ||178.175.36.194$all
 ||178.175.36.198$all
@@ -206122,6 +206380,7 @@
 ||178.175.38.196$all
 ||178.175.38.2$all
 ||178.175.38.20$all
+||178.175.38.200$all
 ||178.175.38.203$all
 ||178.175.38.204$all
 ||178.175.38.206$all
@@ -206198,6 +206457,7 @@
 ||178.175.39.17$all
 ||178.175.39.174$all
 ||178.175.39.175$all
+||178.175.39.176$all
 ||178.175.39.181$all
 ||178.175.39.183$all
 ||178.175.39.190$all
@@ -206292,6 +206552,7 @@
 ||178.175.4.215$all
 ||178.175.4.216$all
 ||178.175.4.218$all
+||178.175.4.219$all
 ||178.175.4.220$all
 ||178.175.4.222$all
 ||178.175.4.233$all
@@ -206362,6 +206623,7 @@
 ||178.175.40.138$all
 ||178.175.40.139$all
 ||178.175.40.14$all
+||178.175.40.145$all
 ||178.175.40.149$all
 ||178.175.40.15$all
 ||178.175.40.151$all
@@ -206497,6 +206759,7 @@
 ||178.175.41.56$all
 ||178.175.41.57$all
 ||178.175.41.6$all
+||178.175.41.60$all
 ||178.175.41.62$all
 ||178.175.41.65$all
 ||178.175.41.66$all
@@ -206615,6 +206878,7 @@
 ||178.175.43.154$all
 ||178.175.43.157$all
 ||178.175.43.158$all
+||178.175.43.16$all
 ||178.175.43.162$all
 ||178.175.43.163$all
 ||178.175.43.165$all
@@ -206656,6 +206920,7 @@
 ||178.175.43.30$all
 ||178.175.43.31$all
 ||178.175.43.33$all
+||178.175.43.34$all
 ||178.175.43.37$all
 ||178.175.43.38$all
 ||178.175.43.41$all
@@ -206686,6 +206951,7 @@
 ||178.175.43.91$all
 ||178.175.43.93$all
 ||178.175.43.94$all
+||178.175.44.0$all
 ||178.175.44.100$all
 ||178.175.44.101$all
 ||178.175.44.102$all
@@ -206785,6 +207051,7 @@
 ||178.175.44.89$all
 ||178.175.44.9$all
 ||178.175.44.90$all
+||178.175.44.95$all
 ||178.175.45.10$all
 ||178.175.45.102$all
 ||178.175.45.107$all
@@ -206897,6 +207164,7 @@
 ||178.175.46.110$all
 ||178.175.46.114$all
 ||178.175.46.116$all
+||178.175.46.119$all
 ||178.175.46.120$all
 ||178.175.46.124$all
 ||178.175.46.125$all
@@ -206909,6 +207177,7 @@
 ||178.175.46.145$all
 ||178.175.46.149$all
 ||178.175.46.150$all
+||178.175.46.151$all
 ||178.175.46.152$all
 ||178.175.46.154$all
 ||178.175.46.158$all
@@ -207161,6 +207430,7 @@
 ||178.175.48.65$all
 ||178.175.48.66$all
 ||178.175.48.71$all
+||178.175.48.76$all
 ||178.175.48.80$all
 ||178.175.48.82$all
 ||178.175.48.85$all
@@ -207187,6 +207457,7 @@
 ||178.175.49.123$all
 ||178.175.49.126$all
 ||178.175.49.127$all
+||178.175.49.129$all
 ||178.175.49.136$all
 ||178.175.49.137$all
 ||178.175.49.138$all
@@ -207200,6 +207471,7 @@
 ||178.175.49.18$all
 ||178.175.49.180$all
 ||178.175.49.185$all
+||178.175.49.188$all
 ||178.175.49.189$all
 ||178.175.49.19$all
 ||178.175.49.194$all
@@ -207387,6 +207659,7 @@
 ||178.175.50.233$all
 ||178.175.50.236$all
 ||178.175.50.237$all
+||178.175.50.239$all
 ||178.175.50.248$all
 ||178.175.50.249$all
 ||178.175.50.27$all
@@ -207414,6 +207687,7 @@
 ||178.175.50.84$all
 ||178.175.50.86$all
 ||178.175.50.87$all
+||178.175.50.9$all
 ||178.175.50.90$all
 ||178.175.50.92$all
 ||178.175.50.95$all
@@ -207652,6 +207926,7 @@
 ||178.175.53.224$all
 ||178.175.53.225$all
 ||178.175.53.227$all
+||178.175.53.228$all
 ||178.175.53.229$all
 ||178.175.53.231$all
 ||178.175.53.233$all
@@ -207813,6 +208088,7 @@
 ||178.175.55.165$all
 ||178.175.55.167$all
 ||178.175.55.169$all
+||178.175.55.170$all
 ||178.175.55.191$all
 ||178.175.55.192$all
 ||178.175.55.194$all
@@ -207860,6 +208136,7 @@
 ||178.175.55.70$all
 ||178.175.55.72$all
 ||178.175.55.77$all
+||178.175.55.85$all
 ||178.175.55.86$all
 ||178.175.55.88$all
 ||178.175.55.91$all
@@ -208127,6 +208404,7 @@
 ||178.175.58.35$all
 ||178.175.58.39$all
 ||178.175.58.40$all
+||178.175.58.42$all
 ||178.175.58.43$all
 ||178.175.58.48$all
 ||178.175.58.49$all
@@ -208383,6 +208661,7 @@
 ||178.175.60.32$all
 ||178.175.60.34$all
 ||178.175.60.36$all
+||178.175.60.37$all
 ||178.175.60.41$all
 ||178.175.60.42$all
 ||178.175.60.46$all
@@ -208463,6 +208742,7 @@
 ||178.175.61.36$all
 ||178.175.61.37$all
 ||178.175.61.40$all
+||178.175.61.42$all
 ||178.175.61.43$all
 ||178.175.61.45$all
 ||178.175.61.52$all
@@ -208520,6 +208800,7 @@
 ||178.175.62.209$all
 ||178.175.62.211$all
 ||178.175.62.213$all
+||178.175.62.216$all
 ||178.175.62.219$all
 ||178.175.62.220$all
 ||178.175.62.222$all
@@ -208545,11 +208826,13 @@
 ||178.175.62.39$all
 ||178.175.62.42$all
 ||178.175.62.43$all
+||178.175.62.44$all
 ||178.175.62.45$all
 ||178.175.62.46$all
 ||178.175.62.50$all
 ||178.175.62.51$all
 ||178.175.62.56$all
+||178.175.62.70$all
 ||178.175.62.72$all
 ||178.175.62.74$all
 ||178.175.62.76$all
@@ -209046,6 +209329,7 @@
 ||178.175.67.78$all
 ||178.175.67.8$all
 ||178.175.67.82$all
+||178.175.67.83$all
 ||178.175.67.84$all
 ||178.175.67.86$all
 ||178.175.67.88$all
@@ -209170,6 +209454,7 @@
 ||178.175.69.140$all
 ||178.175.69.141$all
 ||178.175.69.143$all
+||178.175.69.148$all
 ||178.175.69.149$all
 ||178.175.69.153$all
 ||178.175.69.154$all
@@ -209182,6 +209467,7 @@
 ||178.175.69.166$all
 ||178.175.69.169$all
 ||178.175.69.171$all
+||178.175.69.173$all
 ||178.175.69.174$all
 ||178.175.69.175$all
 ||178.175.69.182$all
@@ -209429,6 +209715,7 @@
 ||178.175.70.92$all
 ||178.175.70.93$all
 ||178.175.70.94$all
+||178.175.71.1$all
 ||178.175.71.102$all
 ||178.175.71.103$all
 ||178.175.71.104$all
@@ -209522,6 +209809,7 @@
 ||178.175.71.59$all
 ||178.175.71.60$all
 ||178.175.71.63$all
+||178.175.71.64$all
 ||178.175.71.65$all
 ||178.175.71.68$all
 ||178.175.71.69$all
@@ -209545,6 +209833,7 @@
 ||178.175.72.101$all
 ||178.175.72.102$all
 ||178.175.72.108$all
+||178.175.72.109$all
 ||178.175.72.110$all
 ||178.175.72.111$all
 ||178.175.72.113$all
@@ -209672,6 +209961,7 @@
 ||178.175.73.199$all
 ||178.175.73.2$all
 ||178.175.73.21$all
+||178.175.73.211$all
 ||178.175.73.214$all
 ||178.175.73.216$all
 ||178.175.73.219$all
@@ -209705,6 +209995,7 @@
 ||178.175.73.6$all
 ||178.175.73.68$all
 ||178.175.73.7$all
+||178.175.73.71$all
 ||178.175.73.72$all
 ||178.175.73.76$all
 ||178.175.73.86$all
@@ -209909,6 +210200,7 @@
 ||178.175.76.11$all
 ||178.175.76.113$all
 ||178.175.76.119$all
+||178.175.76.121$all
 ||178.175.76.124$all
 ||178.175.76.125$all
 ||178.175.76.129$all
@@ -210166,6 +210458,7 @@
 ||178.175.78.92$all
 ||178.175.78.93$all
 ||178.175.78.94$all
+||178.175.78.97$all
 ||178.175.79.101$all
 ||178.175.79.105$all
 ||178.175.79.106$all
@@ -210325,7 +210618,9 @@
 ||178.175.8.9$all
 ||178.175.8.93$all
 ||178.175.8.94$all
+||178.175.8.97$all
 ||178.175.80.10$all
+||178.175.80.100$all
 ||178.175.80.103$all
 ||178.175.80.11$all
 ||178.175.80.110$all
@@ -210404,6 +210699,7 @@
 ||178.175.80.37$all
 ||178.175.80.4$all
 ||178.175.80.40$all
+||178.175.80.41$all
 ||178.175.80.43$all
 ||178.175.80.44$all
 ||178.175.80.46$all
@@ -210496,6 +210792,7 @@
 ||178.175.81.251$all
 ||178.175.81.252$all
 ||178.175.81.30$all
+||178.175.81.32$all
 ||178.175.81.44$all
 ||178.175.81.45$all
 ||178.175.81.49$all
@@ -210510,6 +210807,7 @@
 ||178.175.81.7$all
 ||178.175.81.70$all
 ||178.175.81.79$all
+||178.175.81.8$all
 ||178.175.81.80$all
 ||178.175.81.82$all
 ||178.175.81.83$all
@@ -210530,6 +210828,7 @@
 ||178.175.82.115$all
 ||178.175.82.117$all
 ||178.175.82.12$all
+||178.175.82.120$all
 ||178.175.82.122$all
 ||178.175.82.123$all
 ||178.175.82.126$all
@@ -210883,6 +211182,7 @@
 ||178.175.85.171$all
 ||178.175.85.172$all
 ||178.175.85.183$all
+||178.175.85.184$all
 ||178.175.85.185$all
 ||178.175.85.190$all
 ||178.175.85.192$all
@@ -210899,6 +211199,7 @@
 ||178.175.85.227$all
 ||178.175.85.228$all
 ||178.175.85.229$all
+||178.175.85.23$all
 ||178.175.85.230$all
 ||178.175.85.242$all
 ||178.175.85.243$all
@@ -210938,6 +211239,7 @@
 ||178.175.85.79$all
 ||178.175.85.8$all
 ||178.175.85.80$all
+||178.175.85.81$all
 ||178.175.85.83$all
 ||178.175.85.87$all
 ||178.175.85.89$all
@@ -210965,9 +211267,11 @@
 ||178.175.86.146$all
 ||178.175.86.15$all
 ||178.175.86.157$all
+||178.175.86.159$all
 ||178.175.86.160$all
 ||178.175.86.164$all
 ||178.175.86.165$all
+||178.175.86.166$all
 ||178.175.86.167$all
 ||178.175.86.169$all
 ||178.175.86.174$all
@@ -211032,6 +211336,7 @@
 ||178.175.86.81$all
 ||178.175.86.86$all
 ||178.175.86.90$all
+||178.175.86.92$all
 ||178.175.86.93$all
 ||178.175.86.96$all
 ||178.175.86.97$all
@@ -211040,6 +211345,7 @@
 ||178.175.87.101$all
 ||178.175.87.106$all
 ||178.175.87.107$all
+||178.175.87.108$all
 ||178.175.87.110$all
 ||178.175.87.113$all
 ||178.175.87.115$all
@@ -211213,6 +211519,7 @@
 ||178.175.88.51$all
 ||178.175.88.52$all
 ||178.175.88.53$all
+||178.175.88.57$all
 ||178.175.88.60$all
 ||178.175.88.64$all
 ||178.175.88.78$all
@@ -211249,8 +211556,11 @@
 ||178.175.89.150$all
 ||178.175.89.151$all
 ||178.175.89.153$all
+||178.175.89.157$all
 ||178.175.89.159$all
+||178.175.89.160$all
 ||178.175.89.168$all
+||178.175.89.169$all
 ||178.175.89.171$all
 ||178.175.89.173$all
 ||178.175.89.177$all
@@ -211327,6 +211637,7 @@
 ||178.175.9.132$all
 ||178.175.9.135$all
 ||178.175.9.138$all
+||178.175.9.139$all
 ||178.175.9.140$all
 ||178.175.9.153$all
 ||178.175.9.155$all
@@ -211350,6 +211661,7 @@
 ||178.175.9.196$all
 ||178.175.9.200$all
 ||178.175.9.21$all
+||178.175.9.210$all
 ||178.175.9.215$all
 ||178.175.9.217$all
 ||178.175.9.220$all
@@ -211390,12 +211702,14 @@
 ||178.175.9.92$all
 ||178.175.9.95$all
 ||178.175.9.98$all
+||178.175.90.104$all
 ||178.175.90.109$all
 ||178.175.90.11$all
 ||178.175.90.114$all
 ||178.175.90.115$all
 ||178.175.90.116$all
 ||178.175.90.119$all
+||178.175.90.122$all
 ||178.175.90.124$all
 ||178.175.90.127$all
 ||178.175.90.128$all
@@ -211530,8 +211844,10 @@
 ||178.175.91.219$all
 ||178.175.91.22$all
 ||178.175.91.221$all
+||178.175.91.223$all
 ||178.175.91.224$all
 ||178.175.91.23$all
+||178.175.91.230$all
 ||178.175.91.232$all
 ||178.175.91.236$all
 ||178.175.91.237$all
@@ -211694,6 +212010,7 @@
 ||178.175.93.144$all
 ||178.175.93.145$all
 ||178.175.93.147$all
+||178.175.93.148$all
 ||178.175.93.149$all
 ||178.175.93.15$all
 ||178.175.93.150$all
@@ -211722,6 +212039,7 @@
 ||178.175.93.219$all
 ||178.175.93.220$all
 ||178.175.93.223$all
+||178.175.93.224$all
 ||178.175.93.225$all
 ||178.175.93.226$all
 ||178.175.93.23$all
@@ -211739,6 +212057,7 @@
 ||178.175.93.30$all
 ||178.175.93.31$all
 ||178.175.93.33$all
+||178.175.93.34$all
 ||178.175.93.36$all
 ||178.175.93.38$all
 ||178.175.93.4$all
@@ -211762,6 +212081,7 @@
 ||178.175.93.8$all
 ||178.175.93.82$all
 ||178.175.93.89$all
+||178.175.93.90$all
 ||178.175.93.93$all
 ||178.175.93.95$all
 ||178.175.93.96$all
@@ -211886,6 +212206,7 @@
 ||178.175.95.119$all
 ||178.175.95.122$all
 ||178.175.95.126$all
+||178.175.95.132$all
 ||178.175.95.135$all
 ||178.175.95.136$all
 ||178.175.95.137$all
@@ -211927,6 +212248,7 @@
 ||178.175.95.228$all
 ||178.175.95.230$all
 ||178.175.95.236$all
+||178.175.95.237$all
 ||178.175.95.238$all
 ||178.175.95.24$all
 ||178.175.95.241$all
@@ -212048,6 +212370,7 @@
 ||178.175.96.97$all
 ||178.175.96.98$all
 ||178.175.96.99$all
+||178.175.97.1$all
 ||178.175.97.100$all
 ||178.175.97.101$all
 ||178.175.97.103$all
@@ -212066,6 +212389,7 @@
 ||178.175.97.129$all
 ||178.175.97.130$all
 ||178.175.97.132$all
+||178.175.97.135$all
 ||178.175.97.139$all
 ||178.175.97.140$all
 ||178.175.97.141$all
@@ -212079,6 +212403,7 @@
 ||178.175.97.163$all
 ||178.175.97.167$all
 ||178.175.97.168$all
+||178.175.97.17$all
 ||178.175.97.173$all
 ||178.175.97.175$all
 ||178.175.97.177$all
@@ -212263,6 +212588,7 @@
 ||178.175.99.222$all
 ||178.175.99.223$all
 ||178.175.99.225$all
+||178.175.99.226$all
 ||178.175.99.230$all
 ||178.175.99.233$all
 ||178.175.99.237$all
@@ -214549,6 +214875,7 @@
 ||180.188.241.79$all
 ||180.188.241.86$all
 ||180.188.241.91$all
+||180.188.247.140$all
 ||180.188.252.185$all
 ||180.188.252.37$all
 ||180.188.253.153$all
@@ -218318,6 +218645,7 @@
 ||182.113.232.248$all
 ||182.113.232.81$all
 ||182.113.233.120$all
+||182.113.233.129$all
 ||182.113.233.13$all
 ||182.113.233.20$all
 ||182.113.233.3$all
@@ -221864,6 +222192,7 @@
 ||182.116.103.68$all
 ||182.116.103.76$all
 ||182.116.103.77$all
+||182.116.103.81$all
 ||182.116.103.85$all
 ||182.116.103.90$all
 ||182.116.103.91$all
@@ -222132,6 +222461,7 @@
 ||182.116.108.177$all
 ||182.116.108.178$all
 ||182.116.108.179$all
+||182.116.108.180$all
 ||182.116.108.182$all
 ||182.116.108.183$all
 ||182.116.108.185$all
@@ -222724,6 +223054,7 @@
 ||182.116.119.110$all
 ||182.116.119.111$all
 ||182.116.119.122$all
+||182.116.119.129$all
 ||182.116.119.134$all
 ||182.116.119.139$all
 ||182.116.119.140$all
@@ -224407,6 +224738,7 @@
 ||182.116.99.132$all
 ||182.116.99.141$all
 ||182.116.99.142$all
+||182.116.99.150$all
 ||182.116.99.153$all
 ||182.116.99.160$all
 ||182.116.99.17$all
@@ -225995,6 +226327,7 @@
 ||182.117.29.202$all
 ||182.117.29.212$all
 ||182.117.29.216$all
+||182.117.29.220$all
 ||182.117.29.227$all
 ||182.117.29.228$all
 ||182.117.29.229$all
@@ -229121,6 +229454,7 @@
 ||182.119.13.107$all
 ||182.119.13.109$all
 ||182.119.13.119$all
+||182.119.13.141$all
 ||182.119.13.148$all
 ||182.119.13.159$all
 ||182.119.13.160$all
@@ -230154,6 +230488,7 @@
 ||182.119.191.87$all
 ||182.119.191.92$all
 ||182.119.196.160$all
+||182.119.196.182$all
 ||182.119.196.190$all
 ||182.119.199.158$all
 ||182.119.199.85$all
@@ -230827,6 +231162,7 @@
 ||182.119.227.188$all
 ||182.119.227.194$all
 ||182.119.227.199$all
+||182.119.227.20$all
 ||182.119.227.207$all
 ||182.119.227.21$all
 ||182.119.227.245$all
@@ -231413,6 +231749,7 @@
 ||182.119.49.148$all
 ||182.119.49.162$all
 ||182.119.49.168$all
+||182.119.49.17$all
 ||182.119.49.185$all
 ||182.119.49.207$all
 ||182.119.49.220$all
@@ -231920,6 +232257,7 @@
 ||182.119.7.3$all
 ||182.119.7.41$all
 ||182.119.7.47$all
+||182.119.7.54$all
 ||182.119.7.73$all
 ||182.119.7.75$all
 ||182.119.7.88$all
@@ -233584,6 +233922,7 @@
 ||182.120.85.9$all
 ||182.120.86.203$all
 ||182.120.86.234$all
+||182.120.86.248$all
 ||182.120.86.46$all
 ||182.120.87.160$all
 ||182.120.87.227$all
@@ -234671,6 +235010,7 @@
 ||182.121.133.32$all
 ||182.121.133.37$all
 ||182.121.133.41$all
+||182.121.133.46$all
 ||182.121.133.50$all
 ||182.121.133.58$all
 ||182.121.133.72$all
@@ -235450,6 +235790,7 @@
 ||182.121.164.75$all
 ||182.121.164.85$all
 ||182.121.165.184$all
+||182.121.165.217$all
 ||182.121.166.105$all
 ||182.121.166.123$all
 ||182.121.166.85$all
@@ -235838,6 +236179,7 @@
 ||182.121.204.99$all
 ||182.121.205.100$all
 ||182.121.205.114$all
+||182.121.205.118$all
 ||182.121.205.124$all
 ||182.121.205.131$all
 ||182.121.205.137$all
@@ -237633,6 +237975,7 @@
 ||182.121.49.92$all
 ||182.121.49.94$all
 ||182.121.49.97$all
+||182.121.50.111$all
 ||182.121.50.112$all
 ||182.121.50.119$all
 ||182.121.50.121$all
@@ -238111,6 +238454,7 @@
 ||182.121.78.201$all
 ||182.121.78.220$all
 ||182.121.78.27$all
+||182.121.78.29$all
 ||182.121.78.3$all
 ||182.121.78.36$all
 ||182.121.78.42$all
@@ -239348,6 +239692,7 @@
 ||182.122.202.219$all
 ||182.122.202.229$all
 ||182.122.202.246$all
+||182.122.202.37$all
 ||182.122.202.59$all
 ||182.122.202.62$all
 ||182.122.202.82$all
@@ -239750,6 +240095,7 @@
 ||182.122.246.167$all
 ||182.122.246.170$all
 ||182.122.246.181$all
+||182.122.246.187$all
 ||182.122.246.190$all
 ||182.122.246.197$all
 ||182.122.246.199$all
@@ -239889,6 +240235,7 @@
 ||182.122.251.122$all
 ||182.122.251.124$all
 ||182.122.251.133$all
+||182.122.251.141$all
 ||182.122.251.143$all
 ||182.122.251.145$all
 ||182.122.251.150$all
@@ -240998,6 +241345,7 @@
 ||182.124.134.216$all
 ||182.124.134.235$all
 ||182.124.134.75$all
+||182.124.134.80$all
 ||182.124.134.9$all
 ||182.124.134.90$all
 ||182.124.134.96$all
@@ -241101,6 +241449,7 @@
 ||182.124.149.52$all
 ||182.124.149.67$all
 ||182.124.15.106$all
+||182.124.15.108$all
 ||182.124.15.109$all
 ||182.124.15.111$all
 ||182.124.15.13$all
@@ -241206,6 +241555,7 @@
 ||182.124.166.2$all
 ||182.124.166.228$all
 ||182.124.166.38$all
+||182.124.166.57$all
 ||182.124.166.6$all
 ||182.124.166.7$all
 ||182.124.167.11$all
@@ -243276,6 +243626,7 @@
 ||182.126.180.65$all
 ||182.126.180.72$all
 ||182.126.181.115$all
+||182.126.181.121$all
 ||182.126.181.149$all
 ||182.126.181.204$all
 ||182.126.181.214$all
@@ -243845,6 +244196,7 @@
 ||182.126.241.244$all
 ||182.126.241.30$all
 ||182.126.241.42$all
+||182.126.241.7$all
 ||182.126.241.71$all
 ||182.126.241.92$all
 ||182.126.242.10$all
@@ -243922,6 +244274,7 @@
 ||182.126.52.202$all
 ||182.126.52.214$all
 ||182.126.52.229$all
+||182.126.52.233$all
 ||182.126.52.252$all
 ||182.126.52.47$all
 ||182.126.52.70$all
@@ -244514,6 +244867,7 @@
 ||182.126.87.20$all
 ||182.126.87.201$all
 ||182.126.87.205$all
+||182.126.87.207$all
 ||182.126.87.209$all
 ||182.126.87.217$all
 ||182.126.87.22$all
@@ -248013,6 +248367,7 @@
 ||182.127.70.172$all
 ||182.127.70.185$all
 ||182.127.70.194$all
+||182.127.70.195$all
 ||182.127.70.213$all
 ||182.127.70.216$all
 ||182.127.70.218$all
@@ -249311,6 +249666,7 @@
 ||182.56.115.187$all
 ||182.56.115.191$all
 ||182.56.116.121$all
+||182.56.116.135$all
 ||182.56.116.178$all
 ||182.56.116.56$all
 ||182.56.117.14$all
@@ -251860,6 +252216,7 @@
 ||182.58.137.168$all
 ||182.58.137.66$all
 ||182.58.137.94$all
+||182.58.160.0$all
 ||182.58.160.122$all
 ||182.58.160.252$all
 ||182.58.160.89$all
@@ -254357,6 +254714,7 @@
 ||182.59.226.71$all
 ||182.59.227.10$all
 ||182.59.227.123$all
+||182.59.227.125$all
 ||182.59.227.130$all
 ||182.59.227.151$all
 ||182.59.227.175$all
@@ -257018,6 +257376,7 @@
 ||183.188.184.94$all
 ||183.188.186.52$all
 ||183.188.187.52$all
+||183.188.188.186$all
 ||183.188.194.119$all
 ||183.188.194.231$all
 ||183.188.195.189$all
@@ -257254,6 +257613,7 @@
 ||183.190.24.165$all
 ||183.190.26.125$all
 ||183.190.55.62$all
+||183.191.162.120$all
 ||183.191.204.241$all
 ||183.191.217.113$all
 ||183.191.65.166$all
@@ -257310,6 +257670,7 @@
 ||183.27.195.242$all
 ||183.28.50.158$all
 ||183.28.61.52$all
+||183.30.202.230$all
 ||183.30.202.247$all
 ||183.30.202.59$all
 ||183.30.202.67$all
@@ -257439,6 +257800,7 @@
 ||183.83.104.44$all
 ||183.83.104.68$all
 ||183.83.105.181$all
+||183.83.105.21$all
 ||183.83.105.228$all
 ||183.83.105.252$all
 ||183.83.105.253$all
@@ -258130,6 +258492,7 @@
 ||185.132.53.88$all
 ||185.132.53.9$all
 ||185.132.53.98$all
+||185.133.42.86$all
 ||185.134.122.209$all
 ||185.134.123.140$all
 ||185.134.21.75$all
@@ -258534,6 +258897,7 @@
 ||185.184.221.44$all
 ||185.184.54.15$all
 ||185.185.126.123$all
+||185.185.126.82$all
 ||185.186.142.100$all
 ||185.186.198.120$all
 ||185.186.244.186$all
@@ -262069,6 +262433,7 @@
 ||188.10.21.14$all
 ||188.10.231.246$all
 ||188.112.169.59$all
+||188.113.102.18$all
 ||188.113.107.75$all
 ||188.113.116.133$all
 ||188.113.81.17$all
@@ -262222,6 +262587,7 @@
 ||188.166.179.28$all
 ||188.166.18.52$all
 ||188.166.19.196$all
+||188.166.19.45$all
 ||188.166.207.182$all
 ||188.166.21.10$all
 ||188.166.21.86$all
@@ -264954,6 +265320,7 @@
 ||192.119.106.235$all
 ||192.119.106.9$all
 ||192.119.107.81$all
+||192.119.110.168$all
 ||192.119.110.222$all
 ||192.119.110.44$all
 ||192.119.110.49$all
@@ -265736,6 +266103,7 @@
 ||194.15.36.193$all
 ||194.15.36.194$all
 ||194.15.36.196$all
+||194.15.36.202$all
 ||194.15.36.204$all
 ||194.15.36.207$all
 ||194.15.36.208$all
@@ -265993,6 +266361,7 @@
 ||194.87.138.86$all
 ||194.87.138.88$all
 ||194.87.138.97$all
+||194.87.139.10$all
 ||194.87.139.108$all
 ||194.87.139.110$all
 ||194.87.139.113$all
@@ -268043,6 +268412,7 @@
 ||2.238.18.160$all
 ||2.238.195.223$all
 ||2.248.2.174$all
+||2.249.161.188$all
 ||2.249.161.196$all
 ||2.249.178.219$all
 ||2.25.93.113$all
@@ -268571,6 +268941,7 @@
 ||200.75.107.84$all
 ||200.79.152.109$all
 ||200.79.153.166$all
+||200.8.206.151$all
 ||200.8.206.224$all
 ||200.8.23.209$all
 ||200.8.240.149$all
@@ -268751,6 +269122,7 @@
 ||201.207.235.219$all
 ||201.208.129.111$all
 ||201.208.137.75$all
+||201.208.139.84$all
 ||201.208.153.220$all
 ||201.208.155.206$all
 ||201.208.209.28$all
@@ -269596,6 +269968,7 @@
 ||202.168.153.228$all
 ||202.169.234.10$all
 ||202.169.234.19$all
+||202.169.234.22$all
 ||202.169.234.33$all
 ||202.169.234.36$all
 ||202.169.234.37$all
@@ -270637,6 +271010,7 @@
 ||203.114.116.37$all
 ||203.115.102.243$all
 ||203.115.73.100$all
+||203.115.73.105$all
 ||203.115.73.107$all
 ||203.115.73.11$all
 ||203.115.73.111$all
@@ -270732,6 +271106,7 @@
 ||203.115.85.93$all
 ||203.115.91.129$all
 ||203.115.91.141$all
+||203.115.91.232$all
 ||203.115.91.47$all
 ||203.115.91.66$all
 ||203.123.205.195$all
@@ -273657,6 +274032,7 @@
 ||206.221.176.164$all
 ||206.248.136.50$all
 ||206.248.136.6$all
+||206.248.137.132$all
 ||206.248.139.132$all
 ||206.248.139.15$all
 ||206.248.219.15$all
@@ -273837,6 +274213,7 @@
 ||209.133.223.130$all
 ||209.14.30.121$all
 ||209.14.30.135$all
+||209.14.30.136$all
 ||209.14.30.159$all
 ||209.14.30.161$all
 ||209.14.30.166$all
@@ -273845,6 +274222,7 @@
 ||209.14.30.205$all
 ||209.14.30.30$all
 ||209.14.30.54$all
+||209.14.31.125$all
 ||209.14.31.162$all
 ||209.14.31.163$all
 ||209.14.31.175$all
@@ -274109,6 +274487,7 @@
 ||210.101.157.10$all
 ||210.101.157.199$all
 ||210.101.70.131$all
+||210.102.196.200$all
 ||210.102.58.78$all
 ||210.104.187.179$all
 ||210.104.210.133$all
@@ -276166,6 +276545,7 @@
 ||218.0.88.48$all
 ||218.101.202.186$all
 ||218.101.230.26$all
+||218.103.180.199$all
 ||218.104.175.100$all
 ||218.104.175.103$all
 ||218.104.175.109$all
@@ -278820,6 +279200,7 @@
 ||219.154.140.99$all
 ||219.154.141.138$all
 ||219.154.141.196$all
+||219.154.141.222$all
 ||219.154.141.227$all
 ||219.154.141.242$all
 ||219.154.141.53$all
@@ -279662,6 +280043,7 @@
 ||219.155.12.205$all
 ||219.155.12.215$all
 ||219.155.12.220$all
+||219.155.12.221$all
 ||219.155.12.40$all
 ||219.155.12.51$all
 ||219.155.12.55$all
@@ -279892,6 +280274,7 @@
 ||219.155.170.165$all
 ||219.155.170.185$all
 ||219.155.170.215$all
+||219.155.170.22$all
 ||219.155.170.228$all
 ||219.155.170.244$all
 ||219.155.170.250$all
@@ -280087,6 +280470,7 @@
 ||219.155.207.8$all
 ||219.155.207.96$all
 ||219.155.208.145$all
+||219.155.208.188$all
 ||219.155.208.19$all
 ||219.155.208.211$all
 ||219.155.208.212$all
@@ -280348,6 +280732,7 @@
 ||219.155.225.90$all
 ||219.155.226.130$all
 ||219.155.226.143$all
+||219.155.226.146$all
 ||219.155.226.154$all
 ||219.155.226.188$all
 ||219.155.226.194$all
@@ -280544,6 +280929,7 @@
 ||219.155.240.86$all
 ||219.155.241.11$all
 ||219.155.241.113$all
+||219.155.241.135$all
 ||219.155.241.137$all
 ||219.155.241.144$all
 ||219.155.241.155$all
@@ -281083,6 +281469,7 @@
 ||219.155.37.72$all
 ||219.155.37.87$all
 ||219.155.37.90$all
+||219.155.37.97$all
 ||219.155.38.10$all
 ||219.155.38.112$all
 ||219.155.38.113$all
@@ -281846,6 +282233,7 @@
 ||219.156.103.192$all
 ||219.156.103.225$all
 ||219.156.103.236$all
+||219.156.103.248$all
 ||219.156.103.43$all
 ||219.156.103.46$all
 ||219.156.103.84$all
@@ -282657,6 +283045,7 @@
 ||219.156.23.241$all
 ||219.156.23.245$all
 ||219.156.23.26$all
+||219.156.23.29$all
 ||219.156.23.3$all
 ||219.156.23.41$all
 ||219.156.23.50$all
@@ -282800,6 +283189,7 @@
 ||219.156.48.185$all
 ||219.156.48.50$all
 ||219.156.49.142$all
+||219.156.49.170$all
 ||219.156.49.172$all
 ||219.156.49.250$all
 ||219.156.5.233$all
@@ -282876,6 +283266,7 @@
 ||219.156.60.203$all
 ||219.156.60.208$all
 ||219.156.60.211$all
+||219.156.60.224$all
 ||219.156.60.250$all
 ||219.156.60.27$all
 ||219.156.60.39$all
@@ -283193,6 +283584,7 @@
 ||219.156.9.247$all
 ||219.156.9.254$all
 ||219.156.9.27$all
+||219.156.9.32$all
 ||219.156.9.34$all
 ||219.156.9.42$all
 ||219.156.9.48$all
@@ -284791,6 +285183,7 @@
 ||219.157.220.159$all
 ||219.157.220.163$all
 ||219.157.220.164$all
+||219.157.220.170$all
 ||219.157.220.171$all
 ||219.157.220.177$all
 ||219.157.220.18$all
@@ -284876,6 +285269,7 @@
 ||219.157.223.24$all
 ||219.157.223.241$all
 ||219.157.223.243$all
+||219.157.223.245$all
 ||219.157.223.29$all
 ||219.157.223.4$all
 ||219.157.223.42$all
@@ -284927,6 +285321,7 @@
 ||219.157.226.198$all
 ||219.157.226.4$all
 ||219.157.226.47$all
+||219.157.226.79$all
 ||219.157.227.124$all
 ||219.157.227.170$all
 ||219.157.227.176$all
@@ -285299,6 +285694,7 @@
 ||219.157.244.233$all
 ||219.157.244.236$all
 ||219.157.244.254$all
+||219.157.244.33$all
 ||219.157.244.39$all
 ||219.157.244.43$all
 ||219.157.244.61$all
@@ -286237,6 +286633,7 @@
 ||219.157.50.203$all
 ||219.157.50.208$all
 ||219.157.50.21$all
+||219.157.50.211$all
 ||219.157.50.228$all
 ||219.157.50.233$all
 ||219.157.50.238$all
@@ -286396,6 +286793,7 @@
 ||219.157.54.150$all
 ||219.157.54.155$all
 ||219.157.54.157$all
+||219.157.54.158$all
 ||219.157.54.159$all
 ||219.157.54.177$all
 ||219.157.54.19$all
@@ -286503,6 +286901,7 @@
 ||219.157.56.251$all
 ||219.157.56.254$all
 ||219.157.56.35$all
+||219.157.56.46$all
 ||219.157.56.47$all
 ||219.157.56.50$all
 ||219.157.56.54$all
@@ -289291,6 +289690,7 @@
 ||221.14.56.67$all
 ||221.14.57.62$all
 ||221.14.58.27$all
+||221.14.58.5$all
 ||221.14.58.84$all
 ||221.14.59.255$all
 ||221.14.60.146$all
@@ -289904,6 +290304,7 @@
 ||221.15.147.210$all
 ||221.15.147.214$all
 ||221.15.147.217$all
+||221.15.147.220$all
 ||221.15.147.225$all
 ||221.15.147.227$all
 ||221.15.147.234$all
@@ -291716,6 +292117,7 @@
 ||221.15.236.92$all
 ||221.15.236.93$all
 ||221.15.236.98$all
+||221.15.237.107$all
 ||221.15.237.109$all
 ||221.15.237.11$all
 ||221.15.237.112$all
@@ -292440,6 +292842,7 @@
 ||221.15.7.198$all
 ||221.15.7.199$all
 ||221.15.7.200$all
+||221.15.7.202$all
 ||221.15.7.205$all
 ||221.15.7.207$all
 ||221.15.7.21$all
@@ -293432,6 +293835,7 @@
 ||221.215.170.109$all
 ||221.215.171.80$all
 ||221.215.172.192$all
+||221.215.172.207$all
 ||221.215.172.217$all
 ||221.215.174.4$all
 ||221.215.174.59$all
@@ -294120,6 +294524,7 @@
 ||221.5.30.10$all
 ||221.5.30.100$all
 ||221.5.30.103$all
+||221.5.30.118$all
 ||221.5.30.14$all
 ||221.5.30.140$all
 ||221.5.30.153$all
@@ -297667,6 +298072,7 @@
 ||222.137.22.42$all
 ||222.137.22.59$all
 ||222.137.22.66$all
+||222.137.22.79$all
 ||222.137.220.10$all
 ||222.137.220.123$all
 ||222.137.220.125$all
@@ -297695,6 +298101,7 @@
 ||222.137.220.60$all
 ||222.137.220.63$all
 ||222.137.220.82$all
+||222.137.220.94$all
 ||222.137.220.99$all
 ||222.137.221.101$all
 ||222.137.221.107$all
@@ -298306,6 +298713,7 @@
 ||222.137.49.170$all
 ||222.137.49.29$all
 ||222.137.49.30$all
+||222.137.49.4$all
 ||222.137.49.75$all
 ||222.137.49.99$all
 ||222.137.5.102$all
@@ -298705,6 +299113,7 @@
 ||222.137.83.230$all
 ||222.137.83.39$all
 ||222.137.83.5$all
+||222.137.83.53$all
 ||222.137.84.2$all
 ||222.137.84.240$all
 ||222.137.84.33$all
@@ -300247,6 +300656,7 @@
 ||222.138.189.219$all
 ||222.138.189.223$all
 ||222.138.189.243$all
+||222.138.189.88$all
 ||222.138.19.110$all
 ||222.138.19.135$all
 ||222.138.19.144$all
@@ -300573,6 +300983,7 @@
 ||222.138.215.134$all
 ||222.138.215.146$all
 ||222.138.215.16$all
+||222.138.215.161$all
 ||222.138.215.183$all
 ||222.138.215.215$all
 ||222.138.215.222$all
@@ -300683,6 +301094,7 @@
 ||222.138.224.148$all
 ||222.138.224.15$all
 ||222.138.224.163$all
+||222.138.224.164$all
 ||222.138.224.173$all
 ||222.138.224.2$all
 ||222.138.224.228$all
@@ -301149,6 +301561,7 @@
 ||222.138.49.58$all
 ||222.138.49.67$all
 ||222.138.49.79$all
+||222.138.49.93$all
 ||222.138.50.106$all
 ||222.138.50.237$all
 ||222.138.50.32$all
@@ -301571,6 +301984,7 @@
 ||222.139.16.143$all
 ||222.139.16.173$all
 ||222.139.16.195$all
+||222.139.16.229$all
 ||222.139.16.236$all
 ||222.139.16.32$all
 ||222.139.16.84$all
@@ -302339,6 +302753,7 @@
 ||222.140.111.116$all
 ||222.140.111.192$all
 ||222.140.111.205$all
+||222.140.112.150$all
 ||222.140.112.171$all
 ||222.140.112.224$all
 ||222.140.113.197$all
@@ -304012,6 +304427,7 @@
 ||222.141.164.67$all
 ||222.141.164.88$all
 ||222.141.165.116$all
+||222.141.165.180$all
 ||222.141.165.189$all
 ||222.141.165.2$all
 ||222.141.165.214$all
@@ -304327,6 +304743,7 @@
 ||222.141.244.110$all
 ||222.141.244.147$all
 ||222.141.244.20$all
+||222.141.244.231$all
 ||222.141.244.80$all
 ||222.141.245.10$all
 ||222.141.245.134$all
@@ -304991,6 +305408,7 @@
 ||222.141.73.184$all
 ||222.141.73.219$all
 ||222.141.73.245$all
+||222.141.73.249$all
 ||222.141.73.38$all
 ||222.141.73.55$all
 ||222.141.73.61$all
@@ -306501,6 +306919,7 @@
 ||222.214.53.254$all
 ||222.214.53.62$all
 ||222.214.54.162$all
+||222.214.54.208$all
 ||222.214.54.238$all
 ||222.214.55.138$all
 ||222.214.55.18$all
@@ -308154,6 +308573,7 @@
 ||27.12.232.176$all
 ||27.12.233.205$all
 ||27.12.233.96$all
+||27.12.234.4$all
 ||27.12.235.176$all
 ||27.12.236.127$all
 ||27.12.238.202$all
@@ -312272,6 +312692,7 @@
 ||27.208.242.223$all
 ||27.208.244.172$all
 ||27.208.247.130$all
+||27.208.25.59$all
 ||27.208.30.1$all
 ||27.208.30.87$all
 ||27.208.31.92$all
@@ -312559,6 +312980,7 @@
 ||27.210.146.49$all
 ||27.210.146.54$all
 ||27.210.146.6$all
+||27.210.146.61$all
 ||27.210.146.89$all
 ||27.210.147.172$all
 ||27.210.147.228$all
@@ -313300,6 +313722,7 @@
 ||27.213.145.138$all
 ||27.213.145.143$all
 ||27.213.145.161$all
+||27.213.145.221$all
 ||27.213.146.231$all
 ||27.213.147.121$all
 ||27.213.148.104$all
@@ -313346,6 +313769,7 @@
 ||27.213.166.136$all
 ||27.213.166.174$all
 ||27.213.167.154$all
+||27.213.167.175$all
 ||27.213.167.180$all
 ||27.213.167.210$all
 ||27.213.168.16$all
@@ -314310,6 +314734,7 @@
 ||27.216.130.132$all
 ||27.216.130.185$all
 ||27.216.131.63$all
+||27.216.131.66$all
 ||27.216.132.194$all
 ||27.216.132.221$all
 ||27.216.132.237$all
@@ -318204,6 +318629,7 @@
 ||27.41.146.252$all
 ||27.41.146.27$all
 ||27.41.146.3$all
+||27.41.146.59$all
 ||27.41.146.63$all
 ||27.41.146.73$all
 ||27.41.146.80$all
@@ -318324,6 +318750,7 @@
 ||27.41.153.41$all
 ||27.41.153.54$all
 ||27.41.153.65$all
+||27.41.153.66$all
 ||27.41.153.89$all
 ||27.41.153.91$all
 ||27.41.154.102$all
@@ -319450,6 +319877,7 @@
 ||27.43.151.68$all
 ||27.43.151.86$all
 ||27.43.66.61$all
+||27.43.82.210$all
 ||27.43.92.65$all
 ||27.44.100.126$all
 ||27.44.100.242$all
@@ -319732,6 +320160,7 @@
 ||27.46.47.61$all
 ||27.46.47.69$all
 ||27.46.47.72$all
+||27.46.47.74$all
 ||27.46.47.75$all
 ||27.46.47.76$all
 ||27.46.47.77$all
@@ -319821,6 +320250,7 @@
 ||27.5.16.236$all
 ||27.5.16.237$all
 ||27.5.16.242$all
+||27.5.16.243$all
 ||27.5.16.244$all
 ||27.5.16.245$all
 ||27.5.16.246$all
@@ -320298,6 +320728,7 @@
 ||27.5.21.38$all
 ||27.5.21.4$all
 ||27.5.21.5$all
+||27.5.21.53$all
 ||27.5.21.56$all
 ||27.5.21.57$all
 ||27.5.21.63$all
@@ -320722,6 +321153,7 @@
 ||27.5.26.32$all
 ||27.5.26.33$all
 ||27.5.26.37$all
+||27.5.26.4$all
 ||27.5.26.43$all
 ||27.5.26.44$all
 ||27.5.26.47$all
@@ -321034,6 +321466,7 @@
 ||27.5.30.197$all
 ||27.5.30.20$all
 ||27.5.30.203$all
+||27.5.30.207$all
 ||27.5.30.210$all
 ||27.5.30.212$all
 ||27.5.30.215$all
@@ -321340,6 +321773,7 @@
 ||27.5.34.169$all
 ||27.5.34.171$all
 ||27.5.34.176$all
+||27.5.34.177$all
 ||27.5.34.182$all
 ||27.5.34.183$all
 ||27.5.34.186$all
@@ -321404,6 +321838,7 @@
 ||27.5.35.117$all
 ||27.5.35.12$all
 ||27.5.35.125$all
+||27.5.35.127$all
 ||27.5.35.130$all
 ||27.5.35.131$all
 ||27.5.35.132$all
@@ -342166,6 +342601,7 @@
 ||31.163.189.192$all
 ||31.163.189.220$all
 ||31.163.189.254$all
+||31.163.191.11$all
 ||31.163.57.231$all
 ||31.163.65.250$all
 ||31.164.47.38$all
@@ -342392,6 +342828,7 @@
 ||31.6.70.84$all
 ||31.6.98.137$all
 ||31.62.130.208$all
+||31.62.255.3$all
 ||31.62.91.175$all
 ||31.63.183.192$all
 ||31.63.189.195$all
@@ -344439,6 +344876,7 @@
 ||37.187.73.85$all
 ||37.189.109.110$all
 ||37.19.48.73$all
+||37.19.49.202$all
 ||37.19.49.206$all
 ||37.19.51.174$all
 ||37.19.52.247$all
@@ -346380,6 +346818,7 @@
 ||39.73.44.149$all
 ||39.73.44.155$all
 ||39.73.44.165$all
+||39.73.44.17$all
 ||39.73.44.176$all
 ||39.73.44.185$all
 ||39.73.44.198$all
@@ -349052,6 +349491,7 @@
 ||39.86.150.176$all
 ||39.86.150.37$all
 ||39.86.151.106$all
+||39.86.151.49$all
 ||39.86.151.96$all
 ||39.86.152.128$all
 ||39.86.152.130$all
@@ -349815,6 +350255,7 @@
 ||39.87.84.239$all
 ||39.87.87.117$all
 ||39.87.87.99$all
+||39.87.90.210$all
 ||39.87.93.109$all
 ||39.87.93.54$all
 ||39.87.98.115$all
@@ -352199,6 +352640,7 @@
 ||42.224.122.3$all
 ||42.224.122.30$all
 ||42.224.122.37$all
+||42.224.122.39$all
 ||42.224.122.41$all
 ||42.224.122.43$all
 ||42.224.122.52$all
@@ -353521,6 +353963,7 @@
 ||42.224.176.199$all
 ||42.224.176.202$all
 ||42.224.176.205$all
+||42.224.176.214$all
 ||42.224.176.216$all
 ||42.224.176.217$all
 ||42.224.176.221$all
@@ -354858,6 +355301,7 @@
 ||42.224.249.57$all
 ||42.224.249.73$all
 ||42.224.249.76$all
+||42.224.249.8$all
 ||42.224.249.87$all
 ||42.224.249.88$all
 ||42.224.249.92$all
@@ -357019,6 +357463,7 @@
 ||42.224.90.133$all
 ||42.224.90.151$all
 ||42.224.90.158$all
+||42.224.90.17$all
 ||42.224.90.196$all
 ||42.224.90.240$all
 ||42.224.90.28$all
@@ -358220,6 +358665,7 @@
 ||42.225.33.162$all
 ||42.225.33.199$all
 ||42.225.33.20$all
+||42.225.33.31$all
 ||42.225.34.174$all
 ||42.225.34.18$all
 ||42.225.34.184$all
@@ -358793,6 +359239,7 @@
 ||42.226.89.147$all
 ||42.226.89.157$all
 ||42.226.89.235$all
+||42.226.89.25$all
 ||42.226.89.82$all
 ||42.226.90.0$all
 ||42.226.90.102$all
@@ -359334,6 +359781,7 @@
 ||42.227.176.230$all
 ||42.227.176.239$all
 ||42.227.176.90$all
+||42.227.177.142$all
 ||42.227.177.250$all
 ||42.227.177.84$all
 ||42.227.178.10$all
@@ -361928,6 +362376,7 @@
 ||42.228.75.59$all
 ||42.228.75.63$all
 ||42.228.75.65$all
+||42.228.75.7$all
 ||42.228.75.74$all
 ||42.228.75.79$all
 ||42.228.75.80$all
@@ -363838,6 +364287,7 @@
 ||42.230.173.51$all
 ||42.230.173.66$all
 ||42.230.174.117$all
+||42.230.174.125$all
 ||42.230.174.161$all
 ||42.230.174.171$all
 ||42.230.174.216$all
@@ -364564,6 +365014,7 @@
 ||42.230.219.225$all
 ||42.230.219.231$all
 ||42.230.219.239$all
+||42.230.219.243$all
 ||42.230.219.254$all
 ||42.230.219.37$all
 ||42.230.219.4$all
@@ -367039,6 +367490,7 @@
 ||42.231.223.17$all
 ||42.231.223.191$all
 ||42.231.223.209$all
+||42.231.223.215$all
 ||42.231.223.59$all
 ||42.231.223.95$all
 ||42.231.224.122$all
@@ -367192,6 +367644,7 @@
 ||42.231.244.187$all
 ||42.231.244.189$all
 ||42.231.244.222$all
+||42.231.244.80$all
 ||42.231.244.83$all
 ||42.231.245.111$all
 ||42.231.245.142$all
@@ -367610,6 +368063,7 @@
 ||42.231.95.136$all
 ||42.231.95.154$all
 ||42.231.95.17$all
+||42.231.95.195$all
 ||42.231.95.210$all
 ||42.231.95.230$all
 ||42.231.95.99$all
@@ -369509,6 +369963,7 @@
 ||42.233.90.116$all
 ||42.233.90.138$all
 ||42.233.90.167$all
+||42.233.90.183$all
 ||42.233.90.187$all
 ||42.233.90.52$all
 ||42.233.91.0$all
@@ -369629,6 +370084,7 @@
 ||42.234.105.253$all
 ||42.234.105.3$all
 ||42.234.105.33$all
+||42.234.105.6$all
 ||42.234.105.68$all
 ||42.234.105.93$all
 ||42.234.106.110$all
@@ -369923,6 +370379,7 @@
 ||42.234.162.214$all
 ||42.234.162.4$all
 ||42.234.162.42$all
+||42.234.162.44$all
 ||42.234.162.76$all
 ||42.234.163.119$all
 ||42.234.163.16$all
@@ -374477,6 +374934,7 @@
 ||42.235.90.245$all
 ||42.235.90.29$all
 ||42.235.90.3$all
+||42.235.90.32$all
 ||42.235.90.46$all
 ||42.235.90.50$all
 ||42.235.90.53$all
@@ -375640,6 +376098,7 @@
 ||42.237.44.45$all
 ||42.237.44.47$all
 ||42.237.45.107$all
+||42.237.45.223$all
 ||42.237.45.25$all
 ||42.237.45.90$all
 ||42.237.46.104$all
@@ -375956,6 +376415,7 @@
 ||42.238.109.115$all
 ||42.238.11.212$all
 ||42.238.111.149$all
+||42.238.112.100$all
 ||42.238.112.125$all
 ||42.238.112.132$all
 ||42.238.112.32$all
@@ -376223,6 +376683,7 @@
 ||42.238.175.124$all
 ||42.238.175.14$all
 ||42.238.175.229$all
+||42.238.175.32$all
 ||42.238.175.35$all
 ||42.238.175.61$all
 ||42.238.175.96$all
@@ -379108,6 +379569,7 @@
 ||45.144.225.118$all
 ||45.144.225.142$all
 ||45.144.225.151$all
+||45.144.225.213$all
 ||45.144.225.65$all
 ||45.144.225.96$all
 ||45.144.29.133$all
@@ -385518,6 +385980,7 @@
 ||54.179.174.132$all
 ||54.179.179.37$all
 ||54.179.9.186$all
+||54.180.158.181$all
 ||54.186.24.183$all
 ||54.187.210.136$all
 ||54.197.30.41$all
@@ -385694,6 +386157,7 @@
 ||58.19.163.45$all
 ||58.19.163.92$all
 ||58.19.249.100$all
+||58.19.249.50$all
 ||58.19.250.18$all
 ||58.19.250.190$all
 ||58.19.251.10$all
@@ -386526,6 +386990,7 @@
 ||58.248.143.158$all
 ||58.248.143.164$all
 ||58.248.143.168$all
+||58.248.143.173$all
 ||58.248.143.174$all
 ||58.248.143.176$all
 ||58.248.143.18$all
@@ -386554,6 +387019,7 @@
 ||58.248.144.180$all
 ||58.248.144.186$all
 ||58.248.144.190$all
+||58.248.144.21$all
 ||58.248.144.216$all
 ||58.248.144.217$all
 ||58.248.144.39$all
@@ -386561,6 +387027,7 @@
 ||58.248.144.89$all
 ||58.248.144.94$all
 ||58.248.144.95$all
+||58.248.144.97$all
 ||58.248.145.113$all
 ||58.248.145.129$all
 ||58.248.145.13$all
@@ -386687,6 +387154,7 @@
 ||58.248.149.186$all
 ||58.248.149.207$all
 ||58.248.149.214$all
+||58.248.149.226$all
 ||58.248.149.230$all
 ||58.248.149.231$all
 ||58.248.149.240$all
@@ -387529,6 +387997,7 @@
 ||58.249.73.74$all
 ||58.249.73.90$all
 ||58.249.74.103$all
+||58.249.74.104$all
 ||58.249.74.11$all
 ||58.249.74.118$all
 ||58.249.74.120$all
@@ -387555,6 +388024,7 @@
 ||58.249.74.9$all
 ||58.249.75.101$all
 ||58.249.75.109$all
+||58.249.75.112$all
 ||58.249.75.125$all
 ||58.249.75.126$all
 ||58.249.75.13$all
@@ -387638,6 +388108,7 @@
 ||58.249.78.116$all
 ||58.249.78.128$all
 ||58.249.78.132$all
+||58.249.78.155$all
 ||58.249.78.168$all
 ||58.249.78.174$all
 ||58.249.78.176$all
@@ -387739,6 +388210,7 @@
 ||58.249.80.246$all
 ||58.249.80.37$all
 ||58.249.80.38$all
+||58.249.80.46$all
 ||58.249.80.56$all
 ||58.249.80.61$all
 ||58.249.80.63$all
@@ -387953,6 +388425,7 @@
 ||58.249.87.211$all
 ||58.249.87.222$all
 ||58.249.87.247$all
+||58.249.87.248$all
 ||58.249.87.250$all
 ||58.249.87.253$all
 ||58.249.87.33$all
@@ -388017,6 +388490,7 @@
 ||58.249.89.169$all
 ||58.249.89.178$all
 ||58.249.89.190$all
+||58.249.89.210$all
 ||58.249.89.213$all
 ||58.249.89.218$all
 ||58.249.89.223$all
@@ -388081,6 +388555,7 @@
 ||58.249.90.180$all
 ||58.249.90.19$all
 ||58.249.90.20$all
+||58.249.90.206$all
 ||58.249.90.216$all
 ||58.249.90.220$all
 ||58.249.90.233$all
@@ -388091,6 +388566,7 @@
 ||58.249.90.80$all
 ||58.249.90.82$all
 ||58.249.90.84$all
+||58.249.90.86$all
 ||58.249.90.94$all
 ||58.249.91.102$all
 ||58.249.91.11$all
@@ -388125,6 +388601,7 @@
 ||58.249.91.77$all
 ||58.249.91.98$all
 ||58.252.175.220$all
+||58.252.176.107$all
 ||58.252.176.117$all
 ||58.252.176.12$all
 ||58.252.176.120$all
@@ -388393,6 +388870,7 @@
 ||58.255.135.21$all
 ||58.255.135.228$all
 ||58.255.135.253$all
+||58.255.135.41$all
 ||58.255.135.48$all
 ||58.255.135.56$all
 ||58.255.135.61$all
@@ -388569,6 +389047,7 @@
 ||58.42.195.227$all
 ||58.42.198.13$all
 ||58.42.220.111$all
+||58.46.169.21$all
 ||58.46.248.182$all
 ||58.46.248.4$all
 ||58.46.249.10$all
@@ -388731,6 +389210,7 @@
 ||58.61.51.61$all
 ||58.61.51.73$all
 ||58.61.51.97$all
+||58.62.31.25$all
 ||58.62.80.50$all
 ||58.62.80.54$all
 ||58.62.83.182$all
@@ -392796,6 +393276,7 @@
 ||59.32.97.159$all
 ||59.32.97.187$all
 ||59.32.97.188$all
+||59.32.97.190$all
 ||59.32.97.208$all
 ||59.32.97.217$all
 ||59.32.97.218$all
@@ -394669,6 +395150,7 @@
 ||59.92.182.7$all
 ||59.92.182.70$all
 ||59.92.182.71$all
+||59.92.182.72$all
 ||59.92.182.74$all
 ||59.92.182.75$all
 ||59.92.182.76$all
@@ -395375,6 +395857,7 @@
 ||59.92.218.72$all
 ||59.92.218.73$all
 ||59.92.218.75$all
+||59.92.218.77$all
 ||59.92.218.79$all
 ||59.92.218.8$all
 ||59.92.218.80$all
@@ -395495,6 +395978,7 @@
 ||59.92.219.252$all
 ||59.92.219.254$all
 ||59.92.219.26$all
+||59.92.219.28$all
 ||59.92.219.29$all
 ||59.92.219.30$all
 ||59.92.219.31$all
@@ -396125,6 +396609,7 @@
 ||59.93.19.187$all
 ||59.93.19.189$all
 ||59.93.19.190$all
+||59.93.19.191$all
 ||59.93.19.193$all
 ||59.93.19.194$all
 ||59.93.19.195$all
@@ -396299,6 +396784,7 @@
 ||59.93.21.110$all
 ||59.93.21.111$all
 ||59.93.21.115$all
+||59.93.21.117$all
 ||59.93.21.121$all
 ||59.93.21.126$all
 ||59.93.21.127$all
@@ -397598,6 +398084,7 @@
 ||59.94.182.241$all
 ||59.94.182.242$all
 ||59.94.182.243$all
+||59.94.182.244$all
 ||59.94.182.246$all
 ||59.94.182.247$all
 ||59.94.182.248$all
@@ -400147,6 +400634,7 @@
 ||59.97.169.111$all
 ||59.97.169.112$all
 ||59.97.169.113$all
+||59.97.169.114$all
 ||59.97.169.115$all
 ||59.97.169.116$all
 ||59.97.169.117$all
@@ -401375,6 +401863,7 @@
 ||59.97.174.82$all
 ||59.97.174.83$all
 ||59.97.174.84$all
+||59.97.174.85$all
 ||59.97.174.87$all
 ||59.97.174.89$all
 ||59.97.174.9$all
@@ -403786,6 +404275,7 @@
 ||59.99.44.249$all
 ||59.99.44.253$all
 ||59.99.44.254$all
+||59.99.44.28$all
 ||59.99.44.29$all
 ||59.99.44.30$all
 ||59.99.44.31$all
@@ -404694,6 +405184,7 @@
 ||59.99.93.244$all
 ||59.99.93.245$all
 ||59.99.93.246$all
+||59.99.93.248$all
 ||59.99.93.250$all
 ||59.99.93.251$all
 ||59.99.93.252$all
@@ -404750,6 +405241,7 @@
 ||59.99.93.79$all
 ||59.99.93.8$all
 ||59.99.93.80$all
+||59.99.93.82$all
 ||59.99.93.83$all
 ||59.99.93.84$all
 ||59.99.93.85$all
@@ -404990,6 +405482,7 @@
 ||59.99.95.134$all
 ||59.99.95.135$all
 ||59.99.95.136$all
+||59.99.95.137$all
 ||59.99.95.139$all
 ||59.99.95.14$all
 ||59.99.95.140$all
@@ -404999,6 +405492,7 @@
 ||59.99.95.146$all
 ||59.99.95.147$all
 ||59.99.95.148$all
+||59.99.95.149$all
 ||59.99.95.15$all
 ||59.99.95.151$all
 ||59.99.95.152$all
@@ -407230,6 +407724,7 @@
 ||60.215.4.239$all
 ||60.215.4.89$all
 ||60.215.42.16$all
+||60.215.59.108$all
 ||60.215.61.56$all
 ||60.215.63.173$all
 ||60.216.122.109$all
@@ -416089,6 +416584,7 @@
 ||60.254.49.198$all
 ||60.254.49.201$all
 ||60.254.49.215$all
+||60.254.49.59$all
 ||60.254.49.68$all
 ||60.254.49.94$all
 ||60.254.50.240$all
@@ -416895,6 +417391,7 @@
 ||60.7.64.208$all
 ||60.7.64.243$all
 ||60.7.65.79$all
+||60.7.8.43$all
 ||60.7.94.111$all
 ||60.7.99.254$all
 ||60.9.155.86$all
@@ -419107,11 +419604,13 @@
 ||61.3.124.244$all
 ||61.3.124.25$all
 ||61.3.124.251$all
+||61.3.124.3$all
 ||61.3.124.33$all
 ||61.3.124.34$all
 ||61.3.124.39$all
 ||61.3.124.41$all
 ||61.3.124.46$all
+||61.3.124.51$all
 ||61.3.124.60$all
 ||61.3.124.65$all
 ||61.3.124.71$all
@@ -419123,6 +419622,7 @@
 ||61.3.124.95$all
 ||61.3.125.102$all
 ||61.3.125.107$all
+||61.3.125.112$all
 ||61.3.125.114$all
 ||61.3.125.119$all
 ||61.3.125.12$all
@@ -419218,6 +419718,7 @@
 ||61.3.127.124$all
 ||61.3.127.125$all
 ||61.3.127.135$all
+||61.3.127.138$all
 ||61.3.127.149$all
 ||61.3.127.158$all
 ||61.3.127.178$all
@@ -419913,6 +420414,7 @@
 ||61.52.135.117$all
 ||61.52.135.125$all
 ||61.52.135.144$all
+||61.52.135.192$all
 ||61.52.135.234$all
 ||61.52.135.235$all
 ||61.52.135.253$all
@@ -420989,6 +421491,7 @@
 ||61.52.212.233$all
 ||61.52.212.239$all
 ||61.52.212.244$all
+||61.52.212.250$all
 ||61.52.212.251$all
 ||61.52.212.27$all
 ||61.52.212.30$all
@@ -421825,6 +422328,7 @@
 ||61.52.39.101$all
 ||61.52.39.109$all
 ||61.52.39.110$all
+||61.52.39.119$all
 ||61.52.39.122$all
 ||61.52.39.132$all
 ||61.52.39.144$all
@@ -422132,6 +422636,7 @@
 ||61.52.5.192$all
 ||61.52.5.195$all
 ||61.52.5.198$all
+||61.52.5.217$all
 ||61.52.5.226$all
 ||61.52.5.60$all
 ||61.52.50.109$all
@@ -422705,6 +423210,7 @@
 ||61.52.62.97$all
 ||61.52.63.11$all
 ||61.52.63.110$all
+||61.52.63.119$all
 ||61.52.63.121$all
 ||61.52.63.125$all
 ||61.52.63.127$all
@@ -422868,6 +423374,7 @@
 ||61.52.76.53$all
 ||61.52.76.58$all
 ||61.52.76.59$all
+||61.52.76.72$all
 ||61.52.76.73$all
 ||61.52.76.74$all
 ||61.52.76.87$all
@@ -424066,6 +424573,7 @@
 ||61.53.123.149$all
 ||61.53.123.154$all
 ||61.53.123.161$all
+||61.53.123.162$all
 ||61.53.123.163$all
 ||61.53.123.168$all
 ||61.53.123.169$all
@@ -424152,6 +424660,7 @@
 ||61.53.124.215$all
 ||61.53.124.219$all
 ||61.53.124.223$all
+||61.53.124.225$all
 ||61.53.124.227$all
 ||61.53.124.23$all
 ||61.53.124.230$all
@@ -426707,6 +427216,7 @@
 ||61.54.240.166$all
 ||61.54.240.19$all
 ||61.54.240.198$all
+||61.54.240.20$all
 ||61.54.240.213$all
 ||61.54.240.220$all
 ||61.54.240.44$all
@@ -427065,10 +427575,12 @@
 ||61.54.58.164$all
 ||61.54.58.166$all
 ||61.54.58.172$all
+||61.54.58.190$all
 ||61.54.58.192$all
 ||61.54.58.193$all
 ||61.54.58.197$all
 ||61.54.58.198$all
+||61.54.58.20$all
 ||61.54.58.202$all
 ||61.54.58.211$all
 ||61.54.58.22$all
@@ -427127,6 +427639,7 @@
 ||61.54.60.242$all
 ||61.54.60.255$all
 ||61.54.60.29$all
+||61.54.60.4$all
 ||61.54.60.43$all
 ||61.54.60.55$all
 ||61.54.60.68$all
@@ -427149,6 +427662,7 @@
 ||61.54.61.163$all
 ||61.54.61.168$all
 ||61.54.61.172$all
+||61.54.61.18$all
 ||61.54.61.191$all
 ||61.54.61.199$all
 ||61.54.61.208$all
@@ -427857,6 +428371,7 @@
 ||62.219.131.205$all
 ||62.219.138.44$all
 ||62.219.143.46$all
+||62.219.155.61$all
 ||62.219.163.162$all
 ||62.219.164.224$all
 ||62.219.194.210$all
@@ -429060,6 +429575,7 @@
 ||71.183.150.34$all
 ||71.187.60.8$all
 ||71.19.144.47$all
+||71.19.150.93$all
 ||71.190.64.120$all
 ||71.190.64.189$all
 ||71.190.64.214$all
@@ -429968,6 +430484,7 @@
 ||77.45.182.113$all
 ||77.45.182.196$all
 ||77.45.183.124$all
+||77.45.183.39$all
 ||77.45.184.77$all
 ||77.45.185.57$all
 ||77.45.185.89$all
@@ -432192,6 +432709,7 @@
 ||84.22.38.175$all
 ||84.221.143.108$all
 ||84.224.144.27$all
+||84.224.162.170$all
 ||84.224.177.80$all
 ||84.224.213.50$all
 ||84.228.102.152$all
@@ -432405,6 +432923,7 @@
 ||85.105.77.54$all
 ||85.105.82.225$all
 ||85.105.82.94$all
+||85.105.9.152$all
 ||85.105.98.84$all
 ||85.106.129.231$all
 ||85.106.161.174$all
@@ -435589,6 +436108,7 @@
 ||95.152.49.54$all
 ||95.152.5.232$all
 ||95.152.9.183$all
+||95.153.241.63$all
 ||95.153.94.241$all
 ||95.154.20.231$all
 ||95.154.244.200$all
@@ -437114,8 +437634,7 @@
 ||access-24.jp$all
 ||access-cash.ae.org$all
 ||access-om.neomeric.us$all
-||access-one.us/aym3vh.php$all
-||access-one.us/wp-content/qvrajpy4kvx3pkg4aiuljg98c34dw1yaweefdv7gnbvxygdyki6jqug61dmqb44w7cvth/$all
+||access-one.us$all
 ||access-to-web.com$all
 ||accessclub.jp$all
 ||accessdig.com$all
@@ -437298,6 +437817,7 @@
 ||achutamanasa.com/media/jkslhiclhpj4d8q64fqmm7j/$all
 ||achutamanasa.com/media/te/$all
 ||aci.serabd.com$all
+||aciabogados.com$all
 ||aciitaly.com$all
 ||acilevarkadasi.com$all
 ||acilisbalon.com$all
@@ -437738,6 +438258,7 @@
 ||admin.greenlightcr.com$all
 ||admin.hopehorseback.org$all
 ||admin.jpcar.mystand.pt$all
+||admin.mobilezenie.com$all
 ||admin.searchlowestprice.com$all
 ||admin.solissol.com$all
 ||admin.staging.buildsmart.io$all
@@ -437926,7 +438447,7 @@
 ||adventureexplorer.in$all
 ||adventurehr.com$all
 ||adventureitdate.com$all
-||adventureits.com$all
+||adventureits.com/wp-content/6399952952/q54d7zyhe/$all
 ||adventuremania.com$all
 ||adventureracen.nl/cgi-bin/parts_service/$all
 ||adventurersafaris.com$all
@@ -438353,6 +438874,7 @@
 ||agengarcinia5000.com$all
 ||agenity.com$all
 ||agenlama.com$all
+||agenmovie.xyz$all
 ||agent-14.s3.us-east-2.amazonaws.com/agent_140020000.exe$all
 ||agent-seo.jp$all
 ||agent.ken.by$all
@@ -445605,6 +446127,7 @@
 ||barcelonaevent.es$all
 ||barcelonakartingcenter.com$all
 ||barchaklem.com$all
+||barcionstw.eastus.cloudapp.azure.com$all
 ||barcla.ug$all
 ||barclaysdownloads.com$all
 ||barcoofoods.ir$all
@@ -448491,7 +449014,7 @@
 ||bj5800.com$all
 ||bjarndahl.dk$all
 ||bjbus.net$all
-||bjconstructions.in/6382329/mlrcedkan/$all
+||bjconstructions.in$all
 ||bjdd.org$all
 ||bjenkins.webview.consulting$all
 ||bjenzer.com$all
@@ -449586,6 +450109,7 @@
 ||bnpartnersweb.com$all
 ||bnpgrup.com$all
 ||bnqzjy.cn$all
+||bnrbook.com$all
 ||bnrnews.id$all
 ||bnsddfhjdfgvbxc.ru$all
 ||bnsgroupbd.com$all
@@ -450350,6 +450874,7 @@
 ||braner.com.ua$all
 ||branfinancial.com$all
 ||branner-chile.com$all
+||brannon-powlowski25d.xyz$all
 ||brannudd.com$all
 ||brantech.com$all
 ||brany-profimar.sk/g/8plrj6ossbkavyt3ppmhxo32wnw2g9gmno/$all
@@ -451362,6 +451887,7 @@
 ||buysellfx24.ru$all
 ||buysmart365.net$all
 ||buysmartwebmall.com$all
+||buythebest.pk$all
 ||buytotake.online$all
 ||buytwitterlike.com$all
 ||buyuksigorta.com$all
@@ -452735,6 +453261,7 @@
 ||cashpickup.slmicrocredit.com$all
 ||cashslip.info$all
 ||cashstreamfinancial.com/wp-admin/23/$all
+||cashtunel.com$all
 ||cashyinvestment.org$all
 ||casimiroartes.es$all
 ||casinarium.com$all
@@ -456223,6 +456750,7 @@
 ||clubzone.ca$all
 ||cluebazar.com$all
 ||clukva.ru$all
+||clurbgolf.com$all
 ||clurit.com$all
 ||clusdirectory.xyz$all
 ||cluster-mixture.gq$all
@@ -456442,7 +456970,7 @@
 ||coastmedicalservice.com$all
 ||coastmotorsupply.com$all
 ||coastsignworks.com$all
-||coastwidewaterproofing.com.au/l4s6cpeyo.rar$all
+||coastwidewaterproofing.com.au$all
 ||coatforwinter.com$all
 ||coavce.com$all
 ||cobam.xyz$all
@@ -458536,6 +459064,7 @@
 ||cronolux.com.br$all
 ||croodly.com$all
 ||crookedchristicraddick.com$all
+||crooks-cooper24g.xyz$all
 ||crooks-taylor.com/1676470973/1/$all
 ||croos.org$all
 ||crope.shop$all
@@ -459840,7 +460369,7 @@
 ||dar-sana.com$all
 ||darajelita.com$all
 ||daralsalam-mall.com$all
-||daralsaqi.com$all
+||daralsaqi.com/preview.exe$all
 ||darapartment.com$all
 ||darasrszs.online$all
 ||darassalam.ch$all
@@ -459949,7 +460478,7 @@
 ||dasheriemagazine.com$all
 ||dashfiles.tk$all
 ||dashkevichseo.ru$all
-||dashonweb.com$all
+||dashonweb.com/wp-content/tscyjo/$all
 ||dashudance.com$all
 ||dashvaanjil.mn$all
 ||dasin-obchudek.cz$all
@@ -460280,7 +460809,7 @@
 ||dbravo.pro$all
 ||dbs-ebank.com$all
 ||dbsa-dream.com$all
-||dbsandbox.ca/cgi-bin/wgv9dtltdn9ebgnqzd7fy1me1ltgjuimrk2/$all
+||dbsandbox.ca$all
 ||dbsenvironmental.co.uk$all
 ||dbsgear.com$all
 ||dbsktoporder.yolasite.com$all
@@ -461270,6 +461799,7 @@
 ||denmaar.hplbusiness.com$all
 ||denmarkheating.net$all
 ||denmaytre.vn$all
+||dennis-hill25lw.xyz$all
 ||dennis-roth.de$all
 ||dennishester.com$all
 ||dennisisasshole.com$all
@@ -465771,6 +466301,9 @@
 ||down.posti-fi-fsa.top$all
 ||down.posti-fi-fsaq.top$all
 ||down.posti-fi-fwa.top$all
+||down.posti-fi-ij.top$all
+||down.posti-fi-in.top$all
+||down.posti-fi-iz.top$all
 ||down.pzchao.com$all
 ||down.qm188.com$all
 ||down.qqfarmer.com.cn$all
@@ -482550,7 +483083,7 @@
 ||egyptmotours.com$all
 ||egyptpharaohstours.com$all
 ||egyshadowmen.com$all
-||egyutthato.eu/5341zqvpdr/pay/smallbusiness$all
+||egyutthato.eu$all
 ||egyuttkonnyebb.zolitoth.com$all
 ||egyvision.medicahealthy.net$all
 ||egywebtest.ml$all
@@ -483784,7 +484317,7 @@
 ||ennessehospitality.id$all
 ||ennovate.elin.co.za$all
 ||eno.si$all
-||enolil-loo.com/agillawood/czafm/$all
+||enolil-loo.com$all
 ||enorichie.net$all
 ||enorka.info$all
 ||enosburgreading.pbworks.com$all
@@ -485832,7 +486365,7 @@
 ||faithcompassion.com$all
 ||faithconstructionltd.co.uk$all
 ||faithfight.my.id$all
-||faithmethodistcheras.org/wp-admin/vttrtc-133-57930/$all
+||faithmethodistcheras.org$all
 ||faithmontessorischools.com$all
 ||faithoasis.000webhostapp.com$all
 ||faithworkx.com$all
@@ -487227,6 +487760,7 @@
 ||findyourvoice.ca$all
 ||fine-art-line.de$all
 ||fine.black$all
+||fineartgallerym.com$all
 ||fineconera.com$all
 ||finefeather.info$all
 ||finefoodsfrozen.com$all
@@ -491064,6 +491598,7 @@
 ||girltalkza.co.za$all
 ||girlydesignart.com$all
 ||gironynavarro.com$all
+||girotexuniformes.com$all
 ||girraj2016.gtranzit.com$all
 ||girrajwadi.com$all
 ||gisa.company$all
@@ -491251,6 +491786,7 @@
 ||glafka.com$all
 ||glambooth.nl$all
 ||glamoroushairextension.com$all
+||glamorouspk.com$all
 ||glamour.rosolutions.com.mx$all
 ||glamourequipamiento.com/cxqsm/qt0q8224ftc5ln6/dp3ckgd2wk/$all
 ||glamourgarden-lb.com$all
@@ -492029,6 +492565,7 @@
 ||gordonmilktransport.com$all
 ||gordonruss.com$all
 ||gordyssensors.com$all
+||gorecycle.fahadjutt.com$all
 ||gorenotoservisi.net$all
 ||gorestruly.com$all
 ||goretimmo.lu$all
@@ -493244,7 +493781,7 @@
 ||guneyaski.com$all
 ||gungazcomputer.co.ke$all
 ||gunk.insol.be$all
-||gunma2u.com/ovp50ku/1pjj2peebf/$all
+||gunma2u.com$all
 ||gunmak-com.tk$all
 ||gunnarasgeir.com$all
 ||gunnersexcavating.com$all
@@ -495676,6 +496213,7 @@
 ||hollywoodsmileeg.com$all
 ||holmdalehouse.co.uk$all
 ||holmesgroup-com.azurewebsites.net$all
+||holmesprpmgmt.com$all
 ||holmnkolbas.com$all
 ||holmsater.se$all
 ||holod24.by$all
@@ -496412,6 +496950,7 @@
 ||hpmaytinhtaophongcach.com$all
 ||hpmwqjub.com$all
 ||hpq8fa.db.files.1drv.com$all
+||hprosacco25i.xyz$all
 ||hprpc.cn$all
 ||hps-sk.sk$all
 ||hps.nz$all
@@ -499135,6 +499674,7 @@
 ||instantbonheur.fr$all
 ||instantcashflowtoday.com.ng$all
 ||instantclients.network$all
+||instantindialoan.com$all
 ||instanttaxsolutions.mobi$all
 ||instanttechnology.com.au$all
 ||instantworldpay.com$all
@@ -499995,6 +500535,7 @@
 ||isciyizbiz.com$all
 ||iscleanone.com$all
 ||isclimatechangeahoax.com$all
+||iscoegypt.com$all
 ||iscoming.ir$all
 ||iscon.com.br$all
 ||iscondisth.com$all
@@ -500051,7 +500592,9 @@
 ||iskro.textronic.info$all
 ||iskyservice.ru$all
 ||islaholics.com$all
-||islamabadtrafficpolice.gov.pk$all
+||islamabadtrafficpolice.gov.pk/browse/w6nsp2/fv54115180147v7ko46qxn3bvlmfq1/$all
+||islamabadtrafficpolice.gov.pk/esp/94406698/cppdv/$all
+||islamabadtrafficpolice.gov.pk/i/$all
 ||islamabout.com$all
 ||islamappen.se$all
 ||islamforall.tv$all
@@ -501919,6 +502462,7 @@
 ||jollycharm.com$all
 ||jollyemma.com$all
 ||jolyscortinas.com.br$all
+||jomansea.com$all
 ||jomar2020.com.br$all
 ||jomblo.com$all
 ||jomhermonex.com$all
@@ -502649,6 +503193,7 @@
 ||justkp.com$all
 ||justlficante.mediafire.com/file/4t8lltc9x35wzus/justt1.tgz/file$all
 ||justlficante.mediafire.com/file/g3y3o84bbgkhu4o/jusf1c.tgz/file$all
+||justlficante.mediafire.com/file/jl01o54yy09qrzg/fac215.tgz/file$all
 ||justmaha.com$all
 ||justmail24.com$all
 ||justmyblog.info$all
@@ -503333,6 +503878,7 @@
 ||kasperskysecurity.club$all
 ||kasrasanatsepahan.com$all
 ||kassa.hostsites.ru$all
+||kassandra5024d.xyz$all
 ||kassconnect.ru$all
 ||kasshmira.com$all
 ||kassohome.com.tr$all
@@ -503994,7 +504540,8 @@
 ||khannen.com.vn$all
 ||khannen.vn$all
 ||khanqahebrahimi.com$all
-||khantil.com$all
+||khantil.com/us/payments/122018$all
+||khantil.com/us/payments/122018/$all
 ||khantipong.com$all
 ||khaochills.com$all
 ||khaoden.tech$all
@@ -505910,6 +506457,7 @@
 ||lab.valvolari.it$all
 ||lab.ydigital.asia$all
 ||lab1.ozaki-kyousei.com$all
+||lab18.it$all
 ||lab2.e-century.pl$all
 ||lab5.hu$all
 ||lab6.com.br$all
@@ -511143,6 +511691,7 @@
 ||manageitrisks.com$all
 ||management.vkims.com$all
 ||managementtop.id$all
+||managemysalon.in$all
 ||managemyshoes.tools$all
 ||manageone.co.th$all
 ||manageprint.in$all
@@ -511611,7 +512160,7 @@
 ||marek-paysage-concept.fr$all
 ||marek.in$all
 ||marekvoprsal.cz$all
-||marel.com.br/wp-content/uploads/2020/10/bn8qvr2l/$all
+||marel.com.br$all
 ||marellengifts.com$all
 ||maremarius.pt$all
 ||marematto.it$all
@@ -513050,6 +513599,7 @@
 ||meditec.ma$all
 ||mediterraneavacanze.com$all
 ||meditheraphy.com$all
+||meditreat.itwebservice.in$all
 ||meditsinanarodnaya.ru$all
 ||medius.ge$all
 ||mediusvp.com$all
@@ -515292,7 +515842,7 @@
 ||mojang.com.br$all
 ||mojehaftom.com$all
 ||mojewnetrza.pl$all
-||mojno--vse.ru/content/6tqjfutopvigfknidf0sfae6guwnsxjjicomwynq0qmfksrit2be2/$all
+||mojno--vse.ru$all
 ||mojo-studios.co.uk$all
 ||mojorockstar.com$all
 ||mojstudent.net$all
@@ -516063,7 +516613,7 @@
 ||mrpower.ir$all
 ||mrprintoke.com$all
 ||mrquick.co.il$all
-||mrsambarbershop.nl/wp-content/axm4it/$all
+||mrsambarbershop.nl$all
 ||mrsbow.com$all
 ||mrsconnect.org$all
 ||mrsdiggs.com$all
@@ -516686,7 +517236,7 @@
 ||mvid.com$all
 ||mvidl.site$all
 ||mvisionproperties.com$all
-||mvldesign.ca/durani/2lzs/$all
+||mvldesign.ca$all
 ||mvm368.com$all
 ||mvmskpd.com$all
 ||mvns.railfan.net$all
@@ -518096,7 +518646,7 @@
 ||nelsonhelps.com$all
 ||nelsonhostingcom.000webhostapp.com$all
 ||nelsonpto.org$all
-||nelsonsbutchers.co.uk/cgi-bin/4vlaf1vqrwyfgwgxp33pcd1uydauib40dllquefurt5547d0xsmo/$all
+||nelsonsbutchers.co.uk$all
 ||nelsonsilveti.com$all
 ||neltac.com$all
 ||nelyvos.nl$all
@@ -519486,7 +520036,7 @@
 ||no1angelsescort.com$all
 ||no1spinningfields.90degrees.digital$all
 ||no1websitedesigner.com$all
-||no2politics.com$all
+||no2politics.com/files/us_us/doc/invoice-069345/$all
 ||no70.fun$all
 ||noabuseshere.top$all
 ||noach.nl$all
@@ -520863,6 +521413,7 @@
 ||ohako.com.my$all
 ||ohamburguer.com.br$all
 ||ohanadev.com$all
+||ohatsbd.com$all
 ||ohdratdigital.com$all
 ||ohe.ie$all
 ||ohelloguyzzqq.com$all
@@ -521175,6 +521726,7 @@
 ||omagroup.ru$all
 ||omaharefugees.com$all
 ||omahduwur.com$all
+||omaia.org$all
 ||omaint.ml$all
 ||omalleyco-my.sharepoint.com$all
 ||omalll.com$all
@@ -523361,6 +523913,7 @@
 ||onedrive.live.com/download?cid=d7a53f4e448c59af&resid=d7a53f4e448c59af%21930&authkey=ae8aykwfbemxegw$all
 ||onedrive.live.com/download?cid=d86391352444eeed&resid=d86391352444eeed!107&authkey=ajitiybfqf5qcpw$all
 ||onedrive.live.com/download?cid=d86391352444eeed&resid=d86391352444eeed%21107&authkey=ajitiybfqf5qcpw$all
+||onedrive.live.com/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21107&authkey=alo4lep7wht05na$all
 ||onedrive.live.com/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21109&authkey=adnbm6mekgzvvh8$all
 ||onedrive.live.com/download?cid=d88d6079d4b91bdb&resid=d88d6079d4b91bdb!391&authkey=afgbzttalahmq9a$all
 ||onedrive.live.com/download?cid=d8a7da7154194e40&resid=d8a7da7154194e40!970&authkey=!alf9m4lwilj_jre$all
@@ -529915,6 +530468,7 @@
 ||pastebin.com/raw/qmhtgbwv$all
 ||pastebin.com/raw/qmq7ggtb$all
 ||pastebin.com/raw/qmsdyt9z$all
+||pastebin.com/raw/qmue83xz$all
 ||pastebin.com/raw/qmxvzneq$all
 ||pastebin.com/raw/qn1aczmi$all
 ||pastebin.com/raw/qndvdcqj$all
@@ -535382,6 +535936,7 @@
 ||promodont.com$all
 ||promokonyara.ru$all
 ||promolatinconferences.com$all
+||promolyko.com$all
 ||promomitsubishitermurah.net$all
 ||promonoble.com$all
 ||promootzie.nl$all
@@ -536853,7 +537408,7 @@
 ||quickpickapp.co$all
 ||quickreachmedia.com$all
 ||quicksaleecuador.com$all
-||quickshine.co.ke/categoryl/eyoerdilcvrt0wf2zcac6633eytah/$all
+||quickshine.co.ke$all
 ||quickstorevn.com$all
 ||quicktechsupport247.com$all
 ||quicktowtowing.com$all
@@ -539141,6 +539696,7 @@
 ||rgfloors.com.au$all
 ||rgho.st/download/6nnmwrj65/e2fd966cb90832c49db58889a5bce7fa7eb6f67c/e2fd966cb90832c49db58889a5bce7fa7eb6f67c/fornite%20hack%202018.exe$all
 ||rgitabit.in$all
+||rgleason25s.xyz$all
 ||rglgrupomedico.com.mx$all
 ||rgmobilegossip.com$all
 ||rgmvanijya.com$all
@@ -539998,6 +540554,7 @@
 ||rosemaryromero.com.br$all
 ||rosemiracle.com$all
 ||rosemurphy.co.uk$all
+||rosenbaum-jaida24nz.xyz$all
 ||rosenfeldcapital.com$all
 ||rosenlaw.cratima.com$all
 ||roseperfeito.com.br$all
@@ -544283,6 +544840,7 @@
 ||shataikok.com$all
 ||shatelnews.ir$all
 ||shatki.info/templates/ld_benew/images/blue/messg.jpg$all
+||shatteredglass.io$all
 ||shaukya.com$all
 ||shaulla.store$all
 ||shaunodonnell.com$all
@@ -546218,7 +546776,7 @@
 ||smartlync.pk$all
 ||smartmadira.com$all
 ||smartmassive.ru$all
-||smartmatrixs.com/beta/llc/2af68g7w0ysysv95nutlsp_0bunhkbg-9466852086487/$all
+||smartmatrixs.com$all
 ||smartmobilelearning.co.za$all
 ||smartmoneylife.com$all
 ||smartmovie.com.ua$all
@@ -547211,6 +547769,7 @@
 ||sosenfantsburkinafaso.fr$all
 ||sosexymagazine.com$all
 ||sosflam.com$all
+||sosgsm.fr$all
 ||sosh47.citycheb.ru$all
 ||sosoab.com$all
 ||sosofoto.cz$all
@@ -553613,6 +554172,7 @@
 ||tecnologiatech.com$all
 ||tecnologiaz.com$all
 ||tecnologicainformatica.com.br$all
+||tecnologyschool.com$all
 ||tecnolora.com$all
 ||tecnoloxia.com$all
 ||tecnopc.info$all
@@ -556492,7 +557052,7 @@
 ||toby-warren.com$all
 ||tobyetc.com$all
 ||tobysherman.com$all
-||tocaima.co/wp-includes/dj5aol1nnnzjdyzvqurfh2lopouzceyok8ndyuoew/$all
+||tocaima.co$all
 ||tocakids.resultaweb.com.br$all
 ||tocchientv.com/cgi-bin/gegesa/$all
 ||tocgiajojo.com$all
@@ -557667,6 +558227,7 @@
 ||tresnexus.com$all
 ||treterhef.download$all
 ||tretthing-bg.site$all
+||treutel-jamir25ju.xyz$all
 ||trevellinglove.com$all
 ||trevinos.net$all
 ||trevorchristensen.com$all
@@ -561191,6 +561752,7 @@
 ||vastraindia.com$all
 ||vastralaya.shop$all
 ||vastuanalyst.com$all
+||vastubless.com$all
 ||vastuvidyaarchitects.com$all
 ||vasudhagoodharvest.com$all
 ||vasumadhi.com$all
@@ -562559,6 +563121,7 @@
 ||vladetel.org$all
 ||vladimirfilin.com$all
 ||vladimirfilin.ru$all
+||vladimirinternational.com$all
 ||vladneta.lt$all
 ||vladsever.ru$all
 ||vladsp.ru$all
@@ -563594,6 +564157,7 @@
 ||web.emergingsun.com$all
 ||web.emsfabrik.de$all
 ||web.eng.ubu.ac.th$all
+||web.geetle.ga$all
 ||web.geomegasoft.net$all
 ||web.golden-goblin.com$all
 ||web.gotham.com.au$all
@@ -564446,6 +565010,7 @@
 ||whyasksolution.com$all
 ||whybowl.thebotogs.com$all
 ||whyepicshop.com$all
+||whynt.xyz$all
 ||whysquare.co.nz$all
 ||whystudio.cn$all
 ||whytech.info$all
@@ -565546,7 +566111,7 @@
 ||wrrodrigo.com$all
 ||wrtech.com.pl$all
 ||wrusnollet.com$all
-||wrzucacz.pl/download/1211536055165$all
+||wrzucacz.pl$all
 ||wrzutka.co$all
 ||ws-ebavisapia01-dll.ir$all
 ||ws3lfkm.com$all
@@ -566015,6 +566580,7 @@
 ||xhcmnews.com$all
 ||xhd.qhv.mybluehost.me$all
 ||xhencheng.tk$all
+||xherzog24pv.xyz$all
 ||xhjclq.ch.files.1drv.com$all
 ||xhs9a81.com$all
 ||xhsdxm.com$all
@@ -567946,7 +568512,7 @@
 ||zafirotiendas.com$all
 ||zagnet.pl$all
 ||zagogulina.com$all
-||zagoradesertcamp.com/templates/u/$all
+||zagoradesertcamp.com$all
 ||zagrodazbyszka.pl$all
 ||zagros-shahrekord.ir$all
 ||zagrosenergygroup.com$all
@@ -568002,6 +568568,7 @@
 ||zakopane.utazas.hu$all
 ||zakopanedomki.com.pl$all
 ||zakosciele66.cba.pl$all
+||zakra.tecnasulstore.com.br$all
 ||zakrahgroup.com$all
 ||zakriasons.co$all
 ||zakromanoff.com$all
diff --git a/urlhaus-filter-agh-online.txt b/urlhaus-filter-agh-online.txt
index 9a4003b1..b80aecc3 100644
--- a/urlhaus-filter-agh-online.txt
+++ b/urlhaus-filter-agh-online.txt
@@ -1,5 +1,5 @@
 ! Title: Online Malicious URL Blocklist (AdGuard Home)
-! Updated: Thu, 25 Mar 2021 12:12:40 UTC
+! Updated: Fri, 26 Mar 2021 00:12:29 UTC
 ! Expires: 1 day (update frequency)
 ! Homepage: https://gitlab.com/curben/urlhaus-filter
 ! License: https://gitlab.com/curben/urlhaus-filter#license
@@ -12,7 +12,6 @@
 ||1.192.180.19^
 ||1.222.140.251^
 ||1.222.196.60^
-||1.24.132.118^
 ||1.245.4.163^
 ||1.246.222.107^
 ||1.246.222.109^
@@ -22,8 +21,10 @@
 ||1.246.222.153^
 ||1.246.222.165^
 ||1.246.222.16^
+||1.246.222.228^
 ||1.246.222.232^
 ||1.246.222.234^
+||1.246.222.237^
 ||1.246.222.245^
 ||1.246.222.249^
 ||1.246.222.38^
@@ -35,7 +36,6 @@
 ||1.246.222.80^
 ||1.246.222.8^
 ||1.246.222.98^
-||1.246.222.9^
 ||1.246.223.103^
 ||1.246.223.105^
 ||1.246.223.10^
@@ -66,23 +66,19 @@
 ||1.250.159.41^
 ||1.252.102.28^
 ||1.254.250.52^
+||1.58.223.96^
 ||1.60.77.53^
-||1.62.195.101^
 ||1.65.166.225^
 ||1.82.104.89^
-||1.85.84.38^
 ||100.12.184.63^
 ||100.2.131.143^
 ||100.8.77.4^
 ||1008691.com^
 ||101.108.130.108^
-||101.108.131.202^
-||101.108.133.231^
 ||101.16.183.179^
 ||101.16.98.170^
 ||101.229.85.127^
 ||101.255.36.154^
-||101.28.102.38^
 ||101.28.105.132^
 ||101.28.106.134^
 ||101.28.145.2^
@@ -93,45 +89,49 @@
 ||101.75.157.99^
 ||102.130.115.14^
 ||102.141.240.139^
-||103.106.29.148^
 ||103.107.113.22^
 ||103.113.99.79^
 ||103.124.104.118^
 ||103.125.218.107^
 ||103.136.82.50^
-||103.139.89.205^
 ||103.141.138.12^
 ||103.144.36.20^
 ||103.145.13.24^
 ||103.146.174.208^
 ||103.156.221.66^
 ||103.16.145.25^
+||103.161.232.16^
+||103.207.0.134^
 ||103.217.215.21^
 ||103.224.200.40^
 ||103.233.64.182^
-||103.235.165.183^
 ||103.238.228.3^
 ||103.238.228.4^
 ||103.240.249.121^
+||103.4.117.26^
 ||103.70.160.51^
 ||103.79.112.254^
+||103.82.144.197^
 ||103.82.145.111^
+||103.82.98.151^
 ||103.82.98.170^
-||103.84.240.130^
 ||103.84.240.228^
-||103.91.245.11^
 ||103.91.245.12^
+||103.91.245.16^
 ||103.91.245.17^
 ||103.91.245.19^
 ||103.91.245.20^
+||103.91.245.27^
+||103.91.245.30^
 ||103.91.245.36^
 ||103.91.245.3^
+||103.91.245.41^
 ||103.91.245.46^
 ||103.91.245.47^
 ||103.91.245.54^
 ||103.92.25.90^
 ||103.92.25.95^
-||104.168.44.57^
+||104.168.98.105^
 ||104.184.75.123^
 ||104.33.52.85^
 ||104.61.86.37^
@@ -140,6 +140,7 @@
 ||106.104.193.155^
 ||106.113.145.32^
 ||106.113.177.60^
+||106.4.138.95^
 ||107.172.134.48^
 ||107.172.193.132^
 ||107.172.249.148^
@@ -158,8 +159,8 @@
 ||109.124.90.229^
 ||109.233.196.232^
 ||109.235.7.228^
-||109.248.58.238^
 ||109.86.85.253^
+||109.88.185.119^
 ||109.95.200.102^
 ||109.95.200.230^
 ||109.96.127.90^
@@ -174,6 +175,7 @@
 ||110.228.195.46^
 ||110.241.119.168^
 ||110.241.23.107^
+||110.247.151.4^
 ||110.248.124.254^
 ||110.248.224.19^
 ||110.248.251.194^
@@ -183,22 +185,25 @@
 ||110.253.51.112^
 ||110.255.101.184^
 ||110.255.167.147^
-||110.35.145.127^
 ||110.35.208.21^
 ||110.35.209.175^
-||110.35.221.77^
 ||110.35.223.92^
+||110.35.225.24^
+||110.35.233.147^
 ||110.35.235.57^
+||110.35.249.21^
 ||110.35.4.2^
-||110.82.195.88^
 ||110fss.net^
-||111.118.124.223^
+||111.118.111.207^
 ||111.118.41.173^
 ||111.118.88.61^
+||111.119.245.114^
 ||111.125.67.125^
 ||111.160.112.142^
 ||111.162.224.14^
 ||111.163.50.120^
+||111.165.21.195^
+||111.165.28.234^
 ||111.17.186.194^
 ||111.170.84.182^
 ||111.170.86.133^
@@ -212,6 +217,7 @@
 ||111.185.230.136^
 ||111.185.27.9^
 ||111.185.48.248^
+||111.38.103.114^
 ||111.38.103.122^
 ||111.38.103.13^
 ||111.38.103.66^
@@ -234,16 +240,16 @@
 ||111.61.52.53^
 ||111.73.99.162^
 ||111.91.185.131^
+||111.92.63.24^
 ||111.93.169.90^
 ||112.105.117.227^
 ||112.111.100.236^
 ||112.111.108.184^
 ||112.111.31.175^
 ||112.122.36.108^
-||112.123.109.156^
 ||112.123.200.47^
-||112.123.61.115^
 ||112.132.134.106^
+||112.159.108.96^
 ||112.170.124.75^
 ||112.170.233.9^
 ||112.186.210.211^
@@ -299,10 +305,10 @@
 ||112.242.2.247^
 ||112.243.115.183^
 ||112.245.12.89^
-||112.245.246.253^
 ||112.245.5.141^
 ||112.245.8.24^
 ||112.246.162.50^
+||112.246.180.49^
 ||112.247.100.14^
 ||112.247.121.39^
 ||112.247.14.135^
@@ -310,6 +316,7 @@
 ||112.247.191.118^
 ||112.247.214.146^
 ||112.247.240.226^
+||112.247.248.76^
 ||112.247.81.173^
 ||112.247.82.122^
 ||112.247.89.81^
@@ -318,8 +325,10 @@
 ||112.248.44.153^
 ||112.249.109.217^
 ||112.249.118.157^
+||112.249.206.69^
 ||112.249.26.129^
 ||112.249.41.142^
+||112.249.79.98^
 ||112.250.102.173^
 ||112.250.57.99^
 ||112.251.17.5^
@@ -332,6 +341,7 @@
 ||112.252.237.109^
 ||112.252.239.103^
 ||112.252.245.249^
+||112.252.46.212^
 ||112.254.208.123^
 ||112.255.38.10^
 ||112.255.52.179^
@@ -346,6 +356,7 @@
 ||112.27.124.119^
 ||112.27.124.120^
 ||112.27.124.122^
+||112.27.124.124^
 ||112.27.124.127^
 ||112.27.124.128^
 ||112.27.124.130^
@@ -361,7 +372,6 @@
 ||112.27.124.146^
 ||112.27.124.149^
 ||112.27.124.150^
-||112.27.124.151^
 ||112.27.124.155^
 ||112.27.124.158^
 ||112.27.124.160^
@@ -450,12 +460,10 @@
 ||112.72.153.37^
 ||112.72.162.159^
 ||112.72.162.49^
-||112.72.162.53^
 ||112.72.175.147^
 ||112.72.176.112^
 ||112.72.176.84^
 ||112.72.226.202^
-||112.72.231.35^
 ||112.78.45.158^
 ||112.80.118.16^
 ||112.80.127.91^
@@ -472,18 +480,17 @@
 ||112.82.227.41^
 ||112.82.228.175^
 ||112.86.133.125^
-||112.86.23.41^
 ||112.86.253.238^
 ||112.9.140.247^
 ||112.93.29.211^
 ||112.95.22.17^
 ||112.95.23.121^
 ||113.103.10.209^
+||113.104.237.52^
 ||113.105.71.239^
-||113.11.95.254^
-||113.110.247.207^
 ||113.116.121.167^
 ||113.116.149.83^
+||113.116.150.147^
 ||113.116.246.109^
 ||113.116.48.217^
 ||113.118.195.247^
@@ -492,11 +499,11 @@
 ||113.161.58.249^
 ||113.172.250.35^
 ||113.179.129.99^
-||113.188.76.31^
 ||113.194.133.9^
 ||113.194.135.154^
 ||113.195.163.26^
 ||113.195.166.46^
+||113.201.24.26^
 ||113.224.225.172^
 ||113.226.42.250^
 ||113.227.128.9^
@@ -506,31 +513,28 @@
 ||113.231.93.142^
 ||113.232.141.23^
 ||113.232.211.182^
+||113.234.224.130^
 ||113.235.116.209^
 ||113.237.129.7^
-||113.245.218.18^
+||113.253.144.141^
 ||113.254.169.251^
 ||113.3.153.57^
 ||113.3.155.199^
 ||113.59.133.16^
-||113.59.136.39^
-||113.59.144.42^
 ||113.59.154.21^
-||113.59.191.47^
 ||113.61.204.205^
+||113.81.112.35^
 ||113.86.204.13^
 ||113.87.175.112^
-||113.87.32.93^
+||113.87.248.177^
+||113.88.100.120^
 ||113.88.208.189^
 ||113.88.232.36^
+||113.88.242.0^
 ||113.88.38.232^
-||113.89.41.33^
+||113.89.245.13^
 ||113.89.41.51^
-||113.92.156.196^
-||113.93.225.12^
 ||114.199.204.37^
-||114.199.253.235^
-||114.223.122.19^
 ||114.226.100.56^
 ||114.227.156.119^
 ||114.228.205.101^
@@ -539,53 +543,62 @@
 ||114.229.52.14^
 ||114.235.115.236^
 ||114.235.42.152^
-||114.30.54.64^
 ||114.79.161.94^
 ||114.79.172.42^
 ||115.165.216.112^
+||115.171.239.28^
 ||115.193.130.126^
+||115.201.38.185^
 ||115.208.101.195^
+||115.213.187.251^
 ||115.223.159.80^
 ||115.23.88.135^
 ||115.42.47.36^
+||115.45.178.12^
 ||115.48.130.181^
+||115.48.130.187^
+||115.48.135.151^
 ||115.48.141.239^
 ||115.48.198.142^
-||115.48.215.189^
+||115.48.200.115^
 ||115.48.22.130^
 ||115.48.228.176^
 ||115.48.9.246^
 ||115.49.100.124^
-||115.49.18.53^
-||115.49.216.150^
+||115.49.152.10^
+||115.49.242.100^
 ||115.49.60.231^
+||115.49.80.117^
+||115.49.96.88^
 ||115.50.1.143^
 ||115.50.158.223^
 ||115.50.2.251^
-||115.50.219.100^
-||115.50.22.86^
+||115.50.202.11^
 ||115.50.220.156^
-||115.50.224.175^
-||115.50.230.43^
-||115.50.232.149^
 ||115.50.239.222^
-||115.50.3.25^
-||115.50.56.198^
-||115.50.8.131^
+||115.50.240.230^
+||115.50.61.247^
+||115.50.64.182^
 ||115.50.81.194^
 ||115.51.104.85^
+||115.51.107.18^
 ||115.51.123.216^
 ||115.51.93.76^
 ||115.52.112.200^
+||115.52.17.196^
 ||115.52.19.250^
 ||115.52.200.245^
+||115.52.201.231^
 ||115.52.21.5^
-||115.54.192.172^
-||115.54.222.126^
+||115.52.22.162^
+||115.54.160.25^
+||115.54.212.227^
 ||115.54.236.22^
+||115.54.240.173^
 ||115.54.241.122^
+||115.54.70.108^
 ||115.54.73.162^
-||115.55.105.163^
+||115.54.73.50^
 ||115.55.144.146^
 ||115.55.144.222^
 ||115.55.144.42^
@@ -593,58 +606,70 @@
 ||115.55.149.30^
 ||115.55.178.67^
 ||115.55.198.209^
+||115.55.211.41^
 ||115.55.211.86^
+||115.55.3.36^
 ||115.55.42.200^
 ||115.55.53.51^
 ||115.56.134.116^
 ||115.56.134.220^
+||115.56.136.144^
 ||115.56.139.122^
 ||115.56.142.251^
 ||115.56.143.241^
 ||115.56.148.22^
+||115.56.154.147^
 ||115.56.155.72^
 ||115.56.156.185^
+||115.56.156.54^
 ||115.56.162.173^
-||115.56.178.107^
+||115.56.177.202^
 ||115.56.188.24^
 ||115.56.31.54^
-||115.56.67.22^
 ||115.56.86.251^
 ||115.56.87.42^
 ||115.56.98.205^
 ||115.58.111.222^
 ||115.58.119.171^
+||115.58.132.199^
 ||115.58.134.143^
 ||115.58.141.177^
+||115.58.167.90^
+||115.58.20.186^
 ||115.58.83.233^
 ||115.58.88.163^
 ||115.58.93.151^
 ||115.59.197.123^
 ||115.59.198.165^
+||115.59.198.200^
 ||115.59.210.228^
+||115.59.215.96^
 ||115.59.235.229^
 ||115.59.253.202^
-||115.59.26.134^
 ||115.59.63.220^
+||115.59.95.247^
+||115.60.201.176^
 ||115.61.107.203^
-||115.61.111.142^
+||115.61.118.201^
 ||115.61.119.187^
 ||115.61.119.198^
 ||115.61.119.77^
 ||115.61.125.184^
-||115.61.137.47^
 ||115.61.180.193^
 ||115.61.182.138^
 ||115.61.185.246^
 ||115.61.97.190^
+||115.61.97.55^
+||115.62.152.207^
 ||115.62.26.39^
-||115.62.60.206^
 ||115.63.135.206^
+||115.63.140.242^
 ||115.63.4.244^
 ||115.63.56.176^
 ||115.73.3.11^
 ||115.74.217.2^
 ||115.75.217.79^
+||115.78.133.146^
 ||115.92.174.231^
 ||116.124.219.2^
 ||116.127.207.224^
@@ -655,18 +680,20 @@
 ||116.211.100.26^
 ||116.212.142.215^
 ||116.24.153.40^
-||116.72.201.93^
-||116.75.192.140^
+||116.72.202.126^
+||116.72.202.87^
+||116.72.203.143^
+||116.74.84.65^
+||116.75.194.14^
 ||116.76.114.71^
 ||116.88.65.131^
 ||117.11.234.35^
-||117.11.95.179^
 ||117.15.201.1^
-||117.192.224.243^
-||117.192.225.29^
-||117.192.226.96^
-||117.194.162.116^
-||117.194.163.237^
+||117.156.69.22^
+||117.194.160.84^
+||117.194.161.143^
+||117.194.162.121^
+||117.196.48.216^
 ||117.20.204.138^
 ||117.20.204.5^
 ||117.20.210.52^
@@ -676,39 +703,25 @@
 ||117.200.76.54^
 ||117.200.76.60^
 ||117.201.128.152^
-||117.202.66.23^
-||117.202.67.181^
-||117.202.67.218^
-||117.202.68.75^
-||117.213.41.18^
-||117.213.42.147^
-||117.213.42.226^
-||117.213.44.184^
-||117.213.45.119^
-||117.213.45.150^
-||117.213.45.204^
-||117.213.46.124^
-||117.213.46.243^
-||117.215.213.155^
-||117.215.215.188^
-||117.222.160.86^
-||117.222.165.221^
-||117.222.166.6^
-||117.222.169.193^
-||117.222.170.122^
-||117.222.175.220^
+||117.202.66.177^
+||117.202.68.94^
+||117.208.133.121^
+||117.222.161.68^
+||117.222.162.144^
+||117.222.163.150^
+||117.222.165.31^
+||117.222.170.189^
+||117.222.171.68^
+||117.222.172.97^
 ||117.241.66.200^
 ||117.241.67.68^
-||117.242.211.217^
-||117.247.204.33^
-||117.247.206.195^
-||117.248.60.21^
-||117.251.56.191^
-||117.251.56.244^
-||117.251.56.64^
-||117.251.56.73^
+||117.242.210.69^
+||117.242.211.111^
+||117.242.211.98^
+||117.251.56.135^
+||117.251.59.242^
 ||117.251.60.161^
-||117.251.63.211^
+||117.251.60.69^
 ||117.26.110.17^
 ||117.26.235.164^
 ||117.27.10.73^
@@ -716,8 +729,11 @@
 ||117.63.195.140^
 ||117.63.252.82^
 ||117.63.53.15^
+||117.63.56.81^
+||117.86.105.110^
 ||117.87.170.32^
 ||117.90.78.120^
+||117.91.240.50^
 ||117.93.115.242^
 ||117.93.79.40^
 ||118.176.104.35^
@@ -734,19 +750,20 @@
 ||118.232.88.146^
 ||118.232.96.150^
 ||118.232.96.6^
-||118.233.165.213^
 ||118.233.221.162^
+||118.233.63.194^
 ||118.233.65.93^
 ||118.249.136.112^
 ||118.250.51.192^
-||118.38.189.207^
 ||118.42.125.246^
 ||118.43.180.33^
 ||118.68.245.69^
+||118.75.120.136^
+||118.75.240.239^
 ||118.75.50.253^
 ||118.75.70.70^
 ||118.79.125.92^
-||118.79.143.45^
+||118.79.164.102^
 ||118.79.218.157^
 ||118.79.50.203^
 ||118.79.58.82^
@@ -762,7 +779,7 @@
 ||119.112.22.58^
 ||119.118.251.73^
 ||119.119.52.202^
-||119.123.219.137^
+||119.123.175.133^
 ||119.14.143.145^
 ||119.147.213.57^
 ||119.162.109.111^
@@ -774,6 +791,7 @@
 ||119.165.107.93^
 ||119.165.163.220^
 ||119.165.174.63^
+||119.165.208.73^
 ||119.165.241.222^
 ||119.165.27.77^
 ||119.165.68.145^
@@ -793,6 +811,7 @@
 ||119.179.170.212^
 ||119.179.27.213^
 ||119.179.43.1^
+||119.179.44.141^
 ||119.179.75.8^
 ||119.18.38.144^
 ||119.180.101.151^
@@ -803,6 +822,7 @@
 ||119.180.231.79^
 ||119.180.33.161^
 ||119.180.80.69^
+||119.180.9.35^
 ||119.180.94.80^
 ||119.181.124.203^
 ||119.181.43.18^
@@ -829,6 +849,7 @@
 ||119.191.215.221^
 ||119.191.253.206^
 ||119.204.30.144^
+||119.250.129.231^
 ||119.250.218.177^
 ||119.251.105.221^
 ||119.251.12.85^
@@ -836,12 +857,12 @@
 ||119.56.131.155^
 ||119.56.143.46^
 ||119.56.143.71^
+||119.56.144.75^
 ||119.56.148.115^
 ||119.56.155.57^
+||119.56.166.36^
 ||119.56.172.28^
-||119.56.175.41^
 ||119.56.206.43^
-||119.56.220.170^
 ||119.96.37.55^
 ||119.96.70.116^
 ||119.99.188.187^
@@ -856,6 +877,7 @@
 ||12.207.39.227^
 ||120.12.144.232^
 ||120.12.153.54^
+||120.12.212.5^
 ||120.142.222.22^
 ||120.150.213.110^
 ||120.151.248.134^
@@ -900,20 +922,19 @@
 ||120.43.54.218^
 ||120.50.66.60^
 ||120.50.93.115^
-||120.59.245.212^
 ||120.6.141.142^
 ||120.6.8.11^
 ||120.69.113.208^
 ||120.69.131.51^
 ||120.7.90.104^
 ||120.85.165.141^
-||120.85.169.138^
+||120.85.173.137^
 ||120.85.174.165^
 ||120.85.174.175^
-||120.85.186.112^
+||120.85.174.39^
+||120.85.199.222^
+||120.85.212.45^
 ||120.85.237.129^
-||120.85.239.77^
-||120.86.84.72^
 ||120.9.32.51^
 ||121.100.114.164^
 ||121.100.96.8^
@@ -941,6 +962,7 @@
 ||121.24.116.173^
 ||121.25.101.86^
 ||121.254.43.215^
+||121.34.150.32^
 ||121.61.101.93^
 ||121.61.102.1^
 ||121.61.107.189^
@@ -950,6 +972,8 @@
 ||122.100.150.204^
 ||122.137.52.122^
 ||122.160.147.53^
+||122.188.86.225^
+||122.190.19.204^
 ||122.192.190.203^
 ||122.194.191.57^
 ||122.199.72.23^
@@ -957,19 +981,18 @@
 ||122.199.83.86^
 ||122.202.37.85^
 ||122.202.41.23^
-||122.252.241.170^
 ||122.252.250.22^
 ||122.254.183.207^
 ||122.254.29.37^
 ||122.254.33.214^
 ||123.0.240.58^
 ||123.10.128.46^
+||123.10.131.225^
 ||123.10.140.225^
-||123.10.210.87^
+||123.10.209.95^
 ||123.10.36.124^
 ||123.10.41.32^
-||123.11.1.232^
-||123.11.74.72^
+||123.10.83.136^
 ||123.110.124.238^
 ||123.110.124.244^
 ||123.110.170.237^
@@ -977,13 +1000,15 @@
 ||123.110.19.248^
 ||123.110.200.98^
 ||123.110.238.188^
-||123.12.238.89^
+||123.12.229.243^
 ||123.12.3.58^
+||123.12.36.185^
 ||123.128.128.205^
 ||123.128.133.91^
 ||123.129.84.36^
 ||123.129.88.123^
-||123.130.169.45^
+||123.13.101.56^
+||123.13.30.75^
 ||123.130.208.52^
 ||123.130.23.110^
 ||123.130.37.182^
@@ -1000,9 +1025,9 @@
 ||123.135.71.150^
 ||123.14.101.111^
 ||123.14.150.79^
+||123.14.205.23^
 ||123.14.217.22^
 ||123.14.235.65^
-||123.14.248.97^
 ||123.14.76.38^
 ||123.14.88.195^
 ||123.152.42.4^
@@ -1013,6 +1038,7 @@
 ||123.159.137.101^
 ||123.159.31.110^
 ||123.159.8.100^
+||123.183.123.41^
 ||123.191.173.88^
 ||123.192.101.163^
 ||123.192.194.233^
@@ -1033,7 +1059,6 @@
 ||123.234.116.110^
 ||123.234.184.57^
 ||123.234.246.103^
-||123.235.107.135^
 ||123.240.103.89^
 ||123.240.181.57^
 ||123.240.79.61^
@@ -1041,39 +1066,42 @@
 ||123.241.184.124^
 ||123.27.44.219^
 ||123.28.217.23^
+||123.4.180.137^
+||123.4.185.137^
 ||123.4.193.171^
 ||123.4.44.217^
 ||123.4.85.76^
-||123.4.88.225^
 ||123.4.92.3^
 ||123.5.123.162^
-||123.5.13.128^
 ||123.5.178.213^
+||123.5.188.181^
+||123.5.22.220^
 ||123.5.27.66^
-||123.8.253.37^
+||123.8.183.194^
 ||123.8.254.172^
 ||123.8.40.20^
 ||123.8.41.63^
 ||123.8.62.165^
-||123.9.110.119^
 ||123.9.243.93^
-||123.9.245.134^
 ||124.105.105.222^
 ||124.129.162.169^
 ||124.129.221.150^
 ||124.129.76.230^
 ||124.130.167.20^
+||124.130.40.31^
 ||124.131.104.82^
 ||124.131.130.95^
 ||124.131.136.75^
 ||124.131.151.135^
 ||124.131.21.39^
+||124.131.26.243^
 ||124.131.26.78^
 ||124.131.54.33^
 ||124.131.70.49^
 ||124.131.72.208^
 ||124.132.110.150^
 ||124.135.34.49^
+||124.153.136.175^
 ||124.153.236.6^
 ||124.160.126.238^
 ||124.163.138.104^
@@ -1093,9 +1121,11 @@
 ||124.6.0.4^
 ||124.7.254.85^
 ||124.80.46.73^
-||124.92.132.207^
 ||124.92.148.218^
+||124.95.17.41^
 ||125.106.125.119^
+||125.106.252.96^
+||125.126.69.95^
 ||125.128.28.161^
 ||125.142.93.34^
 ||125.168.10.234^
@@ -1103,79 +1133,82 @@
 ||125.40.1.127^
 ||125.40.107.252^
 ||125.40.113.66^
+||125.40.136.25^
 ||125.40.150.131^
 ||125.40.16.231^
 ||125.40.163.112^
+||125.40.237.130^
 ||125.40.65.120^
 ||125.40.73.6^
 ||125.40.74.153^
 ||125.40.75.22^
-||125.41.0.209^
 ||125.41.106.180^
 ||125.41.138.208^
 ||125.41.189.235^
 ||125.41.191.183^
 ||125.41.196.151^
-||125.41.2.58^
+||125.41.200.189^
 ||125.41.204.126^
 ||125.41.205.197^
-||125.41.245.135^
 ||125.41.6.192^
 ||125.41.7.204^
 ||125.41.80.153^
 ||125.41.86.72^
 ||125.41.96.53^
-||125.41.97.22^
 ||125.42.124.114^
+||125.42.125.103^
 ||125.42.234.197^
 ||125.42.96.17^
-||125.42.96.209^
 ||125.42.98.24^
+||125.43.105.157^
 ||125.43.106.162^
 ||125.43.112.123^
 ||125.43.126.184^
+||125.43.130.232^
 ||125.43.136.23^
 ||125.43.177.48^
+||125.43.21.157^
 ||125.43.26.36^
 ||125.43.34.132^
-||125.43.5.247^
 ||125.43.53.9^
-||125.43.93.164^
+||125.43.73.19^
 ||125.44.168.169^
+||125.44.212.107^
 ||125.44.213.216^
-||125.44.248.76^
-||125.44.29.38^
+||125.44.230.191^
 ||125.44.30.143^
-||125.44.42.12^
-||125.44.61.172^
+||125.44.31.79^
 ||125.44.8.227^
+||125.45.57.249^
 ||125.45.65.166^
+||125.45.90.158^
+||125.46.138.117^
 ||125.46.184.28^
-||125.46.203.85^
 ||125.46.206.206^
 ||125.47.193.134^
 ||125.47.200.11^
-||125.47.207.239^
 ||125.47.209.166^
 ||125.47.244.201^
-||125.47.29.173^
+||125.47.252.106^
+||125.47.254.44^
+||125.47.28.217^
 ||125.47.36.171^
 ||125.47.45.218^
 ||125.47.71.30^
 ||125.47.90.82^
 ||125.47.91.51^
+||125.99.220.202^
 ||128.116.133.92^
 ||130.255.159.133^
 ||134.195.139.4^
-||134.236.252.28^
 ||138.99.204.224^
 ||139.159.226.180^
 ||139.170.173.198^
 ||139.170.174.162^
+||139.170.228.166^
 ||139.216.102.151^
 ||139.227.46.137^
 ||14.102.17.222^
-||14.102.97.204^
 ||14.136.80.242^
 ||14.138.109.129^
 ||14.138.109.26^
@@ -1191,16 +1224,21 @@
 ||14.46.25.17^
 ||14.46.98.241^
 ||14.55.29.2^
+||140.237.30.113^
+||140.237.5.43^
 ||142.11.216.5^
 ||142.177.56.127^
 ||146.71.79.230^
 ||148.69.108.177^
-||149.255.15.121^
+||149.20.176.179^
 ||149.255.15.180^
 ||149.255.15.182^
+||149.255.15.191^
+||149.255.15.235^
 ||149.255.15.87^
-||149.3.36.210^
+||149.3.85.55^
 ||150.116.207.99^
+||150.129.105.61^
 ||151.177.163.87^
 ||151.33.230.191^
 ||151.51.158.195^
@@ -1213,10 +1251,12 @@
 ||153.34.135.92^
 ||153.34.23.76^
 ||153.34.29.28^
-||153.34.52.74^
+||153.35.111.46^
 ||153.35.27.49^
 ||153.36.126.35^
 ||154.126.178.16^
+||154.91.1.27^
+||157.122.105.142^
 ||158.101.165.14^
 ||158.174.213.128^
 ||158.51.125.115^
@@ -1226,12 +1266,16 @@
 ||162.191.249.195^
 ||162.194.28.60^
 ||162.209.98.174^
-||162.212.203.250^
+||163.125.183.111^
 ||163.125.195.108^
-||163.125.200.233^
+||163.125.200.72^
 ||163.125.200.73^
-||163.125.203.85^
-||163.125.223.16^
+||163.125.202.174^
+||163.125.202.74^
+||163.125.203.179^
+||163.125.207.125^
+||163.125.250.202^
+||163.125.68.29^
 ||163.53.206.228^
 ||165.90.16.5^
 ||170.78.39.3^
@@ -1245,30 +1289,31 @@
 ||171.120.125.147^
 ||171.121.6.162^
 ||171.123.189.154^
-||171.125.114.254^
 ||171.125.30.233^
 ||171.125.30.93^
 ||171.125.64.223^
+||171.125.65.22^
 ||171.126.109.145^
 ||171.34.112.42^
+||171.34.114.181^
 ||171.34.179.178^
 ||171.35.161.234^
 ||171.35.162.156^
 ||171.35.173.151^
 ||171.35.174.198^
+||171.36.42.154^
 ||171.38.219.189^
 ||171.44.254.4^
 ||172.105.36.168^
 ||172.114.244.127^
 ||172.245.5.185^
-||172.93.176.137^
+||172.245.5.190^
 ||173.167.85.89^
 ||173.169.46.85^
 ||173.19.58.108^
 ||173.220.222.227^
 ||173.233.85.171^
 ||173.235.209.70^
-||173.237.254.251^
 ||173.25.113.8^
 ||173.52.95.134^
 ||173.52.97.25^
@@ -1281,12 +1326,11 @@
 ||174.84.148.29^
 ||174.96.30.156^
 ||175.10.147.167^
-||175.10.48.233^
-||175.11.212.203^
-||175.11.96.155^
+||175.11.193.66^
 ||175.115.241.87^
 ||175.117.66.74^
 ||175.145.200.216^
+||175.146.17.227^
 ||175.153.144.2^
 ||175.162.69.13^
 ||175.169.172.216^
@@ -1303,17 +1347,20 @@
 ||176.111.174.63^
 ||176.111.174.66^
 ||176.111.174.67^
+||176.113.161.101^
 ||176.113.161.104^
 ||176.113.161.113^
 ||176.113.161.120^
 ||176.113.161.128^
 ||176.113.161.138^
 ||176.113.161.59^
+||176.113.161.60^
 ||176.113.161.65^
 ||176.113.161.66^
 ||176.113.161.84^
 ||176.113.161.88^
 ||176.113.161.91^
+||176.113.161.93^
 ||176.113.174.139^
 ||176.12.117.70^
 ||176.123.4.115^
@@ -1321,6 +1368,7 @@
 ||176.123.7.127^
 ||176.123.9.243^
 ||176.124.7.225^
+||176.221.251.147^
 ||176.240.40.142^
 ||176.240.84.106^
 ||176.32.151.180^
@@ -1329,90 +1377,103 @@
 ||177.54.82.154^
 ||177.86.235.143^
 ||178.124.182.187^
-||178.136.195.90^
-||178.141.210.251^
+||178.134.185.112^
+||178.141.161.129^
 ||178.141.25.82^
 ||178.141.57.166^
 ||178.150.174.65^
 ||178.165.122.141^
 ||178.175.0.140^
-||178.175.1.109^
+||178.175.0.232^
 ||178.175.1.247^
 ||178.175.1.250^
+||178.175.1.252^
 ||178.175.1.80^
 ||178.175.10.108^
 ||178.175.10.156^
 ||178.175.10.26^
+||178.175.10.34^
+||178.175.10.42^
 ||178.175.100.129^
 ||178.175.100.180^
 ||178.175.100.190^
 ||178.175.100.223^
 ||178.175.100.4^
+||178.175.100.87^
 ||178.175.101.110^
+||178.175.101.207^
 ||178.175.102.134^
 ||178.175.102.136^
 ||178.175.102.152^
+||178.175.102.221^
 ||178.175.102.228^
-||178.175.102.232^
 ||178.175.102.245^
-||178.175.102.81^
 ||178.175.103.172^
+||178.175.103.195^
 ||178.175.103.91^
+||178.175.104.106^
+||178.175.104.110^
 ||178.175.104.120^
 ||178.175.104.128^
 ||178.175.104.153^
-||178.175.104.161^
+||178.175.104.155^
 ||178.175.104.169^
 ||178.175.104.16^
 ||178.175.104.183^
 ||178.175.104.206^
-||178.175.104.220^
 ||178.175.104.49^
+||178.175.104.64^
 ||178.175.104.80^
 ||178.175.105.111^
+||178.175.105.125^
 ||178.175.105.146^
+||178.175.105.177^
 ||178.175.105.217^
 ||178.175.105.245^
 ||178.175.105.247^
 ||178.175.105.27^
+||178.175.105.28^
 ||178.175.105.49^
-||178.175.105.85^
+||178.175.105.94^
 ||178.175.106.118^
 ||178.175.106.18^
 ||178.175.106.193^
 ||178.175.106.219^
+||178.175.106.253^
 ||178.175.106.37^
-||178.175.106.63^
 ||178.175.106.77^
 ||178.175.106.87^
 ||178.175.107.0^
 ||178.175.107.133^
+||178.175.107.245^
 ||178.175.107.83^
+||178.175.107.86^
 ||178.175.108.116^
 ||178.175.108.145^
 ||178.175.108.148^
-||178.175.108.16^
 ||178.175.108.179^
-||178.175.108.18^
+||178.175.108.232^
 ||178.175.108.67^
 ||178.175.108.87^
+||178.175.108.94^
+||178.175.109.127^
+||178.175.109.193^
 ||178.175.109.1^
+||178.175.109.37^
 ||178.175.109.77^
+||178.175.109.78^
 ||178.175.11.176^
 ||178.175.11.184^
 ||178.175.11.204^
 ||178.175.11.57^
 ||178.175.110.150^
 ||178.175.110.155^
-||178.175.110.173^
 ||178.175.110.214^
 ||178.175.110.221^
-||178.175.110.43^
 ||178.175.110.90^
 ||178.175.110.97^
 ||178.175.111.105^
 ||178.175.111.157^
-||178.175.111.16^
 ||178.175.111.190^
 ||178.175.111.206^
 ||178.175.111.36^
@@ -1420,35 +1481,40 @@
 ||178.175.112.159^
 ||178.175.112.26^
 ||178.175.112.4^
-||178.175.113.130^
-||178.175.113.150^
+||178.175.112.79^
+||178.175.113.0^
 ||178.175.113.171^
 ||178.175.113.174^
 ||178.175.113.35^
+||178.175.113.64^
 ||178.175.113.85^
 ||178.175.114.107^
-||178.175.114.211^
 ||178.175.114.215^
 ||178.175.114.234^
 ||178.175.114.238^
 ||178.175.114.241^
+||178.175.114.247^
 ||178.175.114.254^
-||178.175.114.27^
 ||178.175.114.55^
 ||178.175.114.5^
 ||178.175.114.63^
 ||178.175.114.82^
 ||178.175.114.90^
 ||178.175.114.99^
+||178.175.115.12^
 ||178.175.115.13^
 ||178.175.115.142^
 ||178.175.115.143^
 ||178.175.115.19^
 ||178.175.115.1^
+||178.175.115.206^
+||178.175.115.208^
 ||178.175.115.221^
-||178.175.115.222^
 ||178.175.115.242^
 ||178.175.115.35^
+||178.175.115.40^
+||178.175.116.15^
+||178.175.116.236^
 ||178.175.116.48^
 ||178.175.116.64^
 ||178.175.116.87^
@@ -1456,123 +1522,124 @@
 ||178.175.117.32^
 ||178.175.117.51^
 ||178.175.117.63^
-||178.175.117.90^
+||178.175.117.84^
 ||178.175.118.112^
+||178.175.118.139^
 ||178.175.118.192^
 ||178.175.118.225^
-||178.175.118.34^
 ||178.175.118.60^
 ||178.175.119.205^
 ||178.175.119.209^
+||178.175.119.26^
 ||178.175.119.86^
 ||178.175.119.88^
-||178.175.12.179^
+||178.175.12.114^
 ||178.175.12.252^
 ||178.175.12.53^
 ||178.175.12.97^
 ||178.175.120.133^
 ||178.175.120.184^
+||178.175.120.196^
 ||178.175.120.203^
 ||178.175.120.251^
 ||178.175.121.123^
 ||178.175.121.155^
 ||178.175.121.55^
 ||178.175.121.62^
+||178.175.121.63^
 ||178.175.121.68^
 ||178.175.121.99^
-||178.175.122.144^
 ||178.175.122.172^
 ||178.175.122.245^
+||178.175.122.26^
 ||178.175.122.28^
 ||178.175.123.113^
 ||178.175.123.20^
-||178.175.123.223^
 ||178.175.123.2^
+||178.175.123.30^
 ||178.175.123.56^
 ||178.175.123.60^
 ||178.175.124.109^
 ||178.175.124.122^
 ||178.175.124.131^
 ||178.175.124.141^
-||178.175.124.157^
-||178.175.124.175^
 ||178.175.124.211^
-||178.175.124.233^
 ||178.175.124.4^
 ||178.175.124.79^
 ||178.175.124.89^
-||178.175.124.9^
 ||178.175.125.118^
-||178.175.125.143^
 ||178.175.125.14^
 ||178.175.125.153^
 ||178.175.125.156^
 ||178.175.125.174^
 ||178.175.125.219^
 ||178.175.125.39^
-||178.175.125.54^
-||178.175.126.101^
+||178.175.126.124^
 ||178.175.126.131^
 ||178.175.126.141^
 ||178.175.126.167^
 ||178.175.126.220^
 ||178.175.126.222^
 ||178.175.126.237^
-||178.175.126.80^
 ||178.175.126.83^
 ||178.175.127.109^
+||178.175.127.10^
 ||178.175.127.116^
+||178.175.127.129^
 ||178.175.127.142^
 ||178.175.127.15^
 ||178.175.127.182^
-||178.175.127.212^
 ||178.175.127.230^
 ||178.175.127.231^
 ||178.175.127.236^
+||178.175.127.238^
 ||178.175.127.63^
 ||178.175.127.75^
+||178.175.13.237^
 ||178.175.14.106^
 ||178.175.14.185^
 ||178.175.14.246^
-||178.175.14.28^
 ||178.175.14.60^
 ||178.175.15.17^
 ||178.175.15.217^
+||178.175.15.232^
+||178.175.15.246^
 ||178.175.15.252^
 ||178.175.15.35^
+||178.175.15.44^
 ||178.175.15.45^
 ||178.175.15.85^
 ||178.175.16.108^
-||178.175.16.121^
+||178.175.16.114^
 ||178.175.16.179^
 ||178.175.16.17^
+||178.175.16.193^
 ||178.175.16.1^
 ||178.175.16.208^
+||178.175.16.73^
 ||178.175.16.97^
 ||178.175.17.176^
 ||178.175.17.245^
 ||178.175.18.238^
-||178.175.18.6^
+||178.175.18.27^
 ||178.175.18.93^
 ||178.175.19.144^
 ||178.175.19.150^
 ||178.175.19.163^
 ||178.175.19.174^
+||178.175.19.229^
 ||178.175.19.242^
 ||178.175.19.44^
 ||178.175.19.47^
 ||178.175.2.110^
 ||178.175.2.237^
-||178.175.2.245^
 ||178.175.2.41^
 ||178.175.2.5^
-||178.175.2.80^
 ||178.175.20.117^
 ||178.175.20.145^
 ||178.175.20.170^
 ||178.175.20.21^
 ||178.175.20.225^
-||178.175.20.227^
 ||178.175.20.237^
 ||178.175.20.238^
 ||178.175.20.24^
@@ -1581,19 +1648,21 @@
 ||178.175.21.149^
 ||178.175.21.184^
 ||178.175.21.238^
-||178.175.21.58^
 ||178.175.21.76^
+||178.175.22.207^
+||178.175.22.248^
+||178.175.23.102^
 ||178.175.23.156^
 ||178.175.23.250^
+||178.175.23.6^
 ||178.175.24.138^
 ||178.175.24.13^
 ||178.175.24.15^
 ||178.175.24.171^
 ||178.175.24.227^
-||178.175.24.239^
-||178.175.24.251^
+||178.175.24.230^
 ||178.175.25.117^
-||178.175.25.156^
+||178.175.25.169^
 ||178.175.25.244^
 ||178.175.25.28^
 ||178.175.25.56^
@@ -1601,17 +1670,16 @@
 ||178.175.25.77^
 ||178.175.26.134^
 ||178.175.26.164^
-||178.175.26.168^
+||178.175.26.165^
+||178.175.26.215^
 ||178.175.26.219^
 ||178.175.26.224^
 ||178.175.26.246^
-||178.175.26.38^
-||178.175.26.69^
+||178.175.26.34^
 ||178.175.27.122^
 ||178.175.27.138^
 ||178.175.27.14^
 ||178.175.27.167^
-||178.175.27.169^
 ||178.175.27.179^
 ||178.175.27.199^
 ||178.175.27.202^
@@ -1619,107 +1687,106 @@
 ||178.175.27.225^
 ||178.175.27.233^
 ||178.175.27.239^
-||178.175.27.241^
+||178.175.27.32^
+||178.175.27.48^
 ||178.175.27.68^
 ||178.175.27.69^
 ||178.175.27.84^
-||178.175.28.118^
 ||178.175.28.124^
-||178.175.28.128^
-||178.175.28.167^
 ||178.175.28.168^
+||178.175.28.75^
 ||178.175.28.8^
+||178.175.29.12^
 ||178.175.29.16^
 ||178.175.29.173^
 ||178.175.29.174^
-||178.175.29.184^
 ||178.175.29.207^
 ||178.175.3.116^
+||178.175.3.123^
 ||178.175.3.130^
 ||178.175.3.172^
 ||178.175.3.190^
+||178.175.3.194^
 ||178.175.3.196^
 ||178.175.3.214^
 ||178.175.3.56^
 ||178.175.3.81^
 ||178.175.30.0^
-||178.175.30.213^
-||178.175.30.255^
 ||178.175.30.77^
 ||178.175.31.211^
 ||178.175.31.232^
 ||178.175.31.249^
 ||178.175.31.251^
 ||178.175.32.0^
-||178.175.32.105^
-||178.175.32.141^
 ||178.175.32.172^
-||178.175.32.196^
 ||178.175.32.198^
 ||178.175.32.208^
 ||178.175.32.211^
+||178.175.32.229^
 ||178.175.32.243^
-||178.175.32.32^
+||178.175.32.255^
 ||178.175.32.42^
 ||178.175.32.89^
 ||178.175.33.112^
-||178.175.33.118^
-||178.175.33.151^
 ||178.175.33.155^
 ||178.175.33.161^
 ||178.175.33.162^
 ||178.175.33.170^
+||178.175.33.173^
 ||178.175.33.174^
 ||178.175.33.181^
+||178.175.33.205^
 ||178.175.33.216^
 ||178.175.33.234^
 ||178.175.33.236^
-||178.175.33.239^
 ||178.175.33.26^
 ||178.175.33.2^
+||178.175.34.219^
+||178.175.34.56^
+||178.175.34.5^
 ||178.175.34.96^
-||178.175.35.160^
 ||178.175.35.215^
 ||178.175.35.21^
-||178.175.35.253^
 ||178.175.35.38^
 ||178.175.35.83^
 ||178.175.35.89^
 ||178.175.36.0^
 ||178.175.36.102^
 ||178.175.36.112^
+||178.175.36.127^
 ||178.175.36.12^
-||178.175.36.16^
+||178.175.36.176^
 ||178.175.36.199^
+||178.175.36.19^
 ||178.175.36.1^
-||178.175.36.200^
 ||178.175.36.218^
 ||178.175.36.223^
 ||178.175.36.22^
 ||178.175.36.33^
-||178.175.36.88^
+||178.175.36.78^
 ||178.175.37.121^
 ||178.175.37.135^
 ||178.175.37.159^
 ||178.175.37.6^
-||178.175.38.126^
 ||178.175.38.132^
-||178.175.38.148^
 ||178.175.38.162^
 ||178.175.38.165^
 ||178.175.38.191^
 ||178.175.38.1^
-||178.175.38.7^
+||178.175.38.200^
+||178.175.38.53^
 ||178.175.38.98^
 ||178.175.39.167^
+||178.175.39.176^
 ||178.175.39.245^
+||178.175.39.61^
+||178.175.4.219^
 ||178.175.4.222^
 ||178.175.4.42^
-||178.175.4.58^
 ||178.175.4.95^
+||178.175.40.145^
 ||178.175.40.151^
 ||178.175.40.166^
-||178.175.40.191^
 ||178.175.40.199^
 ||178.175.40.1^
 ||178.175.40.226^
@@ -1728,10 +1795,10 @@
 ||178.175.40.67^
 ||178.175.40.70^
 ||178.175.40.71^
-||178.175.40.73^
 ||178.175.40.82^
 ||178.175.41.165^
 ||178.175.41.178^
+||178.175.41.200^
 ||178.175.41.203^
 ||178.175.41.210^
 ||178.175.41.216^
@@ -1747,75 +1814,82 @@
 ||178.175.43.121^
 ||178.175.43.125^
 ||178.175.43.147^
-||178.175.43.176^
-||178.175.43.17^
+||178.175.43.16^
 ||178.175.43.1^
-||178.175.43.22^
 ||178.175.43.33^
-||178.175.43.44^
-||178.175.43.47^
+||178.175.43.34^
+||178.175.44.0^
 ||178.175.44.134^
 ||178.175.44.143^
 ||178.175.44.155^
+||178.175.44.197^
+||178.175.44.209^
 ||178.175.44.218^
+||178.175.44.219^
 ||178.175.44.22^
 ||178.175.44.241^
+||178.175.44.70^
 ||178.175.44.89^
 ||178.175.44.90^
+||178.175.44.95^
 ||178.175.45.205^
 ||178.175.45.221^
 ||178.175.45.224^
 ||178.175.45.230^
+||178.175.46.119^
+||178.175.46.132^
+||178.175.46.151^
 ||178.175.46.187^
 ||178.175.47.141^
 ||178.175.47.151^
 ||178.175.48.121^
 ||178.175.48.195^
 ||178.175.48.243^
+||178.175.48.76^
+||178.175.49.100^
 ||178.175.49.107^
+||178.175.49.129^
+||178.175.49.138^
+||178.175.49.188^
 ||178.175.49.247^
 ||178.175.49.3^
-||178.175.49.98^
-||178.175.5.16^
 ||178.175.5.247^
 ||178.175.5.251^
 ||178.175.5.70^
 ||178.175.50.131^
 ||178.175.50.177^
+||178.175.50.196^
 ||178.175.50.201^
 ||178.175.50.218^
 ||178.175.50.236^
 ||178.175.50.237^
-||178.175.50.47^
-||178.175.51.150^
 ||178.175.51.197^
 ||178.175.51.202^
 ||178.175.51.223^
-||178.175.51.37^
 ||178.175.51.66^
 ||178.175.52.149^
 ||178.175.52.161^
-||178.175.52.79^
 ||178.175.53.103^
-||178.175.53.15^
 ||178.175.53.186^
 ||178.175.53.20^
+||178.175.53.228^
 ||178.175.53.4^
 ||178.175.53.5^
 ||178.175.53.79^
 ||178.175.54.105^
 ||178.175.54.205^
 ||178.175.54.214^
+||178.175.54.35^
 ||178.175.54.72^
 ||178.175.55.101^
-||178.175.55.111^
 ||178.175.55.163^
-||178.175.55.204^
+||178.175.55.170^
 ||178.175.55.216^
+||178.175.55.248^
 ||178.175.55.29^
 ||178.175.55.41^
 ||178.175.55.77^
-||178.175.55.86^
+||178.175.55.85^
 ||178.175.56.103^
 ||178.175.56.196^
 ||178.175.56.33^
@@ -1824,10 +1898,8 @@
 ||178.175.57.141^
 ||178.175.57.178^
 ||178.175.57.192^
-||178.175.57.7^
-||178.175.58.117^
 ||178.175.58.141^
-||178.175.58.223^
+||178.175.58.42^
 ||178.175.59.142^
 ||178.175.59.161^
 ||178.175.59.229^
@@ -1837,37 +1909,40 @@
 ||178.175.59.91^
 ||178.175.6.134^
 ||178.175.6.151^
-||178.175.6.154^
 ||178.175.6.162^
-||178.175.6.171^
-||178.175.60.154^
+||178.175.6.72^
 ||178.175.60.181^
-||178.175.60.32^
-||178.175.60.99^
-||178.175.61.151^
+||178.175.60.209^
+||178.175.61.117^
 ||178.175.61.156^
 ||178.175.61.219^
 ||178.175.61.229^
 ||178.175.61.234^
 ||178.175.61.253^
 ||178.175.61.40^
-||178.175.61.96^
+||178.175.61.42^
+||178.175.61.82^
 ||178.175.62.110^
 ||178.175.62.115^
+||178.175.62.168^
+||178.175.62.216^
 ||178.175.62.43^
-||178.175.63.185^
+||178.175.62.44^
+||178.175.62.70^
+||178.175.63.194^
 ||178.175.63.218^
 ||178.175.63.21^
 ||178.175.64.116^
 ||178.175.64.12^
 ||178.175.64.142^
 ||178.175.64.158^
+||178.175.64.219^
 ||178.175.64.30^
 ||178.175.64.66^
 ||178.175.65.115^
-||178.175.65.136^
 ||178.175.65.171^
 ||178.175.65.223^
+||178.175.65.44^
 ||178.175.65.70^
 ||178.175.65.95^
 ||178.175.65.96^
@@ -1878,18 +1953,16 @@
 ||178.175.66.199^
 ||178.175.66.211^
 ||178.175.66.228^
-||178.175.66.237^
 ||178.175.66.93^
 ||178.175.67.0^
 ||178.175.67.184^
-||178.175.67.185^
 ||178.175.67.201^
 ||178.175.67.254^
-||178.175.67.31^
+||178.175.67.83^
 ||178.175.68.109^
 ||178.175.68.126^
-||178.175.68.166^
 ||178.175.68.170^
+||178.175.68.1^
 ||178.175.68.227^
 ||178.175.68.232^
 ||178.175.68.29^
@@ -1897,12 +1970,14 @@
 ||178.175.68.66^
 ||178.175.68.83^
 ||178.175.69.111^
+||178.175.69.112^
 ||178.175.69.119^
 ||178.175.69.128^
 ||178.175.69.138^
+||178.175.69.148^
 ||178.175.69.149^
+||178.175.69.173^
 ||178.175.69.188^
-||178.175.69.205^
 ||178.175.69.77^
 ||178.175.7.163^
 ||178.175.70.119^
@@ -1916,64 +1991,57 @@
 ||178.175.71.148^
 ||178.175.71.153^
 ||178.175.71.185^
-||178.175.71.196^
 ||178.175.71.22^
+||178.175.71.240^
 ||178.175.71.55^
 ||178.175.71.63^
+||178.175.71.64^
 ||178.175.71.84^
-||178.175.71.89^
-||178.175.72.113^
 ||178.175.72.13^
 ||178.175.72.164^
-||178.175.72.173^
 ||178.175.72.196^
 ||178.175.72.222^
-||178.175.72.47^
-||178.175.72.75^
-||178.175.72.91^
-||178.175.72.98^
-||178.175.73.220^
+||178.175.73.211^
+||178.175.73.71^
 ||178.175.74.182^
 ||178.175.74.48^
-||178.175.75.135^
+||178.175.74.77^
 ||178.175.75.181^
 ||178.175.75.19^
 ||178.175.75.209^
-||178.175.75.249^
-||178.175.75.54^
 ||178.175.75.84^
 ||178.175.75.87^
 ||178.175.76.109^
+||178.175.76.121^
 ||178.175.76.167^
 ||178.175.76.187^
 ||178.175.76.214^
 ||178.175.76.215^
 ||178.175.76.217^
 ||178.175.76.24^
-||178.175.77.132^
-||178.175.77.145^
 ||178.175.77.46^
 ||178.175.77.47^
 ||178.175.77.95^
 ||178.175.78.106^
-||178.175.78.202^
+||178.175.78.118^
 ||178.175.78.233^
 ||178.175.78.46^
 ||178.175.78.76^
+||178.175.78.97^
 ||178.175.79.156^
 ||178.175.79.227^
 ||178.175.79.247^
-||178.175.79.24^
 ||178.175.79.45^
 ||178.175.79.77^
 ||178.175.8.100^
-||178.175.8.165^
 ||178.175.8.199^
-||178.175.8.205^
 ||178.175.8.217^
 ||178.175.8.254^
+||178.175.8.97^
+||178.175.80.100^
+||178.175.80.136^
 ||178.175.80.237^
-||178.175.80.244^
+||178.175.80.41^
 ||178.175.80.79^
 ||178.175.80.86^
 ||178.175.81.141^
@@ -1982,43 +2050,47 @@
 ||178.175.81.17^
 ||178.175.81.194^
 ||178.175.81.1^
-||178.175.81.216^
 ||178.175.81.226^
 ||178.175.81.244^
+||178.175.81.32^
 ||178.175.81.50^
-||178.175.81.82^
+||178.175.81.8^
+||178.175.82.120^
 ||178.175.82.61^
 ||178.175.83.147^
 ||178.175.83.196^
+||178.175.83.247^
 ||178.175.84.102^
 ||178.175.84.109^
 ||178.175.84.148^
+||178.175.84.158^
 ||178.175.84.159^
 ||178.175.84.215^
 ||178.175.84.42^
 ||178.175.85.153^
-||178.175.85.165^
 ||178.175.85.183^
 ||178.175.85.190^
-||178.175.85.229^
+||178.175.85.23^
+||178.175.85.81^
 ||178.175.85.87^
-||178.175.85.9^
 ||178.175.86.119^
-||178.175.86.218^
-||178.175.87.107^
+||178.175.86.159^
+||178.175.86.166^
+||178.175.87.108^
 ||178.175.87.123^
 ||178.175.87.162^
 ||178.175.87.253^
-||178.175.87.90^
 ||178.175.88.180^
 ||178.175.88.181^
-||178.175.88.78^
 ||178.175.89.130^
-||178.175.89.19^
+||178.175.89.157^
+||178.175.89.160^
+||178.175.89.169^
 ||178.175.89.37^
-||178.175.89.51^
-||178.175.9.178^
+||178.175.9.106^
+||178.175.9.139^
 ||178.175.9.183^
+||178.175.9.210^
 ||178.175.9.215^
 ||178.175.9.217^
 ||178.175.9.245^
@@ -2026,8 +2098,8 @@
 ||178.175.9.80^
 ||178.175.9.84^
 ||178.175.9.95^
-||178.175.90.115^
-||178.175.90.160^
+||178.175.90.104^
+||178.175.90.122^
 ||178.175.90.178^
 ||178.175.90.187^
 ||178.175.90.212^
@@ -2038,72 +2110,73 @@
 ||178.175.91.165^
 ||178.175.91.172^
 ||178.175.91.191^
+||178.175.91.223^
+||178.175.91.230^
 ||178.175.91.253^
-||178.175.91.47^
 ||178.175.91.58^
-||178.175.91.71^
 ||178.175.91.96^
 ||178.175.92.132^
 ||178.175.92.186^
 ||178.175.92.201^
 ||178.175.92.208^
 ||178.175.92.215^
-||178.175.92.224^
 ||178.175.92.231^
 ||178.175.92.248^
 ||178.175.92.45^
 ||178.175.93.143^
+||178.175.93.148^
 ||178.175.93.150^
 ||178.175.93.155^
+||178.175.93.171^
 ||178.175.93.198^
+||178.175.93.224^
 ||178.175.93.225^
-||178.175.93.245^
 ||178.175.93.31^
+||178.175.93.34^
 ||178.175.93.45^
 ||178.175.93.4^
 ||178.175.93.6^
+||178.175.93.90^
 ||178.175.94.116^
-||178.175.94.184^
 ||178.175.94.195^
 ||178.175.94.238^
+||178.175.94.248^
 ||178.175.94.40^
+||178.175.95.111^
+||178.175.95.132^
 ||178.175.95.147^
 ||178.175.95.227^
+||178.175.95.237^
 ||178.175.95.244^
-||178.175.95.249^
 ||178.175.95.4^
+||178.175.95.7^
 ||178.175.95.89^
-||178.175.95.99^
 ||178.175.96.13^
-||178.175.96.180^
 ||178.175.96.195^
-||178.175.96.24^
 ||178.175.96.6^
-||178.175.97.111^
-||178.175.97.181^
-||178.175.97.243^
-||178.175.98.140^
+||178.175.97.128^
+||178.175.97.135^
+||178.175.97.162^
+||178.175.97.17^
+||178.175.97.1^
+||178.175.97.208^
 ||178.175.98.228^
 ||178.175.98.254^
 ||178.175.98.50^
 ||178.175.98.68^
-||178.175.99.108^
 ||178.175.99.123^
 ||178.175.99.130^
 ||178.175.99.22^
 ||178.175.99.45^
-||178.175.99.75^
 ||178.175.99.8^
 ||178.175.99.91^
 ||178.19.183.14^
-||178.205.101.33^
 ||178.21.164.68^
 ||178.217.8.194^
 ||178.22.117.102^
 ||178.222.252.130^
 ||178.34.183.30^
 ||178.92.246.246^
-||178.93.112.88^
 ||178.95.115.33^
 ||179.159.58.134^
 ||179.4.187.39^
@@ -2116,7 +2189,6 @@
 ||180.116.203.220^
 ||180.120.149.106^
 ||180.122.13.227^
-||180.125.155.69^
 ||180.125.44.194^
 ||180.157.66.204^
 ||180.175.93.52^
@@ -2137,7 +2209,6 @@
 ||181.112.218.238^
 ||181.112.218.6^
 ||181.143.60.163^
-||181.174.63.114^
 ||181.193.107.10^
 ||181.199.170.210^
 ||181.199.170.222^
@@ -2154,79 +2225,86 @@
 ||182.112.52.131^
 ||182.113.0.79^
 ||182.113.222.154^
+||182.113.233.129^
 ||182.113.24.21^
 ||182.114.106.207^
-||182.114.122.228^
 ||182.114.202.186^
-||182.114.31.65^
-||182.114.50.124^
-||182.114.50.93^
 ||182.114.64.27^
-||182.114.70.177^
-||182.114.93.165^
-||182.114.94.255^
 ||182.116.101.82^
-||182.116.104.125^
+||182.116.103.81^
+||182.116.108.180^
+||182.116.108.244^
 ||182.116.110.31^
-||182.116.44.70^
-||182.116.49.171^
+||182.116.119.129^
 ||182.116.60.73^
 ||182.116.61.252^
 ||182.116.65.157^
 ||182.116.65.245^
 ||182.116.68.40^
 ||182.116.69.37^
-||182.116.69.47^
 ||182.116.94.196^
+||182.116.99.150^
 ||182.116.99.17^
 ||182.117.155.204^
 ||182.117.25.120^
 ||182.117.26.235^
-||182.117.27.150^
+||182.117.29.220^
 ||182.117.29.74^
 ||182.117.43.27^
 ||182.118.140.117^
 ||182.119.100.228^
+||182.119.13.141^
 ||182.119.14.252^
 ||182.119.166.208^
+||182.119.196.182^
 ||182.119.211.69^
 ||182.119.220.48^
-||182.119.227.82^
-||182.119.229.96^
 ||182.119.236.21^
+||182.119.49.17^
 ||182.119.50.155^
+||182.119.7.54^
 ||182.119.81.33^
 ||182.120.10.21^
 ||182.120.16.22^
 ||182.120.16.46^
 ||182.120.37.251^
 ||182.120.43.0^
+||182.120.86.248^
 ||182.121.101.100^
 ||182.121.109.190^
+||182.121.12.128^
 ||182.121.125.170^
 ||182.121.129.232^
-||182.121.131.69^
 ||182.121.133.200^
-||182.121.135.160^
+||182.121.133.46^
+||182.121.134.73^
 ||182.121.148.236^
 ||182.121.157.221^
-||182.121.200.151^
+||182.121.165.217^
+||182.121.205.118^
 ||182.121.206.132^
 ||182.121.219.239^
 ||182.121.233.191^
 ||182.121.249.26^
-||182.121.68.100^
+||182.121.50.111^
+||182.121.78.29^
 ||182.121.81.241^
 ||182.121.92.113^
 ||182.121.93.174^
 ||182.121.98.21^
 ||182.122.170.19^
+||182.122.202.37^
 ||182.122.220.203^
 ||182.122.229.102^
 ||182.122.245.2^
+||182.122.246.187^
 ||182.122.249.24^
+||182.122.251.141^
+||182.124.134.80^
+||182.124.15.108^
+||182.124.166.57^
 ||182.124.188.23^
-||182.124.53.111^
+||182.124.95.139^
 ||182.126.113.127^
 ||182.126.117.41^
 ||182.126.124.47^
@@ -2236,22 +2314,27 @@
 ||182.126.139.66^
 ||182.126.140.30^
 ||182.126.178.187^
+||182.126.181.121^
+||182.126.241.7^
+||182.126.52.233^
 ||182.126.82.29^
 ||182.126.83.79^
-||182.126.87.58^
+||182.126.87.207^
 ||182.126.95.209^
 ||182.127.155.157^
 ||182.127.166.232^
 ||182.127.210.107^
 ||182.127.6.12^
+||182.127.70.195^
 ||182.127.78.61^
-||182.127.87.72^
 ||182.127.91.161^
+||182.127.96.120^
 ||182.172.36.164^
-||182.207.219.164^
 ||182.233.0.252^
 ||182.235.252.31^
 ||182.53.197.62^
+||182.58.160.0^
+||182.59.227.125^
 ||182.88.235.221^
 ||183.105.104.83^
 ||183.105.225.154^
@@ -2264,7 +2347,9 @@
 ||183.188.151.225^
 ||183.188.180.116^
 ||183.188.180.68^
-||183.188.76.196^
+||183.188.188.186^
+||183.191.162.120^
+||183.83.105.21^
 ||183.83.14.35^
 ||183.83.15.116^
 ||183.83.23.138^
@@ -2273,6 +2358,7 @@
 ||183.95.147.102^
 ||183.97.22.14^
 ||184.164.185.41^
+||184.175.115.10^
 ||184.74.149.230^
 ||185.106.209.68^
 ||185.107.3.8^
@@ -2293,50 +2379,47 @@
 ||185.68.230.207^
 ||185.81.157.186^
 ||185.82.217.185^
-||185.82.217.213^
 ||185.82.219.160^
 ||185.82.219.161^
 ||185.82.219.219^
-||185.82.219.80^
 ||185.90.166.56^
 ||186.151.144.85^
 ||186.179.219.164^
 ||186.179.243.112^
 ||186.179.243.77^
+||186.179.243.91^
 ||186.179.253.150^
 ||186.225.120.173^
 ||186.227.148.107^
+||186.232.44.86^
 ||186.28.60.184^
-||186.4.125.48^
+||186.33.112.28^
 ||186.73.188.132^
 ||187.12.10.98^
 ||187.188.124.229^
 ||187.212.200.162^
-||187.56.88.170^
-||187.75.218.102^
 ||188.10.21.14^
 ||188.10.231.246^
+||188.113.102.18^
 ||188.113.81.17^
-||188.127.224.149^
 ||188.127.224.61^
+||188.127.227.173^
 ||188.127.227.99^
-||188.127.230.133^
 ||188.127.231.226^
 ||188.127.231.55^
 ||188.127.235.232^
-||188.127.235.70^
+||188.127.235.244^
 ||188.127.235.71^
+||188.127.237.152^
 ||188.127.254.114^
 ||188.13.179.87^
 ||188.138.200.32^
 ||188.152.41.141^
 ||188.169.178.50^
-||188.169.199.59^
 ||188.169.30.30^
 ||188.169.36.163^
 ||188.242.167.159^
 ||188.242.242.144^
-||188.81.100.83^
 ||188.83.202.25^
 ||188.93.233.223^
 ||189.222.157.241^
@@ -2355,14 +2438,12 @@
 ||190.130.15.212^
 ||190.130.20.14^
 ||190.141.117.41^
-||190.147.16.184^
 ||190.159.240.9^
 ||190.187.55.150^
 ||190.210.214.130^
 ||190.213.177.39^
 ||190.213.226.63^
 ||190.213.49.207^
-||190.214.24.194^
 ||190.216.140.123^
 ||190.35.225.36^
 ||190.65.206.162^
@@ -2376,13 +2457,17 @@
 ||192.227.185.106^
 ||192.227.209.27^
 ||192.227.228.67^
+||192.3.152.166^
 ||192.3.73.205^
 ||192.99.240.77^
+||193.142.146.25^
 ||193.228.135.144^
 ||193.91.131.237^
+||194.15.36.167^
+||194.15.36.202^
 ||194.152.35.139^
 ||194.38.20.199^
-||195.123.208.140^
+||194.87.139.10^
 ||195.123.213.154^
 ||195.139.126.51^
 ||195.228.231.218^
@@ -2395,12 +2480,14 @@
 ||197.159.2.106^
 ||197.50.27.115^
 ||198.23.133.218^
+||198.23.207.121^
+||198.23.213.57^
 ||198.23.251.105^
 ||198.46.201.76^
 ||198.46.202.7^
 ||1am.co.nz^
 ||2.229.89.119^
-||2.37.203.65^
+||2.249.161.188^
 ||2.45.111.158^
 ||2.45.4.24^
 ||2.55.125.182^
@@ -2416,27 +2503,26 @@
 ||201.184.163.170^
 ||201.184.248.190^
 ||201.187.102.73^
-||201.193.17.190^
+||201.200.254.86^
 ||201.203.221.20^
+||201.208.139.84^
 ||201.215.84.97^
 ||201.218.97.142^
 ||202.107.233.41^
 ||202.111.131.91^
-||202.150.176.100^
 ||202.164.150.115^
 ||202.166.217.54^
+||202.169.234.22^
 ||202.169.234.47^
 ||202.169.234.52^
 ||202.169.234.56^
-||202.178.113.26^
+||202.169.234.9^
 ||202.29.95.12^
 ||202.4.124.58^
 ||202.51.176.114^
 ||202.51.191.174^
 ||202.74.236.9^
 ||203.109.201.243^
-||203.130.69.205^
-||203.170.105.156^
 ||203.170.115.82^
 ||203.189.156.107^
 ||203.202.248.237^
@@ -2451,28 +2537,25 @@
 ||203.82.36.34^
 ||203.93.6.28^
 ||204.195.116.171^
-||205.185.115.74^
 ||205.185.123.217^
+||206.248.137.132^
 ||206.47.41.166^
 ||207.200.247.187^
 ||207.44.28.234^
 ||207.5.32.6^
 ||208.163.58.18^
-||209.133.223.130^
 ||209.141.39.50^
 ||209.141.40.190^
-||209.141.40.31^
 ||209.145.60.38^
+||210.102.196.200^
 ||210.124.149.19^
 ||210.216.152.122^
 ||210.216.153.142^
-||210.57.234.131^
 ||210.57.237.70^
+||210.57.245.109^
 ||210.68.242.114^
 ||210.96.116.236^
-||211.116.220.37^
 ||211.172.11.169^
-||211.179.243.103^
 ||211.187.132.204^
 ||211.187.75.220^
 ||211.204.215.157^
@@ -2484,8 +2567,8 @@
 ||211.238.83.238^
 ||211.247.113.49^
 ||211.247.5.96^
-||211.32.122.110^
 ||211.36.174.137^
+||211.41.197.30^
 ||211.47.102.51^
 ||211.51.174.149^
 ||212.122.86.105^
@@ -2499,24 +2582,22 @@
 ||213.14.173.117^
 ||213.149.182.113^
 ||213.149.190.193^
+||213.163.104.10^
 ||213.163.104.12^
 ||213.163.104.20^
 ||213.163.104.99^
 ||213.163.113.100^
 ||213.163.113.199^
 ||213.163.113.225^
-||213.163.113.226^
-||213.163.113.237^
 ||213.163.113.51^
 ||213.163.113.79^
-||213.163.114.107^
-||213.163.114.36^
+||213.163.114.80^
 ||213.163.115.11^
 ||213.163.115.15^
 ||213.163.115.26^
+||213.163.115.33^
 ||213.163.115.71^
-||213.163.116.149^
-||213.163.116.160^
+||213.163.116.132^
 ||213.163.116.164^
 ||213.163.116.203^
 ||213.163.116.249^
@@ -2530,10 +2611,8 @@
 ||213.163.126.131^
 ||213.163.126.243^
 ||213.163.126.60^
-||213.163.126.61^
+||213.163.126.71^
 ||213.163.126.7^
-||213.163.126.96^
-||213.163.127.178^
 ||213.163.127.217^
 ||213.163.127.46^
 ||213.189.178.163^
@@ -2541,8 +2620,6 @@
 ||213.249.156.189^
 ||213.27.8.6^
 ||213.80.44.17^
-||213.87.87.173^
-||213.92.254.214^
 ||213.92.254.52^
 ||213.92.255.36^
 ||213.92.255.84^
@@ -2554,10 +2631,9 @@
 ||216.36.12.98^
 ||217.11.75.162^
 ||217.127.133.214^
-||218.104.175.64^
+||218.103.180.199^
 ||218.215.243.65^
 ||218.238.246.3^
-||218.255.226.166^
 ||218.28.160.174^
 ||218.35.207.119^
 ||218.35.227.133^
@@ -2566,38 +2642,45 @@
 ||218.48.135.50^
 ||218.56.93.129^
 ||218.57.53.55^
-||218.58.3.119^
-||218.58.3.38^
 ||218.59.116.203^
 ||218.72.198.15^
-||218.72.248.42^
 ||218.79.103.159^
 ||219.154.104.209^
 ||219.154.119.145^
+||219.154.141.222^
 ||219.154.182.197^
 ||219.155.102.14^
+||219.155.12.221^
 ||219.155.14.17^
+||219.155.170.22^
+||219.155.208.188^
 ||219.155.24.246^
+||219.155.241.135^
 ||219.155.26.37^
-||219.155.28.41^
 ||219.155.31.15^
 ||219.155.31.67^
+||219.155.37.97^
 ||219.155.9.202^
-||219.155.97.226^
+||219.156.103.248^
 ||219.156.21.73^
-||219.157.139.165^
+||219.156.23.29^
+||219.156.60.224^
+||219.156.9.32^
 ||219.157.146.200^
 ||219.157.150.91^
 ||219.157.162.205^
 ||219.157.17.8^
-||219.157.177.232^
 ||219.157.178.201^
 ||219.157.183.29^
 ||219.157.202.66^
-||219.157.215.242^
+||219.157.220.170^
 ||219.157.221.133^
+||219.157.223.245^
+||219.157.244.33^
 ||219.157.32.244^
-||219.157.64.251^
+||219.157.50.211^
+||219.157.54.158^
+||219.157.56.46^
 ||219.241.6.180^
 ||219.68.1.148^
 ||219.68.1.84^
@@ -2615,34 +2698,34 @@
 ||220.173.160.53^
 ||220.200.22.163^
 ||220.71.239.115^
+||220.90.159.188^
 ||221.0.16.221^
 ||221.1.162.82^
 ||221.124.78.15^
 ||221.14.122.127^
 ||221.14.182.157^
 ||221.14.46.33^
+||221.14.58.5^
 ||221.14.58.84^
-||221.15.124.188^
+||221.15.147.220^
 ||221.15.153.17^
-||221.15.160.67^
-||221.15.194.218^
-||221.15.199.35^
 ||221.15.218.173^
 ||221.15.234.159^
 ||221.15.234.175^
+||221.15.237.107^
 ||221.15.54.237^
+||221.15.7.202^
 ||221.157.191.178^
 ||221.160.136.213^
 ||221.160.177.104^
 ||221.160.177.107^
 ||221.160.177.224^
 ||221.196.12.96^
-||221.208.4.71^
 ||221.214.130.147^
-||221.214.146.73^
 ||221.214.162.109^
 ||221.214.224.184^
 ||221.215.116.167^
+||221.215.172.207^
 ||221.215.184.31^
 ||221.215.237.220^
 ||221.215.239.162^
@@ -2657,6 +2740,7 @@
 ||221.3.34.43^
 ||221.3.43.223^
 ||221.3.68.16^
+||221.5.30.118^
 ||222.108.17.64^
 ||222.119.65.145^
 ||222.132.125.138^
@@ -2666,13 +2750,10 @@
 ||222.135.113.41^
 ||222.135.219.29^
 ||222.135.26.161^
-||222.136.21.126^
-||222.136.218.233^
 ||222.136.231.197^
 ||222.136.49.252^
 ||222.137.101.251^
 ||222.137.113.184^
-||222.137.120.3^
 ||222.137.121.127^
 ||222.137.136.241^
 ||222.137.137.5^
@@ -2684,18 +2765,26 @@
 ||222.137.172.250^
 ||222.137.175.242^
 ||222.137.186.150^
+||222.137.22.79^
+||222.137.220.94^
 ||222.137.221.128^
+||222.137.49.4^
 ||222.137.5.150^
 ||222.137.72.146^
-||222.137.8.96^
 ||222.137.81.67^
+||222.137.83.53^
 ||222.138.137.188^
 ||222.138.143.84^
+||222.138.189.88^
 ||222.138.203.22^
+||222.138.215.161^
 ||222.138.232.159^
+||222.138.232.84^
+||222.138.49.93^
 ||222.138.96.79^
+||222.139.16.229^
 ||222.139.59.63^
-||222.140.10.235^
+||222.140.112.150^
 ||222.140.117.221^
 ||222.140.161.11^
 ||222.140.163.112^
@@ -2703,27 +2792,26 @@
 ||222.140.209.222^
 ||222.140.219.212^
 ||222.140.39.66^
-||222.141.120.17^
-||222.141.147.104^
 ||222.141.150.38^
+||222.141.165.180^
+||222.141.244.231^
 ||222.141.40.136^
-||222.141.40.2^
 ||222.141.41.155^
+||222.141.44.36^
 ||222.141.45.153^
-||222.141.45.255^
 ||222.141.60.251^
+||222.141.73.249^
 ||222.141.85.128^
 ||222.142.162.164^
 ||222.142.192.66^
 ||222.142.209.7^
 ||222.142.65.30^
-||222.184.129.122^
+||222.179.215.189^
 ||222.185.116.233^
-||222.186.20.19^
 ||222.187.9.178^
 ||222.211.72.66^
+||222.214.54.208^
 ||222.218.220.219^
-||222.236.85.220^
 ||222.238.230.7^
 ||222.239.83.232^
 ||222.248.64.253^
@@ -2733,21 +2821,17 @@
 ||222.99.171.192^
 ||223.166.117.210^
 ||223.167.118.17^
-||223.175.121.249^
 ||223.212.225.68^
 ||223.212.234.84^
 ||223.212.252.180^
 ||223.212.5.29^
-||223.212.57.78^
 ||223.212.73.175^
-||223.213.164.81^
 ||23.125.186.135^
 ||23.126.120.25^
 ||23.228.143.58^
 ||23.24.213.121^
 ||23.243.149.13^
 ||23.243.21.167^
-||23.81.246.58^
 ||23.95.89.21^
 ||24.103.74.180^
 ||24.11.141.134^
@@ -2774,6 +2858,7 @@
 ||27.105.106.201^
 ||27.105.152.107^
 ||27.116.84.57^
+||27.12.234.4^
 ||27.12.245.238^
 ||27.13.83.77^
 ||27.14.211.219^
@@ -2789,7 +2874,6 @@
 ||27.193.217.210^
 ||27.194.149.142^
 ||27.194.158.229^
-||27.194.166.45^
 ||27.194.192.66^
 ||27.194.210.20^
 ||27.194.224.96^
@@ -2841,14 +2925,15 @@
 ||27.208.166.13^
 ||27.208.201.212^
 ||27.208.247.130^
+||27.208.25.59^
 ||27.208.34.2^
 ||27.208.92.64^
 ||27.209.160.222^
 ||27.209.231.15^
 ||27.209.60.21^
-||27.21.159.174^
 ||27.210.107.125^
 ||27.210.127.11^
+||27.210.146.61^
 ||27.210.172.245^
 ||27.210.234.28^
 ||27.210.236.134^
@@ -2857,6 +2942,8 @@
 ||27.213.104.201^
 ||27.213.109.105^
 ||27.213.109.58^
+||27.213.145.221^
+||27.213.167.175^
 ||27.213.175.208^
 ||27.213.220.5^
 ||27.213.255.202^
@@ -2871,6 +2958,7 @@
 ||27.215.38.166^
 ||27.215.71.243^
 ||27.215.98.242^
+||27.216.131.66^
 ||27.216.144.66^
 ||27.216.193.217^
 ||27.216.197.193^
@@ -2897,7 +2985,6 @@
 ||27.219.184.94^
 ||27.219.192.223^
 ||27.219.83.244^
-||27.220.243.172^
 ||27.220.40.189^
 ||27.220.85.168^
 ||27.221.239.223^
@@ -2909,25 +2996,27 @@
 ||27.223.242.164^
 ||27.223.44.106^
 ||27.24.28.134^
-||27.35.127.129^
 ||27.35.129.198^
 ||27.35.154.13^
+||27.35.16.145^
 ||27.35.2.30^
 ||27.35.212.124^
 ||27.35.58.5^
-||27.36.143.238^
-||27.41.159.216^
-||27.41.36.15^
-||27.41.38.79^
-||27.46.45.90^
-||27.5.38.169^
-||27.5.41.251^
-||27.5.42.169^
-||27.6.196.172^
+||27.41.153.66^
+||27.41.154.31^
+||27.43.82.210^
+||27.46.45.248^
+||27.46.47.74^
+||27.5.16.243^
+||27.5.26.105^
+||27.5.26.4^
+||27.5.27.1^
+||27.5.35.127^
 ||31.0.98.131^
 ||31.11.51.57^
 ||31.13.23.180^
 ||31.154.234.3^
+||31.163.191.11^
 ||31.168.124.130^
 ||31.168.179.83^
 ||31.168.184.59^
@@ -2946,8 +3035,10 @@
 ||31.204.174.180^
 ||31.210.20.138^
 ||31.210.20.177^
+||31.210.20.227^
 ||31.28.7.159^
 ||31.30.119.23^
+||31.62.255.3^
 ||32.208.157.193^
 ||32792.prolocksmithwinterpark.com^
 ||35.184.169.169^
@@ -2959,8 +3050,6 @@
 ||36.251.19.88^
 ||36.251.51.244^
 ||36.255.90.219^
-||36.32.203.118^
-||36.32.25.158^
 ||36.33.128.60^
 ||36.33.160.167^
 ||36.36.243.67^
@@ -2970,7 +3059,6 @@
 ||36.66.139.36^
 ||36.67.152.161^
 ||36.89.18.133^
-||36.91.89.187^
 ||36.96.187.93^
 ||360.lcy2zzx.pw^
 ||360down7.miiyun.cn^
@@ -3008,8 +3096,8 @@
 ||39.72.67.64^
 ||39.73.10.198^
 ||39.73.163.231^
-||39.73.183.14^
 ||39.73.203.225^
+||39.73.44.17^
 ||39.74.104.228^
 ||39.74.21.201^
 ||39.74.28.89^
@@ -3035,7 +3123,6 @@
 ||39.79.91.244^
 ||39.79.93.171^
 ||39.80.127.214^
-||39.80.188.238^
 ||39.80.191.137^
 ||39.80.205.255^
 ||39.80.24.54^
@@ -3052,8 +3139,10 @@
 ||39.84.34.217^
 ||39.84.95.200^
 ||39.85.54.191^
+||39.85.54.4^
 ||39.86.129.233^
 ||39.86.13.0^
+||39.86.151.49^
 ||39.86.170.209^
 ||39.86.184.164^
 ||39.86.211.20^
@@ -3064,6 +3153,7 @@
 ||39.86.76.9^
 ||39.86.78.228^
 ||39.87.63.58^
+||39.87.90.210^
 ||39.87.93.109^
 ||39.88.141.172^
 ||39.88.155.96^
@@ -3084,95 +3174,100 @@
 ||41.219.185.171^
 ||41.230.31.58^
 ||41.72.203.82^
-||41.76.157.2^
+||41.86.18.133^
 ||41.86.18.147^
 ||41.86.18.148^
+||41.86.18.165^
 ||41.86.18.200^
 ||41.86.18.71^
-||41.86.21.35^
-||41.86.21.40^
+||41.86.21.28^
+||41.86.21.5^
+||41.86.21.62^
 ||41.86.5.103^
-||41.86.5.104^
-||41.86.5.198^
-||41.86.5.237^
 ||42.176.112.72^
 ||42.202.101.147^
+||42.224.122.39^
 ||42.224.128.210^
 ||42.224.168.142^
 ||42.224.168.97^
-||42.224.170.140^
+||42.224.176.214^
 ||42.224.179.49^
-||42.224.181.121^
-||42.224.183.11^
 ||42.224.209.156^
 ||42.224.212.124^
 ||42.224.218.16^
 ||42.224.233.247^
 ||42.224.235.4^
+||42.224.249.8^
 ||42.224.37.186^
 ||42.224.37.44^
 ||42.224.43.25^
 ||42.224.64.34^
-||42.224.66.246^
 ||42.224.70.213^
 ||42.224.76.168^
 ||42.224.76.198^
 ||42.224.8.136^
+||42.224.90.17^
 ||42.224.91.8^
-||42.225.24.101^
 ||42.225.240.244^
 ||42.225.250.39^
-||42.226.76.62^
+||42.225.33.31^
+||42.226.89.25^
 ||42.227.179.209^
-||42.227.204.4^
 ||42.227.66.88^
 ||42.228.198.102^
 ||42.228.60.114^
 ||42.228.65.201^
 ||42.228.70.126^
 ||42.228.70.231^
+||42.228.75.7^
 ||42.228.76.135^
 ||42.230.100.114^
+||42.230.174.125^
+||42.230.219.243^
 ||42.230.228.78^
-||42.230.57.145^
 ||42.230.66.255^
 ||42.230.82.44^
 ||42.230.88.107^
 ||42.230.93.169^
+||42.231.223.215^
+||42.231.244.80^
 ||42.231.66.174^
+||42.231.95.195^
 ||42.232.102.163^
 ||42.232.170.117^
 ||42.232.226.16^
+||42.233.90.183^
+||42.234.105.6^
+||42.234.162.44^
 ||42.234.166.242^
-||42.234.180.136^
 ||42.234.255.20^
 ||42.235.124.55^
-||42.235.160.215^
 ||42.235.169.85^
 ||42.235.23.163^
 ||42.235.66.249^
-||42.235.83.180^
+||42.235.90.32^
+||42.235.92.111^
 ||42.236.148.201^
 ||42.236.212.174^
 ||42.236.212.83^
 ||42.236.215.63^
 ||42.236.236.179^
+||42.237.45.223^
 ||42.237.54.162^
-||42.238.175.61^
+||42.238.175.32^
 ||42.238.191.210^
 ||42.238.241.239^
 ||42.238.59.222^
 ||42.239.192.128^
-||42.239.207.166^
-||42.239.42.135^
 ||42.242.200.90^
 ||42.52.180.36^
 ||42.56.15.227^
 ||42.61.99.155^
+||42.82.217.241^
 ||42.84.14.5^
 ||43.230.156.44^
-||43.230.207.204^
 ||43.241.106.183^
+||43.241.106.234^
 ||43.252.8.94^
 ||45.112.203.218^
 ||45.130.138.66^
@@ -3184,16 +3279,20 @@
 ||45.14.149.204^
 ||45.14.149.244^
 ||45.14.149.66^
-||45.141.84.182^
 ||45.141.84.184^
+||45.144.225.142^
+||45.144.225.213^
 ||45.144.225.65^
 ||45.148.10.47^
 ||45.15.143.158^
 ||45.164.140.133^
-||45.165.215.19^
 ||45.176.108.116^
 ||45.176.108.248^
+||45.176.110.99^
+||45.176.111.154^
 ||45.176.111.16^
+||45.176.111.202^
+||45.176.111.84^
 ||45.178.101.22^
 ||45.201.165.164^
 ||45.22.209.58^
@@ -3207,10 +3306,8 @@
 ||46.172.75.231^
 ||46.175.184.121^
 ||46.182.173.246^
-||46.182.173.247^
 ||46.20.63.218^
 ||46.201.214.64^
-||46.201.38.162^
 ||46.21.153.231^
 ||46.214.27.4^
 ||46.24.130.254^
@@ -3242,7 +3339,6 @@
 ||49.68.221.252^
 ||49.68.249.121^
 ||49.70.15.16^
-||49.70.2.100^
 ||5.181.135.114^
 ||5.2.70.50^
 ||5.53.146.179^
@@ -3252,6 +3348,7 @@
 ||50.252.47.29^
 ||51.171.146.13^
 ||51.222.56.159^
+||54.180.158.181^
 ||54.253.194.14^
 ||54.36.114.136^
 ||54.36.180.122^
@@ -3264,9 +3361,10 @@
 ||58.142.166.120^
 ||58.142.200.124^
 ||58.143.142.142^
+||58.143.189.75^
 ||58.18.103.109^
+||58.19.249.50^
 ||58.217.171.157^
-||58.218.67.253^
 ||58.22.212.107^
 ||58.226.129.29^
 ||58.229.194.122^
@@ -3277,44 +3375,36 @@
 ||58.240.147.97^
 ||58.241.57.237^
 ||58.241.78.55^
-||58.248.112.16^
-||58.248.116.2^
 ||58.248.117.188^
-||58.248.140.132^
-||58.248.142.137^
-||58.248.142.174^
+||58.248.143.173^
+||58.248.144.97^
 ||58.248.149.117^
-||58.248.150.204^
-||58.248.150.244^
-||58.248.153.194^
+||58.248.149.226^
 ||58.248.154.55^
 ||58.248.154.66^
 ||58.248.76.206^
 ||58.248.79.25^
-||58.249.15.148^
 ||58.249.18.244^
-||58.249.22.210^
-||58.249.72.121^
+||58.249.74.104^
 ||58.249.74.124^
 ||58.249.74.248^
 ||58.249.77.227^
-||58.249.79.134^
+||58.249.78.155^
 ||58.249.80.23^
+||58.249.80.46^
 ||58.249.86.85^
-||58.249.88.207^
-||58.252.177.212^
+||58.249.87.248^
+||58.249.89.210^
+||58.249.90.206^
+||58.249.90.86^
+||58.252.176.107^
 ||58.252.177.66^
-||58.252.178.167^
-||58.252.178.55^
-||58.253.14.46^
-||58.255.140.156^
 ||58.255.43.163^
 ||58.48.154.143^
 ||58.50.178.137^
 ||58.50.221.148^
 ||58.72.165.153^
 ||58.72.165.39^
-||58.76.151.51^
 ||58.97.201.45^
 ||58.97.206.33^
 ||59.0.211.161^
@@ -3322,48 +3412,18 @@
 ||59.151.202.3^
 ||59.151.214.4^
 ||59.151.237.51^
-||59.151.246.125^
 ||59.29.133.229^
 ||59.30.12.254^
+||59.32.97.190^
 ||59.58.104.244^
 ||59.58.117.226^
 ||59.7.124.148^
 ||59.8.35.22^
-||59.89.243.76^
-||59.92.176.136^
-||59.92.178.202^
-||59.92.18.175^
-||59.92.182.177^
-||59.92.216.255^
-||59.93.17.196^
-||59.93.17.204^
-||59.93.17.72^
-||59.93.19.11^
-||59.93.23.154^
-||59.93.23.215^
-||59.93.23.23^
-||59.93.23.7^
-||59.94.180.237^
-||59.96.36.131^
-||59.96.36.137^
-||59.96.39.91^
-||59.97.168.110^
-||59.97.170.16^
-||59.97.175.101^
-||59.97.175.96^
-||59.97.193.118^
-||59.99.137.46^
-||59.99.138.222^
-||59.99.139.252^
-||59.99.139.66^
-||59.99.141.103^
-||59.99.141.219^
-||59.99.142.43^
-||59.99.188.93^
-||59.99.41.26^
-||59.99.43.225^
-||59.99.46.7^
-||59.99.47.64^
+||59.92.182.72^
+||59.92.218.77^
+||59.92.219.28^
+||59.97.174.85^
+||59.99.47.93^
 ||60.13.61.12^
 ||60.14.48.221^
 ||60.162.122.36^
@@ -3402,24 +3462,24 @@
 ||60.220.22.89^
 ||60.25.115.48^
 ||60.25.76.224^
-||60.253.15.104^
-||60.253.39.88^
+||60.253.4.72^
 ||60.253.42.72^
-||60.253.44.99^
 ||60.253.51.127^
 ||60.253.60.174^
+||60.253.8.36^
 ||60.253.8.81^
+||60.254.49.59^
 ||60.7.10.121^
 ||60.7.136.8^
 ||60.7.202.153^
+||60.7.8.43^
 ||60.7.99.254^
 ||61.102.243.124^
+||61.109.164.140^
+||61.141.124.123^
 ||61.162.169.210^
 ||61.162.55.42^
-||61.163.129.97^
 ||61.164.96.98^
-||61.167.211.218^
-||61.168.139.87^
 ||61.179.171.60^
 ||61.179.91.194^
 ||61.179.91.230^
@@ -3429,37 +3489,42 @@
 ||61.213.118.28^
 ||61.247.224.66^
 ||61.253.94.230^
-||61.3.126.128^
-||61.3.144.90^
-||61.3.147.175^
+||61.3.124.3^
+||61.3.124.51^
 ||61.47.220.169^
 ||61.52.102.61^
 ||61.52.103.144^
 ||61.52.11.87^
+||61.52.135.192^
 ||61.52.157.4^
 ||61.52.159.231^
 ||61.52.195.226^
 ||61.52.212.191^
+||61.52.212.250^
 ||61.52.243.169^
 ||61.52.247.208^
-||61.52.30.49^
 ||61.52.35.86^
+||61.52.39.119^
 ||61.52.43.174^
 ||61.52.48.112^
+||61.52.5.217^
+||61.52.63.119^
+||61.52.76.72^
 ||61.52.9.166^
-||61.52.97.134^
 ||61.52.99.183^
 ||61.53.100.87^
-||61.53.121.19^
+||61.53.123.162^
+||61.53.125.182^
 ||61.53.251.243^
 ||61.53.62.169^
 ||61.53.73.171^
-||61.53.74.27^
 ||61.53.81.18^
 ||61.53.83.14^
-||61.53.86.195^
 ||61.54.172.248^
-||61.54.41.143^
+||61.54.240.20^
+||61.54.58.190^
+||61.54.58.20^
+||61.54.61.18^
 ||61.54.64.104^
 ||61.54.77.175^
 ||61.56.180.67^
@@ -3482,6 +3547,7 @@
 ||62.141.73.58^
 ||62.219.131.205^
 ||62.219.143.46^
+||62.219.155.61^
 ||62.219.227.31^
 ||62.31.126.33^
 ||62.38.149.66^
@@ -3493,16 +3559,13 @@
 ||65.125.128.196^
 ||65.21.58.252^
 ||65.26.155.131^
-||65.35.61.255^
 ||66.153.233.87^
-||66.207.93.46^
 ||66.229.214.115^
 ||66.57.55.210^
 ||66.74.7.197^
 ||66.91.21.31^
 ||66.97.181.196^
 ||66.97.181.213^
-||67.221.107.75^
 ||67.245.151.203^
 ||67.3.169.223^
 ||67.8.138.101^
@@ -3541,7 +3604,7 @@
 ||70.33.144.248^
 ||70.93.129.118^
 ||71.127.148.69^
-||71.146.190.91^
+||71.19.150.93^
 ||71.204.63.239^
 ||71.29.48.164^
 ||71.34.191.213^
@@ -3566,7 +3629,6 @@
 ||74.199.84.77^
 ||74.75.165.81^
 ||75.127.141.52^
-||75.176.213.114^
 ||75.82.36.220^
 ||75.83.102.27^
 ||75.99.213.61^
@@ -3578,11 +3640,13 @@
 ||76.84.134.33^
 ||76.95.12.137^
 ||77.237.25.210^
+||77.45.183.39^
 ||77.71.50.153^
 ||77.71.52.220^
 ||77.79.191.32^
 ||77.89.203.238^
 ||78.179.225.254^
+||78.186.155.18^
 ||78.187.141.144^
 ||78.187.240.125^
 ||78.187.41.200^
@@ -3600,7 +3664,6 @@
 ||79.170.31.56^
 ||79.175.42.244^
 ||79.21.84.63^
-||79.22.176.145^
 ||79.7.170.58^
 ||79.79.58.94^
 ||79.8.70.162^
@@ -3616,7 +3679,6 @@
 ||81.198.7.22^
 ||81.213.111.60^
 ||81.213.141.184^
-||81.213.166.175^
 ||81.215.199.29^
 ||81.218.187.113^
 ||81.218.195.216^
@@ -3660,7 +3722,7 @@
 ||84.210.219.208^
 ||84.210.219.213^
 ||84.212.219.127^
-||84.214.103.73^
+||84.224.162.170^
 ||84.228.50.118^
 ||84.228.95.204^
 ||84.238.24.35^
@@ -3677,12 +3739,12 @@
 ||85.105.208.25^
 ||85.105.224.141^
 ||85.105.241.2^
+||85.105.9.152^
 ||85.214.149.236^
 ||85.64.181.50^
 ||85.74.215.180^
 ||85.97.130.227^
 ||85.97.195.129^
-||85.98.40.5^
 ||86.35.43.220^
 ||87.121.98.51^
 ||87.61.89.40^
@@ -3697,7 +3759,6 @@
 ||88.250.204.12^
 ||88.250.226.26^
 ||88.250.254.90^
-||88.37.171.141^
 ||89.122.183.130^
 ||89.136.197.170^
 ||89.29.213.33^
@@ -3718,11 +3779,10 @@
 ||91.244.169.139^
 ||91.92.16.244^
 ||91.98.4.181^
-||92.113.192.30^
-||92.113.195.115^
 ||92.114.191.82^
 ||92.241.78.114^
 ||92.27.246.202^
+||92.54.237.237^
 ||92.85.18.138^
 ||93.171.157.73^
 ||93.21.224.154^
@@ -3747,7 +3807,6 @@
 ||95.170.201.34^
 ||95.181.155.112^
 ||95.214.52.64^
-||95.53.229.84^
 ||95.54.11.179^
 ||95.60.146.134^
 ||95.60.6.114^
@@ -3768,7 +3827,6 @@
 ||98.30.24.54^
 ||99.150.245.203^
 ||99.33.195.164^
-||99centsdigitals.com^
 ||abcd.bg^
 ||abclicks.in^
 ||abissnet.net^
@@ -3776,11 +3834,12 @@
 ||absoftechworld.com^
 ||absupplies.co.uk^
 ||abyssos.eu^
+||academyshademani.com^
 ||acbick.com^
 ||accounts.thesmarttechhub.com^
 ||aceeprc.com.aceeprc.com^
 ||acellr.co.uk^
-||aclassapart.in^
+||aciabogados.com^
 ||acteon.com.ar^
 ||activateyourdiscount.com^
 ||activecost.com.au^
@@ -3798,6 +3857,7 @@
 ||agenciadigitalwdys.com^
 ||agenciatabletshouse.com.br^
 ||agenda.gmelloinformatica.com.br^
+||agenmovie.xyz^
 ||agentt.ac.ug^
 ||agile8studio.com^
 ||agmcarpetcare.co.uk^
@@ -3809,7 +3869,6 @@
 ||alasdemariposas.org^
 ||alemelektronik.com^
 ||alena1971.es^
-||alertlauncher.fr^
 ||alexdubai.com.aldiabsteel.com^
 ||alka.institute^
 ||allforcreative.com.au^
@@ -3821,6 +3880,7 @@
 ||amarteargentina.com.ar^
 ||amenyan.zouri.jp^
 ||amos524.org^
+||ams.alvinasschools.org.ng^
 ||anantam.net.in^
 ||andreelapeyre.com^
 ||andremaraisbeleggings.co.za^
@@ -3840,10 +3900,9 @@
 ||aplicativoparasindicato.com.br^
 ||apoolcondo.com^
 ||app.adsensearticle.com^
-||app.explicitsurveys.co.uk^
 ||app.prerana.info^
 ||apps.saintsoporte.com^
-||aras.iuc.ac^
+||aqv.news^
 ||areyoulivingwell.com^
 ||arsapetrolab.com^
 ||artedibujoyarquitectura.com^
@@ -3862,11 +3921,12 @@
 ||ayamallah.com^
 ||azmeasurement.com^
 ||azraktours.com^
-||b2b.toptanakaryakit.com.tr^
 ||backgrounds.pk^
 ||backup.agewsage.com^
 ||badeggdesign.com^
+||balealgodon.mx^
 ||bangkok-orchids.com^
+||barcionstw.eastus.cloudapp.azure.com^
 ||bary.sz4h.com^
 ||basma.com.kw^
 ||bausch.kr-atlas.monaxikoslykos@zytrox.tk^
@@ -3875,7 +3935,6 @@
 ||bcmt.elin.co.za^
 ||bcrg.co.za^
 ||bearcatpumps.com.cn^
-||beatyamerican.com^
 ||beautincollagen.rs^
 ||bekape.co.id^
 ||bespokeweddings.ie^
@@ -3883,6 +3942,8 @@
 ||betone.co.kr^
 ||betycopaints.com^
 ||beveragesmiami.solucioneslink.com^
+||bhavaniengineering.com^
+||bigbag.wootraining.certificacion.cl^
 ||bilbosaquet.ug^
 ||bilhen.co.za^
 ||billing.rahitechnosoft.com^
@@ -3890,11 +3951,10 @@
 ||birminghamlink.org^
 ||blog.callensaxen.com^
 ||blog.oyinblogs.com^
-||blog.takbelit.com^
 ||bmlifestyle.co.uk^
+||bnrbook.com^
 ||bnrnews.id^
 ||bodenstein.co.za^
-||bolnicaloznica.rs^
 ||booksearch.com^
 ||bounces.mi-fs.com^
 ||bpo.correct.go.th^
@@ -3908,23 +3968,21 @@
 ||brightstarshop.com^
 ||browardinsurancemiami.solucioneslink.com^
 ||bt2.elin.co.za^
-||btdapi.robotake.com^
 ||bucrinsuranlceonlines.com^
 ||buenavista.co^
-||buigiaphat.com.vn^
 ||bullseyemedia.in^
 ||busandvanrentalmalaysia.com^
 ||buscascolegios.diit.cl^
 ||business.softberg.ro^
 ||buyingmusiconline.com^
-||buypropertyfast.com^
 ||bwsr.eu^
 ||c.oooooooooo.ga^
 ||c0140529.ferozo.com^
+||caballo.com.au^
 ||cacapavaonline.sdserver144.com.br^
+||calgaryautorepairservice.com^
 ||callbury.in^
 ||camminachetipassa.it^
-||campusvirtual.cepsanjuanbosco.net.pe^
 ||cancer.educandome.co^
 ||capitalgroup-kw.com^
 ||capitalnewsagency.com^
@@ -3937,12 +3995,10 @@
 ||ccauthority.net^
 ||cdaonline.com.ar^
 ||cec.asso.ac-amiens.fr^
-||cellas.sk^
 ||cendekiabinaaksara.com^
 ||cespol-bote.com.mx^
 ||cfs5.tistory.com^
 ||ch.rmu.ac.th^
-||changematterscounselling.com^
 ||chardhamdodham.com^
 ||cheacrilnsurances.com^
 ||chealablilitycarinsurances.com^
@@ -3950,15 +4006,14 @@
 ||childselect.com^
 ||chinhdropfile.myvnc.com^
 ||chinhdropfile80.myvnc.com^
-||chipmania.it^
 ||cible-energy.com^
 ||cifeer.net^
 ||citycapproperty.ru^
 ||cityglobalgospel.com^
 ||civi.istmejia.com^
 ||cleanbydesignllc.com^
-||clim34000.fr^
 ||cloud.fc.co.mz^
+||clurbgolf.com^
 ||codsambal.com^
 ||colinde.pricesne.com^
 ||colorpak.pl^
@@ -3980,7 +4035,6 @@
 ||crecerco.com^
 ||crittersbythebay.com^
 ||crm.notariavieitoyvelamazan.com^
-||crmmanivela.net^
 ||crscorretordeimoveis.com.br^
 ||cse-engineer.com^
 ||csnserver.com^
@@ -4027,7 +4081,6 @@
 ||detorre.es^
 ||dev-interestingtech.pantheonsite.io^
 ||dev.sebpo.net^
-||dezcom.com^
 ||dfcf.91756.cn^
 ||dfsfcsfcdsfsdvcfsvcscv.com^
 ||diamantenegro.mi-fs.com^
@@ -4050,7 +4103,6 @@
 ||doncedyhall.com^
 ||donghobinhminh.com^
 ||dongphuctop.com^
-||donwnloasecury.ath.cx^
 ||dosame.com^
 ||dosman.pl^
 ||dovberger.com^
@@ -4058,6 +4110,9 @@
 ||down.pcclear.com^
 ||down.posti-fi-fsa.top^
 ||down.posti-fi-fwa.top^
+||down.posti-fi-ij.top^
+||down.posti-fi-in.top^
+||down.posti-fi-iz.top^
 ||down.udashi.com^
 ||down.webbora.com^
 ||down1.arpun.com^
@@ -4074,7 +4129,6 @@
 ||drbaby.com.sa^
 ||drohnen.ensenanzainteligente.com^
 ||drools-moved.46999.n3.nabble.com^
-||drrohanfonseca.com^
 ||drsha.innovativesolutions.mobi^
 ||dsenterprize.co.za^
 ||dsspainting.com^
@@ -4088,19 +4142,15 @@
 ||e.sldov.ru^
 ||ebruyatkin.com^
 ||econews.treegle.org^
-||edelweissdecoration.com^
 ||efficientegroup.com^
 ||elliot.newreadermedia.net^
-||emaids.co.za^
 ||en.baoend.com^
 ||enc-tech.com^
 ||endurotanzania.co.tz^
-||enkonooh.com^
 ||ennovate.elin.co.za^
 ||enriquecendocomconsorcio.com.br^
 ||envios.petpienso.cl^
 ||equimination.ee^
-||es.paymelist.com^
 ||escola.probommar.org.br^
 ||esnconsultants.com^
 ||essentia.org.br^
@@ -4112,15 +4162,14 @@
 ||f1sol.com^
 ||familydentist.site^
 ||farmaciasdrogaminas.com.br^
-||farmnatural.in^
 ||faveraprojects.com^
 ||fc.co.mz^
 ||felicienne.nl^
 ||fi.bonitastores.com^
 ||files.martellexpress.us^
 ||files6.uludagbilisim.com^
-||filmotainment.com^
 ||final.makkahkmcc.com^
+||fineartgallerym.com^
 ||fkd.derpcity.ru^
 ||flintspin.com^
 ||flyingbuddhadesign.com^
@@ -4128,20 +4177,17 @@
 ||fms.buladde.or.ug^
 ||foothills.com.br^
 ||footweardirect.elin.co.za^
-||formestore.evencsoft.co^
 ||forum.mdb.nu^
 ||fotoobjetivo.com^
 ||foundationrepairhoustontx.net^
 ||foxeps.com.br^
 ||freecnetdownload.com^
-||freedombookshop.tickme.lk^
 ||freisites.com.br^
 ||ftp.n3twork30cm.ml^
 ||fullelectronica.com.ar^
 ||funletters.net^
 ||fusionfiresolutions.com^
 ||futuregraphics.com.ar^
-||gahanassociates.com^
 ||gametwogame.com^
 ||garayvidalabogados.com^
 ||garciadogshow.com^
@@ -4149,7 +4195,6 @@
 ||garenanow4.myvnc.com^
 ||gbbulls.co.uk^
 ||gcpc.co.id.chronoscurtain.com^
-||gcrcorporation.com^
 ||generaldeviales.com^
 ||gfmodd1.webselffiles01.com^
 ||gfold1.webselffiles01.com^
@@ -4157,6 +4202,8 @@
 ||ghislain.dartois.pagesperso-orange.fr^
 ||giadungg7.com^
 ||giddos.ga^
+||gilliem.com^
+||girotexuniformes.com^
 ||giteletropical.com^
 ||globaltask.ar^
 ||glowinmedia.co.ke^
@@ -4171,10 +4218,12 @@
 ||goldcupmortgage.com^
 ||golden-memories-funerals.yourpageserver.com^
 ||goldmen.in^
+||gorecycle.fahadjutt.com^
 ||gracejukes.com^
 ||grupoinmare.com^
 ||gruposelt.000webhostapp.com^
 ||gs.monerorx.com^
+||guide-to-cell-phones.com^
 ||gulfac-house.com^
 ||gvpcdpgc.edu.in^
 ||habbotips.free.fr^
@@ -4200,6 +4249,7 @@
 ||hmpmall.co.kr^
 ||hoagietesting10.com^
 ||hoayeuthuong-my.sharepoint.com^
+||holmesprpmgmt.com^
 ||homefindersolutions.com^
 ||hongluosi.com^
 ||hookedupboatclub.com^
@@ -4211,7 +4261,6 @@
 ||hsmwebapp.com^
 ||htownbars.com^
 ||hubtech.co.za^
-||huequito.evencsoft.co^
 ||hunggiang.vn^
 ||husamiyahschool.com^
 ||iam313.com^
@@ -4223,6 +4272,7 @@
 ||iesanjosemonitos.edu.co^
 ||ikexpert.com^
 ||ilrafrica.com^
+||images.jermiau.com^
 ||imbueautoworx.co.za^
 ||imperiumtherapy.co.za^
 ||in-tune2016.com^
@@ -4237,6 +4287,7 @@
 ||inovations.searchkero.com^
 ||inrajahmundry.co.in^
 ||insignificantfinecore.testmail4.repl.co^
+||instantindialoan.com^
 ||instvisionmexico.edu.mx^
 ||intellectsmart.in^
 ||intersel-idf.org^
@@ -4247,6 +4298,7 @@
 ||iremart.es^
 ||iris101.co.uk^
 ||iscamenabe.com^
+||ismf.com.ng^
 ||iso-dubai.net^
 ||israrulhaq.me^
 ||isrorg.com^
@@ -4267,7 +4319,6 @@
 ||jiaoyuzixun.cn^
 ||jing-da.com.tw^
 ||jktnet.xyz^
-||jmcomputacion.com.ar^
 ||jmtc.91756.cn^
 ||jnanbharati.com^
 ||jobs.thebeessolution.com^
@@ -4276,9 +4327,7 @@
 ||josegene.com^
 ||josuarochoa.com^
 ||jpwoodfordco.com^
-||julietlaser.site^
 ||jumpmanualjacobhiller.com^
-||jumpnjamchicago.com^
 ||jupiter.toxsl.in^
 ||jurgensen.newreadermedia.net^
 ||justinscott.com.au^
@@ -4300,6 +4349,7 @@
 ||kumaralok.in^
 ||kwanfromhongkong.com^
 ||kz.sldov.ru^
+||lab18.it^
 ||lacasadelosalebrijes.com^
 ||ladylabonde.com^
 ||lameguard.ru^
@@ -4345,6 +4395,7 @@
 ||lp.difusodesign.com^
 ||lp.juancamilogarciareyes.com^
 ||lp.tecnimasdecolombia.com.co^
+||ltc.typoten.com^
 ||luckybrownie.com^
 ||luminouspneuma.com^
 ||luxomodels.com^
@@ -4353,15 +4404,15 @@
 ||madicon.co.za^
 ||magianegramagiablancayamarres.com^
 ||mail.bs-eiendomme.co.za^
+||mail.golimoapp.com^
 ||mail.jeffsono.org^
 ||maksi.feb.unib.ac.id^
 ||malaya.tv^
 ||malwarecoding.github.io^
 ||managed.oss-cn-beijing.aliyuncs.com^
+||managemysalon.in^
 ||manantialesdelnorte.uy^
-||manivelasst.com^
 ||marcapinyo.ru^
-||marcusthepoet.com^
 ||mario-sunjic.com^
 ||mariobrown.net^
 ||mariotessarollo.com^
@@ -4370,7 +4421,6 @@
 ||marksidfgs.ug^
 ||masjidhabeebiyarazviya.mysunni.com^
 ||materialescantu.com^
-||matinal-nominal.pt^
 ||matruchhaya.co.in^
 ||mattysplayground.com^
 ||maxtox.com.pk^
@@ -4382,6 +4432,7 @@
 ||mediamaster.co.za^
 ||medianews.ge^
 ||medistaffconsulting.com^
+||meditreat.itwebservice.in^
 ||meeweb.com^
 ||megamart.afnan-amc.com^
 ||merbay.ru^
@@ -4402,7 +4453,6 @@
 ||mindfulbuildingandliving.com^
 ||mingguanwms.com^
 ||minuevavida.org^
-||mirror.mypage.sk^
 ||mis.nbcc.ac.th^
 ||misterson.com^
 ||mixr.at^
@@ -4410,12 +4460,14 @@
 ||mktf.mx^
 ||mmogollon.com.mx^
 ||mncarteam.com^
+||mobile.illumetechnology.com^
 ||modelhouseturkey.com^
 ||modernmanna.org^
 ||monetization.business^
 ||moninediy.com^
 ||mopai.sg^
 ||motorcomunicacion.com^
+||msacontabil.com.br^
 ||mtspsmjeli.sch.id^
 ||muzimbiti.xigubo.co.mz^
 ||mxpiqw.am.files.1drv.com^
@@ -4448,8 +4500,8 @@
 ||nicolas.ug^
 ||nidhi.iexist.in^
 ||nikanpolimer.ir^
+||nilehouse.co.ug^
 ||nilinkeji.com^
-||nisacooks.com^
 ||njtiledesigncenter.com^
 ||nobius.org^
 ||nocalnoodle.elin.co.za^
@@ -4467,10 +4519,13 @@
 ||oakleyandfriends.co.uk^
 ||obseques-conseils.com^
 ||ocean.tecnasulstore.com.br^
+||ohe.ie^
 ||ohsewgorgeous.co.uk^
+||oknoplastik.sk^
 ||oleholeh.memangbeda.website^
 ||olirecords.mixture.ltd^
 ||olooom.com^
+||omaia.org^
 ||omaromatic.com^
 ||omega.az^
 ||oms.pappai.com^
@@ -4479,6 +4534,7 @@
 ||onedrive.listifyapp.co^
 ||online.creedglobal.in^
 ||onlinestatis.bar^
+||ont.proman.id^
 ||open.warehousesaas.co.uk^
 ||opolis.io^
 ||optimus.com.sg^
@@ -4486,6 +4542,8 @@
 ||order.bizpeed.com^
 ||orientgatewayltd.com^
 ||orion445.com^
+||oserve.pk^
+||otolithenrichment.fahadjutt.com^
 ||ottimade.com^
 ||ourteam.searchkero.com^
 ||ozemag.com^
@@ -4507,6 +4565,7 @@
 ||paths.elin.co.za^
 ||paulmercier.biz^
 ||payerrealty.com^
+||payments.atifsiddiqui.me^
 ||pcsoori.com^
 ||pd.oceaniarp.net^
 ||perpus.onlineman7-jombang.sch.id^
@@ -4519,6 +4578,7 @@
 ||photo360.kubooking.com^
 ||photographytipsclub.com^
 ||pink99.com^
+||pizzabarletta.com.br^
 ||plasfan.ind.br^
 ||pmglance.startwriteup.com^
 ||pokojewewladyslawowie.pl^
@@ -4528,15 +4588,13 @@
 ||posmicrosystems.com^
 ||poulman.panagiotopoulos-tours.gr^
 ||ppdb.smk-ciptaskill.sch.id^
-||pptvideotemplates.com^
 ||prestasicash.com.ar^
 ||prestigehomeautomation.net^
 ||prishaartcreations.com^
 ||production.sparshims.com^
-||productprecise.com^
-||prof-dr-ahmedalmoatasem.com^
 ||programaoperadoronline.com.br^
 ||project.exquitec.com^
+||promolyko.com^
 ||promotoradescomplica.com.br^
 ||promoversdubai.com^
 ||propertiq.elin.co.za^
@@ -4549,7 +4607,7 @@
 ||pujashoppe.in^
 ||punchdialogues.com^
 ||punjabdevelopersassociation.com.pk^
-||purefoe.top^
+||pvcprinting.co.uk^
 ||qadir.tickfa.ir^
 ||qatarglobalconsulting.com^
 ||qmsled.com^
@@ -4565,7 +4623,6 @@
 ||ravenproductionsltd.com^
 ||rc.ixiaoyang.cn^
 ||readymmade.com^
-||realtheprocess.co^
 ||redchillicrackers.com^
 ||reifenquick.de^
 ||relaxindulge.co.nz^
@@ -4615,7 +4672,6 @@
 ||sarakem.cl^
 ||sasystemsuk.com^
 ||savasaachi.systems^
-||savingchintu.com^
 ||scarfaceindustries.com^
 ||scglobal.co.th^
 ||schalke04rss.de^
@@ -4623,10 +4679,8 @@
 ||schoolbustracker.softgig.co.ke^
 ||sec-doc-w.com^
 ||secure-doc-reader.com^
-||sefp-boispro.fr^
 ||segalsmetals.elin.co.za^
 ||sellmyphonela.com^
-||selltechtoday.com^
 ||senbiaojita.com^
 ||sentierodelviandante.ml^
 ||serendibsourcing.com^
@@ -4643,7 +4697,6 @@
 ||shivakunwar.com.np^
 ||shoblasaathitrust.org^
 ||shooka-co.com^
-||shop.clarostudio.ro^
 ||shop.goldspot.agency^
 ||shopsofe.com^
 ||shrushtiinfotech.com^
@@ -4655,11 +4708,11 @@
 ||simoneporzi.it^
 ||simplithy.co.uk^
 ||sindicato1ucm.cl^
+||sindpol.tiejuris.com.br^
 ||sinergidwireka.com^
 ||sipahielektrik.com^
 ||siperb.in^
 ||sistelligent.com^
-||site.sjc.co.ke^
 ||skkksolo.beweiretail.com^
 ||skyflyfares.com^
 ||skyscan.com^
@@ -4669,7 +4722,6 @@
 ||smokeandgrowrichtour.com^
 ||smokesolutionindia.com^
 ||sobethuacademy.com^
-||soft.110route.com^
 ||soft.officelabo.net^
 ||sohs.conceptechs.info^
 ||solar.amazingtribe.lk^
@@ -4678,11 +4730,11 @@
 ||somir.com.mx^
 ||soralapps.com^
 ||sorteio.orgaostalita.com.br^
+||sosgsm.fr^
 ||sota-france.fr^
 ||sowingminerals.cl^
 ||space.proactint.org^
 ||spaceframe.mobi.space-frame.co.za^
-||specfloors.net^
 ||special-key.cf^
 ||spent.com.pl^
 ||spetsesyachtcharter.gr^
@@ -4714,6 +4766,7 @@
 ||support-4-free.com^
 ||support.clz.kr^
 ||supportit.online^
+||surestdysbonescagexc.dns.army^
 ||sw.yourpageserver.com^
 ||sweaty.dk^
 ||sweet-diet.com^
@@ -4739,11 +4792,11 @@
 ||tc.snpsresidential.com^
 ||tcy.198424.com^
 ||tdsp.yngw518.com^
-||tech332.synology.me^
 ||techgms.com^
 ||technogreen.crmmanivela.com^
 ||technohub.searchkero.com^
 ||tecnicaencolectores.com.mx^
+||tecnologyschool.com^
 ||teduae.com^
 ||teleargentina.com^
 ||telescopelms.com^
@@ -4751,9 +4804,9 @@
 ||temptmag.com^
 ||tennisafrica.com^
 ||tentandoserfitness.000webhostapp.com^
-||tepresto.net.pe^
 ||test.adventser.com^
 ||test.letraele.es^
+||test.typoten.com^
 ||test.wanepghana.org^
 ||test1.asistencia247.com^
 ||test1.milenial.id^
@@ -4766,9 +4819,7 @@
 ||teteaffiche.stephanebillon.com^
 ||tewoerd.eu^
 ||textile.softberg.ro^
-||texts.bfftexts.com^
 ||texturesbyvinita.com^
-||tharringtonsponsorship.com^
 ||thecleaningladiespdx.com^
 ||thecreativecafe.co.uk^
 ||thefuturelife.in^
@@ -4776,12 +4827,11 @@
 ||thehouseofpragya.com^
 ||thekassia.co.uk^
 ||thelaunchpadteam.com^
-||thelekhak.com^
 ||thelogicalgroup.co.uk^
 ||thesummitpc.net^
 ||theurbantutors.com^
+||thewwpc.com^
 ||thosewebbs.com^
-||thriveink.com^
 ||tianangdep.com^
 ||tickfood.tickme.lk^
 ||tickjobs.tickme.lk^
@@ -4814,7 +4864,6 @@
 ||tulli.info^
 ||tupperware.michaelroberge.ca^
 ||turanggaresources.com^
-||tushartyagiji.digitalswagger.in^
 ||uat.indianfilmzone.com^
 ||ublretailerdemo.cstdevs.com^
 ||udesk.searchkero.com^
@@ -4824,7 +4873,6 @@
 ||unicorpbrunei.com^
 ||uniengrisb.com^
 ||unisoftcc.com^
-||unitedpestsolutionstx.com^
 ||unyazitelecom.com^
 ||upcbpta.com^
 ||urbane.dezinetimes.com^
@@ -4851,17 +4899,18 @@
 ||vivationdesign.com^
 ||viveirodoiscorregos.com.br^
 ||vksales.com^
+||vladimirinternational.com^
 ||vokasi.ub.ac.id^
 ||vologroup.com.br^
 ||voteyouramerica.dekitout.com^
 ||vstsample.com^
 ||vtube.fadlymotivator.com^
 ||vvsskmodinationalschool.com^
-||wahrewah.nl^
 ||wanepliberia.org^
 ||wanepniger.org^
 ||weareactum.com^
 ||web.eng.ubu.ac.th^
+||web.geetle.ga^
 ||web.geomegasoft.net^
 ||web.newinnovationtechnology.com^
 ||web.smarts-works.com^
@@ -4875,13 +4924,12 @@
 ||whcms.yourpageserver.com^
 ||whiteglovetailgate.com^
 ||whiteresponse.com^
+||whynt.xyz^
 ||wi522012.ferozo.com^
 ||wikalen.co.za^
 ||wildnights.co.uk^
 ||wildtrust.mediadevstaging.com^
 ||wimbamusica.com^
-||windcomtechnologies.com^
-||winnercircle.it^
 ||wishesconcierge.com^
 ||woezon.agency^
 ||wolfgang-brodte.de^
@@ -4897,7 +4945,6 @@
 ||xia.beihaixue.com^
 ||xixaoclothing.com^
 ||xk.996is.com^
-||xmp.myracingaccounts.com^
 ||xn--80akinnkiib6h.xn--90ais^
 ||xn--polimerbizmimarlk-rvc.com^
 ||ybom.urbanolab.com^
@@ -4908,5 +4955,6 @@
 ||yskadvisors.com^
 ||yummyyogaudaipur.com^
 ||yzkzixun.com^
+||zakra.tecnasulstore.com.br^
 ||zytrox.tk^
 ||zz.690tx.com^
diff --git a/urlhaus-filter-agh.txt b/urlhaus-filter-agh.txt
index d66182c4..4a9590ad 100644
--- a/urlhaus-filter-agh.txt
+++ b/urlhaus-filter-agh.txt
@@ -1,5 +1,5 @@
 ! Title: Malicious URL Blocklist (AdGuard Home)
-! Updated: Thu, 25 Mar 2021 12:12:40 UTC
+! Updated: Fri, 26 Mar 2021 00:12:29 UTC
 ! Expires: 1 day (update frequency)
 ! Homepage: https://gitlab.com/curben/urlhaus-filter
 ! License: https://gitlab.com/curben/urlhaus-filter#license
@@ -1023,6 +1023,7 @@
 ||1.58.206.122^
 ||1.58.206.199^
 ||1.58.220.198^
+||1.58.223.96^
 ||1.58.50.67^
 ||1.59.181.177^
 ||1.59.249.83^
@@ -3599,6 +3600,7 @@
 ||103.217.116.166^
 ||103.217.116.245^
 ||103.217.117.108^
+||103.217.117.134^
 ||103.217.119.74^
 ||103.217.119.75^
 ||103.217.119.76^
@@ -3667,6 +3669,7 @@
 ||103.217.121.228^
 ||103.217.121.22^
 ||103.217.121.231^
+||103.217.121.234^
 ||103.217.121.237^
 ||103.217.121.238^
 ||103.217.121.239^
@@ -3733,6 +3736,7 @@
 ||103.217.123.199^
 ||103.217.123.200^
 ||103.217.123.204^
+||103.217.123.210^
 ||103.217.123.213^
 ||103.217.123.216^
 ||103.217.123.218^
@@ -5206,6 +5210,7 @@
 ||103.78.183.40^
 ||103.78.183.4^
 ||103.78.21.238^
+||103.78.22.157^
 ||103.78.22.177^
 ||103.78.22.207^
 ||103.78.22.219^
@@ -6683,6 +6688,7 @@
 ||104.168.151.198^
 ||104.168.152.230^
 ||104.168.157.45^
+||104.168.158.127^
 ||104.168.158.148^
 ||104.168.158.248^
 ||104.168.158.38^
@@ -6777,6 +6783,7 @@
 ||104.168.96.11^
 ||104.168.96.168^
 ||104.168.96.194^
+||104.168.98.105^
 ||104.168.98.206^
 ||104.168.99.220^
 ||104.168.99.30^
@@ -8389,6 +8396,7 @@
 ||106.36.159.125^
 ||106.36.4.112^
 ||106.37.121.250^
+||106.4.138.95^
 ||106.4.140.29^
 ||106.4.209.123^
 ||106.4.241.59^
@@ -10192,6 +10200,7 @@
 ||110.244.46.196^
 ||110.244.48.104^
 ||110.244.51.22^
+||110.247.151.4^
 ||110.247.16.153^
 ||110.247.16.64^
 ||110.247.180.69^
@@ -10816,6 +10825,7 @@
 ||111.165.186.127^
 ||111.165.202.37^
 ||111.165.207.179^
+||111.165.21.195^
 ||111.165.210.227^
 ||111.165.210.249^
 ||111.165.214.179^
@@ -10848,6 +10858,7 @@
 ||111.165.255.240^
 ||111.165.26.73^
 ||111.165.27.112^
+||111.165.28.234^
 ||111.165.31.62^
 ||111.165.33.132^
 ||111.165.33.210^
@@ -16983,6 +16994,7 @@
 ||112.246.18.70^
 ||112.246.18.84^
 ||112.246.18.99^
+||112.246.180.49^
 ||112.246.181.139^
 ||112.246.184.252^
 ||112.246.184.97^
@@ -17233,6 +17245,7 @@
 ||112.247.247.234^
 ||112.247.248.114^
 ||112.247.248.14^
+||112.247.248.76^
 ||112.247.249.198^
 ||112.247.249.82^
 ||112.247.250.193^
@@ -17920,6 +17933,7 @@
 ||112.249.205.67^
 ||112.249.206.105^
 ||112.249.206.52^
+||112.249.206.69^
 ||112.249.206.8^
 ||112.249.207.154^
 ||112.249.207.198^
@@ -18283,6 +18297,7 @@
 ||112.249.78.69^
 ||112.249.79.230^
 ||112.249.79.88^
+||112.249.79.98^
 ||112.249.80.217^
 ||112.249.80.53^
 ||112.249.80.69^
@@ -18565,6 +18580,7 @@
 ||112.252.41.80^
 ||112.252.42.128^
 ||112.252.43.218^
+||112.252.46.212^
 ||112.252.59.78^
 ||112.252.66.17^
 ||112.252.66.55^
@@ -20162,6 +20178,7 @@
 ||112.93.7.60^
 ||112.93.89.37^
 ||112.94.188.182^
+||112.94.188.230^
 ||112.94.189.107^
 ||112.95.12.157^
 ||112.95.13.15^
@@ -20527,6 +20544,7 @@
 ||113.104.237.236^
 ||113.104.237.34^
 ||113.104.237.36^
+||113.104.237.52^
 ||113.104.237.72^
 ||113.104.237.74^
 ||113.104.237.83^
@@ -21248,6 +21266,7 @@
 ||113.116.150.101^
 ||113.116.150.110^
 ||113.116.150.144^
+||113.116.150.147^
 ||113.116.150.161^
 ||113.116.150.176^
 ||113.116.150.180^
@@ -22453,6 +22472,7 @@
 ||113.118.13.222^
 ||113.118.13.226^
 ||113.118.13.26^
+||113.118.13.29^
 ||113.118.13.44^
 ||113.118.13.47^
 ||113.118.13.50^
@@ -23959,6 +23979,7 @@
 ||113.201.24.202^
 ||113.201.24.206^
 ||113.201.24.24^
+||113.201.24.26^
 ||113.201.24.30^
 ||113.201.24.4^
 ||113.201.24.5^
@@ -24400,6 +24421,7 @@
 ||113.234.185.255^
 ||113.234.195.226^
 ||113.234.197.125^
+||113.234.224.130^
 ||113.234.224.160^
 ||113.234.231.172^
 ||113.234.231.202^
@@ -25299,6 +25321,7 @@
 ||113.81.112.13^
 ||113.81.112.159^
 ||113.81.112.228^
+||113.81.112.35^
 ||113.81.112.66^
 ||113.81.112.72^
 ||113.81.113.119^
@@ -25820,6 +25843,7 @@
 ||113.87.248.15^
 ||113.87.248.162^
 ||113.87.248.163^
+||113.87.248.177^
 ||113.87.248.181^
 ||113.87.248.206^
 ||113.87.248.28^
@@ -26006,6 +26030,7 @@
 ||113.88.1.69^
 ||113.88.100.105^
 ||113.88.100.117^
+||113.88.100.120^
 ||113.88.100.130^
 ||113.88.100.160^
 ||113.88.100.172^
@@ -26631,6 +26656,7 @@
 ||113.88.241.92^
 ||113.88.241.98^
 ||113.88.241.9^
+||113.88.242.0^
 ||113.88.242.10^
 ||113.88.242.116^
 ||113.88.242.121^
@@ -26960,6 +26986,7 @@
 ||113.89.244.93^
 ||113.89.245.118^
 ||113.89.245.132^
+||113.89.245.13^
 ||113.89.245.144^
 ||113.89.245.174^
 ||113.89.245.186^
@@ -29687,6 +29714,7 @@
 ||115.171.238.92^
 ||115.171.239.20^
 ||115.171.239.25^
+||115.171.239.28^
 ||115.171.90.159^
 ||115.171.91.155^
 ||115.171.91.195^
@@ -29858,6 +29886,7 @@
 ||115.201.37.74^
 ||115.201.37.84^
 ||115.201.37.88^
+||115.201.38.185^
 ||115.201.40.156^
 ||115.201.40.65^
 ||115.201.40.66^
@@ -29931,6 +29960,7 @@
 ||115.202.187.124^
 ||115.202.187.242^
 ||115.202.187.61^
+||115.202.188.84^
 ||115.202.210.224^
 ||115.202.210.228^
 ||115.202.214.217^
@@ -30259,6 +30289,7 @@
 ||115.213.176.80^
 ||115.213.186.121^
 ||115.213.186.152^
+||115.213.187.251^
 ||115.213.188.167^
 ||115.213.198.25^
 ||115.213.199.79^
@@ -30752,6 +30783,7 @@
 ||115.48.130.177^
 ||115.48.130.181^
 ||115.48.130.184^
+||115.48.130.187^
 ||115.48.130.193^
 ||115.48.130.196^
 ||115.48.130.197^
@@ -30915,6 +30947,7 @@
 ||115.48.135.123^
 ||115.48.135.126^
 ||115.48.135.150^
+||115.48.135.151^
 ||115.48.135.152^
 ||115.48.135.154^
 ||115.48.135.155^
@@ -32469,6 +32502,7 @@
 ||115.48.200.103^
 ||115.48.200.104^
 ||115.48.200.114^
+||115.48.200.115^
 ||115.48.200.124^
 ||115.48.200.126^
 ||115.48.200.134^
@@ -33716,6 +33750,7 @@
 ||115.49.113.126^
 ||115.49.113.59^
 ||115.49.116.148^
+||115.49.116.237^
 ||115.49.118.13^
 ||115.49.12.164^
 ||115.49.12.26^
@@ -33833,6 +33868,7 @@
 ||115.49.150.203^
 ||115.49.150.86^
 ||115.49.151.207^
+||115.49.152.10^
 ||115.49.152.116^
 ||115.49.152.140^
 ||115.49.152.89^
@@ -34327,6 +34363,7 @@
 ||115.49.241.6^
 ||115.49.241.87^
 ||115.49.241.94^
+||115.49.242.100^
 ||115.49.242.17^
 ||115.49.242.79^
 ||115.49.242.91^
@@ -35159,6 +35196,7 @@
 ||115.49.79.87^
 ||115.49.79.98^
 ||115.49.8.244^
+||115.49.80.117^
 ||115.49.80.149^
 ||115.49.80.161^
 ||115.49.80.74^
@@ -37024,6 +37062,7 @@
 ||115.50.201.85^
 ||115.50.201.87^
 ||115.50.201.91^
+||115.50.202.11^
 ||115.50.202.131^
 ||115.50.202.13^
 ||115.50.202.157^
@@ -38458,6 +38497,7 @@
 ||115.50.240.216^
 ||115.50.240.220^
 ||115.50.240.228^
+||115.50.240.230^
 ||115.50.240.237^
 ||115.50.240.252^
 ||115.50.240.27^
@@ -39874,6 +39914,7 @@
 ||115.50.61.22^
 ||115.50.61.233^
 ||115.50.61.23^
+||115.50.61.247^
 ||115.50.61.252^
 ||115.50.61.254^
 ||115.50.61.25^
@@ -40006,6 +40047,7 @@
 ||115.50.64.177^
 ||115.50.64.178^
 ||115.50.64.179^
+||115.50.64.182^
 ||115.50.64.189^
 ||115.50.64.212^
 ||115.50.64.229^
@@ -41126,6 +41168,7 @@
 ||115.51.107.163^
 ||115.51.107.164^
 ||115.51.107.183^
+||115.51.107.18^
 ||115.51.107.193^
 ||115.51.107.195^
 ||115.51.107.203^
@@ -42442,6 +42485,7 @@
 ||115.52.20.97^
 ||115.52.200.245^
 ||115.52.201.220^
+||115.52.201.231^
 ||115.52.201.254^
 ||115.52.202.73^
 ||115.52.204.80^
@@ -42485,6 +42529,7 @@
 ||115.52.22.140^
 ||115.52.22.145^
 ||115.52.22.149^
+||115.52.22.162^
 ||115.52.22.166^
 ||115.52.22.177^
 ||115.52.22.193^
@@ -42741,6 +42786,7 @@
 ||115.52.35.151^
 ||115.52.35.6^
 ||115.52.36.27^
+||115.52.37.164^
 ||115.52.38.110^
 ||115.52.38.132^
 ||115.52.38.182^
@@ -43945,6 +43991,7 @@
 ||115.54.159.16^
 ||115.54.159.206^
 ||115.54.159.33^
+||115.54.160.25^
 ||115.54.168.18^
 ||115.54.168.190^
 ||115.54.168.237^
@@ -44730,6 +44777,7 @@
 ||115.54.212.203^
 ||115.54.212.205^
 ||115.54.212.207^
+||115.54.212.227^
 ||115.54.212.22^
 ||115.54.212.233^
 ||115.54.212.239^
@@ -45044,6 +45092,7 @@
 ||115.54.240.128^
 ||115.54.240.166^
 ||115.54.240.170^
+||115.54.240.173^
 ||115.54.240.195^
 ||115.54.240.197^
 ||115.54.240.198^
@@ -45219,6 +45268,7 @@
 ||115.54.69.60^
 ||115.54.69.89^
 ||115.54.69.9^
+||115.54.70.108^
 ||115.54.70.139^
 ||115.54.70.150^
 ||115.54.70.161^
@@ -45265,6 +45315,7 @@
 ||115.54.73.254^
 ||115.54.73.37^
 ||115.54.73.42^
+||115.54.73.50^
 ||115.54.73.51^
 ||115.54.74.109^
 ||115.54.74.142^
@@ -48105,6 +48156,7 @@
 ||115.55.211.247^
 ||115.55.211.24^
 ||115.55.211.251^
+||115.55.211.41^
 ||115.55.211.48^
 ||115.55.211.4^
 ||115.55.211.54^
@@ -48508,6 +48560,7 @@
 ||115.55.3.155^
 ||115.55.3.204^
 ||115.55.3.20^
+||115.55.3.36^
 ||115.55.3.54^
 ||115.55.30.105^
 ||115.55.30.138^
@@ -49823,6 +49876,7 @@
 ||115.56.136.124^
 ||115.56.136.127^
 ||115.56.136.141^
+||115.56.136.144^
 ||115.56.136.145^
 ||115.56.136.146^
 ||115.56.136.154^
@@ -50713,6 +50767,7 @@
 ||115.56.154.139^
 ||115.56.154.142^
 ||115.56.154.145^
+||115.56.154.147^
 ||115.56.154.14^
 ||115.56.154.164^
 ||115.56.154.173^
@@ -50831,6 +50886,7 @@
 ||115.56.156.30^
 ||115.56.156.39^
 ||115.56.156.53^
+||115.56.156.54^
 ||115.56.156.55^
 ||115.56.156.62^
 ||115.56.156.67^
@@ -51160,6 +51216,7 @@
 ||115.56.177.190^
 ||115.56.177.192^
 ||115.56.177.198^
+||115.56.177.202^
 ||115.56.177.205^
 ||115.56.177.214^
 ||115.56.177.220^
@@ -52960,6 +53017,7 @@
 ||115.58.132.194^
 ||115.58.132.196^
 ||115.58.132.197^
+||115.58.132.199^
 ||115.58.132.19^
 ||115.58.132.205^
 ||115.58.132.211^
@@ -53606,6 +53664,7 @@
 ||115.58.167.23^
 ||115.58.167.50^
 ||115.58.167.78^
+||115.58.167.90^
 ||115.58.168.104^
 ||115.58.168.117^
 ||115.58.168.14^
@@ -53745,6 +53804,7 @@
 ||115.58.20.147^
 ||115.58.20.152^
 ||115.58.20.180^
+||115.58.20.186^
 ||115.58.20.193^
 ||115.58.20.197^
 ||115.58.20.199^
@@ -55038,6 +55098,7 @@
 ||115.59.198.181^
 ||115.59.198.184^
 ||115.59.198.194^
+||115.59.198.200^
 ||115.59.198.211^
 ||115.59.198.215^
 ||115.59.198.218^
@@ -55589,6 +55650,7 @@
 ||115.59.215.74^
 ||115.59.215.8^
 ||115.59.215.95^
+||115.59.215.96^
 ||115.59.215.99^
 ||115.59.216.103^
 ||115.59.216.106^
@@ -57071,6 +57133,7 @@
 ||115.59.90.149^
 ||115.59.90.155^
 ||115.59.90.182^
+||115.59.90.197^
 ||115.59.90.204^
 ||115.59.90.22^
 ||115.59.90.236^
@@ -57193,6 +57256,7 @@
 ||115.60.201.105^
 ||115.60.201.142^
 ||115.60.201.144^
+||115.60.201.176^
 ||115.60.201.181^
 ||115.60.201.186^
 ||115.60.201.211^
@@ -57840,6 +57904,7 @@
 ||115.61.118.182^
 ||115.61.118.185^
 ||115.61.118.189^
+||115.61.118.201^
 ||115.61.118.210^
 ||115.61.118.226^
 ||115.61.118.245^
@@ -59519,6 +59584,7 @@
 ||115.61.97.25^
 ||115.61.97.39^
 ||115.61.97.46^
+||115.61.97.55^
 ||115.61.97.63^
 ||115.61.97.65^
 ||115.61.97.70^
@@ -59751,6 +59817,7 @@
 ||115.62.152.143^
 ||115.62.152.144^
 ||115.62.152.206^
+||115.62.152.207^
 ||115.62.152.37^
 ||115.62.152.55^
 ||115.62.152.70^
@@ -60265,6 +60332,7 @@
 ||115.63.130.14^
 ||115.63.130.150^
 ||115.63.130.161^
+||115.63.130.162^
 ||115.63.130.169^
 ||115.63.130.170^
 ||115.63.130.173^
@@ -60565,6 +60633,7 @@
 ||115.63.140.216^
 ||115.63.140.218^
 ||115.63.140.236^
+||115.63.140.242^
 ||115.63.140.27^
 ||115.63.140.32^
 ||115.63.140.39^
@@ -66908,6 +66977,7 @@
 ||115.96.87.95^
 ||115.96.88.171^
 ||115.96.90.226^
+||115.96.92.151^
 ||115.96.94.114^
 ||115.97.102.100^
 ||115.97.102.102^
@@ -68386,6 +68456,7 @@
 ||115.97.142.180^
 ||115.97.142.182^
 ||115.97.142.188^
+||115.97.142.18^
 ||115.97.142.190^
 ||115.97.142.192^
 ||115.97.142.193^
@@ -91409,6 +91480,7 @@
 ||116.24.152.157^
 ||116.24.152.158^
 ||116.24.152.164^
+||116.24.152.217^
 ||116.24.152.245^
 ||116.24.152.34^
 ||116.24.152.80^
@@ -94034,6 +94106,7 @@
 ||116.72.202.80^
 ||116.72.202.81^
 ||116.72.202.83^
+||116.72.202.87^
 ||116.72.202.89^
 ||116.72.202.8^
 ||116.72.202.90^
@@ -94074,6 +94147,7 @@
 ||116.72.203.13^
 ||116.72.203.141^
 ||116.72.203.142^
+||116.72.203.143^
 ||116.72.203.145^
 ||116.72.203.146^
 ||116.72.203.148^
@@ -102332,6 +102406,7 @@
 ||116.74.83.94^
 ||116.74.83.98^
 ||116.74.83.9^
+||116.74.84.65^
 ||116.74.85.131^
 ||116.74.85.1^
 ||116.74.87.107^
@@ -105663,6 +105738,7 @@
 ||116.75.194.147^
 ||116.75.194.148^
 ||116.75.194.149^
+||116.75.194.14^
 ||116.75.194.150^
 ||116.75.194.151^
 ||116.75.194.152^
@@ -107850,6 +107926,7 @@
 ||116.75.214.51^
 ||116.75.214.52^
 ||116.75.214.53^
+||116.75.214.56^
 ||116.75.214.58^
 ||116.75.214.59^
 ||116.75.214.61^
@@ -107879,6 +107956,7 @@
 ||116.75.214.96^
 ||116.75.214.97^
 ||116.75.214.98^
+||116.75.214.99^
 ||116.75.215.0^
 ||116.75.215.100^
 ||116.75.215.102^
@@ -112645,6 +112723,7 @@
 ||117.194.149.247^
 ||117.194.149.250^
 ||117.194.149.252^
+||117.194.149.26^
 ||117.194.149.28^
 ||117.194.149.33^
 ||117.194.149.37^
@@ -112988,6 +113067,7 @@
 ||117.194.160.79^
 ||117.194.160.81^
 ||117.194.160.83^
+||117.194.160.84^
 ||117.194.160.85^
 ||117.194.160.87^
 ||117.194.160.88^
@@ -116420,6 +116500,7 @@
 ||117.202.70.224^
 ||117.202.70.225^
 ||117.202.70.226^
+||117.202.70.227^
 ||117.202.70.228^
 ||117.202.70.229^
 ||117.202.70.22^
@@ -118620,6 +118701,7 @@
 ||117.213.11.106^
 ||117.213.11.136^
 ||117.213.11.205^
+||117.213.11.225^
 ||117.213.11.47^
 ||117.213.11.50^
 ||117.213.11.8^
@@ -119037,6 +119119,7 @@
 ||117.213.42.153^
 ||117.213.42.154^
 ||117.213.42.157^
+||117.213.42.158^
 ||117.213.42.159^
 ||117.213.42.15^
 ||117.213.42.160^
@@ -120078,6 +120161,7 @@
 ||117.213.9.58^
 ||117.213.9.71^
 ||117.213.9.77^
+||117.213.9.78^
 ||117.214.11.249^
 ||117.214.11.8^
 ||117.214.242.73^
@@ -120375,6 +120459,7 @@
 ||117.215.248.20^
 ||117.215.248.214^
 ||117.215.248.217^
+||117.215.248.223^
 ||117.215.248.237^
 ||117.215.248.23^
 ||117.215.248.242^
@@ -120414,6 +120499,7 @@
 ||117.215.249.221^
 ||117.215.249.22^
 ||117.215.249.230^
+||117.215.249.23^
 ||117.215.249.240^
 ||117.215.249.241^
 ||117.215.249.242^
@@ -120999,6 +121085,7 @@
 ||117.222.161.65^
 ||117.222.161.66^
 ||117.222.161.67^
+||117.222.161.68^
 ||117.222.161.6^
 ||117.222.161.70^
 ||117.222.161.74^
@@ -121266,6 +121353,7 @@
 ||117.222.163.147^
 ||117.222.163.148^
 ||117.222.163.149^
+||117.222.163.150^
 ||117.222.163.151^
 ||117.222.163.153^
 ||117.222.163.154^
@@ -121393,6 +121481,7 @@
 ||117.222.163.59^
 ||117.222.163.5^
 ||117.222.163.60^
+||117.222.163.61^
 ||117.222.163.62^
 ||117.222.163.63^
 ||117.222.163.65^
@@ -121404,6 +121493,7 @@
 ||117.222.163.70^
 ||117.222.163.71^
 ||117.222.163.72^
+||117.222.163.73^
 ||117.222.163.74^
 ||117.222.163.77^
 ||117.222.163.78^
@@ -121771,6 +121861,7 @@
 ||117.222.165.27^
 ||117.222.165.28^
 ||117.222.165.29^
+||117.222.165.31^
 ||117.222.165.32^
 ||117.222.165.33^
 ||117.222.165.34^
@@ -122217,6 +122308,7 @@
 ||117.222.168.114^
 ||117.222.168.115^
 ||117.222.168.116^
+||117.222.168.119^
 ||117.222.168.11^
 ||117.222.168.122^
 ||117.222.168.123^
@@ -122238,6 +122330,7 @@
 ||117.222.168.181^
 ||117.222.168.183^
 ||117.222.168.185^
+||117.222.168.186^
 ||117.222.168.191^
 ||117.222.168.194^
 ||117.222.168.195^
@@ -122303,6 +122396,7 @@
 ||117.222.169.112^
 ||117.222.169.113^
 ||117.222.169.114^
+||117.222.169.115^
 ||117.222.169.117^
 ||117.222.169.11^
 ||117.222.169.124^
@@ -122520,6 +122614,7 @@
 ||117.222.171.1^
 ||117.222.171.202^
 ||117.222.171.203^
+||117.222.171.205^
 ||117.222.171.209^
 ||117.222.171.217^
 ||117.222.171.218^
@@ -122667,6 +122762,7 @@
 ||117.222.172.87^
 ||117.222.172.92^
 ||117.222.172.94^
+||117.222.172.97^
 ||117.222.172.98^
 ||117.222.172.9^
 ||117.222.173.100^
@@ -124121,6 +124217,7 @@
 ||117.242.210.65^
 ||117.242.210.67^
 ||117.242.210.68^
+||117.242.210.69^
 ||117.242.210.6^
 ||117.242.210.70^
 ||117.242.210.71^
@@ -124670,6 +124767,7 @@
 ||117.247.200.16^
 ||117.247.200.170^
 ||117.247.200.172^
+||117.247.200.179^
 ||117.247.200.181^
 ||117.247.200.182^
 ||117.247.200.185^
@@ -124747,6 +124845,7 @@
 ||117.247.201.158^
 ||117.247.201.15^
 ||117.247.201.161^
+||117.247.201.163^
 ||117.247.201.172^
 ||117.247.201.175^
 ||117.247.201.179^
@@ -124871,6 +124970,7 @@
 ||117.247.202.37^
 ||117.247.202.46^
 ||117.247.202.48^
+||117.247.202.4^
 ||117.247.202.50^
 ||117.247.202.51^
 ||117.247.202.54^
@@ -124969,6 +125069,7 @@
 ||117.247.203.27^
 ||117.247.203.31^
 ||117.247.203.33^
+||117.247.203.38^
 ||117.247.203.39^
 ||117.247.203.3^
 ||117.247.203.40^
@@ -126641,6 +126742,7 @@
 ||117.251.59.232^
 ||117.251.59.237^
 ||117.251.59.23^
+||117.251.59.242^
 ||117.251.59.243^
 ||117.251.59.244^
 ||117.251.59.246^
@@ -127505,6 +127607,7 @@
 ||117.63.51.128^
 ||117.63.53.15^
 ||117.63.53.172^
+||117.63.56.81^
 ||117.63.69.253^
 ||117.63.7.177^
 ||117.63.7.192^
@@ -127568,6 +127671,7 @@
 ||117.85.89.213^
 ||117.85.95.220^
 ||117.86.1.7^
+||117.86.105.110^
 ||117.86.110.91^
 ||117.86.148.199^
 ||117.86.155.77^
@@ -127806,6 +127910,7 @@
 ||117.91.156.66^
 ||117.91.172.11^
 ||117.91.172.49^
+||117.91.240.50^
 ||117.91.241.17^
 ||117.92.177.76^
 ||117.92.196.126^
@@ -129134,6 +129239,7 @@
 ||118.75.114.227^
 ||118.75.115.154^
 ||118.75.119.214^
+||118.75.120.136^
 ||118.75.120.209^
 ||118.75.120.229^
 ||118.75.120.98^
@@ -129262,6 +129368,7 @@
 ||118.75.236.238^
 ||118.75.239.142^
 ||118.75.240.141^
+||118.75.240.239^
 ||118.75.240.9^
 ||118.75.241.204^
 ||118.75.241.26^
@@ -129573,6 +129680,7 @@
 ||118.79.163.61^
 ||118.79.163.86^
 ||118.79.163.91^
+||118.79.164.102^
 ||118.79.164.108^
 ||118.79.167.240^
 ||118.79.167.41^
@@ -130605,6 +130713,7 @@
 ||119.123.175.124^
 ||119.123.175.126^
 ||119.123.175.128^
+||119.123.175.133^
 ||119.123.175.139^
 ||119.123.175.144^
 ||119.123.175.145^
@@ -131795,6 +131904,7 @@
 ||119.165.207.118^
 ||119.165.208.188^
 ||119.165.208.216^
+||119.165.208.73^
 ||119.165.209.0^
 ||119.165.209.121^
 ||119.165.209.127^
@@ -132945,6 +133055,7 @@
 ||119.179.42.247^
 ||119.179.43.1^
 ||119.179.43.27^
+||119.179.44.141^
 ||119.179.44.157^
 ||119.179.44.192^
 ||119.179.45.108^
@@ -133420,6 +133531,7 @@
 ||119.180.9.183^
 ||119.180.9.209^
 ||119.180.9.241^
+||119.180.9.35^
 ||119.180.90.121^
 ||119.180.92.176^
 ||119.180.92.224^
@@ -135244,6 +135356,7 @@
 ||119.250.10.222^
 ||119.250.117.131^
 ||119.250.119.227^
+||119.250.129.231^
 ||119.250.132.83^
 ||119.250.166.153^
 ||119.250.218.177^
@@ -135770,6 +135883,7 @@
 ||120.12.211.237^
 ||120.12.212.231^
 ||120.12.212.234^
+||120.12.212.5^
 ||120.12.213.82^
 ||120.12.217.158^
 ||120.12.217.91^
@@ -136955,6 +137069,7 @@
 ||120.57.102.243^
 ||120.57.102.246^
 ||120.57.102.254^
+||120.57.102.32^
 ||120.57.102.46^
 ||120.57.102.58^
 ||120.57.102.5^
@@ -139437,6 +139552,7 @@
 ||120.82.169.73^
 ||120.82.170.40^
 ||120.82.170.75^
+||120.82.217.176^
 ||120.82.217.197^
 ||120.82.228.185^
 ||120.82.38.219^
@@ -139760,6 +139876,7 @@
 ||120.85.173.121^
 ||120.85.173.126^
 ||120.85.173.135^
+||120.85.173.137^
 ||120.85.173.143^
 ||120.85.173.145^
 ||120.85.173.149^
@@ -139805,6 +139922,7 @@
 ||120.85.174.24^
 ||120.85.174.30^
 ||120.85.174.38^
+||120.85.174.39^
 ||120.85.174.41^
 ||120.85.174.42^
 ||120.85.174.45^
@@ -140061,6 +140179,7 @@
 ||120.85.199.184^
 ||120.85.199.195^
 ||120.85.199.19^
+||120.85.199.222^
 ||120.85.199.242^
 ||120.85.199.247^
 ||120.85.199.253^
@@ -140182,6 +140301,7 @@
 ||120.85.211.82^
 ||120.85.211.84^
 ||120.85.211.85^
+||120.85.212.45^
 ||120.85.232.107^
 ||120.85.232.64^
 ||120.85.234.15^
@@ -140281,6 +140401,7 @@
 ||120.85.238.80^
 ||120.85.238.87^
 ||120.85.238.89^
+||120.85.238.97^
 ||120.85.239.100^
 ||120.85.239.113^
 ||120.85.239.11^
@@ -140697,6 +140818,7 @@
 ||121.154.163.88^
 ||121.154.190.19^
 ||121.154.190.232^
+||121.154.190.73^
 ||121.154.226.39^
 ||121.154.37.14^
 ||121.154.39.26^
@@ -141692,6 +141814,7 @@
 ||121.34.150.234^
 ||121.34.150.251^
 ||121.34.150.27^
+||121.34.150.32^
 ||121.34.150.36^
 ||121.34.150.43^
 ||121.34.150.45^
@@ -142485,6 +142608,7 @@
 ||122.188.61.157^
 ||122.188.61.231^
 ||122.188.61.239^
+||122.188.86.225^
 ||122.189.101.23^
 ||122.189.105.132^
 ||122.189.105.250^
@@ -142494,6 +142618,7 @@
 ||122.189.7.14^
 ||122.190.115.86^
 ||122.190.19.131^
+||122.190.19.204^
 ||122.190.192.182^
 ||122.190.192.92^
 ||122.190.244.85^
@@ -143087,6 +143212,7 @@
 ||123.10.131.179^
 ||123.10.131.204^
 ||123.10.131.223^
+||123.10.131.225^
 ||123.10.131.245^
 ||123.10.131.251^
 ||123.10.131.47^
@@ -143749,6 +143875,7 @@
 ||123.10.209.61^
 ||123.10.209.65^
 ||123.10.209.87^
+||123.10.209.95^
 ||123.10.21.116^
 ||123.10.21.172^
 ||123.10.21.184^
@@ -143793,6 +143920,7 @@
 ||123.10.214.114^
 ||123.10.214.129^
 ||123.10.214.174^
+||123.10.214.193^
 ||123.10.214.25^
 ||123.10.214.60^
 ||123.10.214.75^
@@ -144546,6 +144674,7 @@
 ||123.10.82.119^
 ||123.10.82.192^
 ||123.10.82.228^
+||123.10.83.136^
 ||123.10.84.166^
 ||123.10.84.187^
 ||123.10.84.188^
@@ -145330,6 +145459,7 @@
 ||123.11.174.47^
 ||123.11.174.61^
 ||123.11.175.108^
+||123.11.175.136^
 ||123.11.175.190^
 ||123.11.175.197^
 ||123.11.175.227^
@@ -147109,6 +147239,7 @@
 ||123.12.229.177^
 ||123.12.229.211^
 ||123.12.229.232^
+||123.12.229.243^
 ||123.12.229.24^
 ||123.12.229.252^
 ||123.12.229.253^
@@ -147527,6 +147658,7 @@
 ||123.12.35.198^
 ||123.12.35.29^
 ||123.12.36.167^
+||123.12.36.185^
 ||123.12.36.193^
 ||123.12.36.3^
 ||123.12.36.54^
@@ -148135,6 +148267,7 @@
 ||123.13.100.254^
 ||123.13.101.202^
 ||123.13.101.30^
+||123.13.101.56^
 ||123.13.102.179^
 ||123.13.102.204^
 ||123.13.102.205^
@@ -148441,6 +148574,7 @@
 ||123.13.30.167^
 ||123.13.30.219^
 ||123.13.30.2^
+||123.13.30.75^
 ||123.13.31.104^
 ||123.13.31.144^
 ||123.13.31.175^
@@ -150448,6 +150582,7 @@
 ||123.14.205.212^
 ||123.14.205.223^
 ||123.14.205.236^
+||123.14.205.23^
 ||123.14.205.241^
 ||123.14.205.246^
 ||123.14.205.34^
@@ -152258,6 +152393,7 @@
 ||123.183.123.153^
 ||123.183.123.187^
 ||123.183.123.212^
+||123.183.123.41^
 ||123.183.123.5^
 ||123.183.124.131^
 ||123.183.124.188^
@@ -153689,6 +153825,7 @@
 ||123.4.179.75^
 ||123.4.179.82^
 ||123.4.179.8^
+||123.4.180.137^
 ||123.4.180.152^
 ||123.4.180.156^
 ||123.4.180.171^
@@ -153736,6 +153873,7 @@
 ||123.4.184.8^
 ||123.4.185.112^
 ||123.4.185.12^
+||123.4.185.137^
 ||123.4.185.14^
 ||123.4.185.168^
 ||123.4.185.220^
@@ -156551,6 +156689,7 @@
 ||123.5.145.233^
 ||123.5.145.23^
 ||123.5.145.242^
+||123.5.145.245^
 ||123.5.145.248^
 ||123.5.145.42^
 ||123.5.145.55^
@@ -157747,6 +157886,7 @@
 ||123.5.22.110^
 ||123.5.22.175^
 ||123.5.22.210^
+||123.5.22.220^
 ||123.5.22.221^
 ||123.5.22.238^
 ||123.5.22.49^
@@ -158425,6 +158565,7 @@
 ||123.8.183.124^
 ||123.8.183.145^
 ||123.8.183.185^
+||123.8.183.194^
 ||123.8.183.207^
 ||123.8.183.31^
 ||123.8.183.46^
@@ -159421,6 +159562,7 @@
 ||123.9.103.190^
 ||123.9.103.200^
 ||123.9.103.23^
+||123.9.103.252^
 ||123.9.103.36^
 ||123.9.103.53^
 ||123.9.103.61^
@@ -161541,6 +161683,7 @@
 ||124.130.31.18^
 ||124.130.40.15^
 ||124.130.40.162^
+||124.130.40.31^
 ||124.130.56.200^
 ||124.130.56.42^
 ||124.130.57.12^
@@ -162184,6 +162327,7 @@
 ||124.131.24.86^
 ||124.131.25.69^
 ||124.131.26.238^
+||124.131.26.243^
 ||124.131.26.78^
 ||124.131.28.172^
 ||124.131.28.196^
@@ -163596,6 +163740,7 @@
 ||124.94.244.153^
 ||124.94.57.133^
 ||124.95.16.252^
+||124.95.17.41^
 ||124.95.81.24^
 ||124.com.ua^
 ||124.cpanel.realwebsitesite.com^
@@ -164012,6 +164157,7 @@
 ||125.126.66.6^
 ||125.126.67.145^
 ||125.126.69.198^
+||125.126.69.95^
 ||125.126.71.207^
 ||125.126.72.174^
 ||125.126.73.123^
@@ -164142,6 +164288,7 @@
 ||125.160.137.80^
 ||125.160.213.219^
 ||125.161.14.114^
+||125.161.70.34^
 ||125.161.96.233^
 ||125.162.65.174^
 ||125.163.199.90^
@@ -164929,6 +165076,7 @@
 ||125.40.136.22^
 ||125.40.136.252^
 ||125.40.136.253^
+||125.40.136.25^
 ||125.40.136.33^
 ||125.40.136.74^
 ||125.40.137.101^
@@ -165472,6 +165620,7 @@
 ||125.40.234.169^
 ||125.40.234.73^
 ||125.40.235.80^
+||125.40.237.130^
 ||125.40.24.117^
 ||125.40.24.134^
 ||125.40.24.143^
@@ -167351,6 +167500,7 @@
 ||125.41.200.172^
 ||125.41.200.181^
 ||125.41.200.188^
+||125.41.200.189^
 ||125.41.200.193^
 ||125.41.200.203^
 ||125.41.200.210^
@@ -169352,6 +169502,7 @@
 ||125.42.120.9^
 ||125.42.121.101^
 ||125.42.121.103^
+||125.42.121.106^
 ||125.42.121.108^
 ||125.42.121.109^
 ||125.42.121.110^
@@ -169651,6 +169802,7 @@
 ||125.42.124.88^
 ||125.42.124.93^
 ||125.42.124.97^
+||125.42.125.103^
 ||125.42.125.107^
 ||125.42.125.110^
 ||125.42.125.115^
@@ -170453,6 +170605,7 @@
 ||125.42.97.100^
 ||125.42.97.101^
 ||125.42.97.102^
+||125.42.97.103^
 ||125.42.97.119^
 ||125.42.97.122^
 ||125.42.97.123^
@@ -170712,6 +170865,7 @@
 ||125.43.105.129^
 ||125.43.105.135^
 ||125.43.105.149^
+||125.43.105.157^
 ||125.43.105.158^
 ||125.43.105.168^
 ||125.43.105.172^
@@ -170995,6 +171149,7 @@
 ||125.43.13.73^
 ||125.43.13.92^
 ||125.43.130.108^
+||125.43.130.232^
 ||125.43.130.23^
 ||125.43.130.24^
 ||125.43.131.111^
@@ -171344,6 +171499,7 @@
 ||125.43.21.146^
 ||125.43.21.147^
 ||125.43.21.152^
+||125.43.21.157^
 ||125.43.21.159^
 ||125.43.21.161^
 ||125.43.21.174^
@@ -174471,6 +174627,7 @@
 ||125.44.211.83^
 ||125.44.211.98^
 ||125.44.212.105^
+||125.44.212.107^
 ||125.44.212.108^
 ||125.44.212.109^
 ||125.44.212.114^
@@ -174931,6 +175088,7 @@
 ||125.44.230.125^
 ||125.44.230.164^
 ||125.44.230.176^
+||125.44.230.191^
 ||125.44.230.200^
 ||125.44.230.226^
 ||125.44.230.244^
@@ -175393,6 +175551,7 @@
 ||125.44.31.61^
 ||125.44.31.64^
 ||125.44.31.69^
+||125.44.31.79^
 ||125.44.31.82^
 ||125.44.31.84^
 ||125.44.31.87^
@@ -176645,6 +176804,7 @@
 ||125.45.57.231^
 ||125.45.57.238^
 ||125.45.57.247^
+||125.45.57.249^
 ||125.45.57.35^
 ||125.45.57.46^
 ||125.45.57.50^
@@ -177195,6 +177355,7 @@
 ||125.45.90.131^
 ||125.45.90.151^
 ||125.45.90.153^
+||125.45.90.158^
 ||125.45.90.16^
 ||125.45.90.184^
 ||125.45.90.189^
@@ -177313,6 +177474,7 @@
 ||125.46.137.54^
 ||125.46.138.0^
 ||125.46.138.10^
+||125.46.138.117^
 ||125.46.138.122^
 ||125.46.138.149^
 ||125.46.138.151^
@@ -179991,6 +180153,7 @@
 ||125.47.251.96^
 ||125.47.251.98^
 ||125.47.252.105^
+||125.47.252.106^
 ||125.47.252.107^
 ||125.47.252.109^
 ||125.47.252.110^
@@ -180208,6 +180371,7 @@
 ||125.47.255.94^
 ||125.47.255.97^
 ||125.47.28.150^
+||125.47.28.217^
 ||125.47.29.173^
 ||125.47.29.191^
 ||125.47.32.201^
@@ -182340,10 +182504,12 @@
 ||125.99.207.92^
 ||125.99.212.13^
 ||125.99.220.105^
+||125.99.220.202^
 ||125.99.222.152^
 ||125.99.222.245^
 ||125.99.222.76^
 ||125.99.223.227^
+||125.99.223.26^
 ||125.99.224.101^
 ||125.99.224.102^
 ||125.99.224.106^
@@ -184209,6 +184375,7 @@
 ||134.209.202.202^
 ||134.209.203.101^
 ||134.209.203.205^
+||134.209.203.221^
 ||134.209.203.223^
 ||134.209.203.70^
 ||134.209.204.77^
@@ -184716,6 +184883,7 @@
 ||139.170.181.68^
 ||139.170.200.29^
 ||139.170.206.148^
+||139.170.228.166^
 ||139.170.228.217^
 ||139.170.228.55^
 ||139.170.230.204^
@@ -186128,6 +186296,7 @@
 ||140.237.255.239^
 ||140.237.28.148^
 ||140.237.29.28^
+||140.237.30.113^
 ||140.237.30.179^
 ||140.237.30.188^
 ||140.237.31.197^
@@ -186138,6 +186307,7 @@
 ||140.237.4.82^
 ||140.237.5.254^
 ||140.237.5.41^
+||140.237.5.43^
 ||140.240.100.181^
 ||140.240.100.94^
 ||140.240.102.181^
@@ -186926,6 +187096,8 @@
 ||149.255.15.121^
 ||149.255.15.180^
 ||149.255.15.182^
+||149.255.15.191^
+||149.255.15.235^
 ||149.255.15.87^
 ||149.255.36.133^
 ||149.255.36.156^
@@ -187176,6 +187348,7 @@
 ||151.226.2.198^
 ||151.227.42.63^
 ||151.232.180.152^
+||151.232.249.222^
 ||151.232.56.134^
 ||151.233.52.223^
 ||151.233.56.139^
@@ -187310,6 +187483,7 @@
 ||152.173.25.125^
 ||152.231.127.54^
 ||152.231.25.253^
+||152.241.13.197^
 ||152.241.13.246^
 ||152.241.24.181^
 ||152.241.33.96^
@@ -187542,6 +187716,7 @@
 ||153.34.65.168^
 ||153.34.67.119^
 ||153.34.86.53^
+||153.35.111.46^
 ||153.35.141.25^
 ||153.35.141.60^
 ||153.35.141.74^
@@ -187742,6 +187917,7 @@
 ||157.119.214.172^
 ||157.119.214.233^
 ||157.119.215.224^
+||157.122.105.142^
 ||157.122.106.12^
 ||157.230.0.237^
 ||157.230.1.18^
@@ -189492,6 +189668,7 @@
 ||163.125.181.187^
 ||163.125.181.76^
 ||163.125.181.87^
+||163.125.183.111^
 ||163.125.183.142^
 ||163.125.183.180^
 ||163.125.183.75^
@@ -189616,6 +189793,7 @@
 ||163.125.200.64^
 ||163.125.200.6^
 ||163.125.200.70^
+||163.125.200.72^
 ||163.125.200.73^
 ||163.125.200.75^
 ||163.125.200.76^
@@ -189673,6 +189851,7 @@
 ||163.125.202.159^
 ||163.125.202.15^
 ||163.125.202.16^
+||163.125.202.174^
 ||163.125.202.183^
 ||163.125.202.186^
 ||163.125.202.190^
@@ -189690,6 +189869,7 @@
 ||163.125.202.4^
 ||163.125.202.57^
 ||163.125.202.72^
+||163.125.202.74^
 ||163.125.202.83^
 ||163.125.202.8^
 ||163.125.202.9^
@@ -189700,6 +189880,7 @@
 ||163.125.203.146^
 ||163.125.203.148^
 ||163.125.203.154^
+||163.125.203.179^
 ||163.125.203.184^
 ||163.125.203.198^
 ||163.125.203.200^
@@ -189778,6 +189959,7 @@
 ||163.125.207.0^
 ||163.125.207.102^
 ||163.125.207.116^
+||163.125.207.125^
 ||163.125.207.140^
 ||163.125.207.143^
 ||163.125.207.158^
@@ -189862,6 +190044,7 @@
 ||163.125.248.230^
 ||163.125.248.254^
 ||163.125.250.176^
+||163.125.250.202^
 ||163.125.251.214^
 ||163.125.251.225^
 ||163.125.251.227^
@@ -189883,6 +190066,7 @@
 ||163.125.30.28^
 ||163.125.31.183^
 ||163.125.34.24^
+||163.125.37.201^
 ||163.125.38.226^
 ||163.125.4.131^
 ||163.125.4.147^
@@ -189926,6 +190110,7 @@
 ||163.125.68.229^
 ||163.125.68.240^
 ||163.125.68.243^
+||163.125.68.29^
 ||163.125.68.31^
 ||163.125.68.65^
 ||163.125.68.7^
@@ -192416,6 +192601,7 @@
 ||171.125.65.115^
 ||171.125.65.193^
 ||171.125.65.202^
+||171.125.65.22^
 ||171.125.66.6^
 ||171.125.68.45^
 ||171.125.7.181^
@@ -192667,6 +192853,7 @@
 ||171.34.114.167^
 ||171.34.114.179^
 ||171.34.114.180^
+||171.34.114.181^
 ||171.34.114.215^
 ||171.34.114.217^
 ||171.34.114.227^
@@ -192878,6 +193065,7 @@
 ||171.36.251.189^
 ||171.36.251.66^
 ||171.36.41.151^
+||171.36.42.154^
 ||171.36.42.159^
 ||171.36.42.39^
 ||171.36.42.3^
@@ -193573,6 +193761,7 @@
 ||172.245.5.120^
 ||172.245.5.122^
 ||172.245.5.185^
+||172.245.5.190^
 ||172.245.52.102^
 ||172.245.52.122^
 ||172.245.52.160^
@@ -196964,6 +197153,7 @@
 ||175.11.193.118^
 ||175.11.193.122^
 ||175.11.193.157^
+||175.11.193.66^
 ||175.11.193.71^
 ||175.11.193.82^
 ||175.11.194.130^
@@ -197124,6 +197314,7 @@
 ||175.145.200.51^
 ||175.146.121.210^
 ||175.146.16.118^
+||175.146.17.227^
 ||175.146.18.195^
 ||175.146.19.126^
 ||175.146.20.229^
@@ -200174,6 +200365,7 @@
 ||178.141.159.159^
 ||178.141.16.64^
 ||178.141.160.15^
+||178.141.161.129^
 ||178.141.162.124^
 ||178.141.162.211^
 ||178.141.162.8^
@@ -200567,8 +200759,10 @@
 ||178.175.0.226^
 ||178.175.0.229^
 ||178.175.0.22^
+||178.175.0.232^
 ||178.175.0.234^
 ||178.175.0.236^
+||178.175.0.239^
 ||178.175.0.241^
 ||178.175.0.246^
 ||178.175.0.249^
@@ -200638,6 +200832,7 @@
 ||178.175.1.178^
 ||178.175.1.179^
 ||178.175.1.186^
+||178.175.1.187^
 ||178.175.1.188^
 ||178.175.1.193^
 ||178.175.1.194^
@@ -200655,6 +200850,7 @@
 ||178.175.1.247^
 ||178.175.1.24^
 ||178.175.1.250^
+||178.175.1.252^
 ||178.175.1.255^
 ||178.175.1.25^
 ||178.175.1.26^
@@ -200732,8 +200928,10 @@
 ||178.175.10.255^
 ||178.175.10.26^
 ||178.175.10.28^
+||178.175.10.34^
 ||178.175.10.37^
 ||178.175.10.41^
+||178.175.10.42^
 ||178.175.10.44^
 ||178.175.10.46^
 ||178.175.10.50^
@@ -200879,6 +201077,7 @@
 ||178.175.101.203^
 ||178.175.101.204^
 ||178.175.101.205^
+||178.175.101.207^
 ||178.175.101.208^
 ||178.175.101.209^
 ||178.175.101.210^
@@ -200987,6 +201186,7 @@
 ||178.175.102.214^
 ||178.175.102.216^
 ||178.175.102.220^
+||178.175.102.221^
 ||178.175.102.223^
 ||178.175.102.225^
 ||178.175.102.227^
@@ -201121,6 +201321,7 @@
 ||178.175.104.104^
 ||178.175.104.106^
 ||178.175.104.10^
+||178.175.104.110^
 ||178.175.104.112^
 ||178.175.104.114^
 ||178.175.104.116^
@@ -201142,6 +201343,7 @@
 ||178.175.104.152^
 ||178.175.104.153^
 ||178.175.104.154^
+||178.175.104.155^
 ||178.175.104.158^
 ||178.175.104.15^
 ||178.175.104.161^
@@ -201199,6 +201401,7 @@
 ||178.175.104.54^
 ||178.175.104.59^
 ||178.175.104.62^
+||178.175.104.64^
 ||178.175.104.66^
 ||178.175.104.69^
 ||178.175.104.80^
@@ -201227,6 +201430,7 @@
 ||178.175.105.121^
 ||178.175.105.122^
 ||178.175.105.124^
+||178.175.105.125^
 ||178.175.105.130^
 ||178.175.105.131^
 ||178.175.105.143^
@@ -201279,6 +201483,7 @@
 ||178.175.105.255^
 ||178.175.105.26^
 ||178.175.105.27^
+||178.175.105.28^
 ||178.175.105.29^
 ||178.175.105.30^
 ||178.175.105.31^
@@ -201308,6 +201513,7 @@
 ||178.175.105.90^
 ||178.175.105.91^
 ||178.175.105.93^
+||178.175.105.94^
 ||178.175.105.96^
 ||178.175.106.100^
 ||178.175.106.102^
@@ -201363,6 +201569,7 @@
 ||178.175.106.219^
 ||178.175.106.21^
 ||178.175.106.220^
+||178.175.106.222^
 ||178.175.106.224^
 ||178.175.106.226^
 ||178.175.106.228^
@@ -201378,6 +201585,7 @@
 ||178.175.106.24^
 ||178.175.106.251^
 ||178.175.106.252^
+||178.175.106.253^
 ||178.175.106.25^
 ||178.175.106.27^
 ||178.175.106.28^
@@ -201575,6 +201783,7 @@
 ||178.175.108.223^
 ||178.175.108.227^
 ||178.175.108.229^
+||178.175.108.232^
 ||178.175.108.237^
 ||178.175.108.239^
 ||178.175.108.23^
@@ -201615,6 +201824,7 @@
 ||178.175.108.88^
 ||178.175.108.90^
 ||178.175.108.93^
+||178.175.108.94^
 ||178.175.108.97^
 ||178.175.108.98^
 ||178.175.108.99^
@@ -201629,6 +201839,7 @@
 ||178.175.109.121^
 ||178.175.109.123^
 ||178.175.109.126^
+||178.175.109.127^
 ||178.175.109.132^
 ||178.175.109.134^
 ||178.175.109.137^
@@ -201653,6 +201864,7 @@
 ||178.175.109.189^
 ||178.175.109.190^
 ||178.175.109.191^
+||178.175.109.193^
 ||178.175.109.195^
 ||178.175.109.196^
 ||178.175.109.198^
@@ -201698,6 +201910,7 @@
 ||178.175.109.71^
 ||178.175.109.75^
 ||178.175.109.77^
+||178.175.109.78^
 ||178.175.109.7^
 ||178.175.109.82^
 ||178.175.109.83^
@@ -202101,6 +202314,7 @@
 ||178.175.112.90^
 ||178.175.112.97^
 ||178.175.112.99^
+||178.175.113.0^
 ||178.175.113.100^
 ||178.175.113.106^
 ||178.175.113.112^
@@ -202263,6 +202477,7 @@
 ||178.175.114.242^
 ||178.175.114.244^
 ||178.175.114.245^
+||178.175.114.247^
 ||178.175.114.250^
 ||178.175.114.251^
 ||178.175.114.254^
@@ -202316,6 +202531,7 @@
 ||178.175.115.126^
 ||178.175.115.127^
 ||178.175.115.128^
+||178.175.115.12^
 ||178.175.115.130^
 ||178.175.115.131^
 ||178.175.115.132^
@@ -202354,6 +202570,7 @@
 ||178.175.115.1^
 ||178.175.115.202^
 ||178.175.115.205^
+||178.175.115.206^
 ||178.175.115.207^
 ||178.175.115.208^
 ||178.175.115.209^
@@ -202388,6 +202605,7 @@
 ||178.175.115.35^
 ||178.175.115.37^
 ||178.175.115.39^
+||178.175.115.40^
 ||178.175.115.43^
 ||178.175.115.45^
 ||178.175.115.46^
@@ -202440,6 +202658,7 @@
 ||178.175.116.152^
 ||178.175.116.154^
 ||178.175.116.159^
+||178.175.116.15^
 ||178.175.116.165^
 ||178.175.116.169^
 ||178.175.116.171^
@@ -202470,6 +202689,7 @@
 ||178.175.116.226^
 ||178.175.116.228^
 ||178.175.116.22^
+||178.175.116.236^
 ||178.175.116.237^
 ||178.175.116.238^
 ||178.175.116.23^
@@ -202638,6 +202858,7 @@
 ||178.175.118.133^
 ||178.175.118.137^
 ||178.175.118.138^
+||178.175.118.139^
 ||178.175.118.141^
 ||178.175.118.143^
 ||178.175.118.144^
@@ -202822,6 +203043,7 @@
 ||178.175.12.105^
 ||178.175.12.109^
 ||178.175.12.111^
+||178.175.12.114^
 ||178.175.12.118^
 ||178.175.12.11^
 ||178.175.12.123^
@@ -202943,6 +203165,7 @@
 ||178.175.120.189^
 ||178.175.120.191^
 ||178.175.120.193^
+||178.175.120.196^
 ||178.175.120.197^
 ||178.175.120.203^
 ||178.175.120.207^
@@ -203168,6 +203391,7 @@
 ||178.175.122.246^
 ||178.175.122.252^
 ||178.175.122.254^
+||178.175.122.26^
 ||178.175.122.27^
 ||178.175.122.28^
 ||178.175.122.35^
@@ -203615,6 +203839,7 @@
 ||178.175.127.102^
 ||178.175.127.106^
 ||178.175.127.109^
+||178.175.127.10^
 ||178.175.127.111^
 ||178.175.127.112^
 ||178.175.127.114^
@@ -203626,6 +203851,7 @@
 ||178.175.127.120^
 ||178.175.127.122^
 ||178.175.127.125^
+||178.175.127.129^
 ||178.175.127.130^
 ||178.175.127.133^
 ||178.175.127.139^
@@ -203654,6 +203880,7 @@
 ||178.175.127.182^
 ||178.175.127.185^
 ||178.175.127.190^
+||178.175.127.192^
 ||178.175.127.195^
 ||178.175.127.197^
 ||178.175.127.198^
@@ -203675,6 +203902,7 @@
 ||178.175.127.231^
 ||178.175.127.236^
 ||178.175.127.237^
+||178.175.127.238^
 ||178.175.127.23^
 ||178.175.127.240^
 ||178.175.127.242^
@@ -203918,6 +204146,7 @@
 ||178.175.15.225^
 ||178.175.15.228^
 ||178.175.15.229^
+||178.175.15.232^
 ||178.175.15.233^
 ||178.175.15.236^
 ||178.175.15.238^
@@ -203925,6 +204154,7 @@
 ||178.175.15.241^
 ||178.175.15.244^
 ||178.175.15.245^
+||178.175.15.246^
 ||178.175.15.248^
 ||178.175.15.24^
 ||178.175.15.250^
@@ -203940,6 +204170,7 @@
 ||178.175.15.35^
 ||178.175.15.37^
 ||178.175.15.38^
+||178.175.15.44^
 ||178.175.15.45^
 ||178.175.15.47^
 ||178.175.15.48^
@@ -203968,9 +204199,11 @@
 ||178.175.15.99^
 ||178.175.15.9^
 ||178.175.16.108^
+||178.175.16.10^
 ||178.175.16.110^
 ||178.175.16.112^
 ||178.175.16.113^
+||178.175.16.114^
 ||178.175.16.115^
 ||178.175.16.118^
 ||178.175.16.121^
@@ -204002,6 +204235,7 @@
 ||178.175.16.186^
 ||178.175.16.189^
 ||178.175.16.18^
+||178.175.16.193^
 ||178.175.16.195^
 ||178.175.16.196^
 ||178.175.16.1^
@@ -204173,6 +204407,7 @@
 ||178.175.18.249^
 ||178.175.18.250^
 ||178.175.18.253^
+||178.175.18.27^
 ||178.175.18.2^
 ||178.175.18.32^
 ||178.175.18.42^
@@ -204243,6 +204478,7 @@
 ||178.175.19.224^
 ||178.175.19.225^
 ||178.175.19.227^
+||178.175.19.229^
 ||178.175.19.22^
 ||178.175.19.232^
 ||178.175.19.236^
@@ -204576,6 +204812,7 @@
 ||178.175.22.194^
 ||178.175.22.1^
 ||178.175.22.203^
+||178.175.22.207^
 ||178.175.22.209^
 ||178.175.22.210^
 ||178.175.22.211^
@@ -204592,6 +204829,7 @@
 ||178.175.22.23^
 ||178.175.22.241^
 ||178.175.22.245^
+||178.175.22.248^
 ||178.175.22.249^
 ||178.175.22.255^
 ||178.175.22.32^
@@ -204691,6 +204929,7 @@
 ||178.175.23.58^
 ||178.175.23.61^
 ||178.175.23.69^
+||178.175.23.6^
 ||178.175.23.71^
 ||178.175.23.73^
 ||178.175.23.74^
@@ -204754,6 +204993,7 @@
 ||178.175.24.222^
 ||178.175.24.223^
 ||178.175.24.227^
+||178.175.24.230^
 ||178.175.24.232^
 ||178.175.24.238^
 ||178.175.24.239^
@@ -204820,6 +205060,7 @@
 ||178.175.25.164^
 ||178.175.25.166^
 ||178.175.25.168^
+||178.175.25.169^
 ||178.175.25.172^
 ||178.175.25.173^
 ||178.175.25.177^
@@ -204911,6 +205152,7 @@
 ||178.175.26.161^
 ||178.175.26.162^
 ||178.175.26.164^
+||178.175.26.165^
 ||178.175.26.168^
 ||178.175.26.169^
 ||178.175.26.170^
@@ -204934,6 +205176,7 @@
 ||178.175.26.20^
 ||178.175.26.211^
 ||178.175.26.214^
+||178.175.26.215^
 ||178.175.26.217^
 ||178.175.26.218^
 ||178.175.26.219^
@@ -204957,6 +205200,7 @@
 ||178.175.26.2^
 ||178.175.26.31^
 ||178.175.26.32^
+||178.175.26.34^
 ||178.175.26.36^
 ||178.175.26.38^
 ||178.175.26.3^
@@ -205053,11 +205297,13 @@
 ||178.175.27.252^
 ||178.175.27.25^
 ||178.175.27.30^
+||178.175.27.32^
 ||178.175.27.36^
 ||178.175.27.38^
 ||178.175.27.39^
 ||178.175.27.41^
 ||178.175.27.47^
+||178.175.27.48^
 ||178.175.27.49^
 ||178.175.27.4^
 ||178.175.27.53^
@@ -205161,6 +205407,7 @@
 ||178.175.28.6^
 ||178.175.28.72^
 ||178.175.28.74^
+||178.175.28.75^
 ||178.175.28.79^
 ||178.175.28.7^
 ||178.175.28.81^
@@ -205181,6 +205428,7 @@
 ||178.175.29.114^
 ||178.175.29.127^
 ||178.175.29.128^
+||178.175.29.12^
 ||178.175.29.130^
 ||178.175.29.135^
 ||178.175.29.138^
@@ -205289,6 +205537,7 @@
 ||178.175.3.190^
 ||178.175.3.192^
 ||178.175.3.193^
+||178.175.3.194^
 ||178.175.3.196^
 ||178.175.3.199^
 ||178.175.3.1^
@@ -205373,6 +205622,7 @@
 ||178.175.30.177^
 ||178.175.30.178^
 ||178.175.30.180^
+||178.175.30.181^
 ||178.175.30.183^
 ||178.175.30.185^
 ||178.175.30.186^
@@ -205567,6 +205817,7 @@
 ||178.175.32.221^
 ||178.175.32.223^
 ||178.175.32.227^
+||178.175.32.229^
 ||178.175.32.230^
 ||178.175.32.233^
 ||178.175.32.235^
@@ -205595,6 +205846,7 @@
 ||178.175.32.72^
 ||178.175.32.77^
 ||178.175.32.7^
+||178.175.32.83^
 ||178.175.32.85^
 ||178.175.32.87^
 ||178.175.32.89^
@@ -205630,6 +205882,7 @@
 ||178.175.33.165^
 ||178.175.33.167^
 ||178.175.33.170^
+||178.175.33.173^
 ||178.175.33.174^
 ||178.175.33.177^
 ||178.175.33.178^
@@ -205642,6 +205895,7 @@
 ||178.175.33.198^
 ||178.175.33.1^
 ||178.175.33.202^
+||178.175.33.205^
 ||178.175.33.209^
 ||178.175.33.210^
 ||178.175.33.211^
@@ -205728,6 +205982,7 @@
 ||178.175.34.208^
 ||178.175.34.216^
 ||178.175.34.217^
+||178.175.34.219^
 ||178.175.34.21^
 ||178.175.34.223^
 ||178.175.34.224^
@@ -205756,6 +206011,7 @@
 ||178.175.34.46^
 ||178.175.34.49^
 ||178.175.34.53^
+||178.175.34.56^
 ||178.175.34.58^
 ||178.175.34.5^
 ||178.175.34.60^
@@ -205902,6 +206158,7 @@
 ||178.175.36.172^
 ||178.175.36.173^
 ||178.175.36.174^
+||178.175.36.176^
 ||178.175.36.177^
 ||178.175.36.182^
 ||178.175.36.184^
@@ -205911,6 +206168,7 @@
 ||178.175.36.194^
 ||178.175.36.198^
 ||178.175.36.199^
+||178.175.36.19^
 ||178.175.36.1^
 ||178.175.36.200^
 ||178.175.36.204^
@@ -206114,6 +206372,7 @@
 ||178.175.38.196^
 ||178.175.38.19^
 ||178.175.38.1^
+||178.175.38.200^
 ||178.175.38.203^
 ||178.175.38.204^
 ||178.175.38.206^
@@ -206191,6 +206450,7 @@
 ||178.175.39.167^
 ||178.175.39.174^
 ||178.175.39.175^
+||178.175.39.176^
 ||178.175.39.17^
 ||178.175.39.181^
 ||178.175.39.183^
@@ -206286,6 +206546,7 @@
 ||178.175.4.215^
 ||178.175.4.216^
 ||178.175.4.218^
+||178.175.4.219^
 ||178.175.4.220^
 ||178.175.4.222^
 ||178.175.4.233^
@@ -206354,6 +206615,7 @@
 ||178.175.40.131^
 ||178.175.40.138^
 ||178.175.40.139^
+||178.175.40.145^
 ||178.175.40.149^
 ||178.175.40.14^
 ||178.175.40.151^
@@ -206490,6 +206752,7 @@
 ||178.175.41.53^
 ||178.175.41.56^
 ||178.175.41.57^
+||178.175.41.60^
 ||178.175.41.62^
 ||178.175.41.65^
 ||178.175.41.66^
@@ -206612,6 +206875,7 @@
 ||178.175.43.163^
 ||178.175.43.165^
 ||178.175.43.166^
+||178.175.43.16^
 ||178.175.43.171^
 ||178.175.43.174^
 ||178.175.43.175^
@@ -206650,6 +206914,7 @@
 ||178.175.43.30^
 ||178.175.43.31^
 ||178.175.43.33^
+||178.175.43.34^
 ||178.175.43.37^
 ||178.175.43.38^
 ||178.175.43.41^
@@ -206680,6 +206945,7 @@
 ||178.175.43.93^
 ||178.175.43.94^
 ||178.175.43.9^
+||178.175.44.0^
 ||178.175.44.100^
 ||178.175.44.101^
 ||178.175.44.102^
@@ -206778,6 +207044,7 @@
 ||178.175.44.89^
 ||178.175.44.8^
 ||178.175.44.90^
+||178.175.44.95^
 ||178.175.44.9^
 ||178.175.45.102^
 ||178.175.45.107^
@@ -206891,6 +207158,7 @@
 ||178.175.46.110^
 ||178.175.46.114^
 ||178.175.46.116^
+||178.175.46.119^
 ||178.175.46.120^
 ||178.175.46.124^
 ||178.175.46.125^
@@ -206903,6 +207171,7 @@
 ||178.175.46.145^
 ||178.175.46.149^
 ||178.175.46.150^
+||178.175.46.151^
 ||178.175.46.152^
 ||178.175.46.154^
 ||178.175.46.158^
@@ -207155,6 +207424,7 @@
 ||178.175.48.66^
 ||178.175.48.6^
 ||178.175.48.71^
+||178.175.48.76^
 ||178.175.48.80^
 ||178.175.48.82^
 ||178.175.48.85^
@@ -207181,6 +207451,7 @@
 ||178.175.49.123^
 ||178.175.49.126^
 ||178.175.49.127^
+||178.175.49.129^
 ||178.175.49.136^
 ||178.175.49.137^
 ||178.175.49.138^
@@ -207193,6 +207464,7 @@
 ||178.175.49.169^
 ||178.175.49.180^
 ||178.175.49.185^
+||178.175.49.188^
 ||178.175.49.189^
 ||178.175.49.18^
 ||178.175.49.194^
@@ -207379,6 +207651,7 @@
 ||178.175.50.233^
 ||178.175.50.236^
 ||178.175.50.237^
+||178.175.50.239^
 ||178.175.50.23^
 ||178.175.50.248^
 ||178.175.50.249^
@@ -207413,6 +207686,7 @@
 ||178.175.50.95^
 ||178.175.50.96^
 ||178.175.50.98^
+||178.175.50.9^
 ||178.175.51.0^
 ||178.175.51.102^
 ||178.175.51.104^
@@ -207645,6 +207919,7 @@
 ||178.175.53.224^
 ||178.175.53.225^
 ||178.175.53.227^
+||178.175.53.228^
 ||178.175.53.229^
 ||178.175.53.22^
 ||178.175.53.231^
@@ -207806,6 +208081,7 @@
 ||178.175.55.165^
 ||178.175.55.167^
 ||178.175.55.169^
+||178.175.55.170^
 ||178.175.55.191^
 ||178.175.55.192^
 ||178.175.55.194^
@@ -207854,6 +208130,7 @@
 ||178.175.55.72^
 ||178.175.55.77^
 ||178.175.55.7^
+||178.175.55.85^
 ||178.175.55.86^
 ||178.175.55.88^
 ||178.175.55.91^
@@ -208121,6 +208398,7 @@
 ||178.175.58.35^
 ||178.175.58.39^
 ||178.175.58.40^
+||178.175.58.42^
 ||178.175.58.43^
 ||178.175.58.48^
 ||178.175.58.49^
@@ -208376,6 +208654,7 @@
 ||178.175.60.32^
 ||178.175.60.34^
 ||178.175.60.36^
+||178.175.60.37^
 ||178.175.60.3^
 ||178.175.60.41^
 ||178.175.60.42^
@@ -208457,6 +208736,7 @@
 ||178.175.61.36^
 ||178.175.61.37^
 ||178.175.61.40^
+||178.175.61.42^
 ||178.175.61.43^
 ||178.175.61.45^
 ||178.175.61.52^
@@ -208514,6 +208794,7 @@
 ||178.175.62.209^
 ||178.175.62.211^
 ||178.175.62.213^
+||178.175.62.216^
 ||178.175.62.219^
 ||178.175.62.220^
 ||178.175.62.222^
@@ -208539,11 +208820,13 @@
 ||178.175.62.3^
 ||178.175.62.42^
 ||178.175.62.43^
+||178.175.62.44^
 ||178.175.62.45^
 ||178.175.62.46^
 ||178.175.62.50^
 ||178.175.62.51^
 ||178.175.62.56^
+||178.175.62.70^
 ||178.175.62.72^
 ||178.175.62.74^
 ||178.175.62.76^
@@ -209039,6 +209322,7 @@
 ||178.175.67.78^
 ||178.175.67.7^
 ||178.175.67.82^
+||178.175.67.83^
 ||178.175.67.84^
 ||178.175.67.86^
 ||178.175.67.88^
@@ -209164,6 +209448,7 @@
 ||178.175.69.140^
 ||178.175.69.141^
 ||178.175.69.143^
+||178.175.69.148^
 ||178.175.69.149^
 ||178.175.69.153^
 ||178.175.69.154^
@@ -209176,6 +209461,7 @@
 ||178.175.69.169^
 ||178.175.69.16^
 ||178.175.69.171^
+||178.175.69.173^
 ||178.175.69.174^
 ||178.175.69.175^
 ||178.175.69.182^
@@ -209472,6 +209758,7 @@
 ||178.175.71.195^
 ||178.175.71.196^
 ||178.175.71.198^
+||178.175.71.1^
 ||178.175.71.201^
 ||178.175.71.202^
 ||178.175.71.203^
@@ -209516,6 +209803,7 @@
 ||178.175.71.59^
 ||178.175.71.60^
 ||178.175.71.63^
+||178.175.71.64^
 ||178.175.71.65^
 ||178.175.71.68^
 ||178.175.71.69^
@@ -209539,6 +209827,7 @@
 ||178.175.72.101^
 ||178.175.72.102^
 ||178.175.72.108^
+||178.175.72.109^
 ||178.175.72.110^
 ||178.175.72.111^
 ||178.175.72.113^
@@ -209664,6 +209953,7 @@
 ||178.175.73.193^
 ||178.175.73.198^
 ||178.175.73.199^
+||178.175.73.211^
 ||178.175.73.214^
 ||178.175.73.216^
 ||178.175.73.219^
@@ -209698,6 +209988,7 @@
 ||178.175.73.5^
 ||178.175.73.68^
 ||178.175.73.6^
+||178.175.73.71^
 ||178.175.73.72^
 ||178.175.73.76^
 ||178.175.73.7^
@@ -209903,6 +210194,7 @@
 ||178.175.76.113^
 ||178.175.76.119^
 ||178.175.76.11^
+||178.175.76.121^
 ||178.175.76.124^
 ||178.175.76.125^
 ||178.175.76.129^
@@ -210160,6 +210452,7 @@
 ||178.175.78.92^
 ||178.175.78.93^
 ||178.175.78.94^
+||178.175.78.97^
 ||178.175.79.101^
 ||178.175.79.105^
 ||178.175.79.106^
@@ -210318,7 +210611,9 @@
 ||178.175.8.87^
 ||178.175.8.93^
 ||178.175.8.94^
+||178.175.8.97^
 ||178.175.8.9^
+||178.175.80.100^
 ||178.175.80.103^
 ||178.175.80.10^
 ||178.175.80.110^
@@ -210397,6 +210692,7 @@
 ||178.175.80.34^
 ||178.175.80.37^
 ||178.175.80.40^
+||178.175.80.41^
 ||178.175.80.43^
 ||178.175.80.44^
 ||178.175.80.46^
@@ -210490,6 +210786,7 @@
 ||178.175.81.252^
 ||178.175.81.2^
 ||178.175.81.30^
+||178.175.81.32^
 ||178.175.81.44^
 ||178.175.81.45^
 ||178.175.81.49^
@@ -210512,6 +210809,7 @@
 ||178.175.81.86^
 ||178.175.81.88^
 ||178.175.81.89^
+||178.175.81.8^
 ||178.175.81.93^
 ||178.175.82.0^
 ||178.175.82.100^
@@ -210523,6 +210821,7 @@
 ||178.175.82.111^
 ||178.175.82.115^
 ||178.175.82.117^
+||178.175.82.120^
 ||178.175.82.122^
 ||178.175.82.123^
 ||178.175.82.126^
@@ -210876,6 +211175,7 @@
 ||178.175.85.171^
 ||178.175.85.172^
 ||178.175.85.183^
+||178.175.85.184^
 ||178.175.85.185^
 ||178.175.85.190^
 ||178.175.85.192^
@@ -210894,6 +211194,7 @@
 ||178.175.85.228^
 ||178.175.85.229^
 ||178.175.85.230^
+||178.175.85.23^
 ||178.175.85.242^
 ||178.175.85.243^
 ||178.175.85.244^
@@ -210931,6 +211232,7 @@
 ||178.175.85.79^
 ||178.175.85.7^
 ||178.175.85.80^
+||178.175.85.81^
 ||178.175.85.83^
 ||178.175.85.87^
 ||178.175.85.89^
@@ -210957,10 +211259,12 @@
 ||178.175.86.145^
 ||178.175.86.146^
 ||178.175.86.157^
+||178.175.86.159^
 ||178.175.86.15^
 ||178.175.86.160^
 ||178.175.86.164^
 ||178.175.86.165^
+||178.175.86.166^
 ||178.175.86.167^
 ||178.175.86.169^
 ||178.175.86.174^
@@ -211026,6 +211330,7 @@
 ||178.175.86.86^
 ||178.175.86.8^
 ||178.175.86.90^
+||178.175.86.92^
 ||178.175.86.93^
 ||178.175.86.96^
 ||178.175.86.97^
@@ -211033,6 +211338,7 @@
 ||178.175.87.101^
 ||178.175.87.106^
 ||178.175.87.107^
+||178.175.87.108^
 ||178.175.87.110^
 ||178.175.87.113^
 ||178.175.87.115^
@@ -211206,6 +211512,7 @@
 ||178.175.88.51^
 ||178.175.88.52^
 ||178.175.88.53^
+||178.175.88.57^
 ||178.175.88.5^
 ||178.175.88.60^
 ||178.175.88.64^
@@ -211243,8 +211550,11 @@
 ||178.175.89.150^
 ||178.175.89.151^
 ||178.175.89.153^
+||178.175.89.157^
 ||178.175.89.159^
+||178.175.89.160^
 ||178.175.89.168^
+||178.175.89.169^
 ||178.175.89.171^
 ||178.175.89.173^
 ||178.175.89.177^
@@ -211320,6 +211630,7 @@
 ||178.175.9.132^
 ||178.175.9.135^
 ||178.175.9.138^
+||178.175.9.139^
 ||178.175.9.140^
 ||178.175.9.153^
 ||178.175.9.155^
@@ -211343,6 +211654,7 @@
 ||178.175.9.196^
 ||178.175.9.1^
 ||178.175.9.200^
+||178.175.9.210^
 ||178.175.9.215^
 ||178.175.9.217^
 ||178.175.9.21^
@@ -211384,12 +211696,14 @@
 ||178.175.9.92^
 ||178.175.9.95^
 ||178.175.9.98^
+||178.175.90.104^
 ||178.175.90.109^
 ||178.175.90.114^
 ||178.175.90.115^
 ||178.175.90.116^
 ||178.175.90.119^
 ||178.175.90.11^
+||178.175.90.122^
 ||178.175.90.124^
 ||178.175.90.127^
 ||178.175.90.128^
@@ -211523,8 +211837,10 @@
 ||178.175.91.216^
 ||178.175.91.219^
 ||178.175.91.221^
+||178.175.91.223^
 ||178.175.91.224^
 ||178.175.91.22^
+||178.175.91.230^
 ||178.175.91.232^
 ||178.175.91.236^
 ||178.175.91.237^
@@ -211687,6 +212003,7 @@
 ||178.175.93.144^
 ||178.175.93.145^
 ||178.175.93.147^
+||178.175.93.148^
 ||178.175.93.149^
 ||178.175.93.150^
 ||178.175.93.151^
@@ -211716,6 +212033,7 @@
 ||178.175.93.219^
 ||178.175.93.220^
 ||178.175.93.223^
+||178.175.93.224^
 ||178.175.93.225^
 ||178.175.93.226^
 ||178.175.93.230^
@@ -211733,6 +212051,7 @@
 ||178.175.93.30^
 ||178.175.93.31^
 ||178.175.93.33^
+||178.175.93.34^
 ||178.175.93.36^
 ||178.175.93.38^
 ||178.175.93.40^
@@ -211756,6 +212075,7 @@
 ||178.175.93.82^
 ||178.175.93.89^
 ||178.175.93.8^
+||178.175.93.90^
 ||178.175.93.93^
 ||178.175.93.95^
 ||178.175.93.96^
@@ -211880,6 +212200,7 @@
 ||178.175.95.119^
 ||178.175.95.122^
 ||178.175.95.126^
+||178.175.95.132^
 ||178.175.95.135^
 ||178.175.95.136^
 ||178.175.95.137^
@@ -211920,6 +212241,7 @@
 ||178.175.95.22^
 ||178.175.95.230^
 ||178.175.95.236^
+||178.175.95.237^
 ||178.175.95.238^
 ||178.175.95.241^
 ||178.175.95.244^
@@ -212060,6 +212382,7 @@
 ||178.175.97.12^
 ||178.175.97.130^
 ||178.175.97.132^
+||178.175.97.135^
 ||178.175.97.139^
 ||178.175.97.140^
 ||178.175.97.141^
@@ -212076,6 +212399,7 @@
 ||178.175.97.173^
 ||178.175.97.175^
 ||178.175.97.177^
+||178.175.97.17^
 ||178.175.97.180^
 ||178.175.97.181^
 ||178.175.97.183^
@@ -212087,6 +212411,7 @@
 ||178.175.97.195^
 ||178.175.97.197^
 ||178.175.97.198^
+||178.175.97.1^
 ||178.175.97.208^
 ||178.175.97.20^
 ||178.175.97.210^
@@ -212256,6 +212581,7 @@
 ||178.175.99.222^
 ||178.175.99.223^
 ||178.175.99.225^
+||178.175.99.226^
 ||178.175.99.22^
 ||178.175.99.230^
 ||178.175.99.233^
@@ -214543,6 +214869,7 @@
 ||180.188.241.79^
 ||180.188.241.86^
 ||180.188.241.91^
+||180.188.247.140^
 ||180.188.252.185^
 ||180.188.252.37^
 ||180.188.253.153^
@@ -218312,6 +218639,7 @@
 ||182.113.232.248^
 ||182.113.232.81^
 ||182.113.233.120^
+||182.113.233.129^
 ||182.113.233.13^
 ||182.113.233.20^
 ||182.113.233.32^
@@ -221858,6 +222186,7 @@
 ||182.116.103.68^
 ||182.116.103.76^
 ||182.116.103.77^
+||182.116.103.81^
 ||182.116.103.85^
 ||182.116.103.90^
 ||182.116.103.91^
@@ -222126,6 +222455,7 @@
 ||182.116.108.177^
 ||182.116.108.178^
 ||182.116.108.179^
+||182.116.108.180^
 ||182.116.108.182^
 ||182.116.108.183^
 ||182.116.108.185^
@@ -222718,6 +223048,7 @@
 ||182.116.119.111^
 ||182.116.119.11^
 ||182.116.119.122^
+||182.116.119.129^
 ||182.116.119.134^
 ||182.116.119.139^
 ||182.116.119.140^
@@ -224401,6 +224732,7 @@
 ||182.116.99.13^
 ||182.116.99.141^
 ||182.116.99.142^
+||182.116.99.150^
 ||182.116.99.153^
 ||182.116.99.160^
 ||182.116.99.179^
@@ -225989,6 +226321,7 @@
 ||182.117.29.202^
 ||182.117.29.212^
 ||182.117.29.216^
+||182.117.29.220^
 ||182.117.29.227^
 ||182.117.29.228^
 ||182.117.29.229^
@@ -229114,6 +229447,7 @@
 ||182.119.13.107^
 ||182.119.13.109^
 ||182.119.13.119^
+||182.119.13.141^
 ||182.119.13.148^
 ||182.119.13.159^
 ||182.119.13.160^
@@ -230148,6 +230482,7 @@
 ||182.119.191.8^
 ||182.119.191.92^
 ||182.119.196.160^
+||182.119.196.182^
 ||182.119.196.190^
 ||182.119.199.158^
 ||182.119.199.85^
@@ -230822,6 +231157,7 @@
 ||182.119.227.194^
 ||182.119.227.199^
 ||182.119.227.207^
+||182.119.227.20^
 ||182.119.227.21^
 ||182.119.227.245^
 ||182.119.227.254^
@@ -231407,6 +231743,7 @@
 ||182.119.49.14^
 ||182.119.49.162^
 ||182.119.49.168^
+||182.119.49.17^
 ||182.119.49.185^
 ||182.119.49.207^
 ||182.119.49.220^
@@ -231914,6 +232251,7 @@
 ||182.119.7.3^
 ||182.119.7.41^
 ||182.119.7.47^
+||182.119.7.54^
 ||182.119.7.73^
 ||182.119.7.75^
 ||182.119.7.88^
@@ -233578,6 +233916,7 @@
 ||182.120.85.9^
 ||182.120.86.203^
 ||182.120.86.234^
+||182.120.86.248^
 ||182.120.86.46^
 ||182.120.87.160^
 ||182.120.87.227^
@@ -234665,6 +235004,7 @@
 ||182.121.133.32^
 ||182.121.133.37^
 ||182.121.133.41^
+||182.121.133.46^
 ||182.121.133.50^
 ||182.121.133.58^
 ||182.121.133.72^
@@ -235444,6 +235784,7 @@
 ||182.121.164.75^
 ||182.121.164.85^
 ||182.121.165.184^
+||182.121.165.217^
 ||182.121.166.105^
 ||182.121.166.123^
 ||182.121.166.85^
@@ -235832,6 +236173,7 @@
 ||182.121.204.99^
 ||182.121.205.100^
 ||182.121.205.114^
+||182.121.205.118^
 ||182.121.205.124^
 ||182.121.205.131^
 ||182.121.205.137^
@@ -237627,6 +237969,7 @@
 ||182.121.49.94^
 ||182.121.49.97^
 ||182.121.49.9^
+||182.121.50.111^
 ||182.121.50.112^
 ||182.121.50.119^
 ||182.121.50.121^
@@ -238105,6 +238448,7 @@
 ||182.121.78.201^
 ||182.121.78.220^
 ||182.121.78.27^
+||182.121.78.29^
 ||182.121.78.36^
 ||182.121.78.3^
 ||182.121.78.42^
@@ -239342,6 +239686,7 @@
 ||182.122.202.219^
 ||182.122.202.229^
 ||182.122.202.246^
+||182.122.202.37^
 ||182.122.202.59^
 ||182.122.202.62^
 ||182.122.202.82^
@@ -239744,6 +240089,7 @@
 ||182.122.246.167^
 ||182.122.246.170^
 ||182.122.246.181^
+||182.122.246.187^
 ||182.122.246.190^
 ||182.122.246.197^
 ||182.122.246.199^
@@ -239883,6 +240229,7 @@
 ||182.122.251.124^
 ||182.122.251.12^
 ||182.122.251.133^
+||182.122.251.141^
 ||182.122.251.143^
 ||182.122.251.145^
 ||182.122.251.150^
@@ -240992,6 +241339,7 @@
 ||182.124.134.216^
 ||182.124.134.235^
 ||182.124.134.75^
+||182.124.134.80^
 ||182.124.134.90^
 ||182.124.134.96^
 ||182.124.134.9^
@@ -241095,6 +241443,7 @@
 ||182.124.149.52^
 ||182.124.149.67^
 ||182.124.15.106^
+||182.124.15.108^
 ||182.124.15.109^
 ||182.124.15.111^
 ||182.124.15.137^
@@ -241200,6 +241549,7 @@
 ||182.124.166.228^
 ||182.124.166.2^
 ||182.124.166.38^
+||182.124.166.57^
 ||182.124.166.6^
 ||182.124.166.7^
 ||182.124.167.11^
@@ -243270,6 +243620,7 @@
 ||182.126.180.65^
 ||182.126.180.72^
 ||182.126.181.115^
+||182.126.181.121^
 ||182.126.181.149^
 ||182.126.181.204^
 ||182.126.181.214^
@@ -243840,6 +244191,7 @@
 ||182.126.241.30^
 ||182.126.241.42^
 ||182.126.241.71^
+||182.126.241.7^
 ||182.126.241.92^
 ||182.126.242.10^
 ||182.126.242.127^
@@ -243916,6 +244268,7 @@
 ||182.126.52.202^
 ||182.126.52.214^
 ||182.126.52.229^
+||182.126.52.233^
 ||182.126.52.252^
 ||182.126.52.47^
 ||182.126.52.70^
@@ -244507,6 +244860,7 @@
 ||182.126.87.194^
 ||182.126.87.201^
 ||182.126.87.205^
+||182.126.87.207^
 ||182.126.87.209^
 ||182.126.87.20^
 ||182.126.87.217^
@@ -248007,6 +248361,7 @@
 ||182.127.70.172^
 ||182.127.70.185^
 ||182.127.70.194^
+||182.127.70.195^
 ||182.127.70.213^
 ||182.127.70.216^
 ||182.127.70.218^
@@ -249305,6 +249660,7 @@
 ||182.56.115.187^
 ||182.56.115.191^
 ||182.56.116.121^
+||182.56.116.135^
 ||182.56.116.178^
 ||182.56.116.56^
 ||182.56.117.14^
@@ -251854,6 +252210,7 @@
 ||182.58.137.168^
 ||182.58.137.66^
 ||182.58.137.94^
+||182.58.160.0^
 ||182.58.160.122^
 ||182.58.160.252^
 ||182.58.160.89^
@@ -254351,6 +254708,7 @@
 ||182.59.226.71^
 ||182.59.227.10^
 ||182.59.227.123^
+||182.59.227.125^
 ||182.59.227.130^
 ||182.59.227.151^
 ||182.59.227.175^
@@ -257012,6 +257370,7 @@
 ||183.188.184.94^
 ||183.188.186.52^
 ||183.188.187.52^
+||183.188.188.186^
 ||183.188.194.119^
 ||183.188.194.231^
 ||183.188.195.189^
@@ -257248,6 +257607,7 @@
 ||183.190.24.165^
 ||183.190.26.125^
 ||183.190.55.62^
+||183.191.162.120^
 ||183.191.204.241^
 ||183.191.217.113^
 ||183.191.65.166^
@@ -257304,6 +257664,7 @@
 ||183.27.195.242^
 ||183.28.50.158^
 ||183.28.61.52^
+||183.30.202.230^
 ||183.30.202.247^
 ||183.30.202.59^
 ||183.30.202.67^
@@ -257433,6 +257794,7 @@
 ||183.83.104.44^
 ||183.83.104.68^
 ||183.83.105.181^
+||183.83.105.21^
 ||183.83.105.228^
 ||183.83.105.252^
 ||183.83.105.253^
@@ -258124,6 +258486,7 @@
 ||185.132.53.88^
 ||185.132.53.98^
 ||185.132.53.9^
+||185.133.42.86^
 ||185.134.122.209^
 ||185.134.123.140^
 ||185.134.21.75^
@@ -258528,6 +258891,7 @@
 ||185.184.221.44^
 ||185.184.54.15^
 ||185.185.126.123^
+||185.185.126.82^
 ||185.186.142.100^
 ||185.186.198.120^
 ||185.186.244.186^
@@ -262063,6 +262427,7 @@
 ||188.10.21.14^
 ||188.10.231.246^
 ||188.112.169.59^
+||188.113.102.18^
 ||188.113.107.75^
 ||188.113.116.133^
 ||188.113.81.17^
@@ -262216,6 +262581,7 @@
 ||188.166.179.28^
 ||188.166.18.52^
 ||188.166.19.196^
+||188.166.19.45^
 ||188.166.207.182^
 ||188.166.21.10^
 ||188.166.21.86^
@@ -264948,6 +265314,7 @@
 ||192.119.106.235^
 ||192.119.106.9^
 ||192.119.107.81^
+||192.119.110.168^
 ||192.119.110.222^
 ||192.119.110.44^
 ||192.119.110.49^
@@ -265730,6 +266097,7 @@
 ||194.15.36.194^
 ||194.15.36.196^
 ||194.15.36.19^
+||194.15.36.202^
 ||194.15.36.204^
 ||194.15.36.207^
 ||194.15.36.208^
@@ -265988,6 +266356,7 @@
 ||194.87.138.8^
 ||194.87.138.97^
 ||194.87.139.108^
+||194.87.139.10^
 ||194.87.139.110^
 ||194.87.139.113^
 ||194.87.139.116^
@@ -267652,6 +268021,7 @@
 ||2.238.18.160^
 ||2.238.195.223^
 ||2.248.2.174^
+||2.249.161.188^
 ||2.249.161.196^
 ||2.249.178.219^
 ||2.25.93.113^
@@ -268172,6 +268542,7 @@
 ||200.75.107.84^
 ||200.79.152.109^
 ||200.79.153.166^
+||200.8.206.151^
 ||200.8.206.224^
 ||200.8.23.209^
 ||200.8.240.149^
@@ -268352,6 +268723,7 @@
 ||201.207.235.219^
 ||201.208.129.111^
 ||201.208.137.75^
+||201.208.139.84^
 ||201.208.153.220^
 ||201.208.155.206^
 ||201.208.209.28^
@@ -269193,6 +269565,7 @@
 ||202.168.153.228^
 ||202.169.234.10^
 ||202.169.234.19^
+||202.169.234.22^
 ||202.169.234.33^
 ||202.169.234.36^
 ||202.169.234.37^
@@ -270234,6 +270607,7 @@
 ||203.114.116.37^
 ||203.115.102.243^
 ||203.115.73.100^
+||203.115.73.105^
 ||203.115.73.107^
 ||203.115.73.111^
 ||203.115.73.119^
@@ -270329,6 +270703,7 @@
 ||203.115.85.93^
 ||203.115.91.129^
 ||203.115.91.141^
+||203.115.91.232^
 ||203.115.91.47^
 ||203.115.91.66^
 ||203.123.205.195^
@@ -273254,6 +273629,7 @@
 ||206.221.176.164^
 ||206.248.136.50^
 ||206.248.136.6^
+||206.248.137.132^
 ||206.248.139.132^
 ||206.248.139.15^
 ||206.248.219.15^
@@ -273434,6 +273810,7 @@
 ||209.133.223.130^
 ||209.14.30.121^
 ||209.14.30.135^
+||209.14.30.136^
 ||209.14.30.159^
 ||209.14.30.161^
 ||209.14.30.166^
@@ -273442,6 +273819,7 @@
 ||209.14.30.205^
 ||209.14.30.30^
 ||209.14.30.54^
+||209.14.31.125^
 ||209.14.31.162^
 ||209.14.31.163^
 ||209.14.31.175^
@@ -273706,6 +274084,7 @@
 ||210.101.157.10^
 ||210.101.157.199^
 ||210.101.70.131^
+||210.102.196.200^
 ||210.102.58.78^
 ||210.104.187.179^
 ||210.104.210.133^
@@ -275763,6 +276142,7 @@
 ||218.0.88.48^
 ||218.101.202.186^
 ||218.101.230.26^
+||218.103.180.199^
 ||218.104.175.100^
 ||218.104.175.103^
 ||218.104.175.109^
@@ -278417,6 +278797,7 @@
 ||219.154.140.99^
 ||219.154.141.138^
 ||219.154.141.196^
+||219.154.141.222^
 ||219.154.141.227^
 ||219.154.141.242^
 ||219.154.141.53^
@@ -279259,6 +279640,7 @@
 ||219.155.12.205^
 ||219.155.12.215^
 ||219.155.12.220^
+||219.155.12.221^
 ||219.155.12.40^
 ||219.155.12.51^
 ||219.155.12.55^
@@ -279490,6 +279872,7 @@
 ||219.155.170.185^
 ||219.155.170.215^
 ||219.155.170.228^
+||219.155.170.22^
 ||219.155.170.244^
 ||219.155.170.250^
 ||219.155.170.48^
@@ -279684,6 +280067,7 @@
 ||219.155.207.8^
 ||219.155.207.96^
 ||219.155.208.145^
+||219.155.208.188^
 ||219.155.208.19^
 ||219.155.208.211^
 ||219.155.208.212^
@@ -279945,6 +280329,7 @@
 ||219.155.225.90^
 ||219.155.226.130^
 ||219.155.226.143^
+||219.155.226.146^
 ||219.155.226.154^
 ||219.155.226.188^
 ||219.155.226.194^
@@ -280141,6 +280526,7 @@
 ||219.155.240.86^
 ||219.155.241.113^
 ||219.155.241.11^
+||219.155.241.135^
 ||219.155.241.137^
 ||219.155.241.144^
 ||219.155.241.155^
@@ -280680,6 +281066,7 @@
 ||219.155.37.72^
 ||219.155.37.87^
 ||219.155.37.90^
+||219.155.37.97^
 ||219.155.38.10^
 ||219.155.38.112^
 ||219.155.38.113^
@@ -281443,6 +281830,7 @@
 ||219.156.103.192^
 ||219.156.103.225^
 ||219.156.103.236^
+||219.156.103.248^
 ||219.156.103.43^
 ||219.156.103.46^
 ||219.156.103.84^
@@ -282254,6 +282642,7 @@
 ||219.156.23.241^
 ||219.156.23.245^
 ||219.156.23.26^
+||219.156.23.29^
 ||219.156.23.3^
 ||219.156.23.41^
 ||219.156.23.50^
@@ -282397,6 +282786,7 @@
 ||219.156.48.185^
 ||219.156.48.50^
 ||219.156.49.142^
+||219.156.49.170^
 ||219.156.49.172^
 ||219.156.49.250^
 ||219.156.5.233^
@@ -282473,6 +282863,7 @@
 ||219.156.60.203^
 ||219.156.60.208^
 ||219.156.60.211^
+||219.156.60.224^
 ||219.156.60.250^
 ||219.156.60.27^
 ||219.156.60.39^
@@ -282790,6 +283181,7 @@
 ||219.156.9.247^
 ||219.156.9.254^
 ||219.156.9.27^
+||219.156.9.32^
 ||219.156.9.34^
 ||219.156.9.42^
 ||219.156.9.48^
@@ -284388,6 +284780,7 @@
 ||219.157.220.159^
 ||219.157.220.163^
 ||219.157.220.164^
+||219.157.220.170^
 ||219.157.220.171^
 ||219.157.220.177^
 ||219.157.220.18^
@@ -284472,6 +284865,7 @@
 ||219.157.223.23^
 ||219.157.223.241^
 ||219.157.223.243^
+||219.157.223.245^
 ||219.157.223.24^
 ||219.157.223.29^
 ||219.157.223.42^
@@ -284524,6 +284918,7 @@
 ||219.157.226.198^
 ||219.157.226.47^
 ||219.157.226.4^
+||219.157.226.79^
 ||219.157.227.124^
 ||219.157.227.170^
 ||219.157.227.176^
@@ -284896,6 +285291,7 @@
 ||219.157.244.233^
 ||219.157.244.236^
 ||219.157.244.254^
+||219.157.244.33^
 ||219.157.244.39^
 ||219.157.244.43^
 ||219.157.244.61^
@@ -285833,6 +286229,7 @@
 ||219.157.50.18^
 ||219.157.50.203^
 ||219.157.50.208^
+||219.157.50.211^
 ||219.157.50.21^
 ||219.157.50.228^
 ||219.157.50.233^
@@ -285992,6 +286389,7 @@
 ||219.157.54.150^
 ||219.157.54.155^
 ||219.157.54.157^
+||219.157.54.158^
 ||219.157.54.159^
 ||219.157.54.15^
 ||219.157.54.177^
@@ -286100,6 +286498,7 @@
 ||219.157.56.251^
 ||219.157.56.254^
 ||219.157.56.35^
+||219.157.56.46^
 ||219.157.56.47^
 ||219.157.56.50^
 ||219.157.56.54^
@@ -288883,6 +289282,7 @@
 ||221.14.56.67^
 ||221.14.57.62^
 ||221.14.58.27^
+||221.14.58.5^
 ||221.14.58.84^
 ||221.14.59.255^
 ||221.14.60.146^
@@ -289496,6 +289896,7 @@
 ||221.15.147.210^
 ||221.15.147.214^
 ||221.15.147.217^
+||221.15.147.220^
 ||221.15.147.225^
 ||221.15.147.227^
 ||221.15.147.234^
@@ -291308,6 +291709,7 @@
 ||221.15.236.93^
 ||221.15.236.98^
 ||221.15.236.9^
+||221.15.237.107^
 ||221.15.237.109^
 ||221.15.237.112^
 ||221.15.237.11^
@@ -292032,6 +292434,7 @@
 ||221.15.7.198^
 ||221.15.7.199^
 ||221.15.7.200^
+||221.15.7.202^
 ||221.15.7.205^
 ||221.15.7.207^
 ||221.15.7.210^
@@ -293024,6 +293427,7 @@
 ||221.215.170.109^
 ||221.215.171.80^
 ||221.215.172.192^
+||221.215.172.207^
 ||221.215.172.217^
 ||221.215.174.4^
 ||221.215.174.59^
@@ -293712,6 +294116,7 @@
 ||221.5.30.100^
 ||221.5.30.103^
 ||221.5.30.10^
+||221.5.30.118^
 ||221.5.30.140^
 ||221.5.30.14^
 ||221.5.30.153^
@@ -297259,6 +297664,7 @@
 ||222.137.22.42^
 ||222.137.22.59^
 ||222.137.22.66^
+||222.137.22.79^
 ||222.137.220.10^
 ||222.137.220.123^
 ||222.137.220.125^
@@ -297287,6 +297693,7 @@
 ||222.137.220.60^
 ||222.137.220.63^
 ||222.137.220.82^
+||222.137.220.94^
 ||222.137.220.99^
 ||222.137.221.101^
 ||222.137.221.107^
@@ -297898,6 +298305,7 @@
 ||222.137.49.1^
 ||222.137.49.29^
 ||222.137.49.30^
+||222.137.49.4^
 ||222.137.49.75^
 ||222.137.49.99^
 ||222.137.5.102^
@@ -298296,6 +298704,7 @@
 ||222.137.83.211^
 ||222.137.83.230^
 ||222.137.83.39^
+||222.137.83.53^
 ||222.137.83.5^
 ||222.137.84.240^
 ||222.137.84.2^
@@ -299839,6 +300248,7 @@
 ||222.138.189.219^
 ||222.138.189.223^
 ||222.138.189.243^
+||222.138.189.88^
 ||222.138.19.110^
 ||222.138.19.135^
 ||222.138.19.144^
@@ -300164,6 +300574,7 @@
 ||222.138.215.117^
 ||222.138.215.134^
 ||222.138.215.146^
+||222.138.215.161^
 ||222.138.215.16^
 ||222.138.215.183^
 ||222.138.215.215^
@@ -300275,6 +300686,7 @@
 ||222.138.224.148^
 ||222.138.224.15^
 ||222.138.224.163^
+||222.138.224.164^
 ||222.138.224.173^
 ||222.138.224.228^
 ||222.138.224.2^
@@ -300741,6 +301153,7 @@
 ||222.138.49.58^
 ||222.138.49.67^
 ||222.138.49.79^
+||222.138.49.93^
 ||222.138.50.106^
 ||222.138.50.237^
 ||222.138.50.32^
@@ -301163,6 +301576,7 @@
 ||222.139.16.143^
 ||222.139.16.173^
 ||222.139.16.195^
+||222.139.16.229^
 ||222.139.16.236^
 ||222.139.16.32^
 ||222.139.16.84^
@@ -301931,6 +302345,7 @@
 ||222.140.111.116^
 ||222.140.111.192^
 ||222.140.111.205^
+||222.140.112.150^
 ||222.140.112.171^
 ||222.140.112.224^
 ||222.140.113.197^
@@ -303604,6 +304019,7 @@
 ||222.141.164.67^
 ||222.141.164.88^
 ||222.141.165.116^
+||222.141.165.180^
 ||222.141.165.189^
 ||222.141.165.214^
 ||222.141.165.220^
@@ -303919,6 +304335,7 @@
 ||222.141.244.110^
 ||222.141.244.147^
 ||222.141.244.20^
+||222.141.244.231^
 ||222.141.244.80^
 ||222.141.245.10^
 ||222.141.245.134^
@@ -304583,6 +305000,7 @@
 ||222.141.73.184^
 ||222.141.73.219^
 ||222.141.73.245^
+||222.141.73.249^
 ||222.141.73.38^
 ||222.141.73.55^
 ||222.141.73.61^
@@ -306093,6 +306511,7 @@
 ||222.214.53.254^
 ||222.214.53.62^
 ||222.214.54.162^
+||222.214.54.208^
 ||222.214.54.238^
 ||222.214.55.138^
 ||222.214.55.181^
@@ -307745,6 +308164,7 @@
 ||27.12.232.176^
 ||27.12.233.205^
 ||27.12.233.96^
+||27.12.234.4^
 ||27.12.235.176^
 ||27.12.236.127^
 ||27.12.238.202^
@@ -311863,6 +312283,7 @@
 ||27.208.242.223^
 ||27.208.244.172^
 ||27.208.247.130^
+||27.208.25.59^
 ||27.208.30.1^
 ||27.208.30.87^
 ||27.208.31.92^
@@ -312149,6 +312570,7 @@
 ||27.210.146.47^
 ||27.210.146.49^
 ||27.210.146.54^
+||27.210.146.61^
 ||27.210.146.6^
 ||27.210.146.89^
 ||27.210.147.172^
@@ -312891,6 +313313,7 @@
 ||27.213.145.138^
 ||27.213.145.143^
 ||27.213.145.161^
+||27.213.145.221^
 ||27.213.146.231^
 ||27.213.147.121^
 ||27.213.148.104^
@@ -312937,6 +313360,7 @@
 ||27.213.166.136^
 ||27.213.166.174^
 ||27.213.167.154^
+||27.213.167.175^
 ||27.213.167.180^
 ||27.213.167.210^
 ||27.213.168.162^
@@ -313901,6 +314325,7 @@
 ||27.216.130.132^
 ||27.216.130.185^
 ||27.216.131.63^
+||27.216.131.66^
 ||27.216.132.194^
 ||27.216.132.221^
 ||27.216.132.237^
@@ -317795,6 +318220,7 @@
 ||27.41.146.27^
 ||27.41.146.2^
 ||27.41.146.3^
+||27.41.146.59^
 ||27.41.146.63^
 ||27.41.146.73^
 ||27.41.146.80^
@@ -317915,6 +318341,7 @@
 ||27.41.153.41^
 ||27.41.153.54^
 ||27.41.153.65^
+||27.41.153.66^
 ||27.41.153.89^
 ||27.41.153.91^
 ||27.41.154.102^
@@ -319041,6 +319468,7 @@
 ||27.43.151.68^
 ||27.43.151.86^
 ||27.43.66.61^
+||27.43.82.210^
 ||27.43.92.65^
 ||27.44.100.126^
 ||27.44.100.242^
@@ -319323,6 +319751,7 @@
 ||27.46.47.69^
 ||27.46.47.6^
 ||27.46.47.72^
+||27.46.47.74^
 ||27.46.47.75^
 ||27.46.47.76^
 ||27.46.47.77^
@@ -319412,6 +319841,7 @@
 ||27.5.16.236^
 ||27.5.16.237^
 ||27.5.16.242^
+||27.5.16.243^
 ||27.5.16.244^
 ||27.5.16.245^
 ||27.5.16.246^
@@ -319888,6 +320318,7 @@
 ||27.5.21.37^
 ||27.5.21.38^
 ||27.5.21.4^
+||27.5.21.53^
 ||27.5.21.56^
 ||27.5.21.57^
 ||27.5.21.5^
@@ -320316,6 +320747,7 @@
 ||27.5.26.43^
 ||27.5.26.44^
 ||27.5.26.47^
+||27.5.26.4^
 ||27.5.26.50^
 ||27.5.26.60^
 ||27.5.26.62^
@@ -320624,6 +321056,7 @@
 ||27.5.30.197^
 ||27.5.30.19^
 ||27.5.30.203^
+||27.5.30.207^
 ||27.5.30.20^
 ||27.5.30.210^
 ||27.5.30.212^
@@ -320931,6 +321364,7 @@
 ||27.5.34.169^
 ||27.5.34.171^
 ||27.5.34.176^
+||27.5.34.177^
 ||27.5.34.182^
 ||27.5.34.183^
 ||27.5.34.186^
@@ -320994,6 +321428,7 @@
 ||27.5.35.117^
 ||27.5.35.11^
 ||27.5.35.125^
+||27.5.35.127^
 ||27.5.35.12^
 ||27.5.35.130^
 ||27.5.35.131^
@@ -341749,6 +342184,7 @@
 ||31.163.189.192^
 ||31.163.189.220^
 ||31.163.189.254^
+||31.163.191.11^
 ||31.163.57.231^
 ||31.163.65.250^
 ||31.164.47.38^
@@ -341975,6 +342411,7 @@
 ||31.6.70.84^
 ||31.6.98.137^
 ||31.62.130.208^
+||31.62.255.3^
 ||31.62.91.175^
 ||31.63.183.192^
 ||31.63.189.195^
@@ -344022,6 +344459,7 @@
 ||37.187.73.85^
 ||37.189.109.110^
 ||37.19.48.73^
+||37.19.49.202^
 ||37.19.49.206^
 ||37.19.51.174^
 ||37.19.52.247^
@@ -345964,6 +346402,7 @@
 ||39.73.44.155^
 ||39.73.44.165^
 ||39.73.44.176^
+||39.73.44.17^
 ||39.73.44.185^
 ||39.73.44.198^
 ||39.73.44.227^
@@ -348635,6 +349074,7 @@
 ||39.86.150.176^
 ||39.86.150.37^
 ||39.86.151.106^
+||39.86.151.49^
 ||39.86.151.96^
 ||39.86.152.128^
 ||39.86.152.130^
@@ -349398,6 +349838,7 @@
 ||39.87.84.239^
 ||39.87.87.117^
 ||39.87.87.99^
+||39.87.90.210^
 ||39.87.93.109^
 ||39.87.93.54^
 ||39.87.98.115^
@@ -351779,6 +352220,7 @@
 ||42.224.122.25^
 ||42.224.122.30^
 ||42.224.122.37^
+||42.224.122.39^
 ||42.224.122.3^
 ||42.224.122.41^
 ||42.224.122.43^
@@ -353102,6 +353544,7 @@
 ||42.224.176.199^
 ||42.224.176.202^
 ||42.224.176.205^
+||42.224.176.214^
 ||42.224.176.216^
 ||42.224.176.217^
 ||42.224.176.221^
@@ -354441,6 +354884,7 @@
 ||42.224.249.76^
 ||42.224.249.87^
 ||42.224.249.88^
+||42.224.249.8^
 ||42.224.249.92^
 ||42.224.249.93^
 ||42.224.249.95^
@@ -356600,6 +357044,7 @@
 ||42.224.90.133^
 ||42.224.90.151^
 ||42.224.90.158^
+||42.224.90.17^
 ||42.224.90.196^
 ||42.224.90.240^
 ||42.224.90.28^
@@ -357801,6 +358246,7 @@
 ||42.225.33.162^
 ||42.225.33.199^
 ||42.225.33.20^
+||42.225.33.31^
 ||42.225.34.174^
 ||42.225.34.184^
 ||42.225.34.186^
@@ -358374,6 +358820,7 @@
 ||42.226.89.147^
 ||42.226.89.157^
 ||42.226.89.235^
+||42.226.89.25^
 ||42.226.89.82^
 ||42.226.90.0^
 ||42.226.90.102^
@@ -358915,6 +359362,7 @@
 ||42.227.176.230^
 ||42.227.176.239^
 ||42.227.176.90^
+||42.227.177.142^
 ||42.227.177.250^
 ||42.227.177.84^
 ||42.227.178.10^
@@ -361511,6 +361959,7 @@
 ||42.228.75.65^
 ||42.228.75.74^
 ||42.228.75.79^
+||42.228.75.7^
 ||42.228.75.80^
 ||42.228.75.84^
 ||42.228.75.90^
@@ -363419,6 +363868,7 @@
 ||42.230.173.51^
 ||42.230.173.66^
 ||42.230.174.117^
+||42.230.174.125^
 ||42.230.174.161^
 ||42.230.174.171^
 ||42.230.174.216^
@@ -364145,6 +364595,7 @@
 ||42.230.219.225^
 ||42.230.219.231^
 ||42.230.219.239^
+||42.230.219.243^
 ||42.230.219.254^
 ||42.230.219.37^
 ||42.230.219.41^
@@ -366620,6 +367071,7 @@
 ||42.231.223.17^
 ||42.231.223.191^
 ||42.231.223.209^
+||42.231.223.215^
 ||42.231.223.59^
 ||42.231.223.95^
 ||42.231.224.122^
@@ -366773,6 +367225,7 @@
 ||42.231.244.187^
 ||42.231.244.189^
 ||42.231.244.222^
+||42.231.244.80^
 ||42.231.244.83^
 ||42.231.245.111^
 ||42.231.245.142^
@@ -367191,6 +367644,7 @@
 ||42.231.95.136^
 ||42.231.95.154^
 ||42.231.95.17^
+||42.231.95.195^
 ||42.231.95.210^
 ||42.231.95.230^
 ||42.231.95.99^
@@ -369090,6 +369544,7 @@
 ||42.233.90.116^
 ||42.233.90.138^
 ||42.233.90.167^
+||42.233.90.183^
 ||42.233.90.187^
 ||42.233.90.52^
 ||42.233.91.0^
@@ -369211,6 +369666,7 @@
 ||42.234.105.33^
 ||42.234.105.3^
 ||42.234.105.68^
+||42.234.105.6^
 ||42.234.105.93^
 ||42.234.106.110^
 ||42.234.106.120^
@@ -369503,6 +369959,7 @@
 ||42.234.162.170^
 ||42.234.162.214^
 ||42.234.162.42^
+||42.234.162.44^
 ||42.234.162.4^
 ||42.234.162.76^
 ||42.234.163.119^
@@ -374057,6 +374514,7 @@
 ||42.235.90.243^
 ||42.235.90.245^
 ||42.235.90.29^
+||42.235.90.32^
 ||42.235.90.3^
 ||42.235.90.46^
 ||42.235.90.50^
@@ -375221,6 +375679,7 @@
 ||42.237.44.45^
 ||42.237.44.47^
 ||42.237.45.107^
+||42.237.45.223^
 ||42.237.45.25^
 ||42.237.45.90^
 ||42.237.46.104^
@@ -375537,6 +375996,7 @@
 ||42.238.109.115^
 ||42.238.11.212^
 ||42.238.111.149^
+||42.238.112.100^
 ||42.238.112.125^
 ||42.238.112.132^
 ||42.238.112.32^
@@ -375804,6 +376264,7 @@
 ||42.238.175.124^
 ||42.238.175.14^
 ||42.238.175.229^
+||42.238.175.32^
 ||42.238.175.35^
 ||42.238.175.61^
 ||42.238.175.96^
@@ -378687,6 +379148,7 @@
 ||45.144.225.118^
 ||45.144.225.142^
 ||45.144.225.151^
+||45.144.225.213^
 ||45.144.225.65^
 ||45.144.225.96^
 ||45.144.29.133^
@@ -385085,6 +385547,7 @@
 ||54.179.174.132^
 ||54.179.179.37^
 ||54.179.9.186^
+||54.180.158.181^
 ||54.186.24.183^
 ||54.187.210.136^
 ||54.197.30.41^
@@ -385261,6 +385724,7 @@
 ||58.19.163.45^
 ||58.19.163.92^
 ||58.19.249.100^
+||58.19.249.50^
 ||58.19.250.18^
 ||58.19.250.190^
 ||58.19.251.10^
@@ -386093,6 +386557,7 @@
 ||58.248.143.158^
 ||58.248.143.164^
 ||58.248.143.168^
+||58.248.143.173^
 ||58.248.143.174^
 ||58.248.143.176^
 ||58.248.143.18^
@@ -386123,11 +386588,13 @@
 ||58.248.144.190^
 ||58.248.144.216^
 ||58.248.144.217^
+||58.248.144.21^
 ||58.248.144.39^
 ||58.248.144.88^
 ||58.248.144.89^
 ||58.248.144.94^
 ||58.248.144.95^
+||58.248.144.97^
 ||58.248.145.113^
 ||58.248.145.129^
 ||58.248.145.130^
@@ -386254,6 +386721,7 @@
 ||58.248.149.186^
 ||58.248.149.207^
 ||58.248.149.214^
+||58.248.149.226^
 ||58.248.149.230^
 ||58.248.149.231^
 ||58.248.149.240^
@@ -387096,6 +387564,7 @@
 ||58.249.73.7^
 ||58.249.73.90^
 ||58.249.74.103^
+||58.249.74.104^
 ||58.249.74.118^
 ||58.249.74.11^
 ||58.249.74.120^
@@ -387122,6 +387591,7 @@
 ||58.249.74.9^
 ||58.249.75.101^
 ||58.249.75.109^
+||58.249.75.112^
 ||58.249.75.125^
 ||58.249.75.126^
 ||58.249.75.13^
@@ -387205,6 +387675,7 @@
 ||58.249.78.116^
 ||58.249.78.128^
 ||58.249.78.132^
+||58.249.78.155^
 ||58.249.78.168^
 ||58.249.78.174^
 ||58.249.78.176^
@@ -387306,6 +387777,7 @@
 ||58.249.80.246^
 ||58.249.80.37^
 ||58.249.80.38^
+||58.249.80.46^
 ||58.249.80.56^
 ||58.249.80.61^
 ||58.249.80.63^
@@ -387520,6 +387992,7 @@
 ||58.249.87.211^
 ||58.249.87.222^
 ||58.249.87.247^
+||58.249.87.248^
 ||58.249.87.250^
 ||58.249.87.253^
 ||58.249.87.33^
@@ -387584,6 +388057,7 @@
 ||58.249.89.169^
 ||58.249.89.178^
 ||58.249.89.190^
+||58.249.89.210^
 ||58.249.89.213^
 ||58.249.89.218^
 ||58.249.89.223^
@@ -387647,6 +388121,7 @@
 ||58.249.90.174^
 ||58.249.90.180^
 ||58.249.90.19^
+||58.249.90.206^
 ||58.249.90.20^
 ||58.249.90.216^
 ||58.249.90.220^
@@ -387658,6 +388133,7 @@
 ||58.249.90.80^
 ||58.249.90.82^
 ||58.249.90.84^
+||58.249.90.86^
 ||58.249.90.94^
 ||58.249.91.102^
 ||58.249.91.114^
@@ -387692,6 +388168,7 @@
 ||58.249.91.77^
 ||58.249.91.98^
 ||58.252.175.220^
+||58.252.176.107^
 ||58.252.176.117^
 ||58.252.176.120^
 ||58.252.176.124^
@@ -387960,6 +388437,7 @@
 ||58.255.135.21^
 ||58.255.135.228^
 ||58.255.135.253^
+||58.255.135.41^
 ||58.255.135.48^
 ||58.255.135.56^
 ||58.255.135.61^
@@ -388136,6 +388614,7 @@
 ||58.42.195.227^
 ||58.42.198.13^
 ||58.42.220.111^
+||58.46.169.21^
 ||58.46.248.182^
 ||58.46.248.4^
 ||58.46.249.10^
@@ -388298,6 +388777,7 @@
 ||58.61.51.61^
 ||58.61.51.73^
 ||58.61.51.97^
+||58.62.31.25^
 ||58.62.80.50^
 ||58.62.80.54^
 ||58.62.83.182^
@@ -392363,6 +392843,7 @@
 ||59.32.97.15^
 ||59.32.97.187^
 ||59.32.97.188^
+||59.32.97.190^
 ||59.32.97.208^
 ||59.32.97.217^
 ||59.32.97.218^
@@ -394234,6 +394715,7 @@
 ||59.92.182.6^
 ||59.92.182.70^
 ||59.92.182.71^
+||59.92.182.72^
 ||59.92.182.74^
 ||59.92.182.75^
 ||59.92.182.76^
@@ -394941,6 +395423,7 @@
 ||59.92.218.72^
 ||59.92.218.73^
 ||59.92.218.75^
+||59.92.218.77^
 ||59.92.218.79^
 ||59.92.218.80^
 ||59.92.218.81^
@@ -395060,6 +395543,7 @@
 ||59.92.219.254^
 ||59.92.219.25^
 ||59.92.219.26^
+||59.92.219.28^
 ||59.92.219.29^
 ||59.92.219.2^
 ||59.92.219.30^
@@ -395691,6 +396175,7 @@
 ||59.93.19.189^
 ||59.93.19.18^
 ||59.93.19.190^
+||59.93.19.191^
 ||59.93.19.193^
 ||59.93.19.194^
 ||59.93.19.195^
@@ -395865,6 +396350,7 @@
 ||59.93.21.110^
 ||59.93.21.111^
 ||59.93.21.115^
+||59.93.21.117^
 ||59.93.21.121^
 ||59.93.21.126^
 ||59.93.21.127^
@@ -397163,6 +397649,7 @@
 ||59.94.182.241^
 ||59.94.182.242^
 ||59.94.182.243^
+||59.94.182.244^
 ||59.94.182.246^
 ||59.94.182.247^
 ||59.94.182.248^
@@ -399711,6 +400198,7 @@
 ||59.97.169.111^
 ||59.97.169.112^
 ||59.97.169.113^
+||59.97.169.114^
 ||59.97.169.115^
 ||59.97.169.116^
 ||59.97.169.117^
@@ -400940,6 +401428,7 @@
 ||59.97.174.82^
 ||59.97.174.83^
 ||59.97.174.84^
+||59.97.174.85^
 ||59.97.174.87^
 ||59.97.174.89^
 ||59.97.174.8^
@@ -403352,6 +403841,7 @@
 ||59.99.44.24^
 ||59.99.44.253^
 ||59.99.44.254^
+||59.99.44.28^
 ||59.99.44.29^
 ||59.99.44.30^
 ||59.99.44.31^
@@ -404259,6 +404749,7 @@
 ||59.99.93.244^
 ||59.99.93.245^
 ||59.99.93.246^
+||59.99.93.248^
 ||59.99.93.250^
 ||59.99.93.251^
 ||59.99.93.252^
@@ -404315,6 +404806,7 @@
 ||59.99.93.79^
 ||59.99.93.7^
 ||59.99.93.80^
+||59.99.93.82^
 ||59.99.93.83^
 ||59.99.93.84^
 ||59.99.93.85^
@@ -404555,6 +405047,7 @@
 ||59.99.95.134^
 ||59.99.95.135^
 ||59.99.95.136^
+||59.99.95.137^
 ||59.99.95.139^
 ||59.99.95.140^
 ||59.99.95.141^
@@ -404563,6 +405056,7 @@
 ||59.99.95.146^
 ||59.99.95.147^
 ||59.99.95.148^
+||59.99.95.149^
 ||59.99.95.14^
 ||59.99.95.151^
 ||59.99.95.152^
@@ -406796,6 +407290,7 @@
 ||60.215.4.239^
 ||60.215.4.89^
 ||60.215.42.16^
+||60.215.59.108^
 ||60.215.61.56^
 ||60.215.63.173^
 ||60.216.122.109^
@@ -415655,6 +416150,7 @@
 ||60.254.49.198^
 ||60.254.49.201^
 ||60.254.49.215^
+||60.254.49.59^
 ||60.254.49.68^
 ||60.254.49.94^
 ||60.254.50.240^
@@ -416461,6 +416957,7 @@
 ||60.7.64.208^
 ||60.7.64.243^
 ||60.7.65.79^
+||60.7.8.43^
 ||60.7.94.111^
 ||60.7.99.254^
 ||60.9.155.86^
@@ -418676,8 +419173,10 @@
 ||61.3.124.33^
 ||61.3.124.34^
 ||61.3.124.39^
+||61.3.124.3^
 ||61.3.124.41^
 ||61.3.124.46^
+||61.3.124.51^
 ||61.3.124.60^
 ||61.3.124.65^
 ||61.3.124.71^
@@ -418689,6 +419188,7 @@
 ||61.3.124.95^
 ||61.3.125.102^
 ||61.3.125.107^
+||61.3.125.112^
 ||61.3.125.114^
 ||61.3.125.119^
 ||61.3.125.12^
@@ -418784,6 +419284,7 @@
 ||61.3.127.125^
 ||61.3.127.12^
 ||61.3.127.135^
+||61.3.127.138^
 ||61.3.127.149^
 ||61.3.127.158^
 ||61.3.127.178^
@@ -419479,6 +419980,7 @@
 ||61.52.135.117^
 ||61.52.135.125^
 ||61.52.135.144^
+||61.52.135.192^
 ||61.52.135.234^
 ||61.52.135.235^
 ||61.52.135.253^
@@ -420555,6 +421057,7 @@
 ||61.52.212.239^
 ||61.52.212.23^
 ||61.52.212.244^
+||61.52.212.250^
 ||61.52.212.251^
 ||61.52.212.27^
 ||61.52.212.30^
@@ -421391,6 +421894,7 @@
 ||61.52.39.101^
 ||61.52.39.109^
 ||61.52.39.110^
+||61.52.39.119^
 ||61.52.39.122^
 ||61.52.39.132^
 ||61.52.39.144^
@@ -421698,6 +422202,7 @@
 ||61.52.5.192^
 ||61.52.5.195^
 ||61.52.5.198^
+||61.52.5.217^
 ||61.52.5.226^
 ||61.52.5.60^
 ||61.52.50.109^
@@ -422270,6 +422775,7 @@
 ||61.52.62.94^
 ||61.52.62.97^
 ||61.52.63.110^
+||61.52.63.119^
 ||61.52.63.11^
 ||61.52.63.121^
 ||61.52.63.125^
@@ -422434,6 +422940,7 @@
 ||61.52.76.53^
 ||61.52.76.58^
 ||61.52.76.59^
+||61.52.76.72^
 ||61.52.76.73^
 ||61.52.76.74^
 ||61.52.76.87^
@@ -423632,6 +424139,7 @@
 ||61.53.123.149^
 ||61.53.123.154^
 ||61.53.123.161^
+||61.53.123.162^
 ||61.53.123.163^
 ||61.53.123.168^
 ||61.53.123.169^
@@ -423718,6 +424226,7 @@
 ||61.53.124.215^
 ||61.53.124.219^
 ||61.53.124.223^
+||61.53.124.225^
 ||61.53.124.227^
 ||61.53.124.230^
 ||61.53.124.232^
@@ -426273,6 +426782,7 @@
 ||61.54.240.166^
 ||61.54.240.198^
 ||61.54.240.19^
+||61.54.240.20^
 ||61.54.240.213^
 ||61.54.240.220^
 ||61.54.240.44^
@@ -426631,11 +427141,13 @@
 ||61.54.58.164^
 ||61.54.58.166^
 ||61.54.58.172^
+||61.54.58.190^
 ||61.54.58.192^
 ||61.54.58.193^
 ||61.54.58.197^
 ||61.54.58.198^
 ||61.54.58.202^
+||61.54.58.20^
 ||61.54.58.211^
 ||61.54.58.225^
 ||61.54.58.22^
@@ -426694,6 +427206,7 @@
 ||61.54.60.255^
 ||61.54.60.29^
 ||61.54.60.43^
+||61.54.60.4^
 ||61.54.60.55^
 ||61.54.60.68^
 ||61.54.60.74^
@@ -426715,6 +427228,7 @@
 ||61.54.61.163^
 ||61.54.61.168^
 ||61.54.61.172^
+||61.54.61.18^
 ||61.54.61.191^
 ||61.54.61.199^
 ||61.54.61.208^
@@ -427423,6 +427937,7 @@
 ||62.219.131.205^
 ||62.219.138.44^
 ||62.219.143.46^
+||62.219.155.61^
 ||62.219.163.162^
 ||62.219.164.224^
 ||62.219.194.210^
@@ -428623,6 +429138,7 @@
 ||71.183.150.34^
 ||71.187.60.8^
 ||71.19.144.47^
+||71.19.150.93^
 ||71.190.64.120^
 ||71.190.64.189^
 ||71.190.64.214^
@@ -429531,6 +430047,7 @@
 ||77.45.182.113^
 ||77.45.182.196^
 ||77.45.183.124^
+||77.45.183.39^
 ||77.45.184.77^
 ||77.45.185.57^
 ||77.45.185.89^
@@ -431734,6 +432251,7 @@
 ||84.22.38.175^
 ||84.221.143.108^
 ||84.224.144.27^
+||84.224.162.170^
 ||84.224.177.80^
 ||84.224.213.50^
 ||84.228.102.152^
@@ -431947,6 +432465,7 @@
 ||85.105.77.54^
 ||85.105.82.225^
 ||85.105.82.94^
+||85.105.9.152^
 ||85.105.98.84^
 ||85.106.129.231^
 ||85.106.161.174^
@@ -435127,6 +435646,7 @@
 ||95.152.49.54^
 ||95.152.5.232^
 ||95.152.9.183^
+||95.153.241.63^
 ||95.153.94.241^
 ||95.154.20.231^
 ||95.154.244.200^
@@ -436600,6 +437120,7 @@
 ||access-24.jp^
 ||access-cash.ae.org^
 ||access-om.neomeric.us^
+||access-one.us^
 ||access-to-web.com^
 ||accessclub.jp^
 ||accessdig.com^
@@ -436777,6 +437298,7 @@
 ||acht-stuecken.de^
 ||achuanchaolihai.cn^
 ||aci.serabd.com^
+||aciabogados.com^
 ||aciitaly.com^
 ||acilevarkadasi.com^
 ||acilisbalon.com^
@@ -437193,6 +437715,7 @@
 ||admin.greenlightcr.com^
 ||admin.hopehorseback.org^
 ||admin.jpcar.mystand.pt^
+||admin.mobilezenie.com^
 ||admin.searchlowestprice.com^
 ||admin.solissol.com^
 ||admin.staging.buildsmart.io^
@@ -437372,7 +437895,6 @@
 ||adventureexplorer.in^
 ||adventurehr.com^
 ||adventureitdate.com^
-||adventureits.com^
 ||adventuremania.com^
 ||adventurersafaris.com^
 ||adventuresofarchibald.com^
@@ -437792,6 +438314,7 @@
 ||agengarcinia5000.com^
 ||agenity.com^
 ||agenlama.com^
+||agenmovie.xyz^
 ||agent-seo.jp^
 ||agent.ken.by^
 ||agent2.icu^
@@ -444808,6 +445331,7 @@
 ||barcelonaevent.es^
 ||barcelonakartingcenter.com^
 ||barchaklem.com^
+||barcionstw.eastus.cloudapp.azure.com^
 ||barcla.ug^
 ||barclaysdownloads.com^
 ||barcoofoods.ir^
@@ -447093,6 +447617,7 @@
 ||bj5800.com^
 ||bjarndahl.dk^
 ||bjbus.net^
+||bjconstructions.in^
 ||bjdd.org^
 ||bjenkins.webview.consulting^
 ||bjenzer.com^
@@ -448132,6 +448657,7 @@
 ||bnpartnersweb.com^
 ||bnpgrup.com^
 ||bnqzjy.cn^
+||bnrbook.com^
 ||bnrnews.id^
 ||bnsddfhjdfgvbxc.ru^
 ||bnsgroupbd.com^
@@ -448882,6 +449408,7 @@
 ||braner.com.ua^
 ||branfinancial.com^
 ||branner-chile.com^
+||brannon-powlowski25d.xyz^
 ||brannudd.com^
 ||brantech.com^
 ||brar.aminfortgreene.com^
@@ -449882,6 +450409,7 @@
 ||buysellfx24.ru^
 ||buysmart365.net^
 ||buysmartwebmall.com^
+||buythebest.pk^
 ||buytotake.online^
 ||buytwitterlike.com^
 ||buyuksigorta.com^
@@ -451202,6 +451730,7 @@
 ||cashoutrefitips.com^
 ||cashpickup.slmicrocredit.com^
 ||cashslip.info^
+||cashtunel.com^
 ||cashyinvestment.org^
 ||casimiroartes.es^
 ||casinarium.com^
@@ -453774,6 +454303,7 @@
 ||clubzone.ca^
 ||cluebazar.com^
 ||clukva.ru^
+||clurbgolf.com^
 ||clurit.com^
 ||clusdirectory.xyz^
 ||cluster-mixture.gq^
@@ -453990,6 +454520,7 @@
 ||coastmedicalservice.com^
 ||coastmotorsupply.com^
 ||coastsignworks.com^
+||coastwidewaterproofing.com.au^
 ||coatforwinter.com^
 ||coavce.com^
 ||cobam.xyz^
@@ -456013,6 +456544,7 @@
 ||cronolux.com.br^
 ||croodly.com^
 ||crookedchristicraddick.com^
+||crooks-cooper24g.xyz^
 ||croos.org^
 ||crope.shop^
 ||cropfoods.com^
@@ -457267,7 +457799,6 @@
 ||dar-sana.com^
 ||darajelita.com^
 ||daralsalam-mall.com^
-||daralsaqi.com^
 ||darapartment.com^
 ||darasrszs.online^
 ||darassalam.ch^
@@ -457376,7 +457907,6 @@
 ||dasheriemagazine.com^
 ||dashfiles.tk^
 ||dashkevichseo.ru^
-||dashonweb.com^
 ||dashudance.com^
 ||dashvaanjil.mn^
 ||dasin-obchudek.cz^
@@ -457704,6 +458234,7 @@
 ||dbravo.pro^
 ||dbs-ebank.com^
 ||dbsa-dream.com^
+||dbsandbox.ca^
 ||dbsenvironmental.co.uk^
 ||dbsgear.com^
 ||dbsktoporder.yolasite.com^
@@ -458612,6 +459143,7 @@
 ||denmaar.hplbusiness.com^
 ||denmarkheating.net^
 ||denmaytre.vn^
+||dennis-hill25lw.xyz^
 ||dennis-roth.de^
 ||dennishester.com^
 ||dennisisasshole.com^
@@ -461288,6 +461820,9 @@
 ||down.posti-fi-fsa.top^
 ||down.posti-fi-fsaq.top^
 ||down.posti-fi-fwa.top^
+||down.posti-fi-ij.top^
+||down.posti-fi-in.top^
+||down.posti-fi-iz.top^
 ||down.pzchao.com^
 ||down.qm188.com^
 ||down.qqfarmer.com.cn^
@@ -463499,6 +464034,7 @@
 ||egyptmotours.com^
 ||egyptpharaohstours.com^
 ||egyshadowmen.com^
+||egyutthato.eu^
 ||egyuttkonnyebb.zolitoth.com^
 ||egyvision.medicahealthy.net^
 ||egywebtest.ml^
@@ -464680,6 +465216,7 @@
 ||ennessehospitality.id^
 ||ennovate.elin.co.za^
 ||eno.si^
+||enolil-loo.com^
 ||enorichie.net^
 ||enorka.info^
 ||enosburgreading.pbworks.com^
@@ -466653,6 +467190,7 @@
 ||faithcompassion.com^
 ||faithconstructionltd.co.uk^
 ||faithfight.my.id^
+||faithmethodistcheras.org^
 ||faithmontessorischools.com^
 ||faithoasis.000webhostapp.com^
 ||faithworkx.com^
@@ -467923,6 +468461,7 @@
 ||findyourvoice.ca^
 ||fine-art-line.de^
 ||fine.black^
+||fineartgallerym.com^
 ||fineconera.com^
 ||finefeather.info^
 ||finefoodsfrozen.com^
@@ -471551,6 +472090,7 @@
 ||girltalkza.co.za^
 ||girlydesignart.com^
 ||gironynavarro.com^
+||girotexuniformes.com^
 ||girraj2016.gtranzit.com^
 ||girrajwadi.com^
 ||gisa.company^
@@ -471640,6 +472180,7 @@
 ||glafka.com^
 ||glambooth.nl^
 ||glamoroushairextension.com^
+||glamorouspk.com^
 ||glamour.rosolutions.com.mx^
 ||glamourgarden-lb.com^
 ||glamourlounge.org^
@@ -472396,6 +472937,7 @@
 ||gordonmilktransport.com^
 ||gordonruss.com^
 ||gordyssensors.com^
+||gorecycle.fahadjutt.com^
 ||gorenotoservisi.net^
 ||gorestruly.com^
 ||goretimmo.lu^
@@ -473552,6 +474094,7 @@
 ||guneyaski.com^
 ||gungazcomputer.co.ke^
 ||gunk.insol.be^
+||gunma2u.com^
 ||gunmak-com.tk^
 ||gunnarasgeir.com^
 ||gunnersexcavating.com^
@@ -475903,6 +476446,7 @@
 ||hollywoodsmileeg.com^
 ||holmdalehouse.co.uk^
 ||holmesgroup-com.azurewebsites.net^
+||holmesprpmgmt.com^
 ||holmnkolbas.com^
 ||holmsater.se^
 ||holod24.by^
@@ -476596,6 +477140,7 @@
 ||hpmaytinhtaophongcach.com^
 ||hpmwqjub.com^
 ||hpq8fa.db.files.1drv.com^
+||hprosacco25i.xyz^
 ||hprpc.cn^
 ||hps-sk.sk^
 ||hps.nz^
@@ -479172,6 +479717,7 @@
 ||instantbonheur.fr^
 ||instantcashflowtoday.com.ng^
 ||instantclients.network^
+||instantindialoan.com^
 ||instanttaxsolutions.mobi^
 ||instanttechnology.com.au^
 ||instantworldpay.com^
@@ -479996,6 +480542,7 @@
 ||isciyizbiz.com^
 ||iscleanone.com^
 ||isclimatechangeahoax.com^
+||iscoegypt.com^
 ||iscoming.ir^
 ||iscon.com.br^
 ||iscondisth.com^
@@ -480051,7 +480598,6 @@
 ||iskro.textronic.info^
 ||iskyservice.ru^
 ||islaholics.com^
-||islamabadtrafficpolice.gov.pk^
 ||islamabout.com^
 ||islamappen.se^
 ||islamforall.tv^
@@ -481864,6 +482410,7 @@
 ||jollycharm.com^
 ||jollyemma.com^
 ||jolyscortinas.com.br^
+||jomansea.com^
 ||jomar2020.com.br^
 ||jomblo.com^
 ||jomhermonex.com^
@@ -483243,6 +483790,7 @@
 ||kasperskysecurity.club^
 ||kasrasanatsepahan.com^
 ||kassa.hostsites.ru^
+||kassandra5024d.xyz^
 ||kassconnect.ru^
 ||kasshmira.com^
 ||kassohome.com.tr^
@@ -483887,7 +484435,6 @@
 ||khannen.com.vn^
 ||khannen.vn^
 ||khanqahebrahimi.com^
-||khantil.com^
 ||khantipong.com^
 ||khaochills.com^
 ||khaoden.tech^
@@ -485749,6 +486296,7 @@
 ||lab.valvolari.it^
 ||lab.ydigital.asia^
 ||lab1.ozaki-kyousei.com^
+||lab18.it^
 ||lab2.e-century.pl^
 ||lab5.hu^
 ||lab6.com.br^
@@ -490787,6 +491335,7 @@
 ||manageitrisks.com^
 ||management.vkims.com^
 ||managementtop.id^
+||managemysalon.in^
 ||managemyshoes.tools^
 ||manageone.co.th^
 ||manageprint.in^
@@ -491168,6 +491717,7 @@
 ||marek-paysage-concept.fr^
 ||marek.in^
 ||marekvoprsal.cz^
+||marel.com.br^
 ||marellengifts.com^
 ||maremarius.pt^
 ||marematto.it^
@@ -492448,6 +492998,7 @@
 ||meditec.ma^
 ||mediterraneavacanze.com^
 ||meditheraphy.com^
+||meditreat.itwebservice.in^
 ||meditsinanarodnaya.ru^
 ||medius.ge^
 ||mediusvp.com^
@@ -494624,6 +495175,7 @@
 ||mojang.com.br^
 ||mojehaftom.com^
 ||mojewnetrza.pl^
+||mojno--vse.ru^
 ||mojo-studios.co.uk^
 ||mojorockstar.com^
 ||mojstudent.net^
@@ -495378,6 +495930,7 @@
 ||mrpower.ir^
 ||mrprintoke.com^
 ||mrquick.co.il^
+||mrsambarbershop.nl^
 ||mrsbow.com^
 ||mrsconnect.org^
 ||mrsdiggs.com^
@@ -495978,6 +496531,7 @@
 ||mvid.com^
 ||mvidl.site^
 ||mvisionproperties.com^
+||mvldesign.ca^
 ||mvm368.com^
 ||mvmskpd.com^
 ||mvns.railfan.net^
@@ -497312,6 +497866,7 @@
 ||nelsonhelps.com^
 ||nelsonhostingcom.000webhostapp.com^
 ||nelsonpto.org^
+||nelsonsbutchers.co.uk^
 ||nelsonsilveti.com^
 ||neltac.com^
 ||nelyvos.nl^
@@ -498646,7 +499201,6 @@
 ||no1angelsescort.com^
 ||no1spinningfields.90degrees.digital^
 ||no1websitedesigner.com^
-||no2politics.com^
 ||no70.fun^
 ||noabuseshere.top^
 ||noach.nl^
@@ -499936,6 +500490,7 @@
 ||ohako.com.my^
 ||ohamburguer.com.br^
 ||ohanadev.com^
+||ohatsbd.com^
 ||ohdratdigital.com^
 ||ohe.ie^
 ||ohelloguyzzqq.com^
@@ -500240,6 +500795,7 @@
 ||omagroup.ru^
 ||omaharefugees.com^
 ||omahduwur.com^
+||omaia.org^
 ||omaint.ml^
 ||omalleyco-my.sharepoint.com^
 ||omalll.com^
@@ -505870,6 +506426,7 @@
 ||promodont.com^
 ||promokonyara.ru^
 ||promolatinconferences.com^
+||promolyko.com^
 ||promomitsubishitermurah.net^
 ||promonoble.com^
 ||promootzie.nl^
@@ -507285,6 +507842,7 @@
 ||quickpickapp.co^
 ||quickreachmedia.com^
 ||quicksaleecuador.com^
+||quickshine.co.ke^
 ||quickstorevn.com^
 ||quicktechsupport247.com^
 ||quicktowtowing.com^
@@ -509386,6 +509944,7 @@
 ||rgdecor.org^
 ||rgfloors.com.au^
 ||rgitabit.in^
+||rgleason25s.xyz^
 ||rglgrupomedico.com.mx^
 ||rgmobilegossip.com^
 ||rgmvanijya.com^
@@ -510230,6 +510789,7 @@
 ||rosemaryromero.com.br^
 ||rosemiracle.com^
 ||rosemurphy.co.uk^
+||rosenbaum-jaida24nz.xyz^
 ||rosenfeldcapital.com^
 ||rosenlaw.cratima.com^
 ||roseperfeito.com.br^
@@ -514148,6 +514708,7 @@
 ||shatabbytek.com^
 ||shataikok.com^
 ||shatelnews.ir^
+||shatteredglass.io^
 ||shaukya.com^
 ||shaulla.store^
 ||shaunodonnell.com^
@@ -516009,6 +516570,7 @@
 ||smartlync.pk^
 ||smartmadira.com^
 ||smartmassive.ru^
+||smartmatrixs.com^
 ||smartmobilelearning.co.za^
 ||smartmoneylife.com^
 ||smartmovie.com.ua^
@@ -516971,6 +517533,7 @@
 ||sosenfantsburkinafaso.fr^
 ||sosexymagazine.com^
 ||sosflam.com^
+||sosgsm.fr^
 ||sosh47.citycheb.ru^
 ||sosoab.com^
 ||sosofoto.cz^
@@ -521610,6 +522173,7 @@
 ||tecnologiatech.com^
 ||tecnologiaz.com^
 ||tecnologicainformatica.com.br^
+||tecnologyschool.com^
 ||tecnolora.com^
 ||tecnoloxia.com^
 ||tecnopc.info^
@@ -524374,6 +524938,7 @@
 ||toby-warren.com^
 ||tobyetc.com^
 ||tobysherman.com^
+||tocaima.co^
 ||tocakids.resultaweb.com.br^
 ||tocgiajojo.com^
 ||tochkae.ru^
@@ -525501,6 +526066,7 @@
 ||tresnexus.com^
 ||treterhef.download^
 ||tretthing-bg.site^
+||treutel-jamir25ju.xyz^
 ||trevellinglove.com^
 ||trevinos.net^
 ||trevorchristensen.com^
@@ -528203,6 +528769,7 @@
 ||vastraindia.com^
 ||vastralaya.shop^
 ||vastuanalyst.com^
+||vastubless.com^
 ||vastuvidyaarchitects.com^
 ||vasudhagoodharvest.com^
 ||vasumadhi.com^
@@ -529548,6 +530115,7 @@
 ||vladetel.org^
 ||vladimirfilin.com^
 ||vladimirfilin.ru^
+||vladimirinternational.com^
 ||vladneta.lt^
 ||vladsever.ru^
 ||vladsp.ru^
@@ -530546,6 +531114,7 @@
 ||web.emergingsun.com^
 ||web.emsfabrik.de^
 ||web.eng.ubu.ac.th^
+||web.geetle.ga^
 ||web.geomegasoft.net^
 ||web.golden-goblin.com^
 ||web.gotham.com.au^
@@ -531360,6 +531929,7 @@
 ||whyasksolution.com^
 ||whybowl.thebotogs.com^
 ||whyepicshop.com^
+||whynt.xyz^
 ||whysquare.co.nz^
 ||whystudio.cn^
 ||whytech.info^
@@ -532427,6 +532997,7 @@
 ||wrrodrigo.com^
 ||wrtech.com.pl^
 ||wrusnollet.com^
+||wrzucacz.pl^
 ||wrzutka.co^
 ||ws-ebavisapia01-dll.ir^
 ||ws3lfkm.com^
@@ -532874,6 +533445,7 @@
 ||xhcmnews.com^
 ||xhd.qhv.mybluehost.me^
 ||xhencheng.tk^
+||xherzog24pv.xyz^
 ||xhjclq.ch.files.1drv.com^
 ||xhs9a81.com^
 ||xhsdxm.com^
@@ -534733,6 +535305,7 @@
 ||zafirotiendas.com^
 ||zagnet.pl^
 ||zagogulina.com^
+||zagoradesertcamp.com^
 ||zagrodazbyszka.pl^
 ||zagros-shahrekord.ir^
 ||zagrosenergygroup.com^
@@ -534788,6 +535361,7 @@
 ||zakopane.utazas.hu^
 ||zakopanedomki.com.pl^
 ||zakosciele66.cba.pl^
+||zakra.tecnasulstore.com.br^
 ||zakrahgroup.com^
 ||zakriasons.co^
 ||zakromanoff.com^
diff --git a/urlhaus-filter-bind-online.conf b/urlhaus-filter-bind-online.conf
index 4d75501f..f92a0b5b 100644
--- a/urlhaus-filter-bind-online.conf
+++ b/urlhaus-filter-bind-online.conf
@@ -1,5 +1,5 @@
 # Title: Online Malicious Domains BIND Blocklist
-# Updated: Thu, 25 Mar 2021 12:12:40 UTC
+# Updated: Fri, 26 Mar 2021 00:12:29 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -19,7 +19,6 @@ zone "360.lcy2zzx.pw" { type master; notify no; file "null.zone.file"; };
 zone "360down7.miiyun.cn" { type master; notify no; file "null.zone.file"; };
 zone "8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com" { type master; notify no; file "null.zone.file"; };
 zone "8poieq.bn.files.1drv.com" { type master; notify no; file "null.zone.file"; };
-zone "99centsdigitals.com" { type master; notify no; file "null.zone.file"; };
 zone "abcd.bg" { type master; notify no; file "null.zone.file"; };
 zone "abclicks.in" { type master; notify no; file "null.zone.file"; };
 zone "abissnet.net" { type master; notify no; file "null.zone.file"; };
@@ -27,11 +26,12 @@ zone "aboveandbelow.com.au" { type master; notify no; file "null.zone.file"; };
 zone "absoftechworld.com" { type master; notify no; file "null.zone.file"; };
 zone "absupplies.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "abyssos.eu" { type master; notify no; file "null.zone.file"; };
+zone "academyshademani.com" { type master; notify no; file "null.zone.file"; };
 zone "acbick.com" { type master; notify no; file "null.zone.file"; };
 zone "accounts.thesmarttechhub.com" { type master; notify no; file "null.zone.file"; };
 zone "aceeprc.com.aceeprc.com" { type master; notify no; file "null.zone.file"; };
 zone "acellr.co.uk" { type master; notify no; file "null.zone.file"; };
-zone "aclassapart.in" { type master; notify no; file "null.zone.file"; };
+zone "aciabogados.com" { type master; notify no; file "null.zone.file"; };
 zone "acteon.com.ar" { type master; notify no; file "null.zone.file"; };
 zone "activateyourdiscount.com" { type master; notify no; file "null.zone.file"; };
 zone "activecost.com.au" { type master; notify no; file "null.zone.file"; };
@@ -49,6 +49,7 @@ zone "agemn.co.za" { type master; notify no; file "null.zone.file"; };
 zone "agenciadigitalwdys.com" { type master; notify no; file "null.zone.file"; };
 zone "agenciatabletshouse.com.br" { type master; notify no; file "null.zone.file"; };
 zone "agenda.gmelloinformatica.com.br" { type master; notify no; file "null.zone.file"; };
+zone "agenmovie.xyz" { type master; notify no; file "null.zone.file"; };
 zone "agentt.ac.ug" { type master; notify no; file "null.zone.file"; };
 zone "agile8studio.com" { type master; notify no; file "null.zone.file"; };
 zone "agmcarpetcare.co.uk" { type master; notify no; file "null.zone.file"; };
@@ -60,7 +61,6 @@ zone "al-wahd.com" { type master; notify no; file "null.zone.file"; };
 zone "alasdemariposas.org" { type master; notify no; file "null.zone.file"; };
 zone "alemelektronik.com" { type master; notify no; file "null.zone.file"; };
 zone "alena1971.es" { type master; notify no; file "null.zone.file"; };
-zone "alertlauncher.fr" { type master; notify no; file "null.zone.file"; };
 zone "alexdubai.com.aldiabsteel.com" { type master; notify no; file "null.zone.file"; };
 zone "alka.institute" { type master; notify no; file "null.zone.file"; };
 zone "allforcreative.com.au" { type master; notify no; file "null.zone.file"; };
@@ -72,6 +72,7 @@ zone "amarresdeamorymaestroshechiceros.com" { type master; notify no; file "null
 zone "amarteargentina.com.ar" { type master; notify no; file "null.zone.file"; };
 zone "amenyan.zouri.jp" { type master; notify no; file "null.zone.file"; };
 zone "amos524.org" { type master; notify no; file "null.zone.file"; };
+zone "ams.alvinasschools.org.ng" { type master; notify no; file "null.zone.file"; };
 zone "anantam.net.in" { type master; notify no; file "null.zone.file"; };
 zone "andreelapeyre.com" { type master; notify no; file "null.zone.file"; };
 zone "andremaraisbeleggings.co.za" { type master; notify no; file "null.zone.file"; };
@@ -91,10 +92,9 @@ zone "api.sampy.io" { type master; notify no; file "null.zone.file"; };
 zone "aplicativoparasindicato.com.br" { type master; notify no; file "null.zone.file"; };
 zone "apoolcondo.com" { type master; notify no; file "null.zone.file"; };
 zone "app.adsensearticle.com" { type master; notify no; file "null.zone.file"; };
-zone "app.explicitsurveys.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "app.prerana.info" { type master; notify no; file "null.zone.file"; };
 zone "apps.saintsoporte.com" { type master; notify no; file "null.zone.file"; };
-zone "aras.iuc.ac" { type master; notify no; file "null.zone.file"; };
+zone "aqv.news" { type master; notify no; file "null.zone.file"; };
 zone "areyoulivingwell.com" { type master; notify no; file "null.zone.file"; };
 zone "arsapetrolab.com" { type master; notify no; file "null.zone.file"; };
 zone "artedibujoyarquitectura.com" { type master; notify no; file "null.zone.file"; };
@@ -113,11 +113,12 @@ zone "avissrilanka.com" { type master; notify no; file "null.zone.file"; };
 zone "ayamallah.com" { type master; notify no; file "null.zone.file"; };
 zone "azmeasurement.com" { type master; notify no; file "null.zone.file"; };
 zone "azraktours.com" { type master; notify no; file "null.zone.file"; };
-zone "b2b.toptanakaryakit.com.tr" { type master; notify no; file "null.zone.file"; };
 zone "backgrounds.pk" { type master; notify no; file "null.zone.file"; };
 zone "backup.agewsage.com" { type master; notify no; file "null.zone.file"; };
 zone "badeggdesign.com" { type master; notify no; file "null.zone.file"; };
+zone "balealgodon.mx" { type master; notify no; file "null.zone.file"; };
 zone "bangkok-orchids.com" { type master; notify no; file "null.zone.file"; };
+zone "barcionstw.eastus.cloudapp.azure.com" { type master; notify no; file "null.zone.file"; };
 zone "bary.sz4h.com" { type master; notify no; file "null.zone.file"; };
 zone "basma.com.kw" { type master; notify no; file "null.zone.file"; };
 zone "bausch.kr-atlas.monaxikoslykos@zytrox.tk" { type master; notify no; file "null.zone.file"; };
@@ -126,7 +127,6 @@ zone "bbia.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "bcmt.elin.co.za" { type master; notify no; file "null.zone.file"; };
 zone "bcrg.co.za" { type master; notify no; file "null.zone.file"; };
 zone "bearcatpumps.com.cn" { type master; notify no; file "null.zone.file"; };
-zone "beatyamerican.com" { type master; notify no; file "null.zone.file"; };
 zone "beautincollagen.rs" { type master; notify no; file "null.zone.file"; };
 zone "bekape.co.id" { type master; notify no; file "null.zone.file"; };
 zone "bespokeweddings.ie" { type master; notify no; file "null.zone.file"; };
@@ -134,6 +134,8 @@ zone "bestcarenepal.com" { type master; notify no; file "null.zone.file"; };
 zone "betone.co.kr" { type master; notify no; file "null.zone.file"; };
 zone "betycopaints.com" { type master; notify no; file "null.zone.file"; };
 zone "beveragesmiami.solucioneslink.com" { type master; notify no; file "null.zone.file"; };
+zone "bhavaniengineering.com" { type master; notify no; file "null.zone.file"; };
+zone "bigbag.wootraining.certificacion.cl" { type master; notify no; file "null.zone.file"; };
 zone "bilbosaquet.ug" { type master; notify no; file "null.zone.file"; };
 zone "bilhen.co.za" { type master; notify no; file "null.zone.file"; };
 zone "billing.rahitechnosoft.com" { type master; notify no; file "null.zone.file"; };
@@ -141,11 +143,10 @@ zone "birdi.elin.co.za" { type master; notify no; file "null.zone.file"; };
 zone "birminghamlink.org" { type master; notify no; file "null.zone.file"; };
 zone "blog.callensaxen.com" { type master; notify no; file "null.zone.file"; };
 zone "blog.oyinblogs.com" { type master; notify no; file "null.zone.file"; };
-zone "blog.takbelit.com" { type master; notify no; file "null.zone.file"; };
 zone "bmlifestyle.co.uk" { type master; notify no; file "null.zone.file"; };
+zone "bnrbook.com" { type master; notify no; file "null.zone.file"; };
 zone "bnrnews.id" { type master; notify no; file "null.zone.file"; };
 zone "bodenstein.co.za" { type master; notify no; file "null.zone.file"; };
-zone "bolnicaloznica.rs" { type master; notify no; file "null.zone.file"; };
 zone "booksearch.com" { type master; notify no; file "null.zone.file"; };
 zone "bounces.mi-fs.com" { type master; notify no; file "null.zone.file"; };
 zone "bpo.correct.go.th" { type master; notify no; file "null.zone.file"; };
@@ -159,23 +160,21 @@ zone "brightonrooms.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "brightstarshop.com" { type master; notify no; file "null.zone.file"; };
 zone "browardinsurancemiami.solucioneslink.com" { type master; notify no; file "null.zone.file"; };
 zone "bt2.elin.co.za" { type master; notify no; file "null.zone.file"; };
-zone "btdapi.robotake.com" { type master; notify no; file "null.zone.file"; };
 zone "bucrinsuranlceonlines.com" { type master; notify no; file "null.zone.file"; };
 zone "buenavista.co" { type master; notify no; file "null.zone.file"; };
-zone "buigiaphat.com.vn" { type master; notify no; file "null.zone.file"; };
 zone "bullseyemedia.in" { type master; notify no; file "null.zone.file"; };
 zone "busandvanrentalmalaysia.com" { type master; notify no; file "null.zone.file"; };
 zone "buscascolegios.diit.cl" { type master; notify no; file "null.zone.file"; };
 zone "business.softberg.ro" { type master; notify no; file "null.zone.file"; };
 zone "buyingmusiconline.com" { type master; notify no; file "null.zone.file"; };
-zone "buypropertyfast.com" { type master; notify no; file "null.zone.file"; };
 zone "bwsr.eu" { type master; notify no; file "null.zone.file"; };
 zone "c.oooooooooo.ga" { type master; notify no; file "null.zone.file"; };
 zone "c0140529.ferozo.com" { type master; notify no; file "null.zone.file"; };
+zone "caballo.com.au" { type master; notify no; file "null.zone.file"; };
 zone "cacapavaonline.sdserver144.com.br" { type master; notify no; file "null.zone.file"; };
+zone "calgaryautorepairservice.com" { type master; notify no; file "null.zone.file"; };
 zone "callbury.in" { type master; notify no; file "null.zone.file"; };
 zone "camminachetipassa.it" { type master; notify no; file "null.zone.file"; };
-zone "campusvirtual.cepsanjuanbosco.net.pe" { type master; notify no; file "null.zone.file"; };
 zone "cancer.educandome.co" { type master; notify no; file "null.zone.file"; };
 zone "capitalgroup-kw.com" { type master; notify no; file "null.zone.file"; };
 zone "capitalnewsagency.com" { type master; notify no; file "null.zone.file"; };
@@ -188,12 +187,10 @@ zone "cazyacustomfurniture.com" { type master; notify no; file "null.zone.file";
 zone "ccauthority.net" { type master; notify no; file "null.zone.file"; };
 zone "cdaonline.com.ar" { type master; notify no; file "null.zone.file"; };
 zone "cec.asso.ac-amiens.fr" { type master; notify no; file "null.zone.file"; };
-zone "cellas.sk" { type master; notify no; file "null.zone.file"; };
 zone "cendekiabinaaksara.com" { type master; notify no; file "null.zone.file"; };
 zone "cespol-bote.com.mx" { type master; notify no; file "null.zone.file"; };
 zone "cfs5.tistory.com" { type master; notify no; file "null.zone.file"; };
 zone "ch.rmu.ac.th" { type master; notify no; file "null.zone.file"; };
-zone "changematterscounselling.com" { type master; notify no; file "null.zone.file"; };
 zone "chardhamdodham.com" { type master; notify no; file "null.zone.file"; };
 zone "cheacrilnsurances.com" { type master; notify no; file "null.zone.file"; };
 zone "chealablilitycarinsurances.com" { type master; notify no; file "null.zone.file"; };
@@ -201,15 +198,14 @@ zone "chezalice.co.za" { type master; notify no; file "null.zone.file"; };
 zone "childselect.com" { type master; notify no; file "null.zone.file"; };
 zone "chinhdropfile.myvnc.com" { type master; notify no; file "null.zone.file"; };
 zone "chinhdropfile80.myvnc.com" { type master; notify no; file "null.zone.file"; };
-zone "chipmania.it" { type master; notify no; file "null.zone.file"; };
 zone "cible-energy.com" { type master; notify no; file "null.zone.file"; };
 zone "cifeer.net" { type master; notify no; file "null.zone.file"; };
 zone "citycapproperty.ru" { type master; notify no; file "null.zone.file"; };
 zone "cityglobalgospel.com" { type master; notify no; file "null.zone.file"; };
 zone "civi.istmejia.com" { type master; notify no; file "null.zone.file"; };
 zone "cleanbydesignllc.com" { type master; notify no; file "null.zone.file"; };
-zone "clim34000.fr" { type master; notify no; file "null.zone.file"; };
 zone "cloud.fc.co.mz" { type master; notify no; file "null.zone.file"; };
+zone "clurbgolf.com" { type master; notify no; file "null.zone.file"; };
 zone "codsambal.com" { type master; notify no; file "null.zone.file"; };
 zone "colinde.pricesne.com" { type master; notify no; file "null.zone.file"; };
 zone "colorpak.pl" { type master; notify no; file "null.zone.file"; };
@@ -231,7 +227,6 @@ zone "creationskateboards.com" { type master; notify no; file "null.zone.file";
 zone "crecerco.com" { type master; notify no; file "null.zone.file"; };
 zone "crittersbythebay.com" { type master; notify no; file "null.zone.file"; };
 zone "crm.notariavieitoyvelamazan.com" { type master; notify no; file "null.zone.file"; };
-zone "crmmanivela.net" { type master; notify no; file "null.zone.file"; };
 zone "crscorretordeimoveis.com.br" { type master; notify no; file "null.zone.file"; };
 zone "cse-engineer.com" { type master; notify no; file "null.zone.file"; };
 zone "csnserver.com" { type master; notify no; file "null.zone.file"; };
@@ -278,7 +273,6 @@ zone "destinymc.co.za" { type master; notify no; file "null.zone.file"; };
 zone "detorre.es" { type master; notify no; file "null.zone.file"; };
 zone "dev-interestingtech.pantheonsite.io" { type master; notify no; file "null.zone.file"; };
 zone "dev.sebpo.net" { type master; notify no; file "null.zone.file"; };
-zone "dezcom.com" { type master; notify no; file "null.zone.file"; };
 zone "dfcf.91756.cn" { type master; notify no; file "null.zone.file"; };
 zone "dfsfcsfcdsfsdvcfsvcscv.com" { type master; notify no; file "null.zone.file"; };
 zone "diamantenegro.mi-fs.com" { type master; notify no; file "null.zone.file"; };
@@ -301,7 +295,6 @@ zone "dom.daf.free.fr" { type master; notify no; file "null.zone.file"; };
 zone "doncedyhall.com" { type master; notify no; file "null.zone.file"; };
 zone "donghobinhminh.com" { type master; notify no; file "null.zone.file"; };
 zone "dongphuctop.com" { type master; notify no; file "null.zone.file"; };
-zone "donwnloasecury.ath.cx" { type master; notify no; file "null.zone.file"; };
 zone "dosame.com" { type master; notify no; file "null.zone.file"; };
 zone "dosman.pl" { type master; notify no; file "null.zone.file"; };
 zone "dovberger.com" { type master; notify no; file "null.zone.file"; };
@@ -309,6 +302,9 @@ zone "down.flash-plays.com" { type master; notify no; file "null.zone.file"; };
 zone "down.pcclear.com" { type master; notify no; file "null.zone.file"; };
 zone "down.posti-fi-fsa.top" { type master; notify no; file "null.zone.file"; };
 zone "down.posti-fi-fwa.top" { type master; notify no; file "null.zone.file"; };
+zone "down.posti-fi-ij.top" { type master; notify no; file "null.zone.file"; };
+zone "down.posti-fi-in.top" { type master; notify no; file "null.zone.file"; };
+zone "down.posti-fi-iz.top" { type master; notify no; file "null.zone.file"; };
 zone "down.udashi.com" { type master; notify no; file "null.zone.file"; };
 zone "down.webbora.com" { type master; notify no; file "null.zone.file"; };
 zone "down1.arpun.com" { type master; notify no; file "null.zone.file"; };
@@ -325,7 +321,6 @@ zone "dragonsknot.com" { type master; notify no; file "null.zone.file"; };
 zone "drbaby.com.sa" { type master; notify no; file "null.zone.file"; };
 zone "drohnen.ensenanzainteligente.com" { type master; notify no; file "null.zone.file"; };
 zone "drools-moved.46999.n3.nabble.com" { type master; notify no; file "null.zone.file"; };
-zone "drrohanfonseca.com" { type master; notify no; file "null.zone.file"; };
 zone "drsha.innovativesolutions.mobi" { type master; notify no; file "null.zone.file"; };
 zone "dsenterprize.co.za" { type master; notify no; file "null.zone.file"; };
 zone "dsspainting.com" { type master; notify no; file "null.zone.file"; };
@@ -339,19 +334,15 @@ zone "e-commerce.saleensuporte.com.br" { type master; notify no; file "null.zone
 zone "e.sldov.ru" { type master; notify no; file "null.zone.file"; };
 zone "ebruyatkin.com" { type master; notify no; file "null.zone.file"; };
 zone "econews.treegle.org" { type master; notify no; file "null.zone.file"; };
-zone "edelweissdecoration.com" { type master; notify no; file "null.zone.file"; };
 zone "efficientegroup.com" { type master; notify no; file "null.zone.file"; };
 zone "elliot.newreadermedia.net" { type master; notify no; file "null.zone.file"; };
-zone "emaids.co.za" { type master; notify no; file "null.zone.file"; };
 zone "en.baoend.com" { type master; notify no; file "null.zone.file"; };
 zone "enc-tech.com" { type master; notify no; file "null.zone.file"; };
 zone "endurotanzania.co.tz" { type master; notify no; file "null.zone.file"; };
-zone "enkonooh.com" { type master; notify no; file "null.zone.file"; };
 zone "ennovate.elin.co.za" { type master; notify no; file "null.zone.file"; };
 zone "enriquecendocomconsorcio.com.br" { type master; notify no; file "null.zone.file"; };
 zone "envios.petpienso.cl" { type master; notify no; file "null.zone.file"; };
 zone "equimination.ee" { type master; notify no; file "null.zone.file"; };
-zone "es.paymelist.com" { type master; notify no; file "null.zone.file"; };
 zone "escola.probommar.org.br" { type master; notify no; file "null.zone.file"; };
 zone "esnconsultants.com" { type master; notify no; file "null.zone.file"; };
 zone "essentia.org.br" { type master; notify no; file "null.zone.file"; };
@@ -363,15 +354,14 @@ zone "extrovertoffers.com" { type master; notify no; file "null.zone.file"; };
 zone "f1sol.com" { type master; notify no; file "null.zone.file"; };
 zone "familydentist.site" { type master; notify no; file "null.zone.file"; };
 zone "farmaciasdrogaminas.com.br" { type master; notify no; file "null.zone.file"; };
-zone "farmnatural.in" { type master; notify no; file "null.zone.file"; };
 zone "faveraprojects.com" { type master; notify no; file "null.zone.file"; };
 zone "fc.co.mz" { type master; notify no; file "null.zone.file"; };
 zone "felicienne.nl" { type master; notify no; file "null.zone.file"; };
 zone "fi.bonitastores.com" { type master; notify no; file "null.zone.file"; };
 zone "files.martellexpress.us" { type master; notify no; file "null.zone.file"; };
 zone "files6.uludagbilisim.com" { type master; notify no; file "null.zone.file"; };
-zone "filmotainment.com" { type master; notify no; file "null.zone.file"; };
 zone "final.makkahkmcc.com" { type master; notify no; file "null.zone.file"; };
+zone "fineartgallerym.com" { type master; notify no; file "null.zone.file"; };
 zone "fkd.derpcity.ru" { type master; notify no; file "null.zone.file"; };
 zone "flintspin.com" { type master; notify no; file "null.zone.file"; };
 zone "flyingbuddhadesign.com" { type master; notify no; file "null.zone.file"; };
@@ -379,20 +369,17 @@ zone "fmjplastering.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "fms.buladde.or.ug" { type master; notify no; file "null.zone.file"; };
 zone "foothills.com.br" { type master; notify no; file "null.zone.file"; };
 zone "footweardirect.elin.co.za" { type master; notify no; file "null.zone.file"; };
-zone "formestore.evencsoft.co" { type master; notify no; file "null.zone.file"; };
 zone "forum.mdb.nu" { type master; notify no; file "null.zone.file"; };
 zone "fotoobjetivo.com" { type master; notify no; file "null.zone.file"; };
 zone "foundationrepairhoustontx.net" { type master; notify no; file "null.zone.file"; };
 zone "foxeps.com.br" { type master; notify no; file "null.zone.file"; };
 zone "freecnetdownload.com" { type master; notify no; file "null.zone.file"; };
-zone "freedombookshop.tickme.lk" { type master; notify no; file "null.zone.file"; };
 zone "freisites.com.br" { type master; notify no; file "null.zone.file"; };
 zone "ftp.n3twork30cm.ml" { type master; notify no; file "null.zone.file"; };
 zone "fullelectronica.com.ar" { type master; notify no; file "null.zone.file"; };
 zone "funletters.net" { type master; notify no; file "null.zone.file"; };
 zone "fusionfiresolutions.com" { type master; notify no; file "null.zone.file"; };
 zone "futuregraphics.com.ar" { type master; notify no; file "null.zone.file"; };
-zone "gahanassociates.com" { type master; notify no; file "null.zone.file"; };
 zone "gametwogame.com" { type master; notify no; file "null.zone.file"; };
 zone "garayvidalabogados.com" { type master; notify no; file "null.zone.file"; };
 zone "garciadogshow.com" { type master; notify no; file "null.zone.file"; };
@@ -400,7 +387,6 @@ zone "garenanow.myvnc.com" { type master; notify no; file "null.zone.file"; };
 zone "garenanow4.myvnc.com" { type master; notify no; file "null.zone.file"; };
 zone "gbbulls.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "gcpc.co.id.chronoscurtain.com" { type master; notify no; file "null.zone.file"; };
-zone "gcrcorporation.com" { type master; notify no; file "null.zone.file"; };
 zone "generaldeviales.com" { type master; notify no; file "null.zone.file"; };
 zone "gfmodd1.webselffiles01.com" { type master; notify no; file "null.zone.file"; };
 zone "gfold1.webselffiles01.com" { type master; notify no; file "null.zone.file"; };
@@ -408,6 +394,8 @@ zone "ghettohub.co.za" { type master; notify no; file "null.zone.file"; };
 zone "ghislain.dartois.pagesperso-orange.fr" { type master; notify no; file "null.zone.file"; };
 zone "giadungg7.com" { type master; notify no; file "null.zone.file"; };
 zone "giddos.ga" { type master; notify no; file "null.zone.file"; };
+zone "gilliem.com" { type master; notify no; file "null.zone.file"; };
+zone "girotexuniformes.com" { type master; notify no; file "null.zone.file"; };
 zone "giteletropical.com" { type master; notify no; file "null.zone.file"; };
 zone "globaltask.ar" { type master; notify no; file "null.zone.file"; };
 zone "glowinmedia.co.ke" { type master; notify no; file "null.zone.file"; };
@@ -422,10 +410,12 @@ zone "goldcoastoffice365.com.au" { type master; notify no; file "null.zone.file"
 zone "goldcupmortgage.com" { type master; notify no; file "null.zone.file"; };
 zone "golden-memories-funerals.yourpageserver.com" { type master; notify no; file "null.zone.file"; };
 zone "goldmen.in" { type master; notify no; file "null.zone.file"; };
+zone "gorecycle.fahadjutt.com" { type master; notify no; file "null.zone.file"; };
 zone "gracejukes.com" { type master; notify no; file "null.zone.file"; };
 zone "grupoinmare.com" { type master; notify no; file "null.zone.file"; };
 zone "gruposelt.000webhostapp.com" { type master; notify no; file "null.zone.file"; };
 zone "gs.monerorx.com" { type master; notify no; file "null.zone.file"; };
+zone "guide-to-cell-phones.com" { type master; notify no; file "null.zone.file"; };
 zone "gulfac-house.com" { type master; notify no; file "null.zone.file"; };
 zone "gvpcdpgc.edu.in" { type master; notify no; file "null.zone.file"; };
 zone "habbotips.free.fr" { type master; notify no; file "null.zone.file"; };
@@ -451,6 +441,7 @@ zone "hitstation.nl" { type master; notify no; file "null.zone.file"; };
 zone "hmpmall.co.kr" { type master; notify no; file "null.zone.file"; };
 zone "hoagietesting10.com" { type master; notify no; file "null.zone.file"; };
 zone "hoayeuthuong-my.sharepoint.com" { type master; notify no; file "null.zone.file"; };
+zone "holmesprpmgmt.com" { type master; notify no; file "null.zone.file"; };
 zone "homefindersolutions.com" { type master; notify no; file "null.zone.file"; };
 zone "hongluosi.com" { type master; notify no; file "null.zone.file"; };
 zone "hookedupboatclub.com" { type master; notify no; file "null.zone.file"; };
@@ -462,7 +453,6 @@ zone "hseda.com" { type master; notify no; file "null.zone.file"; };
 zone "hsmwebapp.com" { type master; notify no; file "null.zone.file"; };
 zone "htownbars.com" { type master; notify no; file "null.zone.file"; };
 zone "hubtech.co.za" { type master; notify no; file "null.zone.file"; };
-zone "huequito.evencsoft.co" { type master; notify no; file "null.zone.file"; };
 zone "hunggiang.vn" { type master; notify no; file "null.zone.file"; };
 zone "husamiyahschool.com" { type master; notify no; file "null.zone.file"; };
 zone "iam313.com" { type master; notify no; file "null.zone.file"; };
@@ -474,6 +464,7 @@ zone "idvindia.com" { type master; notify no; file "null.zone.file"; };
 zone "iesanjosemonitos.edu.co" { type master; notify no; file "null.zone.file"; };
 zone "ikexpert.com" { type master; notify no; file "null.zone.file"; };
 zone "ilrafrica.com" { type master; notify no; file "null.zone.file"; };
+zone "images.jermiau.com" { type master; notify no; file "null.zone.file"; };
 zone "imbueautoworx.co.za" { type master; notify no; file "null.zone.file"; };
 zone "imperiumtherapy.co.za" { type master; notify no; file "null.zone.file"; };
 zone "in-tune2016.com" { type master; notify no; file "null.zone.file"; };
@@ -488,6 +479,7 @@ zone "inodesthetotaldesigners.com" { type master; notify no; file "null.zone.fil
 zone "inovations.searchkero.com" { type master; notify no; file "null.zone.file"; };
 zone "inrajahmundry.co.in" { type master; notify no; file "null.zone.file"; };
 zone "insignificantfinecore.testmail4.repl.co" { type master; notify no; file "null.zone.file"; };
+zone "instantindialoan.com" { type master; notify no; file "null.zone.file"; };
 zone "instvisionmexico.edu.mx" { type master; notify no; file "null.zone.file"; };
 zone "intellectsmart.in" { type master; notify no; file "null.zone.file"; };
 zone "intersel-idf.org" { type master; notify no; file "null.zone.file"; };
@@ -498,6 +490,7 @@ zone "ipmes.ma" { type master; notify no; file "null.zone.file"; };
 zone "iremart.es" { type master; notify no; file "null.zone.file"; };
 zone "iris101.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "iscamenabe.com" { type master; notify no; file "null.zone.file"; };
+zone "ismf.com.ng" { type master; notify no; file "null.zone.file"; };
 zone "iso-dubai.net" { type master; notify no; file "null.zone.file"; };
 zone "israrulhaq.me" { type master; notify no; file "null.zone.file"; };
 zone "isrorg.com" { type master; notify no; file "null.zone.file"; };
@@ -518,7 +511,6 @@ zone "jhayesconsulting.com" { type master; notify no; file "null.zone.file"; };
 zone "jiaoyuzixun.cn" { type master; notify no; file "null.zone.file"; };
 zone "jing-da.com.tw" { type master; notify no; file "null.zone.file"; };
 zone "jktnet.xyz" { type master; notify no; file "null.zone.file"; };
-zone "jmcomputacion.com.ar" { type master; notify no; file "null.zone.file"; };
 zone "jmtc.91756.cn" { type master; notify no; file "null.zone.file"; };
 zone "jnanbharati.com" { type master; notify no; file "null.zone.file"; };
 zone "jobs.thebeessolution.com" { type master; notify no; file "null.zone.file"; };
@@ -527,9 +519,7 @@ zone "join.cl8movement.co.za" { type master; notify no; file "null.zone.file"; }
 zone "josegene.com" { type master; notify no; file "null.zone.file"; };
 zone "josuarochoa.com" { type master; notify no; file "null.zone.file"; };
 zone "jpwoodfordco.com" { type master; notify no; file "null.zone.file"; };
-zone "julietlaser.site" { type master; notify no; file "null.zone.file"; };
 zone "jumpmanualjacobhiller.com" { type master; notify no; file "null.zone.file"; };
-zone "jumpnjamchicago.com" { type master; notify no; file "null.zone.file"; };
 zone "jupiter.toxsl.in" { type master; notify no; file "null.zone.file"; };
 zone "jurgensen.newreadermedia.net" { type master; notify no; file "null.zone.file"; };
 zone "justinscott.com.au" { type master; notify no; file "null.zone.file"; };
@@ -551,6 +541,7 @@ zone "kubatoglubaklava.com.tr" { type master; notify no; file "null.zone.file";
 zone "kumaralok.in" { type master; notify no; file "null.zone.file"; };
 zone "kwanfromhongkong.com" { type master; notify no; file "null.zone.file"; };
 zone "kz.sldov.ru" { type master; notify no; file "null.zone.file"; };
+zone "lab18.it" { type master; notify no; file "null.zone.file"; };
 zone "lacasadelosalebrijes.com" { type master; notify no; file "null.zone.file"; };
 zone "ladylabonde.com" { type master; notify no; file "null.zone.file"; };
 zone "lameguard.ru" { type master; notify no; file "null.zone.file"; };
@@ -596,6 +587,7 @@ zone "lp.definerisco.com" { type master; notify no; file "null.zone.file"; };
 zone "lp.difusodesign.com" { type master; notify no; file "null.zone.file"; };
 zone "lp.juancamilogarciareyes.com" { type master; notify no; file "null.zone.file"; };
 zone "lp.tecnimasdecolombia.com.co" { type master; notify no; file "null.zone.file"; };
+zone "ltc.typoten.com" { type master; notify no; file "null.zone.file"; };
 zone "luckybrownie.com" { type master; notify no; file "null.zone.file"; };
 zone "luminouspneuma.com" { type master; notify no; file "null.zone.file"; };
 zone "luxomodels.com" { type master; notify no; file "null.zone.file"; };
@@ -604,15 +596,15 @@ zone "m.estudiomoros.com.ar" { type master; notify no; file "null.zone.file"; };
 zone "madicon.co.za" { type master; notify no; file "null.zone.file"; };
 zone "magianegramagiablancayamarres.com" { type master; notify no; file "null.zone.file"; };
 zone "mail.bs-eiendomme.co.za" { type master; notify no; file "null.zone.file"; };
+zone "mail.golimoapp.com" { type master; notify no; file "null.zone.file"; };
 zone "mail.jeffsono.org" { type master; notify no; file "null.zone.file"; };
 zone "maksi.feb.unib.ac.id" { type master; notify no; file "null.zone.file"; };
 zone "malaya.tv" { type master; notify no; file "null.zone.file"; };
 zone "malwarecoding.github.io" { type master; notify no; file "null.zone.file"; };
 zone "managed.oss-cn-beijing.aliyuncs.com" { type master; notify no; file "null.zone.file"; };
+zone "managemysalon.in" { type master; notify no; file "null.zone.file"; };
 zone "manantialesdelnorte.uy" { type master; notify no; file "null.zone.file"; };
-zone "manivelasst.com" { type master; notify no; file "null.zone.file"; };
 zone "marcapinyo.ru" { type master; notify no; file "null.zone.file"; };
-zone "marcusthepoet.com" { type master; notify no; file "null.zone.file"; };
 zone "mario-sunjic.com" { type master; notify no; file "null.zone.file"; };
 zone "mariobrown.net" { type master; notify no; file "null.zone.file"; };
 zone "mariotessarollo.com" { type master; notify no; file "null.zone.file"; };
@@ -621,7 +613,6 @@ zone "marketing.enexusgroup.com.au" { type master; notify no; file "null.zone.fi
 zone "marksidfgs.ug" { type master; notify no; file "null.zone.file"; };
 zone "masjidhabeebiyarazviya.mysunni.com" { type master; notify no; file "null.zone.file"; };
 zone "materialescantu.com" { type master; notify no; file "null.zone.file"; };
-zone "matinal-nominal.pt" { type master; notify no; file "null.zone.file"; };
 zone "matruchhaya.co.in" { type master; notify no; file "null.zone.file"; };
 zone "mattysplayground.com" { type master; notify no; file "null.zone.file"; };
 zone "maxtox.com.pk" { type master; notify no; file "null.zone.file"; };
@@ -633,6 +624,7 @@ zone "media-server.skyinternet.com.pk" { type master; notify no; file "null.zone
 zone "mediamaster.co.za" { type master; notify no; file "null.zone.file"; };
 zone "medianews.ge" { type master; notify no; file "null.zone.file"; };
 zone "medistaffconsulting.com" { type master; notify no; file "null.zone.file"; };
+zone "meditreat.itwebservice.in" { type master; notify no; file "null.zone.file"; };
 zone "meeweb.com" { type master; notify no; file "null.zone.file"; };
 zone "megamart.afnan-amc.com" { type master; notify no; file "null.zone.file"; };
 zone "merbay.ru" { type master; notify no; file "null.zone.file"; };
@@ -653,7 +645,6 @@ zone "midlandtexasconstruction.com" { type master; notify no; file "null.zone.fi
 zone "mindfulbuildingandliving.com" { type master; notify no; file "null.zone.file"; };
 zone "mingguanwms.com" { type master; notify no; file "null.zone.file"; };
 zone "minuevavida.org" { type master; notify no; file "null.zone.file"; };
-zone "mirror.mypage.sk" { type master; notify no; file "null.zone.file"; };
 zone "mis.nbcc.ac.th" { type master; notify no; file "null.zone.file"; };
 zone "misterson.com" { type master; notify no; file "null.zone.file"; };
 zone "mixr.at" { type master; notify no; file "null.zone.file"; };
@@ -661,12 +652,14 @@ zone "mkontakt.az" { type master; notify no; file "null.zone.file"; };
 zone "mktf.mx" { type master; notify no; file "null.zone.file"; };
 zone "mmogollon.com.mx" { type master; notify no; file "null.zone.file"; };
 zone "mncarteam.com" { type master; notify no; file "null.zone.file"; };
+zone "mobile.illumetechnology.com" { type master; notify no; file "null.zone.file"; };
 zone "modelhouseturkey.com" { type master; notify no; file "null.zone.file"; };
 zone "modernmanna.org" { type master; notify no; file "null.zone.file"; };
 zone "monetization.business" { type master; notify no; file "null.zone.file"; };
 zone "moninediy.com" { type master; notify no; file "null.zone.file"; };
 zone "mopai.sg" { type master; notify no; file "null.zone.file"; };
 zone "motorcomunicacion.com" { type master; notify no; file "null.zone.file"; };
+zone "msacontabil.com.br" { type master; notify no; file "null.zone.file"; };
 zone "mtspsmjeli.sch.id" { type master; notify no; file "null.zone.file"; };
 zone "muzimbiti.xigubo.co.mz" { type master; notify no; file "null.zone.file"; };
 zone "mxpiqw.am.files.1drv.com" { type master; notify no; file "null.zone.file"; };
@@ -699,8 +692,8 @@ zone "nhorangtreem.com" { type master; notify no; file "null.zone.file"; };
 zone "nicolas.ug" { type master; notify no; file "null.zone.file"; };
 zone "nidhi.iexist.in" { type master; notify no; file "null.zone.file"; };
 zone "nikanpolimer.ir" { type master; notify no; file "null.zone.file"; };
+zone "nilehouse.co.ug" { type master; notify no; file "null.zone.file"; };
 zone "nilinkeji.com" { type master; notify no; file "null.zone.file"; };
-zone "nisacooks.com" { type master; notify no; file "null.zone.file"; };
 zone "njtiledesigncenter.com" { type master; notify no; file "null.zone.file"; };
 zone "nobius.org" { type master; notify no; file "null.zone.file"; };
 zone "nocalnoodle.elin.co.za" { type master; notify no; file "null.zone.file"; };
@@ -718,10 +711,13 @@ zone "nyeh2o.com.au" { type master; notify no; file "null.zone.file"; };
 zone "oakleyandfriends.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "obseques-conseils.com" { type master; notify no; file "null.zone.file"; };
 zone "ocean.tecnasulstore.com.br" { type master; notify no; file "null.zone.file"; };
+zone "ohe.ie" { type master; notify no; file "null.zone.file"; };
 zone "ohsewgorgeous.co.uk" { type master; notify no; file "null.zone.file"; };
+zone "oknoplastik.sk" { type master; notify no; file "null.zone.file"; };
 zone "oleholeh.memangbeda.website" { type master; notify no; file "null.zone.file"; };
 zone "olirecords.mixture.ltd" { type master; notify no; file "null.zone.file"; };
 zone "olooom.com" { type master; notify no; file "null.zone.file"; };
+zone "omaia.org" { type master; notify no; file "null.zone.file"; };
 zone "omaromatic.com" { type master; notify no; file "null.zone.file"; };
 zone "omega.az" { type master; notify no; file "null.zone.file"; };
 zone "oms.pappai.com" { type master; notify no; file "null.zone.file"; };
@@ -730,6 +726,7 @@ zone "onedigitalcard.granvizionnecorp.com" { type master; notify no; file "null.
 zone "onedrive.listifyapp.co" { type master; notify no; file "null.zone.file"; };
 zone "online.creedglobal.in" { type master; notify no; file "null.zone.file"; };
 zone "onlinestatis.bar" { type master; notify no; file "null.zone.file"; };
+zone "ont.proman.id" { type master; notify no; file "null.zone.file"; };
 zone "open.warehousesaas.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "opolis.io" { type master; notify no; file "null.zone.file"; };
 zone "optimus.com.sg" { type master; notify no; file "null.zone.file"; };
@@ -737,6 +734,8 @@ zone "optitechsa.co.za" { type master; notify no; file "null.zone.file"; };
 zone "order.bizpeed.com" { type master; notify no; file "null.zone.file"; };
 zone "orientgatewayltd.com" { type master; notify no; file "null.zone.file"; };
 zone "orion445.com" { type master; notify no; file "null.zone.file"; };
+zone "oserve.pk" { type master; notify no; file "null.zone.file"; };
+zone "otolithenrichment.fahadjutt.com" { type master; notify no; file "null.zone.file"; };
 zone "ottimade.com" { type master; notify no; file "null.zone.file"; };
 zone "ourteam.searchkero.com" { type master; notify no; file "null.zone.file"; };
 zone "ozemag.com" { type master; notify no; file "null.zone.file"; };
@@ -758,6 +757,7 @@ zone "patch3.99ddd.com" { type master; notify no; file "null.zone.file"; };
 zone "paths.elin.co.za" { type master; notify no; file "null.zone.file"; };
 zone "paulmercier.biz" { type master; notify no; file "null.zone.file"; };
 zone "payerrealty.com" { type master; notify no; file "null.zone.file"; };
+zone "payments.atifsiddiqui.me" { type master; notify no; file "null.zone.file"; };
 zone "pcsoori.com" { type master; notify no; file "null.zone.file"; };
 zone "pd.oceaniarp.net" { type master; notify no; file "null.zone.file"; };
 zone "perpus.onlineman7-jombang.sch.id" { type master; notify no; file "null.zone.file"; };
@@ -770,6 +770,7 @@ zone "phittc.com" { type master; notify no; file "null.zone.file"; };
 zone "photo360.kubooking.com" { type master; notify no; file "null.zone.file"; };
 zone "photographytipsclub.com" { type master; notify no; file "null.zone.file"; };
 zone "pink99.com" { type master; notify no; file "null.zone.file"; };
+zone "pizzabarletta.com.br" { type master; notify no; file "null.zone.file"; };
 zone "plasfan.ind.br" { type master; notify no; file "null.zone.file"; };
 zone "pmglance.startwriteup.com" { type master; notify no; file "null.zone.file"; };
 zone "pokojewewladyslawowie.pl" { type master; notify no; file "null.zone.file"; };
@@ -779,15 +780,13 @@ zone "pooltablemoversdenver.net" { type master; notify no; file "null.zone.file"
 zone "posmicrosystems.com" { type master; notify no; file "null.zone.file"; };
 zone "poulman.panagiotopoulos-tours.gr" { type master; notify no; file "null.zone.file"; };
 zone "ppdb.smk-ciptaskill.sch.id" { type master; notify no; file "null.zone.file"; };
-zone "pptvideotemplates.com" { type master; notify no; file "null.zone.file"; };
 zone "prestasicash.com.ar" { type master; notify no; file "null.zone.file"; };
 zone "prestigehomeautomation.net" { type master; notify no; file "null.zone.file"; };
 zone "prishaartcreations.com" { type master; notify no; file "null.zone.file"; };
 zone "production.sparshims.com" { type master; notify no; file "null.zone.file"; };
-zone "productprecise.com" { type master; notify no; file "null.zone.file"; };
-zone "prof-dr-ahmedalmoatasem.com" { type master; notify no; file "null.zone.file"; };
 zone "programaoperadoronline.com.br" { type master; notify no; file "null.zone.file"; };
 zone "project.exquitec.com" { type master; notify no; file "null.zone.file"; };
+zone "promolyko.com" { type master; notify no; file "null.zone.file"; };
 zone "promotoradescomplica.com.br" { type master; notify no; file "null.zone.file"; };
 zone "promoversdubai.com" { type master; notify no; file "null.zone.file"; };
 zone "propertiq.elin.co.za" { type master; notify no; file "null.zone.file"; };
@@ -800,7 +799,7 @@ zone "prueba.danielluza.com" { type master; notify no; file "null.zone.file"; };
 zone "pujashoppe.in" { type master; notify no; file "null.zone.file"; };
 zone "punchdialogues.com" { type master; notify no; file "null.zone.file"; };
 zone "punjabdevelopersassociation.com.pk" { type master; notify no; file "null.zone.file"; };
-zone "purefoe.top" { type master; notify no; file "null.zone.file"; };
+zone "pvcprinting.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "qadir.tickfa.ir" { type master; notify no; file "null.zone.file"; };
 zone "qatarglobalconsulting.com" { type master; notify no; file "null.zone.file"; };
 zone "qmsled.com" { type master; notify no; file "null.zone.file"; };
@@ -816,7 +815,6 @@ zone "ratemyfenancialadvisor.com" { type master; notify no; file "null.zone.file
 zone "ravenproductionsltd.com" { type master; notify no; file "null.zone.file"; };
 zone "rc.ixiaoyang.cn" { type master; notify no; file "null.zone.file"; };
 zone "readymmade.com" { type master; notify no; file "null.zone.file"; };
-zone "realtheprocess.co" { type master; notify no; file "null.zone.file"; };
 zone "redchillicrackers.com" { type master; notify no; file "null.zone.file"; };
 zone "reifenquick.de" { type master; notify no; file "null.zone.file"; };
 zone "relaxindulge.co.nz" { type master; notify no; file "null.zone.file"; };
@@ -866,7 +864,6 @@ zone "santyago.org" { type master; notify no; file "null.zone.file"; };
 zone "sarakem.cl" { type master; notify no; file "null.zone.file"; };
 zone "sasystemsuk.com" { type master; notify no; file "null.zone.file"; };
 zone "savasaachi.systems" { type master; notify no; file "null.zone.file"; };
-zone "savingchintu.com" { type master; notify no; file "null.zone.file"; };
 zone "scarfaceindustries.com" { type master; notify no; file "null.zone.file"; };
 zone "scglobal.co.th" { type master; notify no; file "null.zone.file"; };
 zone "schalke04rss.de" { type master; notify no; file "null.zone.file"; };
@@ -874,10 +871,8 @@ zone "scheff.com" { type master; notify no; file "null.zone.file"; };
 zone "schoolbustracker.softgig.co.ke" { type master; notify no; file "null.zone.file"; };
 zone "sec-doc-w.com" { type master; notify no; file "null.zone.file"; };
 zone "secure-doc-reader.com" { type master; notify no; file "null.zone.file"; };
-zone "sefp-boispro.fr" { type master; notify no; file "null.zone.file"; };
 zone "segalsmetals.elin.co.za" { type master; notify no; file "null.zone.file"; };
 zone "sellmyphonela.com" { type master; notify no; file "null.zone.file"; };
-zone "selltechtoday.com" { type master; notify no; file "null.zone.file"; };
 zone "senbiaojita.com" { type master; notify no; file "null.zone.file"; };
 zone "sentierodelviandante.ml" { type master; notify no; file "null.zone.file"; };
 zone "serendibsourcing.com" { type master; notify no; file "null.zone.file"; };
@@ -894,7 +889,6 @@ zone "shembefoundation.com" { type master; notify no; file "null.zone.file"; };
 zone "shivakunwar.com.np" { type master; notify no; file "null.zone.file"; };
 zone "shoblasaathitrust.org" { type master; notify no; file "null.zone.file"; };
 zone "shooka-co.com" { type master; notify no; file "null.zone.file"; };
-zone "shop.clarostudio.ro" { type master; notify no; file "null.zone.file"; };
 zone "shop.goldspot.agency" { type master; notify no; file "null.zone.file"; };
 zone "shopsofe.com" { type master; notify no; file "null.zone.file"; };
 zone "shrushtiinfotech.com" { type master; notify no; file "null.zone.file"; };
@@ -906,11 +900,11 @@ zone "siili.net" { type master; notify no; file "null.zone.file"; };
 zone "simoneporzi.it" { type master; notify no; file "null.zone.file"; };
 zone "simplithy.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "sindicato1ucm.cl" { type master; notify no; file "null.zone.file"; };
+zone "sindpol.tiejuris.com.br" { type master; notify no; file "null.zone.file"; };
 zone "sinergidwireka.com" { type master; notify no; file "null.zone.file"; };
 zone "sipahielektrik.com" { type master; notify no; file "null.zone.file"; };
 zone "siperb.in" { type master; notify no; file "null.zone.file"; };
 zone "sistelligent.com" { type master; notify no; file "null.zone.file"; };
-zone "site.sjc.co.ke" { type master; notify no; file "null.zone.file"; };
 zone "skkksolo.beweiretail.com" { type master; notify no; file "null.zone.file"; };
 zone "skyflyfares.com" { type master; notify no; file "null.zone.file"; };
 zone "skyscan.com" { type master; notify no; file "null.zone.file"; };
@@ -920,7 +914,6 @@ zone "smartzedu.com" { type master; notify no; file "null.zone.file"; };
 zone "smokeandgrowrichtour.com" { type master; notify no; file "null.zone.file"; };
 zone "smokesolutionindia.com" { type master; notify no; file "null.zone.file"; };
 zone "sobethuacademy.com" { type master; notify no; file "null.zone.file"; };
-zone "soft.110route.com" { type master; notify no; file "null.zone.file"; };
 zone "soft.officelabo.net" { type master; notify no; file "null.zone.file"; };
 zone "sohs.conceptechs.info" { type master; notify no; file "null.zone.file"; };
 zone "solar.amazingtribe.lk" { type master; notify no; file "null.zone.file"; };
@@ -929,11 +922,11 @@ zone "somcorbera.cat" { type master; notify no; file "null.zone.file"; };
 zone "somir.com.mx" { type master; notify no; file "null.zone.file"; };
 zone "soralapps.com" { type master; notify no; file "null.zone.file"; };
 zone "sorteio.orgaostalita.com.br" { type master; notify no; file "null.zone.file"; };
+zone "sosgsm.fr" { type master; notify no; file "null.zone.file"; };
 zone "sota-france.fr" { type master; notify no; file "null.zone.file"; };
 zone "sowingminerals.cl" { type master; notify no; file "null.zone.file"; };
 zone "space.proactint.org" { type master; notify no; file "null.zone.file"; };
 zone "spaceframe.mobi.space-frame.co.za" { type master; notify no; file "null.zone.file"; };
-zone "specfloors.net" { type master; notify no; file "null.zone.file"; };
 zone "special-key.cf" { type master; notify no; file "null.zone.file"; };
 zone "spent.com.pl" { type master; notify no; file "null.zone.file"; };
 zone "spetsesyachtcharter.gr" { type master; notify no; file "null.zone.file"; };
@@ -965,6 +958,7 @@ zone "supermercadostia.com" { type master; notify no; file "null.zone.file"; };
 zone "support-4-free.com" { type master; notify no; file "null.zone.file"; };
 zone "support.clz.kr" { type master; notify no; file "null.zone.file"; };
 zone "supportit.online" { type master; notify no; file "null.zone.file"; };
+zone "surestdysbonescagexc.dns.army" { type master; notify no; file "null.zone.file"; };
 zone "sw.yourpageserver.com" { type master; notify no; file "null.zone.file"; };
 zone "sweaty.dk" { type master; notify no; file "null.zone.file"; };
 zone "sweet-diet.com" { type master; notify no; file "null.zone.file"; };
@@ -990,11 +984,11 @@ zone "taxpos.com" { type master; notify no; file "null.zone.file"; };
 zone "tc.snpsresidential.com" { type master; notify no; file "null.zone.file"; };
 zone "tcy.198424.com" { type master; notify no; file "null.zone.file"; };
 zone "tdsp.yngw518.com" { type master; notify no; file "null.zone.file"; };
-zone "tech332.synology.me" { type master; notify no; file "null.zone.file"; };
 zone "techgms.com" { type master; notify no; file "null.zone.file"; };
 zone "technogreen.crmmanivela.com" { type master; notify no; file "null.zone.file"; };
 zone "technohub.searchkero.com" { type master; notify no; file "null.zone.file"; };
 zone "tecnicaencolectores.com.mx" { type master; notify no; file "null.zone.file"; };
+zone "tecnologyschool.com" { type master; notify no; file "null.zone.file"; };
 zone "teduae.com" { type master; notify no; file "null.zone.file"; };
 zone "teleargentina.com" { type master; notify no; file "null.zone.file"; };
 zone "telescopelms.com" { type master; notify no; file "null.zone.file"; };
@@ -1002,9 +996,9 @@ zone "telmed.cl" { type master; notify no; file "null.zone.file"; };
 zone "temptmag.com" { type master; notify no; file "null.zone.file"; };
 zone "tennisafrica.com" { type master; notify no; file "null.zone.file"; };
 zone "tentandoserfitness.000webhostapp.com" { type master; notify no; file "null.zone.file"; };
-zone "tepresto.net.pe" { type master; notify no; file "null.zone.file"; };
 zone "test.adventser.com" { type master; notify no; file "null.zone.file"; };
 zone "test.letraele.es" { type master; notify no; file "null.zone.file"; };
+zone "test.typoten.com" { type master; notify no; file "null.zone.file"; };
 zone "test.wanepghana.org" { type master; notify no; file "null.zone.file"; };
 zone "test1.asistencia247.com" { type master; notify no; file "null.zone.file"; };
 zone "test1.milenial.id" { type master; notify no; file "null.zone.file"; };
@@ -1017,9 +1011,7 @@ zone "testnew.yourpageserver.com" { type master; notify no; file "null.zone.file
 zone "teteaffiche.stephanebillon.com" { type master; notify no; file "null.zone.file"; };
 zone "tewoerd.eu" { type master; notify no; file "null.zone.file"; };
 zone "textile.softberg.ro" { type master; notify no; file "null.zone.file"; };
-zone "texts.bfftexts.com" { type master; notify no; file "null.zone.file"; };
 zone "texturesbyvinita.com" { type master; notify no; file "null.zone.file"; };
-zone "tharringtonsponsorship.com" { type master; notify no; file "null.zone.file"; };
 zone "thecleaningladiespdx.com" { type master; notify no; file "null.zone.file"; };
 zone "thecreativecafe.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "thefuturelife.in" { type master; notify no; file "null.zone.file"; };
@@ -1027,12 +1019,11 @@ zone "thehighlightinterior.com" { type master; notify no; file "null.zone.file";
 zone "thehouseofpragya.com" { type master; notify no; file "null.zone.file"; };
 zone "thekassia.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "thelaunchpadteam.com" { type master; notify no; file "null.zone.file"; };
-zone "thelekhak.com" { type master; notify no; file "null.zone.file"; };
 zone "thelogicalgroup.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "thesummitpc.net" { type master; notify no; file "null.zone.file"; };
 zone "theurbantutors.com" { type master; notify no; file "null.zone.file"; };
+zone "thewwpc.com" { type master; notify no; file "null.zone.file"; };
 zone "thosewebbs.com" { type master; notify no; file "null.zone.file"; };
-zone "thriveink.com" { type master; notify no; file "null.zone.file"; };
 zone "tianangdep.com" { type master; notify no; file "null.zone.file"; };
 zone "tickfood.tickme.lk" { type master; notify no; file "null.zone.file"; };
 zone "tickjobs.tickme.lk" { type master; notify no; file "null.zone.file"; };
@@ -1065,7 +1056,6 @@ zone "tsd.jxwan.com" { type master; notify no; file "null.zone.file"; };
 zone "tulli.info" { type master; notify no; file "null.zone.file"; };
 zone "tupperware.michaelroberge.ca" { type master; notify no; file "null.zone.file"; };
 zone "turanggaresources.com" { type master; notify no; file "null.zone.file"; };
-zone "tushartyagiji.digitalswagger.in" { type master; notify no; file "null.zone.file"; };
 zone "uat.indianfilmzone.com" { type master; notify no; file "null.zone.file"; };
 zone "ublretailerdemo.cstdevs.com" { type master; notify no; file "null.zone.file"; };
 zone "udesk.searchkero.com" { type master; notify no; file "null.zone.file"; };
@@ -1075,7 +1065,6 @@ zone "umwelt-kirchhof.de" { type master; notify no; file "null.zone.file"; };
 zone "unicorpbrunei.com" { type master; notify no; file "null.zone.file"; };
 zone "uniengrisb.com" { type master; notify no; file "null.zone.file"; };
 zone "unisoftcc.com" { type master; notify no; file "null.zone.file"; };
-zone "unitedpestsolutionstx.com" { type master; notify no; file "null.zone.file"; };
 zone "unyazitelecom.com" { type master; notify no; file "null.zone.file"; };
 zone "upcbpta.com" { type master; notify no; file "null.zone.file"; };
 zone "urbane.dezinetimes.com" { type master; notify no; file "null.zone.file"; };
@@ -1102,17 +1091,18 @@ zone "vitoriamodaintima.com.br" { type master; notify no; file "null.zone.file";
 zone "vivationdesign.com" { type master; notify no; file "null.zone.file"; };
 zone "viveirodoiscorregos.com.br" { type master; notify no; file "null.zone.file"; };
 zone "vksales.com" { type master; notify no; file "null.zone.file"; };
+zone "vladimirinternational.com" { type master; notify no; file "null.zone.file"; };
 zone "vokasi.ub.ac.id" { type master; notify no; file "null.zone.file"; };
 zone "vologroup.com.br" { type master; notify no; file "null.zone.file"; };
 zone "voteyouramerica.dekitout.com" { type master; notify no; file "null.zone.file"; };
 zone "vstsample.com" { type master; notify no; file "null.zone.file"; };
 zone "vtube.fadlymotivator.com" { type master; notify no; file "null.zone.file"; };
 zone "vvsskmodinationalschool.com" { type master; notify no; file "null.zone.file"; };
-zone "wahrewah.nl" { type master; notify no; file "null.zone.file"; };
 zone "wanepliberia.org" { type master; notify no; file "null.zone.file"; };
 zone "wanepniger.org" { type master; notify no; file "null.zone.file"; };
 zone "weareactum.com" { type master; notify no; file "null.zone.file"; };
 zone "web.eng.ubu.ac.th" { type master; notify no; file "null.zone.file"; };
+zone "web.geetle.ga" { type master; notify no; file "null.zone.file"; };
 zone "web.geomegasoft.net" { type master; notify no; file "null.zone.file"; };
 zone "web.newinnovationtechnology.com" { type master; notify no; file "null.zone.file"; };
 zone "web.smarts-works.com" { type master; notify no; file "null.zone.file"; };
@@ -1126,13 +1116,12 @@ zone "wexfashion.com" { type master; notify no; file "null.zone.file"; };
 zone "whcms.yourpageserver.com" { type master; notify no; file "null.zone.file"; };
 zone "whiteglovetailgate.com" { type master; notify no; file "null.zone.file"; };
 zone "whiteresponse.com" { type master; notify no; file "null.zone.file"; };
+zone "whynt.xyz" { type master; notify no; file "null.zone.file"; };
 zone "wi522012.ferozo.com" { type master; notify no; file "null.zone.file"; };
 zone "wikalen.co.za" { type master; notify no; file "null.zone.file"; };
 zone "wildnights.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "wildtrust.mediadevstaging.com" { type master; notify no; file "null.zone.file"; };
 zone "wimbamusica.com" { type master; notify no; file "null.zone.file"; };
-zone "windcomtechnologies.com" { type master; notify no; file "null.zone.file"; };
-zone "winnercircle.it" { type master; notify no; file "null.zone.file"; };
 zone "wishesconcierge.com" { type master; notify no; file "null.zone.file"; };
 zone "woezon.agency" { type master; notify no; file "null.zone.file"; };
 zone "wolfgang-brodte.de" { type master; notify no; file "null.zone.file"; };
@@ -1148,7 +1137,6 @@ zone "x2vn.com" { type master; notify no; file "null.zone.file"; };
 zone "xia.beihaixue.com" { type master; notify no; file "null.zone.file"; };
 zone "xixaoclothing.com" { type master; notify no; file "null.zone.file"; };
 zone "xk.996is.com" { type master; notify no; file "null.zone.file"; };
-zone "xmp.myracingaccounts.com" { type master; notify no; file "null.zone.file"; };
 zone "xn--80akinnkiib6h.xn--90ais" { type master; notify no; file "null.zone.file"; };
 zone "xn--polimerbizmimarlk-rvc.com" { type master; notify no; file "null.zone.file"; };
 zone "ybom.urbanolab.com" { type master; notify no; file "null.zone.file"; };
@@ -1159,5 +1147,6 @@ zone "youtubetrainingacademy.com" { type master; notify no; file "null.zone.file
 zone "yskadvisors.com" { type master; notify no; file "null.zone.file"; };
 zone "yummyyogaudaipur.com" { type master; notify no; file "null.zone.file"; };
 zone "yzkzixun.com" { type master; notify no; file "null.zone.file"; };
+zone "zakra.tecnasulstore.com.br" { type master; notify no; file "null.zone.file"; };
 zone "zytrox.tk" { type master; notify no; file "null.zone.file"; };
 zone "zz.690tx.com" { type master; notify no; file "null.zone.file"; };
diff --git a/urlhaus-filter-bind.conf b/urlhaus-filter-bind.conf
index 4c953897..6a6a5330 100644
--- a/urlhaus-filter-bind.conf
+++ b/urlhaus-filter-bind.conf
@@ -1,5 +1,5 @@
 # Title: Malicious Domains BIND Blocklist
-# Updated: Thu, 25 Mar 2021 12:12:40 UTC
+# Updated: Fri, 26 Mar 2021 00:12:29 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -2496,6 +2496,7 @@ zone "accesointerne.theworkpc.com" { type master; notify no; file "null.zone.fil
 zone "access-24.jp" { type master; notify no; file "null.zone.file"; };
 zone "access-cash.ae.org" { type master; notify no; file "null.zone.file"; };
 zone "access-om.neomeric.us" { type master; notify no; file "null.zone.file"; };
+zone "access-one.us" { type master; notify no; file "null.zone.file"; };
 zone "access-to-web.com" { type master; notify no; file "null.zone.file"; };
 zone "accessclub.jp" { type master; notify no; file "null.zone.file"; };
 zone "accessdig.com" { type master; notify no; file "null.zone.file"; };
@@ -2673,6 +2674,7 @@ zone "achremittanceservices.com" { type master; notify no; file "null.zone.file"
 zone "acht-stuecken.de" { type master; notify no; file "null.zone.file"; };
 zone "achuanchaolihai.cn" { type master; notify no; file "null.zone.file"; };
 zone "aci.serabd.com" { type master; notify no; file "null.zone.file"; };
+zone "aciabogados.com" { type master; notify no; file "null.zone.file"; };
 zone "aciitaly.com" { type master; notify no; file "null.zone.file"; };
 zone "acilevarkadasi.com" { type master; notify no; file "null.zone.file"; };
 zone "acilisbalon.com" { type master; notify no; file "null.zone.file"; };
@@ -3089,6 +3091,7 @@ zone "admin.grapejuiceofbrazil.com" { type master; notify no; file "null.zone.fi
 zone "admin.greenlightcr.com" { type master; notify no; file "null.zone.file"; };
 zone "admin.hopehorseback.org" { type master; notify no; file "null.zone.file"; };
 zone "admin.jpcar.mystand.pt" { type master; notify no; file "null.zone.file"; };
+zone "admin.mobilezenie.com" { type master; notify no; file "null.zone.file"; };
 zone "admin.searchlowestprice.com" { type master; notify no; file "null.zone.file"; };
 zone "admin.solissol.com" { type master; notify no; file "null.zone.file"; };
 zone "admin.staging.buildsmart.io" { type master; notify no; file "null.zone.file"; };
@@ -3268,7 +3271,6 @@ zone "adventuredsocks.com" { type master; notify no; file "null.zone.file"; };
 zone "adventureexplorer.in" { type master; notify no; file "null.zone.file"; };
 zone "adventurehr.com" { type master; notify no; file "null.zone.file"; };
 zone "adventureitdate.com" { type master; notify no; file "null.zone.file"; };
-zone "adventureits.com" { type master; notify no; file "null.zone.file"; };
 zone "adventuremania.com" { type master; notify no; file "null.zone.file"; };
 zone "adventurersafaris.com" { type master; notify no; file "null.zone.file"; };
 zone "adventuresofarchibald.com" { type master; notify no; file "null.zone.file"; };
@@ -3688,6 +3690,7 @@ zone "agenforedi.toko-abi.net" { type master; notify no; file "null.zone.file";
 zone "agengarcinia5000.com" { type master; notify no; file "null.zone.file"; };
 zone "agenity.com" { type master; notify no; file "null.zone.file"; };
 zone "agenlama.com" { type master; notify no; file "null.zone.file"; };
+zone "agenmovie.xyz" { type master; notify no; file "null.zone.file"; };
 zone "agent-seo.jp" { type master; notify no; file "null.zone.file"; };
 zone "agent.ken.by" { type master; notify no; file "null.zone.file"; };
 zone "agent2.icu" { type master; notify no; file "null.zone.file"; };
@@ -10704,6 +10707,7 @@ zone "barcaacademyistanbul.com" { type master; notify no; file "null.zone.file";
 zone "barcelonaevent.es" { type master; notify no; file "null.zone.file"; };
 zone "barcelonakartingcenter.com" { type master; notify no; file "null.zone.file"; };
 zone "barchaklem.com" { type master; notify no; file "null.zone.file"; };
+zone "barcionstw.eastus.cloudapp.azure.com" { type master; notify no; file "null.zone.file"; };
 zone "barcla.ug" { type master; notify no; file "null.zone.file"; };
 zone "barclaysdownloads.com" { type master; notify no; file "null.zone.file"; };
 zone "barcoofoods.ir" { type master; notify no; file "null.zone.file"; };
@@ -12989,6 +12993,7 @@ zone "bizzznez.com" { type master; notify no; file "null.zone.file"; };
 zone "bj5800.com" { type master; notify no; file "null.zone.file"; };
 zone "bjarndahl.dk" { type master; notify no; file "null.zone.file"; };
 zone "bjbus.net" { type master; notify no; file "null.zone.file"; };
+zone "bjconstructions.in" { type master; notify no; file "null.zone.file"; };
 zone "bjdd.org" { type master; notify no; file "null.zone.file"; };
 zone "bjenkins.webview.consulting" { type master; notify no; file "null.zone.file"; };
 zone "bjenzer.com" { type master; notify no; file "null.zone.file"; };
@@ -14028,6 +14033,7 @@ zone "bnote.novelux.com" { type master; notify no; file "null.zone.file"; };
 zone "bnpartnersweb.com" { type master; notify no; file "null.zone.file"; };
 zone "bnpgrup.com" { type master; notify no; file "null.zone.file"; };
 zone "bnqzjy.cn" { type master; notify no; file "null.zone.file"; };
+zone "bnrbook.com" { type master; notify no; file "null.zone.file"; };
 zone "bnrnews.id" { type master; notify no; file "null.zone.file"; };
 zone "bnsddfhjdfgvbxc.ru" { type master; notify no; file "null.zone.file"; };
 zone "bnsgroupbd.com" { type master; notify no; file "null.zone.file"; };
@@ -14778,6 +14784,7 @@ zone "brandzzy.com" { type master; notify no; file "null.zone.file"; };
 zone "braner.com.ua" { type master; notify no; file "null.zone.file"; };
 zone "branfinancial.com" { type master; notify no; file "null.zone.file"; };
 zone "branner-chile.com" { type master; notify no; file "null.zone.file"; };
+zone "brannon-powlowski25d.xyz" { type master; notify no; file "null.zone.file"; };
 zone "brannudd.com" { type master; notify no; file "null.zone.file"; };
 zone "brantech.com" { type master; notify no; file "null.zone.file"; };
 zone "brar.aminfortgreene.com" { type master; notify no; file "null.zone.file"; };
@@ -15778,6 +15785,7 @@ zone "buyrigrap.com" { type master; notify no; file "null.zone.file"; };
 zone "buysellfx24.ru" { type master; notify no; file "null.zone.file"; };
 zone "buysmart365.net" { type master; notify no; file "null.zone.file"; };
 zone "buysmartwebmall.com" { type master; notify no; file "null.zone.file"; };
+zone "buythebest.pk" { type master; notify no; file "null.zone.file"; };
 zone "buytotake.online" { type master; notify no; file "null.zone.file"; };
 zone "buytwitterlike.com" { type master; notify no; file "null.zone.file"; };
 zone "buyuksigorta.com" { type master; notify no; file "null.zone.file"; };
@@ -17098,6 +17106,7 @@ zone "cashonlinestore.com" { type master; notify no; file "null.zone.file"; };
 zone "cashoutrefitips.com" { type master; notify no; file "null.zone.file"; };
 zone "cashpickup.slmicrocredit.com" { type master; notify no; file "null.zone.file"; };
 zone "cashslip.info" { type master; notify no; file "null.zone.file"; };
+zone "cashtunel.com" { type master; notify no; file "null.zone.file"; };
 zone "cashyinvestment.org" { type master; notify no; file "null.zone.file"; };
 zone "casimiroartes.es" { type master; notify no; file "null.zone.file"; };
 zone "casinarium.com" { type master; notify no; file "null.zone.file"; };
@@ -19670,6 +19679,7 @@ zone "clubyourlife.ca" { type master; notify no; file "null.zone.file"; };
 zone "clubzone.ca" { type master; notify no; file "null.zone.file"; };
 zone "cluebazar.com" { type master; notify no; file "null.zone.file"; };
 zone "clukva.ru" { type master; notify no; file "null.zone.file"; };
+zone "clurbgolf.com" { type master; notify no; file "null.zone.file"; };
 zone "clurit.com" { type master; notify no; file "null.zone.file"; };
 zone "clusdirectory.xyz" { type master; notify no; file "null.zone.file"; };
 zone "cluster-mixture.gq" { type master; notify no; file "null.zone.file"; };
@@ -19886,6 +19896,7 @@ zone "coastmediagroup.com.au" { type master; notify no; file "null.zone.file"; }
 zone "coastmedicalservice.com" { type master; notify no; file "null.zone.file"; };
 zone "coastmotorsupply.com" { type master; notify no; file "null.zone.file"; };
 zone "coastsignworks.com" { type master; notify no; file "null.zone.file"; };
+zone "coastwidewaterproofing.com.au" { type master; notify no; file "null.zone.file"; };
 zone "coatforwinter.com" { type master; notify no; file "null.zone.file"; };
 zone "coavce.com" { type master; notify no; file "null.zone.file"; };
 zone "cobam.xyz" { type master; notify no; file "null.zone.file"; };
@@ -21909,6 +21920,7 @@ zone "cronicas.com.do" { type master; notify no; file "null.zone.file"; };
 zone "cronolux.com.br" { type master; notify no; file "null.zone.file"; };
 zone "croodly.com" { type master; notify no; file "null.zone.file"; };
 zone "crookedchristicraddick.com" { type master; notify no; file "null.zone.file"; };
+zone "crooks-cooper24g.xyz" { type master; notify no; file "null.zone.file"; };
 zone "croos.org" { type master; notify no; file "null.zone.file"; };
 zone "crope.shop" { type master; notify no; file "null.zone.file"; };
 zone "cropfoods.com" { type master; notify no; file "null.zone.file"; };
@@ -23163,7 +23175,6 @@ zone "dar-ltd.uk" { type master; notify no; file "null.zone.file"; };
 zone "dar-sana.com" { type master; notify no; file "null.zone.file"; };
 zone "darajelita.com" { type master; notify no; file "null.zone.file"; };
 zone "daralsalam-mall.com" { type master; notify no; file "null.zone.file"; };
-zone "daralsaqi.com" { type master; notify no; file "null.zone.file"; };
 zone "darapartment.com" { type master; notify no; file "null.zone.file"; };
 zone "darasrszs.online" { type master; notify no; file "null.zone.file"; };
 zone "darassalam.ch" { type master; notify no; file "null.zone.file"; };
@@ -23272,7 +23283,6 @@ zone "dashcenter.info" { type master; notify no; file "null.zone.file"; };
 zone "dasheriemagazine.com" { type master; notify no; file "null.zone.file"; };
 zone "dashfiles.tk" { type master; notify no; file "null.zone.file"; };
 zone "dashkevichseo.ru" { type master; notify no; file "null.zone.file"; };
-zone "dashonweb.com" { type master; notify no; file "null.zone.file"; };
 zone "dashudance.com" { type master; notify no; file "null.zone.file"; };
 zone "dashvaanjil.mn" { type master; notify no; file "null.zone.file"; };
 zone "dasin-obchudek.cz" { type master; notify no; file "null.zone.file"; };
@@ -23600,6 +23610,7 @@ zone "dboyusa.online" { type master; notify no; file "null.zone.file"; };
 zone "dbravo.pro" { type master; notify no; file "null.zone.file"; };
 zone "dbs-ebank.com" { type master; notify no; file "null.zone.file"; };
 zone "dbsa-dream.com" { type master; notify no; file "null.zone.file"; };
+zone "dbsandbox.ca" { type master; notify no; file "null.zone.file"; };
 zone "dbsenvironmental.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "dbsgear.com" { type master; notify no; file "null.zone.file"; };
 zone "dbsktoporder.yolasite.com" { type master; notify no; file "null.zone.file"; };
@@ -24508,6 +24519,7 @@ zone "denlokale.nu" { type master; notify no; file "null.zone.file"; };
 zone "denmaar.hplbusiness.com" { type master; notify no; file "null.zone.file"; };
 zone "denmarkheating.net" { type master; notify no; file "null.zone.file"; };
 zone "denmaytre.vn" { type master; notify no; file "null.zone.file"; };
+zone "dennis-hill25lw.xyz" { type master; notify no; file "null.zone.file"; };
 zone "dennis-roth.de" { type master; notify no; file "null.zone.file"; };
 zone "dennishester.com" { type master; notify no; file "null.zone.file"; };
 zone "dennisisasshole.com" { type master; notify no; file "null.zone.file"; };
@@ -27184,6 +27196,9 @@ zone "down.posti-fi-fjwa.top" { type master; notify no; file "null.zone.file"; }
 zone "down.posti-fi-fsa.top" { type master; notify no; file "null.zone.file"; };
 zone "down.posti-fi-fsaq.top" { type master; notify no; file "null.zone.file"; };
 zone "down.posti-fi-fwa.top" { type master; notify no; file "null.zone.file"; };
+zone "down.posti-fi-ij.top" { type master; notify no; file "null.zone.file"; };
+zone "down.posti-fi-in.top" { type master; notify no; file "null.zone.file"; };
+zone "down.posti-fi-iz.top" { type master; notify no; file "null.zone.file"; };
 zone "down.pzchao.com" { type master; notify no; file "null.zone.file"; };
 zone "down.qm188.com" { type master; notify no; file "null.zone.file"; };
 zone "down.qqfarmer.com.cn" { type master; notify no; file "null.zone.file"; };
@@ -29395,6 +29410,7 @@ zone "egyptmaint.com" { type master; notify no; file "null.zone.file"; };
 zone "egyptmotours.com" { type master; notify no; file "null.zone.file"; };
 zone "egyptpharaohstours.com" { type master; notify no; file "null.zone.file"; };
 zone "egyshadowmen.com" { type master; notify no; file "null.zone.file"; };
+zone "egyutthato.eu" { type master; notify no; file "null.zone.file"; };
 zone "egyuttkonnyebb.zolitoth.com" { type master; notify no; file "null.zone.file"; };
 zone "egyvision.medicahealthy.net" { type master; notify no; file "null.zone.file"; };
 zone "egywebtest.ml" { type master; notify no; file "null.zone.file"; };
@@ -30576,6 +30592,7 @@ zone "ennaturismo.info" { type master; notify no; file "null.zone.file"; };
 zone "ennessehospitality.id" { type master; notify no; file "null.zone.file"; };
 zone "ennovate.elin.co.za" { type master; notify no; file "null.zone.file"; };
 zone "eno.si" { type master; notify no; file "null.zone.file"; };
+zone "enolil-loo.com" { type master; notify no; file "null.zone.file"; };
 zone "enorichie.net" { type master; notify no; file "null.zone.file"; };
 zone "enorka.info" { type master; notify no; file "null.zone.file"; };
 zone "enosburgreading.pbworks.com" { type master; notify no; file "null.zone.file"; };
@@ -32549,6 +32566,7 @@ zone "faithchorale.com" { type master; notify no; file "null.zone.file"; };
 zone "faithcompassion.com" { type master; notify no; file "null.zone.file"; };
 zone "faithconstructionltd.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "faithfight.my.id" { type master; notify no; file "null.zone.file"; };
+zone "faithmethodistcheras.org" { type master; notify no; file "null.zone.file"; };
 zone "faithmontessorischools.com" { type master; notify no; file "null.zone.file"; };
 zone "faithoasis.000webhostapp.com" { type master; notify no; file "null.zone.file"; };
 zone "faithworkx.com" { type master; notify no; file "null.zone.file"; };
@@ -33819,6 +33837,7 @@ zone "findyourfocusph.com" { type master; notify no; file "null.zone.file"; };
 zone "findyourvoice.ca" { type master; notify no; file "null.zone.file"; };
 zone "fine-art-line.de" { type master; notify no; file "null.zone.file"; };
 zone "fine.black" { type master; notify no; file "null.zone.file"; };
+zone "fineartgallerym.com" { type master; notify no; file "null.zone.file"; };
 zone "fineconera.com" { type master; notify no; file "null.zone.file"; };
 zone "finefeather.info" { type master; notify no; file "null.zone.file"; };
 zone "finefoodsfrozen.com" { type master; notify no; file "null.zone.file"; };
@@ -37447,6 +37466,7 @@ zone "girlsphonenumbers.online" { type master; notify no; file "null.zone.file";
 zone "girltalkza.co.za" { type master; notify no; file "null.zone.file"; };
 zone "girlydesignart.com" { type master; notify no; file "null.zone.file"; };
 zone "gironynavarro.com" { type master; notify no; file "null.zone.file"; };
+zone "girotexuniformes.com" { type master; notify no; file "null.zone.file"; };
 zone "girraj2016.gtranzit.com" { type master; notify no; file "null.zone.file"; };
 zone "girrajwadi.com" { type master; notify no; file "null.zone.file"; };
 zone "gisa.company" { type master; notify no; file "null.zone.file"; };
@@ -37536,6 +37556,7 @@ zone "gladwynecapital.com" { type master; notify no; file "null.zone.file"; };
 zone "glafka.com" { type master; notify no; file "null.zone.file"; };
 zone "glambooth.nl" { type master; notify no; file "null.zone.file"; };
 zone "glamoroushairextension.com" { type master; notify no; file "null.zone.file"; };
+zone "glamorouspk.com" { type master; notify no; file "null.zone.file"; };
 zone "glamour.rosolutions.com.mx" { type master; notify no; file "null.zone.file"; };
 zone "glamourgarden-lb.com" { type master; notify no; file "null.zone.file"; };
 zone "glamourlounge.org" { type master; notify no; file "null.zone.file"; };
@@ -38292,6 +38313,7 @@ zone "gordondeen.net" { type master; notify no; file "null.zone.file"; };
 zone "gordonmilktransport.com" { type master; notify no; file "null.zone.file"; };
 zone "gordonruss.com" { type master; notify no; file "null.zone.file"; };
 zone "gordyssensors.com" { type master; notify no; file "null.zone.file"; };
+zone "gorecycle.fahadjutt.com" { type master; notify no; file "null.zone.file"; };
 zone "gorenotoservisi.net" { type master; notify no; file "null.zone.file"; };
 zone "gorestruly.com" { type master; notify no; file "null.zone.file"; };
 zone "goretimmo.lu" { type master; notify no; file "null.zone.file"; };
@@ -39448,6 +39470,7 @@ zone "gunesulkesi.com" { type master; notify no; file "null.zone.file"; };
 zone "guneyaski.com" { type master; notify no; file "null.zone.file"; };
 zone "gungazcomputer.co.ke" { type master; notify no; file "null.zone.file"; };
 zone "gunk.insol.be" { type master; notify no; file "null.zone.file"; };
+zone "gunma2u.com" { type master; notify no; file "null.zone.file"; };
 zone "gunmak-com.tk" { type master; notify no; file "null.zone.file"; };
 zone "gunnarasgeir.com" { type master; notify no; file "null.zone.file"; };
 zone "gunnersexcavating.com" { type master; notify no; file "null.zone.file"; };
@@ -41799,6 +41822,7 @@ zone "hollywoodremix.com" { type master; notify no; file "null.zone.file"; };
 zone "hollywoodsmileeg.com" { type master; notify no; file "null.zone.file"; };
 zone "holmdalehouse.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "holmesgroup-com.azurewebsites.net" { type master; notify no; file "null.zone.file"; };
+zone "holmesprpmgmt.com" { type master; notify no; file "null.zone.file"; };
 zone "holmnkolbas.com" { type master; notify no; file "null.zone.file"; };
 zone "holmsater.se" { type master; notify no; file "null.zone.file"; };
 zone "holod24.by" { type master; notify no; file "null.zone.file"; };
@@ -42492,6 +42516,7 @@ zone "hpmamerica.com" { type master; notify no; file "null.zone.file"; };
 zone "hpmaytinhtaophongcach.com" { type master; notify no; file "null.zone.file"; };
 zone "hpmwqjub.com" { type master; notify no; file "null.zone.file"; };
 zone "hpq8fa.db.files.1drv.com" { type master; notify no; file "null.zone.file"; };
+zone "hprosacco25i.xyz" { type master; notify no; file "null.zone.file"; };
 zone "hprpc.cn" { type master; notify no; file "null.zone.file"; };
 zone "hps-sk.sk" { type master; notify no; file "null.zone.file"; };
 zone "hps.nz" { type master; notify no; file "null.zone.file"; };
@@ -45068,6 +45093,7 @@ zone "instant-resume.com" { type master; notify no; file "null.zone.file"; };
 zone "instantbonheur.fr" { type master; notify no; file "null.zone.file"; };
 zone "instantcashflowtoday.com.ng" { type master; notify no; file "null.zone.file"; };
 zone "instantclients.network" { type master; notify no; file "null.zone.file"; };
+zone "instantindialoan.com" { type master; notify no; file "null.zone.file"; };
 zone "instanttaxsolutions.mobi" { type master; notify no; file "null.zone.file"; };
 zone "instanttechnology.com.au" { type master; notify no; file "null.zone.file"; };
 zone "instantworldpay.com" { type master; notify no; file "null.zone.file"; };
@@ -45892,6 +45918,7 @@ zone "iscidavasi.com" { type master; notify no; file "null.zone.file"; };
 zone "isciyizbiz.com" { type master; notify no; file "null.zone.file"; };
 zone "iscleanone.com" { type master; notify no; file "null.zone.file"; };
 zone "isclimatechangeahoax.com" { type master; notify no; file "null.zone.file"; };
+zone "iscoegypt.com" { type master; notify no; file "null.zone.file"; };
 zone "iscoming.ir" { type master; notify no; file "null.zone.file"; };
 zone "iscon.com.br" { type master; notify no; file "null.zone.file"; };
 zone "iscondisth.com" { type master; notify no; file "null.zone.file"; };
@@ -45947,7 +45974,6 @@ zone "iskostrip.com" { type master; notify no; file "null.zone.file"; };
 zone "iskro.textronic.info" { type master; notify no; file "null.zone.file"; };
 zone "iskyservice.ru" { type master; notify no; file "null.zone.file"; };
 zone "islaholics.com" { type master; notify no; file "null.zone.file"; };
-zone "islamabadtrafficpolice.gov.pk" { type master; notify no; file "null.zone.file"; };
 zone "islamabout.com" { type master; notify no; file "null.zone.file"; };
 zone "islamappen.se" { type master; notify no; file "null.zone.file"; };
 zone "islamforall.tv" { type master; notify no; file "null.zone.file"; };
@@ -47760,6 +47786,7 @@ zone "jolly-saito-4993.sub.jp" { type master; notify no; file "null.zone.file";
 zone "jollycharm.com" { type master; notify no; file "null.zone.file"; };
 zone "jollyemma.com" { type master; notify no; file "null.zone.file"; };
 zone "jolyscortinas.com.br" { type master; notify no; file "null.zone.file"; };
+zone "jomansea.com" { type master; notify no; file "null.zone.file"; };
 zone "jomar2020.com.br" { type master; notify no; file "null.zone.file"; };
 zone "jomblo.com" { type master; notify no; file "null.zone.file"; };
 zone "jomhermonex.com" { type master; notify no; file "null.zone.file"; };
@@ -49139,6 +49166,7 @@ zone "kaspersky-security.com" { type master; notify no; file "null.zone.file"; }
 zone "kasperskysecurity.club" { type master; notify no; file "null.zone.file"; };
 zone "kasrasanatsepahan.com" { type master; notify no; file "null.zone.file"; };
 zone "kassa.hostsites.ru" { type master; notify no; file "null.zone.file"; };
+zone "kassandra5024d.xyz" { type master; notify no; file "null.zone.file"; };
 zone "kassconnect.ru" { type master; notify no; file "null.zone.file"; };
 zone "kasshmira.com" { type master; notify no; file "null.zone.file"; };
 zone "kassohome.com.tr" { type master; notify no; file "null.zone.file"; };
@@ -49783,7 +49811,6 @@ zone "khannamdo.com" { type master; notify no; file "null.zone.file"; };
 zone "khannen.com.vn" { type master; notify no; file "null.zone.file"; };
 zone "khannen.vn" { type master; notify no; file "null.zone.file"; };
 zone "khanqahebrahimi.com" { type master; notify no; file "null.zone.file"; };
-zone "khantil.com" { type master; notify no; file "null.zone.file"; };
 zone "khantipong.com" { type master; notify no; file "null.zone.file"; };
 zone "khaochills.com" { type master; notify no; file "null.zone.file"; };
 zone "khaoden.tech" { type master; notify no; file "null.zone.file"; };
@@ -51645,6 +51672,7 @@ zone "lab.sjworks.net" { type master; notify no; file "null.zone.file"; };
 zone "lab.valvolari.it" { type master; notify no; file "null.zone.file"; };
 zone "lab.ydigital.asia" { type master; notify no; file "null.zone.file"; };
 zone "lab1.ozaki-kyousei.com" { type master; notify no; file "null.zone.file"; };
+zone "lab18.it" { type master; notify no; file "null.zone.file"; };
 zone "lab2.e-century.pl" { type master; notify no; file "null.zone.file"; };
 zone "lab5.hu" { type master; notify no; file "null.zone.file"; };
 zone "lab6.com.br" { type master; notify no; file "null.zone.file"; };
@@ -56683,6 +56711,7 @@ zone "managegates.com" { type master; notify no; file "null.zone.file"; };
 zone "manageitrisks.com" { type master; notify no; file "null.zone.file"; };
 zone "management.vkims.com" { type master; notify no; file "null.zone.file"; };
 zone "managementtop.id" { type master; notify no; file "null.zone.file"; };
+zone "managemysalon.in" { type master; notify no; file "null.zone.file"; };
 zone "managemyshoes.tools" { type master; notify no; file "null.zone.file"; };
 zone "manageone.co.th" { type master; notify no; file "null.zone.file"; };
 zone "manageprint.in" { type master; notify no; file "null.zone.file"; };
@@ -57064,6 +57093,7 @@ zone "marecsko.hu" { type master; notify no; file "null.zone.file"; };
 zone "marek-paysage-concept.fr" { type master; notify no; file "null.zone.file"; };
 zone "marek.in" { type master; notify no; file "null.zone.file"; };
 zone "marekvoprsal.cz" { type master; notify no; file "null.zone.file"; };
+zone "marel.com.br" { type master; notify no; file "null.zone.file"; };
 zone "marellengifts.com" { type master; notify no; file "null.zone.file"; };
 zone "maremarius.pt" { type master; notify no; file "null.zone.file"; };
 zone "marematto.it" { type master; notify no; file "null.zone.file"; };
@@ -58344,6 +58374,7 @@ zone "meditationsurmesure.com" { type master; notify no; file "null.zone.file";
 zone "meditec.ma" { type master; notify no; file "null.zone.file"; };
 zone "mediterraneavacanze.com" { type master; notify no; file "null.zone.file"; };
 zone "meditheraphy.com" { type master; notify no; file "null.zone.file"; };
+zone "meditreat.itwebservice.in" { type master; notify no; file "null.zone.file"; };
 zone "meditsinanarodnaya.ru" { type master; notify no; file "null.zone.file"; };
 zone "medius.ge" { type master; notify no; file "null.zone.file"; };
 zone "mediusvp.com" { type master; notify no; file "null.zone.file"; };
@@ -60520,6 +60551,7 @@ zone "moitruongtunglam.com" { type master; notify no; file "null.zone.file"; };
 zone "mojang.com.br" { type master; notify no; file "null.zone.file"; };
 zone "mojehaftom.com" { type master; notify no; file "null.zone.file"; };
 zone "mojewnetrza.pl" { type master; notify no; file "null.zone.file"; };
+zone "mojno--vse.ru" { type master; notify no; file "null.zone.file"; };
 zone "mojo-studios.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "mojorockstar.com" { type master; notify no; file "null.zone.file"; };
 zone "mojstudent.net" { type master; notify no; file "null.zone.file"; };
@@ -61274,6 +61306,7 @@ zone "mrpiratz.com" { type master; notify no; file "null.zone.file"; };
 zone "mrpower.ir" { type master; notify no; file "null.zone.file"; };
 zone "mrprintoke.com" { type master; notify no; file "null.zone.file"; };
 zone "mrquick.co.il" { type master; notify no; file "null.zone.file"; };
+zone "mrsambarbershop.nl" { type master; notify no; file "null.zone.file"; };
 zone "mrsbow.com" { type master; notify no; file "null.zone.file"; };
 zone "mrsconnect.org" { type master; notify no; file "null.zone.file"; };
 zone "mrsdiggs.com" { type master; notify no; file "null.zone.file"; };
@@ -61874,6 +61907,7 @@ zone "mvicente.com.br" { type master; notify no; file "null.zone.file"; };
 zone "mvid.com" { type master; notify no; file "null.zone.file"; };
 zone "mvidl.site" { type master; notify no; file "null.zone.file"; };
 zone "mvisionproperties.com" { type master; notify no; file "null.zone.file"; };
+zone "mvldesign.ca" { type master; notify no; file "null.zone.file"; };
 zone "mvm368.com" { type master; notify no; file "null.zone.file"; };
 zone "mvmskpd.com" { type master; notify no; file "null.zone.file"; };
 zone "mvns.railfan.net" { type master; notify no; file "null.zone.file"; };
@@ -63208,6 +63242,7 @@ zone "nellyvonalven.com" { type master; notify no; file "null.zone.file"; };
 zone "nelsonhelps.com" { type master; notify no; file "null.zone.file"; };
 zone "nelsonhostingcom.000webhostapp.com" { type master; notify no; file "null.zone.file"; };
 zone "nelsonpto.org" { type master; notify no; file "null.zone.file"; };
+zone "nelsonsbutchers.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "nelsonsilveti.com" { type master; notify no; file "null.zone.file"; };
 zone "neltac.com" { type master; notify no; file "null.zone.file"; };
 zone "nelyvos.nl" { type master; notify no; file "null.zone.file"; };
@@ -64542,7 +64577,6 @@ zone "no18balloonroom.co.uk" { type master; notify no; file "null.zone.file"; };
 zone "no1angelsescort.com" { type master; notify no; file "null.zone.file"; };
 zone "no1spinningfields.90degrees.digital" { type master; notify no; file "null.zone.file"; };
 zone "no1websitedesigner.com" { type master; notify no; file "null.zone.file"; };
-zone "no2politics.com" { type master; notify no; file "null.zone.file"; };
 zone "no70.fun" { type master; notify no; file "null.zone.file"; };
 zone "noabuseshere.top" { type master; notify no; file "null.zone.file"; };
 zone "noach.nl" { type master; notify no; file "null.zone.file"; };
@@ -65832,6 +65866,7 @@ zone "ogxbody.com" { type master; notify no; file "null.zone.file"; };
 zone "ohako.com.my" { type master; notify no; file "null.zone.file"; };
 zone "ohamburguer.com.br" { type master; notify no; file "null.zone.file"; };
 zone "ohanadev.com" { type master; notify no; file "null.zone.file"; };
+zone "ohatsbd.com" { type master; notify no; file "null.zone.file"; };
 zone "ohdratdigital.com" { type master; notify no; file "null.zone.file"; };
 zone "ohe.ie" { type master; notify no; file "null.zone.file"; };
 zone "ohelloguyzzqq.com" { type master; notify no; file "null.zone.file"; };
@@ -66136,6 +66171,7 @@ zone "omada.edu.gr" { type master; notify no; file "null.zone.file"; };
 zone "omagroup.ru" { type master; notify no; file "null.zone.file"; };
 zone "omaharefugees.com" { type master; notify no; file "null.zone.file"; };
 zone "omahduwur.com" { type master; notify no; file "null.zone.file"; };
+zone "omaia.org" { type master; notify no; file "null.zone.file"; };
 zone "omaint.ml" { type master; notify no; file "null.zone.file"; };
 zone "omalleyco-my.sharepoint.com" { type master; notify no; file "null.zone.file"; };
 zone "omalll.com" { type master; notify no; file "null.zone.file"; };
@@ -71766,6 +71802,7 @@ zone "promodigital.tk" { type master; notify no; file "null.zone.file"; };
 zone "promodont.com" { type master; notify no; file "null.zone.file"; };
 zone "promokonyara.ru" { type master; notify no; file "null.zone.file"; };
 zone "promolatinconferences.com" { type master; notify no; file "null.zone.file"; };
+zone "promolyko.com" { type master; notify no; file "null.zone.file"; };
 zone "promomitsubishitermurah.net" { type master; notify no; file "null.zone.file"; };
 zone "promonoble.com" { type master; notify no; file "null.zone.file"; };
 zone "promootzie.nl" { type master; notify no; file "null.zone.file"; };
@@ -73181,6 +73218,7 @@ zone "quickmusings.com" { type master; notify no; file "null.zone.file"; };
 zone "quickpickapp.co" { type master; notify no; file "null.zone.file"; };
 zone "quickreachmedia.com" { type master; notify no; file "null.zone.file"; };
 zone "quicksaleecuador.com" { type master; notify no; file "null.zone.file"; };
+zone "quickshine.co.ke" { type master; notify no; file "null.zone.file"; };
 zone "quickstorevn.com" { type master; notify no; file "null.zone.file"; };
 zone "quicktechsupport247.com" { type master; notify no; file "null.zone.file"; };
 zone "quicktowtowing.com" { type master; notify no; file "null.zone.file"; };
@@ -75282,6 +75320,7 @@ zone "rgclimatizacion.com" { type master; notify no; file "null.zone.file"; };
 zone "rgdecor.org" { type master; notify no; file "null.zone.file"; };
 zone "rgfloors.com.au" { type master; notify no; file "null.zone.file"; };
 zone "rgitabit.in" { type master; notify no; file "null.zone.file"; };
+zone "rgleason25s.xyz" { type master; notify no; file "null.zone.file"; };
 zone "rglgrupomedico.com.mx" { type master; notify no; file "null.zone.file"; };
 zone "rgmobilegossip.com" { type master; notify no; file "null.zone.file"; };
 zone "rgmvanijya.com" { type master; notify no; file "null.zone.file"; };
@@ -76126,6 +76165,7 @@ zone "roselvi.cl" { type master; notify no; file "null.zone.file"; };
 zone "rosemaryromero.com.br" { type master; notify no; file "null.zone.file"; };
 zone "rosemiracle.com" { type master; notify no; file "null.zone.file"; };
 zone "rosemurphy.co.uk" { type master; notify no; file "null.zone.file"; };
+zone "rosenbaum-jaida24nz.xyz" { type master; notify no; file "null.zone.file"; };
 zone "rosenfeldcapital.com" { type master; notify no; file "null.zone.file"; };
 zone "rosenlaw.cratima.com" { type master; notify no; file "null.zone.file"; };
 zone "roseperfeito.com.br" { type master; notify no; file "null.zone.file"; };
@@ -80044,6 +80084,7 @@ zone "shastri.com" { type master; notify no; file "null.zone.file"; };
 zone "shatabbytek.com" { type master; notify no; file "null.zone.file"; };
 zone "shataikok.com" { type master; notify no; file "null.zone.file"; };
 zone "shatelnews.ir" { type master; notify no; file "null.zone.file"; };
+zone "shatteredglass.io" { type master; notify no; file "null.zone.file"; };
 zone "shaukya.com" { type master; notify no; file "null.zone.file"; };
 zone "shaulla.store" { type master; notify no; file "null.zone.file"; };
 zone "shaunodonnell.com" { type master; notify no; file "null.zone.file"; };
@@ -81905,6 +81946,7 @@ zone "smartlogo.com.br" { type master; notify no; file "null.zone.file"; };
 zone "smartlync.pk" { type master; notify no; file "null.zone.file"; };
 zone "smartmadira.com" { type master; notify no; file "null.zone.file"; };
 zone "smartmassive.ru" { type master; notify no; file "null.zone.file"; };
+zone "smartmatrixs.com" { type master; notify no; file "null.zone.file"; };
 zone "smartmobilelearning.co.za" { type master; notify no; file "null.zone.file"; };
 zone "smartmoneylife.com" { type master; notify no; file "null.zone.file"; };
 zone "smartmovie.com.ua" { type master; notify no; file "null.zone.file"; };
@@ -82867,6 +82909,7 @@ zone "sosctb.com" { type master; notify no; file "null.zone.file"; };
 zone "sosenfantsburkinafaso.fr" { type master; notify no; file "null.zone.file"; };
 zone "sosexymagazine.com" { type master; notify no; file "null.zone.file"; };
 zone "sosflam.com" { type master; notify no; file "null.zone.file"; };
+zone "sosgsm.fr" { type master; notify no; file "null.zone.file"; };
 zone "sosh47.citycheb.ru" { type master; notify no; file "null.zone.file"; };
 zone "sosoab.com" { type master; notify no; file "null.zone.file"; };
 zone "sosofoto.cz" { type master; notify no; file "null.zone.file"; };
@@ -87503,6 +87546,7 @@ zone "tecnologiaoficial.com" { type master; notify no; file "null.zone.file"; };
 zone "tecnologiatech.com" { type master; notify no; file "null.zone.file"; };
 zone "tecnologiaz.com" { type master; notify no; file "null.zone.file"; };
 zone "tecnologicainformatica.com.br" { type master; notify no; file "null.zone.file"; };
+zone "tecnologyschool.com" { type master; notify no; file "null.zone.file"; };
 zone "tecnolora.com" { type master; notify no; file "null.zone.file"; };
 zone "tecnoloxia.com" { type master; notify no; file "null.zone.file"; };
 zone "tecnopc.info" { type master; notify no; file "null.zone.file"; };
@@ -90267,6 +90311,7 @@ zone "tobpm.kz" { type master; notify no; file "null.zone.file"; };
 zone "toby-warren.com" { type master; notify no; file "null.zone.file"; };
 zone "tobyetc.com" { type master; notify no; file "null.zone.file"; };
 zone "tobysherman.com" { type master; notify no; file "null.zone.file"; };
+zone "tocaima.co" { type master; notify no; file "null.zone.file"; };
 zone "tocakids.resultaweb.com.br" { type master; notify no; file "null.zone.file"; };
 zone "tocgiajojo.com" { type master; notify no; file "null.zone.file"; };
 zone "tochkae.ru" { type master; notify no; file "null.zone.file"; };
@@ -91394,6 +91439,7 @@ zone "tresjoliejewellery.com" { type master; notify no; file "null.zone.file"; }
 zone "tresnexus.com" { type master; notify no; file "null.zone.file"; };
 zone "treterhef.download" { type master; notify no; file "null.zone.file"; };
 zone "tretthing-bg.site" { type master; notify no; file "null.zone.file"; };
+zone "treutel-jamir25ju.xyz" { type master; notify no; file "null.zone.file"; };
 zone "trevellinglove.com" { type master; notify no; file "null.zone.file"; };
 zone "trevinos.net" { type master; notify no; file "null.zone.file"; };
 zone "trevorchristensen.com" { type master; notify no; file "null.zone.file"; };
@@ -94096,6 +94142,7 @@ zone "vastintegrated.com" { type master; notify no; file "null.zone.file"; };
 zone "vastraindia.com" { type master; notify no; file "null.zone.file"; };
 zone "vastralaya.shop" { type master; notify no; file "null.zone.file"; };
 zone "vastuanalyst.com" { type master; notify no; file "null.zone.file"; };
+zone "vastubless.com" { type master; notify no; file "null.zone.file"; };
 zone "vastuvidyaarchitects.com" { type master; notify no; file "null.zone.file"; };
 zone "vasudhagoodharvest.com" { type master; notify no; file "null.zone.file"; };
 zone "vasumadhi.com" { type master; notify no; file "null.zone.file"; };
@@ -95441,6 +95488,7 @@ zone "vlad.iset.ro" { type master; notify no; file "null.zone.file"; };
 zone "vladetel.org" { type master; notify no; file "null.zone.file"; };
 zone "vladimirfilin.com" { type master; notify no; file "null.zone.file"; };
 zone "vladimirfilin.ru" { type master; notify no; file "null.zone.file"; };
+zone "vladimirinternational.com" { type master; notify no; file "null.zone.file"; };
 zone "vladneta.lt" { type master; notify no; file "null.zone.file"; };
 zone "vladsever.ru" { type master; notify no; file "null.zone.file"; };
 zone "vladsp.ru" { type master; notify no; file "null.zone.file"; };
@@ -96439,6 +96487,7 @@ zone "web.eficiens.cl" { type master; notify no; file "null.zone.file"; };
 zone "web.emergingsun.com" { type master; notify no; file "null.zone.file"; };
 zone "web.emsfabrik.de" { type master; notify no; file "null.zone.file"; };
 zone "web.eng.ubu.ac.th" { type master; notify no; file "null.zone.file"; };
+zone "web.geetle.ga" { type master; notify no; file "null.zone.file"; };
 zone "web.geomegasoft.net" { type master; notify no; file "null.zone.file"; };
 zone "web.golden-goblin.com" { type master; notify no; file "null.zone.file"; };
 zone "web.gotham.com.au" { type master; notify no; file "null.zone.file"; };
@@ -97253,6 +97302,7 @@ zone "why-h.xyz" { type master; notify no; file "null.zone.file"; };
 zone "whyasksolution.com" { type master; notify no; file "null.zone.file"; };
 zone "whybowl.thebotogs.com" { type master; notify no; file "null.zone.file"; };
 zone "whyepicshop.com" { type master; notify no; file "null.zone.file"; };
+zone "whynt.xyz" { type master; notify no; file "null.zone.file"; };
 zone "whysquare.co.nz" { type master; notify no; file "null.zone.file"; };
 zone "whystudio.cn" { type master; notify no; file "null.zone.file"; };
 zone "whytech.info" { type master; notify no; file "null.zone.file"; };
@@ -98320,6 +98370,7 @@ zone "wroxra.by.files.1drv.com" { type master; notify no; file "null.zone.file";
 zone "wrrodrigo.com" { type master; notify no; file "null.zone.file"; };
 zone "wrtech.com.pl" { type master; notify no; file "null.zone.file"; };
 zone "wrusnollet.com" { type master; notify no; file "null.zone.file"; };
+zone "wrzucacz.pl" { type master; notify no; file "null.zone.file"; };
 zone "wrzutka.co" { type master; notify no; file "null.zone.file"; };
 zone "ws-ebavisapia01-dll.ir" { type master; notify no; file "null.zone.file"; };
 zone "ws3lfkm.com" { type master; notify no; file "null.zone.file"; };
@@ -98767,6 +98818,7 @@ zone "xh.hj46.cn" { type master; notify no; file "null.zone.file"; };
 zone "xhcmnews.com" { type master; notify no; file "null.zone.file"; };
 zone "xhd.qhv.mybluehost.me" { type master; notify no; file "null.zone.file"; };
 zone "xhencheng.tk" { type master; notify no; file "null.zone.file"; };
+zone "xherzog24pv.xyz" { type master; notify no; file "null.zone.file"; };
 zone "xhjclq.ch.files.1drv.com" { type master; notify no; file "null.zone.file"; };
 zone "xhs9a81.com" { type master; notify no; file "null.zone.file"; };
 zone "xhsdxm.com" { type master; notify no; file "null.zone.file"; };
@@ -100626,6 +100678,7 @@ zone "zafinternational.co.id" { type master; notify no; file "null.zone.file"; }
 zone "zafirotiendas.com" { type master; notify no; file "null.zone.file"; };
 zone "zagnet.pl" { type master; notify no; file "null.zone.file"; };
 zone "zagogulina.com" { type master; notify no; file "null.zone.file"; };
+zone "zagoradesertcamp.com" { type master; notify no; file "null.zone.file"; };
 zone "zagrodazbyszka.pl" { type master; notify no; file "null.zone.file"; };
 zone "zagros-shahrekord.ir" { type master; notify no; file "null.zone.file"; };
 zone "zagrosenergygroup.com" { type master; notify no; file "null.zone.file"; };
@@ -100681,6 +100734,7 @@ zone "zakodujbiznes.ml" { type master; notify no; file "null.zone.file"; };
 zone "zakopane.utazas.hu" { type master; notify no; file "null.zone.file"; };
 zone "zakopanedomki.com.pl" { type master; notify no; file "null.zone.file"; };
 zone "zakosciele66.cba.pl" { type master; notify no; file "null.zone.file"; };
+zone "zakra.tecnasulstore.com.br" { type master; notify no; file "null.zone.file"; };
 zone "zakrahgroup.com" { type master; notify no; file "null.zone.file"; };
 zone "zakriasons.co" { type master; notify no; file "null.zone.file"; };
 zone "zakromanoff.com" { type master; notify no; file "null.zone.file"; };
diff --git a/urlhaus-filter-dnsmasq-online.conf b/urlhaus-filter-dnsmasq-online.conf
index ed253f45..8420e2d3 100644
--- a/urlhaus-filter-dnsmasq-online.conf
+++ b/urlhaus-filter-dnsmasq-online.conf
@@ -1,5 +1,5 @@
 # Title: Online Malicious Domains dnsmasq Blocklist
-# Updated: Thu, 25 Mar 2021 12:12:40 UTC
+# Updated: Fri, 26 Mar 2021 00:12:29 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -19,7 +19,6 @@ address=/360.lcy2zzx.pw/0.0.0.0
 address=/360down7.miiyun.cn/0.0.0.0
 address=/8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com/0.0.0.0
 address=/8poieq.bn.files.1drv.com/0.0.0.0
-address=/99centsdigitals.com/0.0.0.0
 address=/abcd.bg/0.0.0.0
 address=/abclicks.in/0.0.0.0
 address=/abissnet.net/0.0.0.0
@@ -27,11 +26,12 @@ address=/aboveandbelow.com.au/0.0.0.0
 address=/absoftechworld.com/0.0.0.0
 address=/absupplies.co.uk/0.0.0.0
 address=/abyssos.eu/0.0.0.0
+address=/academyshademani.com/0.0.0.0
 address=/acbick.com/0.0.0.0
 address=/accounts.thesmarttechhub.com/0.0.0.0
 address=/aceeprc.com.aceeprc.com/0.0.0.0
 address=/acellr.co.uk/0.0.0.0
-address=/aclassapart.in/0.0.0.0
+address=/aciabogados.com/0.0.0.0
 address=/acteon.com.ar/0.0.0.0
 address=/activateyourdiscount.com/0.0.0.0
 address=/activecost.com.au/0.0.0.0
@@ -49,6 +49,7 @@ address=/agemn.co.za/0.0.0.0
 address=/agenciadigitalwdys.com/0.0.0.0
 address=/agenciatabletshouse.com.br/0.0.0.0
 address=/agenda.gmelloinformatica.com.br/0.0.0.0
+address=/agenmovie.xyz/0.0.0.0
 address=/agentt.ac.ug/0.0.0.0
 address=/agile8studio.com/0.0.0.0
 address=/agmcarpetcare.co.uk/0.0.0.0
@@ -60,7 +61,6 @@ address=/al-wahd.com/0.0.0.0
 address=/alasdemariposas.org/0.0.0.0
 address=/alemelektronik.com/0.0.0.0
 address=/alena1971.es/0.0.0.0
-address=/alertlauncher.fr/0.0.0.0
 address=/alexdubai.com.aldiabsteel.com/0.0.0.0
 address=/alka.institute/0.0.0.0
 address=/allforcreative.com.au/0.0.0.0
@@ -72,6 +72,7 @@ address=/amarresdeamorymaestroshechiceros.com/0.0.0.0
 address=/amarteargentina.com.ar/0.0.0.0
 address=/amenyan.zouri.jp/0.0.0.0
 address=/amos524.org/0.0.0.0
+address=/ams.alvinasschools.org.ng/0.0.0.0
 address=/anantam.net.in/0.0.0.0
 address=/andreelapeyre.com/0.0.0.0
 address=/andremaraisbeleggings.co.za/0.0.0.0
@@ -91,10 +92,9 @@ address=/api.sampy.io/0.0.0.0
 address=/aplicativoparasindicato.com.br/0.0.0.0
 address=/apoolcondo.com/0.0.0.0
 address=/app.adsensearticle.com/0.0.0.0
-address=/app.explicitsurveys.co.uk/0.0.0.0
 address=/app.prerana.info/0.0.0.0
 address=/apps.saintsoporte.com/0.0.0.0
-address=/aras.iuc.ac/0.0.0.0
+address=/aqv.news/0.0.0.0
 address=/areyoulivingwell.com/0.0.0.0
 address=/arsapetrolab.com/0.0.0.0
 address=/artedibujoyarquitectura.com/0.0.0.0
@@ -113,11 +113,12 @@ address=/avissrilanka.com/0.0.0.0
 address=/ayamallah.com/0.0.0.0
 address=/azmeasurement.com/0.0.0.0
 address=/azraktours.com/0.0.0.0
-address=/b2b.toptanakaryakit.com.tr/0.0.0.0
 address=/backgrounds.pk/0.0.0.0
 address=/backup.agewsage.com/0.0.0.0
 address=/badeggdesign.com/0.0.0.0
+address=/balealgodon.mx/0.0.0.0
 address=/bangkok-orchids.com/0.0.0.0
+address=/barcionstw.eastus.cloudapp.azure.com/0.0.0.0
 address=/bary.sz4h.com/0.0.0.0
 address=/basma.com.kw/0.0.0.0
 address=/bausch.kr-atlas.monaxikoslykos@zytrox.tk/0.0.0.0
@@ -126,7 +127,6 @@ address=/bbia.co.uk/0.0.0.0
 address=/bcmt.elin.co.za/0.0.0.0
 address=/bcrg.co.za/0.0.0.0
 address=/bearcatpumps.com.cn/0.0.0.0
-address=/beatyamerican.com/0.0.0.0
 address=/beautincollagen.rs/0.0.0.0
 address=/bekape.co.id/0.0.0.0
 address=/bespokeweddings.ie/0.0.0.0
@@ -134,6 +134,8 @@ address=/bestcarenepal.com/0.0.0.0
 address=/betone.co.kr/0.0.0.0
 address=/betycopaints.com/0.0.0.0
 address=/beveragesmiami.solucioneslink.com/0.0.0.0
+address=/bhavaniengineering.com/0.0.0.0
+address=/bigbag.wootraining.certificacion.cl/0.0.0.0
 address=/bilbosaquet.ug/0.0.0.0
 address=/bilhen.co.za/0.0.0.0
 address=/billing.rahitechnosoft.com/0.0.0.0
@@ -141,11 +143,10 @@ address=/birdi.elin.co.za/0.0.0.0
 address=/birminghamlink.org/0.0.0.0
 address=/blog.callensaxen.com/0.0.0.0
 address=/blog.oyinblogs.com/0.0.0.0
-address=/blog.takbelit.com/0.0.0.0
 address=/bmlifestyle.co.uk/0.0.0.0
+address=/bnrbook.com/0.0.0.0
 address=/bnrnews.id/0.0.0.0
 address=/bodenstein.co.za/0.0.0.0
-address=/bolnicaloznica.rs/0.0.0.0
 address=/booksearch.com/0.0.0.0
 address=/bounces.mi-fs.com/0.0.0.0
 address=/bpo.correct.go.th/0.0.0.0
@@ -159,23 +160,21 @@ address=/brightonrooms.co.uk/0.0.0.0
 address=/brightstarshop.com/0.0.0.0
 address=/browardinsurancemiami.solucioneslink.com/0.0.0.0
 address=/bt2.elin.co.za/0.0.0.0
-address=/btdapi.robotake.com/0.0.0.0
 address=/bucrinsuranlceonlines.com/0.0.0.0
 address=/buenavista.co/0.0.0.0
-address=/buigiaphat.com.vn/0.0.0.0
 address=/bullseyemedia.in/0.0.0.0
 address=/busandvanrentalmalaysia.com/0.0.0.0
 address=/buscascolegios.diit.cl/0.0.0.0
 address=/business.softberg.ro/0.0.0.0
 address=/buyingmusiconline.com/0.0.0.0
-address=/buypropertyfast.com/0.0.0.0
 address=/bwsr.eu/0.0.0.0
 address=/c.oooooooooo.ga/0.0.0.0
 address=/c0140529.ferozo.com/0.0.0.0
+address=/caballo.com.au/0.0.0.0
 address=/cacapavaonline.sdserver144.com.br/0.0.0.0
+address=/calgaryautorepairservice.com/0.0.0.0
 address=/callbury.in/0.0.0.0
 address=/camminachetipassa.it/0.0.0.0
-address=/campusvirtual.cepsanjuanbosco.net.pe/0.0.0.0
 address=/cancer.educandome.co/0.0.0.0
 address=/capitalgroup-kw.com/0.0.0.0
 address=/capitalnewsagency.com/0.0.0.0
@@ -188,12 +187,10 @@ address=/cazyacustomfurniture.com/0.0.0.0
 address=/ccauthority.net/0.0.0.0
 address=/cdaonline.com.ar/0.0.0.0
 address=/cec.asso.ac-amiens.fr/0.0.0.0
-address=/cellas.sk/0.0.0.0
 address=/cendekiabinaaksara.com/0.0.0.0
 address=/cespol-bote.com.mx/0.0.0.0
 address=/cfs5.tistory.com/0.0.0.0
 address=/ch.rmu.ac.th/0.0.0.0
-address=/changematterscounselling.com/0.0.0.0
 address=/chardhamdodham.com/0.0.0.0
 address=/cheacrilnsurances.com/0.0.0.0
 address=/chealablilitycarinsurances.com/0.0.0.0
@@ -201,15 +198,14 @@ address=/chezalice.co.za/0.0.0.0
 address=/childselect.com/0.0.0.0
 address=/chinhdropfile.myvnc.com/0.0.0.0
 address=/chinhdropfile80.myvnc.com/0.0.0.0
-address=/chipmania.it/0.0.0.0
 address=/cible-energy.com/0.0.0.0
 address=/cifeer.net/0.0.0.0
 address=/citycapproperty.ru/0.0.0.0
 address=/cityglobalgospel.com/0.0.0.0
 address=/civi.istmejia.com/0.0.0.0
 address=/cleanbydesignllc.com/0.0.0.0
-address=/clim34000.fr/0.0.0.0
 address=/cloud.fc.co.mz/0.0.0.0
+address=/clurbgolf.com/0.0.0.0
 address=/codsambal.com/0.0.0.0
 address=/colinde.pricesne.com/0.0.0.0
 address=/colorpak.pl/0.0.0.0
@@ -231,7 +227,6 @@ address=/creationskateboards.com/0.0.0.0
 address=/crecerco.com/0.0.0.0
 address=/crittersbythebay.com/0.0.0.0
 address=/crm.notariavieitoyvelamazan.com/0.0.0.0
-address=/crmmanivela.net/0.0.0.0
 address=/crscorretordeimoveis.com.br/0.0.0.0
 address=/cse-engineer.com/0.0.0.0
 address=/csnserver.com/0.0.0.0
@@ -278,7 +273,6 @@ address=/destinymc.co.za/0.0.0.0
 address=/detorre.es/0.0.0.0
 address=/dev-interestingtech.pantheonsite.io/0.0.0.0
 address=/dev.sebpo.net/0.0.0.0
-address=/dezcom.com/0.0.0.0
 address=/dfcf.91756.cn/0.0.0.0
 address=/dfsfcsfcdsfsdvcfsvcscv.com/0.0.0.0
 address=/diamantenegro.mi-fs.com/0.0.0.0
@@ -301,7 +295,6 @@ address=/dom.daf.free.fr/0.0.0.0
 address=/doncedyhall.com/0.0.0.0
 address=/donghobinhminh.com/0.0.0.0
 address=/dongphuctop.com/0.0.0.0
-address=/donwnloasecury.ath.cx/0.0.0.0
 address=/dosame.com/0.0.0.0
 address=/dosman.pl/0.0.0.0
 address=/dovberger.com/0.0.0.0
@@ -309,6 +302,9 @@ address=/down.flash-plays.com/0.0.0.0
 address=/down.pcclear.com/0.0.0.0
 address=/down.posti-fi-fsa.top/0.0.0.0
 address=/down.posti-fi-fwa.top/0.0.0.0
+address=/down.posti-fi-ij.top/0.0.0.0
+address=/down.posti-fi-in.top/0.0.0.0
+address=/down.posti-fi-iz.top/0.0.0.0
 address=/down.udashi.com/0.0.0.0
 address=/down.webbora.com/0.0.0.0
 address=/down1.arpun.com/0.0.0.0
@@ -325,7 +321,6 @@ address=/dragonsknot.com/0.0.0.0
 address=/drbaby.com.sa/0.0.0.0
 address=/drohnen.ensenanzainteligente.com/0.0.0.0
 address=/drools-moved.46999.n3.nabble.com/0.0.0.0
-address=/drrohanfonseca.com/0.0.0.0
 address=/drsha.innovativesolutions.mobi/0.0.0.0
 address=/dsenterprize.co.za/0.0.0.0
 address=/dsspainting.com/0.0.0.0
@@ -339,19 +334,15 @@ address=/e-commerce.saleensuporte.com.br/0.0.0.0
 address=/e.sldov.ru/0.0.0.0
 address=/ebruyatkin.com/0.0.0.0
 address=/econews.treegle.org/0.0.0.0
-address=/edelweissdecoration.com/0.0.0.0
 address=/efficientegroup.com/0.0.0.0
 address=/elliot.newreadermedia.net/0.0.0.0
-address=/emaids.co.za/0.0.0.0
 address=/en.baoend.com/0.0.0.0
 address=/enc-tech.com/0.0.0.0
 address=/endurotanzania.co.tz/0.0.0.0
-address=/enkonooh.com/0.0.0.0
 address=/ennovate.elin.co.za/0.0.0.0
 address=/enriquecendocomconsorcio.com.br/0.0.0.0
 address=/envios.petpienso.cl/0.0.0.0
 address=/equimination.ee/0.0.0.0
-address=/es.paymelist.com/0.0.0.0
 address=/escola.probommar.org.br/0.0.0.0
 address=/esnconsultants.com/0.0.0.0
 address=/essentia.org.br/0.0.0.0
@@ -363,15 +354,14 @@ address=/extrovertoffers.com/0.0.0.0
 address=/f1sol.com/0.0.0.0
 address=/familydentist.site/0.0.0.0
 address=/farmaciasdrogaminas.com.br/0.0.0.0
-address=/farmnatural.in/0.0.0.0
 address=/faveraprojects.com/0.0.0.0
 address=/fc.co.mz/0.0.0.0
 address=/felicienne.nl/0.0.0.0
 address=/fi.bonitastores.com/0.0.0.0
 address=/files.martellexpress.us/0.0.0.0
 address=/files6.uludagbilisim.com/0.0.0.0
-address=/filmotainment.com/0.0.0.0
 address=/final.makkahkmcc.com/0.0.0.0
+address=/fineartgallerym.com/0.0.0.0
 address=/fkd.derpcity.ru/0.0.0.0
 address=/flintspin.com/0.0.0.0
 address=/flyingbuddhadesign.com/0.0.0.0
@@ -379,20 +369,17 @@ address=/fmjplastering.co.uk/0.0.0.0
 address=/fms.buladde.or.ug/0.0.0.0
 address=/foothills.com.br/0.0.0.0
 address=/footweardirect.elin.co.za/0.0.0.0
-address=/formestore.evencsoft.co/0.0.0.0
 address=/forum.mdb.nu/0.0.0.0
 address=/fotoobjetivo.com/0.0.0.0
 address=/foundationrepairhoustontx.net/0.0.0.0
 address=/foxeps.com.br/0.0.0.0
 address=/freecnetdownload.com/0.0.0.0
-address=/freedombookshop.tickme.lk/0.0.0.0
 address=/freisites.com.br/0.0.0.0
 address=/ftp.n3twork30cm.ml/0.0.0.0
 address=/fullelectronica.com.ar/0.0.0.0
 address=/funletters.net/0.0.0.0
 address=/fusionfiresolutions.com/0.0.0.0
 address=/futuregraphics.com.ar/0.0.0.0
-address=/gahanassociates.com/0.0.0.0
 address=/gametwogame.com/0.0.0.0
 address=/garayvidalabogados.com/0.0.0.0
 address=/garciadogshow.com/0.0.0.0
@@ -400,7 +387,6 @@ address=/garenanow.myvnc.com/0.0.0.0
 address=/garenanow4.myvnc.com/0.0.0.0
 address=/gbbulls.co.uk/0.0.0.0
 address=/gcpc.co.id.chronoscurtain.com/0.0.0.0
-address=/gcrcorporation.com/0.0.0.0
 address=/generaldeviales.com/0.0.0.0
 address=/gfmodd1.webselffiles01.com/0.0.0.0
 address=/gfold1.webselffiles01.com/0.0.0.0
@@ -408,6 +394,8 @@ address=/ghettohub.co.za/0.0.0.0
 address=/ghislain.dartois.pagesperso-orange.fr/0.0.0.0
 address=/giadungg7.com/0.0.0.0
 address=/giddos.ga/0.0.0.0
+address=/gilliem.com/0.0.0.0
+address=/girotexuniformes.com/0.0.0.0
 address=/giteletropical.com/0.0.0.0
 address=/globaltask.ar/0.0.0.0
 address=/glowinmedia.co.ke/0.0.0.0
@@ -422,10 +410,12 @@ address=/goldcoastoffice365.com.au/0.0.0.0
 address=/goldcupmortgage.com/0.0.0.0
 address=/golden-memories-funerals.yourpageserver.com/0.0.0.0
 address=/goldmen.in/0.0.0.0
+address=/gorecycle.fahadjutt.com/0.0.0.0
 address=/gracejukes.com/0.0.0.0
 address=/grupoinmare.com/0.0.0.0
 address=/gruposelt.000webhostapp.com/0.0.0.0
 address=/gs.monerorx.com/0.0.0.0
+address=/guide-to-cell-phones.com/0.0.0.0
 address=/gulfac-house.com/0.0.0.0
 address=/gvpcdpgc.edu.in/0.0.0.0
 address=/habbotips.free.fr/0.0.0.0
@@ -451,6 +441,7 @@ address=/hitstation.nl/0.0.0.0
 address=/hmpmall.co.kr/0.0.0.0
 address=/hoagietesting10.com/0.0.0.0
 address=/hoayeuthuong-my.sharepoint.com/0.0.0.0
+address=/holmesprpmgmt.com/0.0.0.0
 address=/homefindersolutions.com/0.0.0.0
 address=/hongluosi.com/0.0.0.0
 address=/hookedupboatclub.com/0.0.0.0
@@ -462,7 +453,6 @@ address=/hseda.com/0.0.0.0
 address=/hsmwebapp.com/0.0.0.0
 address=/htownbars.com/0.0.0.0
 address=/hubtech.co.za/0.0.0.0
-address=/huequito.evencsoft.co/0.0.0.0
 address=/hunggiang.vn/0.0.0.0
 address=/husamiyahschool.com/0.0.0.0
 address=/iam313.com/0.0.0.0
@@ -474,6 +464,7 @@ address=/idvindia.com/0.0.0.0
 address=/iesanjosemonitos.edu.co/0.0.0.0
 address=/ikexpert.com/0.0.0.0
 address=/ilrafrica.com/0.0.0.0
+address=/images.jermiau.com/0.0.0.0
 address=/imbueautoworx.co.za/0.0.0.0
 address=/imperiumtherapy.co.za/0.0.0.0
 address=/in-tune2016.com/0.0.0.0
@@ -488,6 +479,7 @@ address=/inodesthetotaldesigners.com/0.0.0.0
 address=/inovations.searchkero.com/0.0.0.0
 address=/inrajahmundry.co.in/0.0.0.0
 address=/insignificantfinecore.testmail4.repl.co/0.0.0.0
+address=/instantindialoan.com/0.0.0.0
 address=/instvisionmexico.edu.mx/0.0.0.0
 address=/intellectsmart.in/0.0.0.0
 address=/intersel-idf.org/0.0.0.0
@@ -498,6 +490,7 @@ address=/ipmes.ma/0.0.0.0
 address=/iremart.es/0.0.0.0
 address=/iris101.co.uk/0.0.0.0
 address=/iscamenabe.com/0.0.0.0
+address=/ismf.com.ng/0.0.0.0
 address=/iso-dubai.net/0.0.0.0
 address=/israrulhaq.me/0.0.0.0
 address=/isrorg.com/0.0.0.0
@@ -518,7 +511,6 @@ address=/jhayesconsulting.com/0.0.0.0
 address=/jiaoyuzixun.cn/0.0.0.0
 address=/jing-da.com.tw/0.0.0.0
 address=/jktnet.xyz/0.0.0.0
-address=/jmcomputacion.com.ar/0.0.0.0
 address=/jmtc.91756.cn/0.0.0.0
 address=/jnanbharati.com/0.0.0.0
 address=/jobs.thebeessolution.com/0.0.0.0
@@ -527,9 +519,7 @@ address=/join.cl8movement.co.za/0.0.0.0
 address=/josegene.com/0.0.0.0
 address=/josuarochoa.com/0.0.0.0
 address=/jpwoodfordco.com/0.0.0.0
-address=/julietlaser.site/0.0.0.0
 address=/jumpmanualjacobhiller.com/0.0.0.0
-address=/jumpnjamchicago.com/0.0.0.0
 address=/jupiter.toxsl.in/0.0.0.0
 address=/jurgensen.newreadermedia.net/0.0.0.0
 address=/justinscott.com.au/0.0.0.0
@@ -551,6 +541,7 @@ address=/kubatoglubaklava.com.tr/0.0.0.0
 address=/kumaralok.in/0.0.0.0
 address=/kwanfromhongkong.com/0.0.0.0
 address=/kz.sldov.ru/0.0.0.0
+address=/lab18.it/0.0.0.0
 address=/lacasadelosalebrijes.com/0.0.0.0
 address=/ladylabonde.com/0.0.0.0
 address=/lameguard.ru/0.0.0.0
@@ -596,6 +587,7 @@ address=/lp.definerisco.com/0.0.0.0
 address=/lp.difusodesign.com/0.0.0.0
 address=/lp.juancamilogarciareyes.com/0.0.0.0
 address=/lp.tecnimasdecolombia.com.co/0.0.0.0
+address=/ltc.typoten.com/0.0.0.0
 address=/luckybrownie.com/0.0.0.0
 address=/luminouspneuma.com/0.0.0.0
 address=/luxomodels.com/0.0.0.0
@@ -604,15 +596,15 @@ address=/m.estudiomoros.com.ar/0.0.0.0
 address=/madicon.co.za/0.0.0.0
 address=/magianegramagiablancayamarres.com/0.0.0.0
 address=/mail.bs-eiendomme.co.za/0.0.0.0
+address=/mail.golimoapp.com/0.0.0.0
 address=/mail.jeffsono.org/0.0.0.0
 address=/maksi.feb.unib.ac.id/0.0.0.0
 address=/malaya.tv/0.0.0.0
 address=/malwarecoding.github.io/0.0.0.0
 address=/managed.oss-cn-beijing.aliyuncs.com/0.0.0.0
+address=/managemysalon.in/0.0.0.0
 address=/manantialesdelnorte.uy/0.0.0.0
-address=/manivelasst.com/0.0.0.0
 address=/marcapinyo.ru/0.0.0.0
-address=/marcusthepoet.com/0.0.0.0
 address=/mario-sunjic.com/0.0.0.0
 address=/mariobrown.net/0.0.0.0
 address=/mariotessarollo.com/0.0.0.0
@@ -621,7 +613,6 @@ address=/marketing.enexusgroup.com.au/0.0.0.0
 address=/marksidfgs.ug/0.0.0.0
 address=/masjidhabeebiyarazviya.mysunni.com/0.0.0.0
 address=/materialescantu.com/0.0.0.0
-address=/matinal-nominal.pt/0.0.0.0
 address=/matruchhaya.co.in/0.0.0.0
 address=/mattysplayground.com/0.0.0.0
 address=/maxtox.com.pk/0.0.0.0
@@ -633,6 +624,7 @@ address=/media-server.skyinternet.com.pk/0.0.0.0
 address=/mediamaster.co.za/0.0.0.0
 address=/medianews.ge/0.0.0.0
 address=/medistaffconsulting.com/0.0.0.0
+address=/meditreat.itwebservice.in/0.0.0.0
 address=/meeweb.com/0.0.0.0
 address=/megamart.afnan-amc.com/0.0.0.0
 address=/merbay.ru/0.0.0.0
@@ -653,7 +645,6 @@ address=/midlandtexasconstruction.com/0.0.0.0
 address=/mindfulbuildingandliving.com/0.0.0.0
 address=/mingguanwms.com/0.0.0.0
 address=/minuevavida.org/0.0.0.0
-address=/mirror.mypage.sk/0.0.0.0
 address=/mis.nbcc.ac.th/0.0.0.0
 address=/misterson.com/0.0.0.0
 address=/mixr.at/0.0.0.0
@@ -661,12 +652,14 @@ address=/mkontakt.az/0.0.0.0
 address=/mktf.mx/0.0.0.0
 address=/mmogollon.com.mx/0.0.0.0
 address=/mncarteam.com/0.0.0.0
+address=/mobile.illumetechnology.com/0.0.0.0
 address=/modelhouseturkey.com/0.0.0.0
 address=/modernmanna.org/0.0.0.0
 address=/monetization.business/0.0.0.0
 address=/moninediy.com/0.0.0.0
 address=/mopai.sg/0.0.0.0
 address=/motorcomunicacion.com/0.0.0.0
+address=/msacontabil.com.br/0.0.0.0
 address=/mtspsmjeli.sch.id/0.0.0.0
 address=/muzimbiti.xigubo.co.mz/0.0.0.0
 address=/mxpiqw.am.files.1drv.com/0.0.0.0
@@ -699,8 +692,8 @@ address=/nhorangtreem.com/0.0.0.0
 address=/nicolas.ug/0.0.0.0
 address=/nidhi.iexist.in/0.0.0.0
 address=/nikanpolimer.ir/0.0.0.0
+address=/nilehouse.co.ug/0.0.0.0
 address=/nilinkeji.com/0.0.0.0
-address=/nisacooks.com/0.0.0.0
 address=/njtiledesigncenter.com/0.0.0.0
 address=/nobius.org/0.0.0.0
 address=/nocalnoodle.elin.co.za/0.0.0.0
@@ -718,10 +711,13 @@ address=/nyeh2o.com.au/0.0.0.0
 address=/oakleyandfriends.co.uk/0.0.0.0
 address=/obseques-conseils.com/0.0.0.0
 address=/ocean.tecnasulstore.com.br/0.0.0.0
+address=/ohe.ie/0.0.0.0
 address=/ohsewgorgeous.co.uk/0.0.0.0
+address=/oknoplastik.sk/0.0.0.0
 address=/oleholeh.memangbeda.website/0.0.0.0
 address=/olirecords.mixture.ltd/0.0.0.0
 address=/olooom.com/0.0.0.0
+address=/omaia.org/0.0.0.0
 address=/omaromatic.com/0.0.0.0
 address=/omega.az/0.0.0.0
 address=/oms.pappai.com/0.0.0.0
@@ -730,6 +726,7 @@ address=/onedigitalcard.granvizionnecorp.com/0.0.0.0
 address=/onedrive.listifyapp.co/0.0.0.0
 address=/online.creedglobal.in/0.0.0.0
 address=/onlinestatis.bar/0.0.0.0
+address=/ont.proman.id/0.0.0.0
 address=/open.warehousesaas.co.uk/0.0.0.0
 address=/opolis.io/0.0.0.0
 address=/optimus.com.sg/0.0.0.0
@@ -737,6 +734,8 @@ address=/optitechsa.co.za/0.0.0.0
 address=/order.bizpeed.com/0.0.0.0
 address=/orientgatewayltd.com/0.0.0.0
 address=/orion445.com/0.0.0.0
+address=/oserve.pk/0.0.0.0
+address=/otolithenrichment.fahadjutt.com/0.0.0.0
 address=/ottimade.com/0.0.0.0
 address=/ourteam.searchkero.com/0.0.0.0
 address=/ozemag.com/0.0.0.0
@@ -758,6 +757,7 @@ address=/patch3.99ddd.com/0.0.0.0
 address=/paths.elin.co.za/0.0.0.0
 address=/paulmercier.biz/0.0.0.0
 address=/payerrealty.com/0.0.0.0
+address=/payments.atifsiddiqui.me/0.0.0.0
 address=/pcsoori.com/0.0.0.0
 address=/pd.oceaniarp.net/0.0.0.0
 address=/perpus.onlineman7-jombang.sch.id/0.0.0.0
@@ -770,6 +770,7 @@ address=/phittc.com/0.0.0.0
 address=/photo360.kubooking.com/0.0.0.0
 address=/photographytipsclub.com/0.0.0.0
 address=/pink99.com/0.0.0.0
+address=/pizzabarletta.com.br/0.0.0.0
 address=/plasfan.ind.br/0.0.0.0
 address=/pmglance.startwriteup.com/0.0.0.0
 address=/pokojewewladyslawowie.pl/0.0.0.0
@@ -779,15 +780,13 @@ address=/pooltablemoversdenver.net/0.0.0.0
 address=/posmicrosystems.com/0.0.0.0
 address=/poulman.panagiotopoulos-tours.gr/0.0.0.0
 address=/ppdb.smk-ciptaskill.sch.id/0.0.0.0
-address=/pptvideotemplates.com/0.0.0.0
 address=/prestasicash.com.ar/0.0.0.0
 address=/prestigehomeautomation.net/0.0.0.0
 address=/prishaartcreations.com/0.0.0.0
 address=/production.sparshims.com/0.0.0.0
-address=/productprecise.com/0.0.0.0
-address=/prof-dr-ahmedalmoatasem.com/0.0.0.0
 address=/programaoperadoronline.com.br/0.0.0.0
 address=/project.exquitec.com/0.0.0.0
+address=/promolyko.com/0.0.0.0
 address=/promotoradescomplica.com.br/0.0.0.0
 address=/promoversdubai.com/0.0.0.0
 address=/propertiq.elin.co.za/0.0.0.0
@@ -800,7 +799,7 @@ address=/prueba.danielluza.com/0.0.0.0
 address=/pujashoppe.in/0.0.0.0
 address=/punchdialogues.com/0.0.0.0
 address=/punjabdevelopersassociation.com.pk/0.0.0.0
-address=/purefoe.top/0.0.0.0
+address=/pvcprinting.co.uk/0.0.0.0
 address=/qadir.tickfa.ir/0.0.0.0
 address=/qatarglobalconsulting.com/0.0.0.0
 address=/qmsled.com/0.0.0.0
@@ -816,7 +815,6 @@ address=/ratemyfenancialadvisor.com/0.0.0.0
 address=/ravenproductionsltd.com/0.0.0.0
 address=/rc.ixiaoyang.cn/0.0.0.0
 address=/readymmade.com/0.0.0.0
-address=/realtheprocess.co/0.0.0.0
 address=/redchillicrackers.com/0.0.0.0
 address=/reifenquick.de/0.0.0.0
 address=/relaxindulge.co.nz/0.0.0.0
@@ -866,7 +864,6 @@ address=/santyago.org/0.0.0.0
 address=/sarakem.cl/0.0.0.0
 address=/sasystemsuk.com/0.0.0.0
 address=/savasaachi.systems/0.0.0.0
-address=/savingchintu.com/0.0.0.0
 address=/scarfaceindustries.com/0.0.0.0
 address=/scglobal.co.th/0.0.0.0
 address=/schalke04rss.de/0.0.0.0
@@ -874,10 +871,8 @@ address=/scheff.com/0.0.0.0
 address=/schoolbustracker.softgig.co.ke/0.0.0.0
 address=/sec-doc-w.com/0.0.0.0
 address=/secure-doc-reader.com/0.0.0.0
-address=/sefp-boispro.fr/0.0.0.0
 address=/segalsmetals.elin.co.za/0.0.0.0
 address=/sellmyphonela.com/0.0.0.0
-address=/selltechtoday.com/0.0.0.0
 address=/senbiaojita.com/0.0.0.0
 address=/sentierodelviandante.ml/0.0.0.0
 address=/serendibsourcing.com/0.0.0.0
@@ -894,7 +889,6 @@ address=/shembefoundation.com/0.0.0.0
 address=/shivakunwar.com.np/0.0.0.0
 address=/shoblasaathitrust.org/0.0.0.0
 address=/shooka-co.com/0.0.0.0
-address=/shop.clarostudio.ro/0.0.0.0
 address=/shop.goldspot.agency/0.0.0.0
 address=/shopsofe.com/0.0.0.0
 address=/shrushtiinfotech.com/0.0.0.0
@@ -906,11 +900,11 @@ address=/siili.net/0.0.0.0
 address=/simoneporzi.it/0.0.0.0
 address=/simplithy.co.uk/0.0.0.0
 address=/sindicato1ucm.cl/0.0.0.0
+address=/sindpol.tiejuris.com.br/0.0.0.0
 address=/sinergidwireka.com/0.0.0.0
 address=/sipahielektrik.com/0.0.0.0
 address=/siperb.in/0.0.0.0
 address=/sistelligent.com/0.0.0.0
-address=/site.sjc.co.ke/0.0.0.0
 address=/skkksolo.beweiretail.com/0.0.0.0
 address=/skyflyfares.com/0.0.0.0
 address=/skyscan.com/0.0.0.0
@@ -920,7 +914,6 @@ address=/smartzedu.com/0.0.0.0
 address=/smokeandgrowrichtour.com/0.0.0.0
 address=/smokesolutionindia.com/0.0.0.0
 address=/sobethuacademy.com/0.0.0.0
-address=/soft.110route.com/0.0.0.0
 address=/soft.officelabo.net/0.0.0.0
 address=/sohs.conceptechs.info/0.0.0.0
 address=/solar.amazingtribe.lk/0.0.0.0
@@ -929,11 +922,11 @@ address=/somcorbera.cat/0.0.0.0
 address=/somir.com.mx/0.0.0.0
 address=/soralapps.com/0.0.0.0
 address=/sorteio.orgaostalita.com.br/0.0.0.0
+address=/sosgsm.fr/0.0.0.0
 address=/sota-france.fr/0.0.0.0
 address=/sowingminerals.cl/0.0.0.0
 address=/space.proactint.org/0.0.0.0
 address=/spaceframe.mobi.space-frame.co.za/0.0.0.0
-address=/specfloors.net/0.0.0.0
 address=/special-key.cf/0.0.0.0
 address=/spent.com.pl/0.0.0.0
 address=/spetsesyachtcharter.gr/0.0.0.0
@@ -965,6 +958,7 @@ address=/supermercadostia.com/0.0.0.0
 address=/support-4-free.com/0.0.0.0
 address=/support.clz.kr/0.0.0.0
 address=/supportit.online/0.0.0.0
+address=/surestdysbonescagexc.dns.army/0.0.0.0
 address=/sw.yourpageserver.com/0.0.0.0
 address=/sweaty.dk/0.0.0.0
 address=/sweet-diet.com/0.0.0.0
@@ -990,11 +984,11 @@ address=/taxpos.com/0.0.0.0
 address=/tc.snpsresidential.com/0.0.0.0
 address=/tcy.198424.com/0.0.0.0
 address=/tdsp.yngw518.com/0.0.0.0
-address=/tech332.synology.me/0.0.0.0
 address=/techgms.com/0.0.0.0
 address=/technogreen.crmmanivela.com/0.0.0.0
 address=/technohub.searchkero.com/0.0.0.0
 address=/tecnicaencolectores.com.mx/0.0.0.0
+address=/tecnologyschool.com/0.0.0.0
 address=/teduae.com/0.0.0.0
 address=/teleargentina.com/0.0.0.0
 address=/telescopelms.com/0.0.0.0
@@ -1002,9 +996,9 @@ address=/telmed.cl/0.0.0.0
 address=/temptmag.com/0.0.0.0
 address=/tennisafrica.com/0.0.0.0
 address=/tentandoserfitness.000webhostapp.com/0.0.0.0
-address=/tepresto.net.pe/0.0.0.0
 address=/test.adventser.com/0.0.0.0
 address=/test.letraele.es/0.0.0.0
+address=/test.typoten.com/0.0.0.0
 address=/test.wanepghana.org/0.0.0.0
 address=/test1.asistencia247.com/0.0.0.0
 address=/test1.milenial.id/0.0.0.0
@@ -1017,9 +1011,7 @@ address=/testnew.yourpageserver.com/0.0.0.0
 address=/teteaffiche.stephanebillon.com/0.0.0.0
 address=/tewoerd.eu/0.0.0.0
 address=/textile.softberg.ro/0.0.0.0
-address=/texts.bfftexts.com/0.0.0.0
 address=/texturesbyvinita.com/0.0.0.0
-address=/tharringtonsponsorship.com/0.0.0.0
 address=/thecleaningladiespdx.com/0.0.0.0
 address=/thecreativecafe.co.uk/0.0.0.0
 address=/thefuturelife.in/0.0.0.0
@@ -1027,12 +1019,11 @@ address=/thehighlightinterior.com/0.0.0.0
 address=/thehouseofpragya.com/0.0.0.0
 address=/thekassia.co.uk/0.0.0.0
 address=/thelaunchpadteam.com/0.0.0.0
-address=/thelekhak.com/0.0.0.0
 address=/thelogicalgroup.co.uk/0.0.0.0
 address=/thesummitpc.net/0.0.0.0
 address=/theurbantutors.com/0.0.0.0
+address=/thewwpc.com/0.0.0.0
 address=/thosewebbs.com/0.0.0.0
-address=/thriveink.com/0.0.0.0
 address=/tianangdep.com/0.0.0.0
 address=/tickfood.tickme.lk/0.0.0.0
 address=/tickjobs.tickme.lk/0.0.0.0
@@ -1065,7 +1056,6 @@ address=/tsd.jxwan.com/0.0.0.0
 address=/tulli.info/0.0.0.0
 address=/tupperware.michaelroberge.ca/0.0.0.0
 address=/turanggaresources.com/0.0.0.0
-address=/tushartyagiji.digitalswagger.in/0.0.0.0
 address=/uat.indianfilmzone.com/0.0.0.0
 address=/ublretailerdemo.cstdevs.com/0.0.0.0
 address=/udesk.searchkero.com/0.0.0.0
@@ -1075,7 +1065,6 @@ address=/umwelt-kirchhof.de/0.0.0.0
 address=/unicorpbrunei.com/0.0.0.0
 address=/uniengrisb.com/0.0.0.0
 address=/unisoftcc.com/0.0.0.0
-address=/unitedpestsolutionstx.com/0.0.0.0
 address=/unyazitelecom.com/0.0.0.0
 address=/upcbpta.com/0.0.0.0
 address=/urbane.dezinetimes.com/0.0.0.0
@@ -1102,17 +1091,18 @@ address=/vitoriamodaintima.com.br/0.0.0.0
 address=/vivationdesign.com/0.0.0.0
 address=/viveirodoiscorregos.com.br/0.0.0.0
 address=/vksales.com/0.0.0.0
+address=/vladimirinternational.com/0.0.0.0
 address=/vokasi.ub.ac.id/0.0.0.0
 address=/vologroup.com.br/0.0.0.0
 address=/voteyouramerica.dekitout.com/0.0.0.0
 address=/vstsample.com/0.0.0.0
 address=/vtube.fadlymotivator.com/0.0.0.0
 address=/vvsskmodinationalschool.com/0.0.0.0
-address=/wahrewah.nl/0.0.0.0
 address=/wanepliberia.org/0.0.0.0
 address=/wanepniger.org/0.0.0.0
 address=/weareactum.com/0.0.0.0
 address=/web.eng.ubu.ac.th/0.0.0.0
+address=/web.geetle.ga/0.0.0.0
 address=/web.geomegasoft.net/0.0.0.0
 address=/web.newinnovationtechnology.com/0.0.0.0
 address=/web.smarts-works.com/0.0.0.0
@@ -1126,13 +1116,12 @@ address=/wexfashion.com/0.0.0.0
 address=/whcms.yourpageserver.com/0.0.0.0
 address=/whiteglovetailgate.com/0.0.0.0
 address=/whiteresponse.com/0.0.0.0
+address=/whynt.xyz/0.0.0.0
 address=/wi522012.ferozo.com/0.0.0.0
 address=/wikalen.co.za/0.0.0.0
 address=/wildnights.co.uk/0.0.0.0
 address=/wildtrust.mediadevstaging.com/0.0.0.0
 address=/wimbamusica.com/0.0.0.0
-address=/windcomtechnologies.com/0.0.0.0
-address=/winnercircle.it/0.0.0.0
 address=/wishesconcierge.com/0.0.0.0
 address=/woezon.agency/0.0.0.0
 address=/wolfgang-brodte.de/0.0.0.0
@@ -1148,7 +1137,6 @@ address=/x2vn.com/0.0.0.0
 address=/xia.beihaixue.com/0.0.0.0
 address=/xixaoclothing.com/0.0.0.0
 address=/xk.996is.com/0.0.0.0
-address=/xmp.myracingaccounts.com/0.0.0.0
 address=/xn--80akinnkiib6h.xn--90ais/0.0.0.0
 address=/xn--polimerbizmimarlk-rvc.com/0.0.0.0
 address=/ybom.urbanolab.com/0.0.0.0
@@ -1159,5 +1147,6 @@ address=/youtubetrainingacademy.com/0.0.0.0
 address=/yskadvisors.com/0.0.0.0
 address=/yummyyogaudaipur.com/0.0.0.0
 address=/yzkzixun.com/0.0.0.0
+address=/zakra.tecnasulstore.com.br/0.0.0.0
 address=/zytrox.tk/0.0.0.0
 address=/zz.690tx.com/0.0.0.0
diff --git a/urlhaus-filter-dnsmasq.conf b/urlhaus-filter-dnsmasq.conf
index 20c1bdbf..a240faad 100644
--- a/urlhaus-filter-dnsmasq.conf
+++ b/urlhaus-filter-dnsmasq.conf
@@ -1,5 +1,5 @@
 # Title: Malicious Domains dnsmasq Blocklist
-# Updated: Thu, 25 Mar 2021 12:12:40 UTC
+# Updated: Fri, 26 Mar 2021 00:12:29 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -2496,6 +2496,7 @@ address=/accesointerne.theworkpc.com/0.0.0.0
 address=/access-24.jp/0.0.0.0
 address=/access-cash.ae.org/0.0.0.0
 address=/access-om.neomeric.us/0.0.0.0
+address=/access-one.us/0.0.0.0
 address=/access-to-web.com/0.0.0.0
 address=/accessclub.jp/0.0.0.0
 address=/accessdig.com/0.0.0.0
@@ -2673,6 +2674,7 @@ address=/achremittanceservices.com/0.0.0.0
 address=/acht-stuecken.de/0.0.0.0
 address=/achuanchaolihai.cn/0.0.0.0
 address=/aci.serabd.com/0.0.0.0
+address=/aciabogados.com/0.0.0.0
 address=/aciitaly.com/0.0.0.0
 address=/acilevarkadasi.com/0.0.0.0
 address=/acilisbalon.com/0.0.0.0
@@ -3089,6 +3091,7 @@ address=/admin.grapejuiceofbrazil.com/0.0.0.0
 address=/admin.greenlightcr.com/0.0.0.0
 address=/admin.hopehorseback.org/0.0.0.0
 address=/admin.jpcar.mystand.pt/0.0.0.0
+address=/admin.mobilezenie.com/0.0.0.0
 address=/admin.searchlowestprice.com/0.0.0.0
 address=/admin.solissol.com/0.0.0.0
 address=/admin.staging.buildsmart.io/0.0.0.0
@@ -3268,7 +3271,6 @@ address=/adventuredsocks.com/0.0.0.0
 address=/adventureexplorer.in/0.0.0.0
 address=/adventurehr.com/0.0.0.0
 address=/adventureitdate.com/0.0.0.0
-address=/adventureits.com/0.0.0.0
 address=/adventuremania.com/0.0.0.0
 address=/adventurersafaris.com/0.0.0.0
 address=/adventuresofarchibald.com/0.0.0.0
@@ -3688,6 +3690,7 @@ address=/agenforedi.toko-abi.net/0.0.0.0
 address=/agengarcinia5000.com/0.0.0.0
 address=/agenity.com/0.0.0.0
 address=/agenlama.com/0.0.0.0
+address=/agenmovie.xyz/0.0.0.0
 address=/agent-seo.jp/0.0.0.0
 address=/agent.ken.by/0.0.0.0
 address=/agent2.icu/0.0.0.0
@@ -10704,6 +10707,7 @@ address=/barcaacademyistanbul.com/0.0.0.0
 address=/barcelonaevent.es/0.0.0.0
 address=/barcelonakartingcenter.com/0.0.0.0
 address=/barchaklem.com/0.0.0.0
+address=/barcionstw.eastus.cloudapp.azure.com/0.0.0.0
 address=/barcla.ug/0.0.0.0
 address=/barclaysdownloads.com/0.0.0.0
 address=/barcoofoods.ir/0.0.0.0
@@ -12989,6 +12993,7 @@ address=/bizzznez.com/0.0.0.0
 address=/bj5800.com/0.0.0.0
 address=/bjarndahl.dk/0.0.0.0
 address=/bjbus.net/0.0.0.0
+address=/bjconstructions.in/0.0.0.0
 address=/bjdd.org/0.0.0.0
 address=/bjenkins.webview.consulting/0.0.0.0
 address=/bjenzer.com/0.0.0.0
@@ -14028,6 +14033,7 @@ address=/bnote.novelux.com/0.0.0.0
 address=/bnpartnersweb.com/0.0.0.0
 address=/bnpgrup.com/0.0.0.0
 address=/bnqzjy.cn/0.0.0.0
+address=/bnrbook.com/0.0.0.0
 address=/bnrnews.id/0.0.0.0
 address=/bnsddfhjdfgvbxc.ru/0.0.0.0
 address=/bnsgroupbd.com/0.0.0.0
@@ -14778,6 +14784,7 @@ address=/brandzzy.com/0.0.0.0
 address=/braner.com.ua/0.0.0.0
 address=/branfinancial.com/0.0.0.0
 address=/branner-chile.com/0.0.0.0
+address=/brannon-powlowski25d.xyz/0.0.0.0
 address=/brannudd.com/0.0.0.0
 address=/brantech.com/0.0.0.0
 address=/brar.aminfortgreene.com/0.0.0.0
@@ -15778,6 +15785,7 @@ address=/buyrigrap.com/0.0.0.0
 address=/buysellfx24.ru/0.0.0.0
 address=/buysmart365.net/0.0.0.0
 address=/buysmartwebmall.com/0.0.0.0
+address=/buythebest.pk/0.0.0.0
 address=/buytotake.online/0.0.0.0
 address=/buytwitterlike.com/0.0.0.0
 address=/buyuksigorta.com/0.0.0.0
@@ -17098,6 +17106,7 @@ address=/cashonlinestore.com/0.0.0.0
 address=/cashoutrefitips.com/0.0.0.0
 address=/cashpickup.slmicrocredit.com/0.0.0.0
 address=/cashslip.info/0.0.0.0
+address=/cashtunel.com/0.0.0.0
 address=/cashyinvestment.org/0.0.0.0
 address=/casimiroartes.es/0.0.0.0
 address=/casinarium.com/0.0.0.0
@@ -19670,6 +19679,7 @@ address=/clubyourlife.ca/0.0.0.0
 address=/clubzone.ca/0.0.0.0
 address=/cluebazar.com/0.0.0.0
 address=/clukva.ru/0.0.0.0
+address=/clurbgolf.com/0.0.0.0
 address=/clurit.com/0.0.0.0
 address=/clusdirectory.xyz/0.0.0.0
 address=/cluster-mixture.gq/0.0.0.0
@@ -19886,6 +19896,7 @@ address=/coastmediagroup.com.au/0.0.0.0
 address=/coastmedicalservice.com/0.0.0.0
 address=/coastmotorsupply.com/0.0.0.0
 address=/coastsignworks.com/0.0.0.0
+address=/coastwidewaterproofing.com.au/0.0.0.0
 address=/coatforwinter.com/0.0.0.0
 address=/coavce.com/0.0.0.0
 address=/cobam.xyz/0.0.0.0
@@ -21909,6 +21920,7 @@ address=/cronicas.com.do/0.0.0.0
 address=/cronolux.com.br/0.0.0.0
 address=/croodly.com/0.0.0.0
 address=/crookedchristicraddick.com/0.0.0.0
+address=/crooks-cooper24g.xyz/0.0.0.0
 address=/croos.org/0.0.0.0
 address=/crope.shop/0.0.0.0
 address=/cropfoods.com/0.0.0.0
@@ -23163,7 +23175,6 @@ address=/dar-ltd.uk/0.0.0.0
 address=/dar-sana.com/0.0.0.0
 address=/darajelita.com/0.0.0.0
 address=/daralsalam-mall.com/0.0.0.0
-address=/daralsaqi.com/0.0.0.0
 address=/darapartment.com/0.0.0.0
 address=/darasrszs.online/0.0.0.0
 address=/darassalam.ch/0.0.0.0
@@ -23272,7 +23283,6 @@ address=/dashcenter.info/0.0.0.0
 address=/dasheriemagazine.com/0.0.0.0
 address=/dashfiles.tk/0.0.0.0
 address=/dashkevichseo.ru/0.0.0.0
-address=/dashonweb.com/0.0.0.0
 address=/dashudance.com/0.0.0.0
 address=/dashvaanjil.mn/0.0.0.0
 address=/dasin-obchudek.cz/0.0.0.0
@@ -23600,6 +23610,7 @@ address=/dboyusa.online/0.0.0.0
 address=/dbravo.pro/0.0.0.0
 address=/dbs-ebank.com/0.0.0.0
 address=/dbsa-dream.com/0.0.0.0
+address=/dbsandbox.ca/0.0.0.0
 address=/dbsenvironmental.co.uk/0.0.0.0
 address=/dbsgear.com/0.0.0.0
 address=/dbsktoporder.yolasite.com/0.0.0.0
@@ -24508,6 +24519,7 @@ address=/denlokale.nu/0.0.0.0
 address=/denmaar.hplbusiness.com/0.0.0.0
 address=/denmarkheating.net/0.0.0.0
 address=/denmaytre.vn/0.0.0.0
+address=/dennis-hill25lw.xyz/0.0.0.0
 address=/dennis-roth.de/0.0.0.0
 address=/dennishester.com/0.0.0.0
 address=/dennisisasshole.com/0.0.0.0
@@ -27184,6 +27196,9 @@ address=/down.posti-fi-fjwa.top/0.0.0.0
 address=/down.posti-fi-fsa.top/0.0.0.0
 address=/down.posti-fi-fsaq.top/0.0.0.0
 address=/down.posti-fi-fwa.top/0.0.0.0
+address=/down.posti-fi-ij.top/0.0.0.0
+address=/down.posti-fi-in.top/0.0.0.0
+address=/down.posti-fi-iz.top/0.0.0.0
 address=/down.pzchao.com/0.0.0.0
 address=/down.qm188.com/0.0.0.0
 address=/down.qqfarmer.com.cn/0.0.0.0
@@ -29395,6 +29410,7 @@ address=/egyptmaint.com/0.0.0.0
 address=/egyptmotours.com/0.0.0.0
 address=/egyptpharaohstours.com/0.0.0.0
 address=/egyshadowmen.com/0.0.0.0
+address=/egyutthato.eu/0.0.0.0
 address=/egyuttkonnyebb.zolitoth.com/0.0.0.0
 address=/egyvision.medicahealthy.net/0.0.0.0
 address=/egywebtest.ml/0.0.0.0
@@ -30576,6 +30592,7 @@ address=/ennaturismo.info/0.0.0.0
 address=/ennessehospitality.id/0.0.0.0
 address=/ennovate.elin.co.za/0.0.0.0
 address=/eno.si/0.0.0.0
+address=/enolil-loo.com/0.0.0.0
 address=/enorichie.net/0.0.0.0
 address=/enorka.info/0.0.0.0
 address=/enosburgreading.pbworks.com/0.0.0.0
@@ -32549,6 +32566,7 @@ address=/faithchorale.com/0.0.0.0
 address=/faithcompassion.com/0.0.0.0
 address=/faithconstructionltd.co.uk/0.0.0.0
 address=/faithfight.my.id/0.0.0.0
+address=/faithmethodistcheras.org/0.0.0.0
 address=/faithmontessorischools.com/0.0.0.0
 address=/faithoasis.000webhostapp.com/0.0.0.0
 address=/faithworkx.com/0.0.0.0
@@ -33819,6 +33837,7 @@ address=/findyourfocusph.com/0.0.0.0
 address=/findyourvoice.ca/0.0.0.0
 address=/fine-art-line.de/0.0.0.0
 address=/fine.black/0.0.0.0
+address=/fineartgallerym.com/0.0.0.0
 address=/fineconera.com/0.0.0.0
 address=/finefeather.info/0.0.0.0
 address=/finefoodsfrozen.com/0.0.0.0
@@ -37447,6 +37466,7 @@ address=/girlsphonenumbers.online/0.0.0.0
 address=/girltalkza.co.za/0.0.0.0
 address=/girlydesignart.com/0.0.0.0
 address=/gironynavarro.com/0.0.0.0
+address=/girotexuniformes.com/0.0.0.0
 address=/girraj2016.gtranzit.com/0.0.0.0
 address=/girrajwadi.com/0.0.0.0
 address=/gisa.company/0.0.0.0
@@ -37536,6 +37556,7 @@ address=/gladwynecapital.com/0.0.0.0
 address=/glafka.com/0.0.0.0
 address=/glambooth.nl/0.0.0.0
 address=/glamoroushairextension.com/0.0.0.0
+address=/glamorouspk.com/0.0.0.0
 address=/glamour.rosolutions.com.mx/0.0.0.0
 address=/glamourgarden-lb.com/0.0.0.0
 address=/glamourlounge.org/0.0.0.0
@@ -38292,6 +38313,7 @@ address=/gordondeen.net/0.0.0.0
 address=/gordonmilktransport.com/0.0.0.0
 address=/gordonruss.com/0.0.0.0
 address=/gordyssensors.com/0.0.0.0
+address=/gorecycle.fahadjutt.com/0.0.0.0
 address=/gorenotoservisi.net/0.0.0.0
 address=/gorestruly.com/0.0.0.0
 address=/goretimmo.lu/0.0.0.0
@@ -39448,6 +39470,7 @@ address=/gunesulkesi.com/0.0.0.0
 address=/guneyaski.com/0.0.0.0
 address=/gungazcomputer.co.ke/0.0.0.0
 address=/gunk.insol.be/0.0.0.0
+address=/gunma2u.com/0.0.0.0
 address=/gunmak-com.tk/0.0.0.0
 address=/gunnarasgeir.com/0.0.0.0
 address=/gunnersexcavating.com/0.0.0.0
@@ -41799,6 +41822,7 @@ address=/hollywoodremix.com/0.0.0.0
 address=/hollywoodsmileeg.com/0.0.0.0
 address=/holmdalehouse.co.uk/0.0.0.0
 address=/holmesgroup-com.azurewebsites.net/0.0.0.0
+address=/holmesprpmgmt.com/0.0.0.0
 address=/holmnkolbas.com/0.0.0.0
 address=/holmsater.se/0.0.0.0
 address=/holod24.by/0.0.0.0
@@ -42492,6 +42516,7 @@ address=/hpmamerica.com/0.0.0.0
 address=/hpmaytinhtaophongcach.com/0.0.0.0
 address=/hpmwqjub.com/0.0.0.0
 address=/hpq8fa.db.files.1drv.com/0.0.0.0
+address=/hprosacco25i.xyz/0.0.0.0
 address=/hprpc.cn/0.0.0.0
 address=/hps-sk.sk/0.0.0.0
 address=/hps.nz/0.0.0.0
@@ -45068,6 +45093,7 @@ address=/instant-resume.com/0.0.0.0
 address=/instantbonheur.fr/0.0.0.0
 address=/instantcashflowtoday.com.ng/0.0.0.0
 address=/instantclients.network/0.0.0.0
+address=/instantindialoan.com/0.0.0.0
 address=/instanttaxsolutions.mobi/0.0.0.0
 address=/instanttechnology.com.au/0.0.0.0
 address=/instantworldpay.com/0.0.0.0
@@ -45892,6 +45918,7 @@ address=/iscidavasi.com/0.0.0.0
 address=/isciyizbiz.com/0.0.0.0
 address=/iscleanone.com/0.0.0.0
 address=/isclimatechangeahoax.com/0.0.0.0
+address=/iscoegypt.com/0.0.0.0
 address=/iscoming.ir/0.0.0.0
 address=/iscon.com.br/0.0.0.0
 address=/iscondisth.com/0.0.0.0
@@ -45947,7 +45974,6 @@ address=/iskostrip.com/0.0.0.0
 address=/iskro.textronic.info/0.0.0.0
 address=/iskyservice.ru/0.0.0.0
 address=/islaholics.com/0.0.0.0
-address=/islamabadtrafficpolice.gov.pk/0.0.0.0
 address=/islamabout.com/0.0.0.0
 address=/islamappen.se/0.0.0.0
 address=/islamforall.tv/0.0.0.0
@@ -47760,6 +47786,7 @@ address=/jolly-saito-4993.sub.jp/0.0.0.0
 address=/jollycharm.com/0.0.0.0
 address=/jollyemma.com/0.0.0.0
 address=/jolyscortinas.com.br/0.0.0.0
+address=/jomansea.com/0.0.0.0
 address=/jomar2020.com.br/0.0.0.0
 address=/jomblo.com/0.0.0.0
 address=/jomhermonex.com/0.0.0.0
@@ -49139,6 +49166,7 @@ address=/kaspersky-security.com/0.0.0.0
 address=/kasperskysecurity.club/0.0.0.0
 address=/kasrasanatsepahan.com/0.0.0.0
 address=/kassa.hostsites.ru/0.0.0.0
+address=/kassandra5024d.xyz/0.0.0.0
 address=/kassconnect.ru/0.0.0.0
 address=/kasshmira.com/0.0.0.0
 address=/kassohome.com.tr/0.0.0.0
@@ -49783,7 +49811,6 @@ address=/khannamdo.com/0.0.0.0
 address=/khannen.com.vn/0.0.0.0
 address=/khannen.vn/0.0.0.0
 address=/khanqahebrahimi.com/0.0.0.0
-address=/khantil.com/0.0.0.0
 address=/khantipong.com/0.0.0.0
 address=/khaochills.com/0.0.0.0
 address=/khaoden.tech/0.0.0.0
@@ -51645,6 +51672,7 @@ address=/lab.sjworks.net/0.0.0.0
 address=/lab.valvolari.it/0.0.0.0
 address=/lab.ydigital.asia/0.0.0.0
 address=/lab1.ozaki-kyousei.com/0.0.0.0
+address=/lab18.it/0.0.0.0
 address=/lab2.e-century.pl/0.0.0.0
 address=/lab5.hu/0.0.0.0
 address=/lab6.com.br/0.0.0.0
@@ -56683,6 +56711,7 @@ address=/managegates.com/0.0.0.0
 address=/manageitrisks.com/0.0.0.0
 address=/management.vkims.com/0.0.0.0
 address=/managementtop.id/0.0.0.0
+address=/managemysalon.in/0.0.0.0
 address=/managemyshoes.tools/0.0.0.0
 address=/manageone.co.th/0.0.0.0
 address=/manageprint.in/0.0.0.0
@@ -57064,6 +57093,7 @@ address=/marecsko.hu/0.0.0.0
 address=/marek-paysage-concept.fr/0.0.0.0
 address=/marek.in/0.0.0.0
 address=/marekvoprsal.cz/0.0.0.0
+address=/marel.com.br/0.0.0.0
 address=/marellengifts.com/0.0.0.0
 address=/maremarius.pt/0.0.0.0
 address=/marematto.it/0.0.0.0
@@ -58344,6 +58374,7 @@ address=/meditationsurmesure.com/0.0.0.0
 address=/meditec.ma/0.0.0.0
 address=/mediterraneavacanze.com/0.0.0.0
 address=/meditheraphy.com/0.0.0.0
+address=/meditreat.itwebservice.in/0.0.0.0
 address=/meditsinanarodnaya.ru/0.0.0.0
 address=/medius.ge/0.0.0.0
 address=/mediusvp.com/0.0.0.0
@@ -60520,6 +60551,7 @@ address=/moitruongtunglam.com/0.0.0.0
 address=/mojang.com.br/0.0.0.0
 address=/mojehaftom.com/0.0.0.0
 address=/mojewnetrza.pl/0.0.0.0
+address=/mojno--vse.ru/0.0.0.0
 address=/mojo-studios.co.uk/0.0.0.0
 address=/mojorockstar.com/0.0.0.0
 address=/mojstudent.net/0.0.0.0
@@ -61274,6 +61306,7 @@ address=/mrpiratz.com/0.0.0.0
 address=/mrpower.ir/0.0.0.0
 address=/mrprintoke.com/0.0.0.0
 address=/mrquick.co.il/0.0.0.0
+address=/mrsambarbershop.nl/0.0.0.0
 address=/mrsbow.com/0.0.0.0
 address=/mrsconnect.org/0.0.0.0
 address=/mrsdiggs.com/0.0.0.0
@@ -61874,6 +61907,7 @@ address=/mvicente.com.br/0.0.0.0
 address=/mvid.com/0.0.0.0
 address=/mvidl.site/0.0.0.0
 address=/mvisionproperties.com/0.0.0.0
+address=/mvldesign.ca/0.0.0.0
 address=/mvm368.com/0.0.0.0
 address=/mvmskpd.com/0.0.0.0
 address=/mvns.railfan.net/0.0.0.0
@@ -63208,6 +63242,7 @@ address=/nellyvonalven.com/0.0.0.0
 address=/nelsonhelps.com/0.0.0.0
 address=/nelsonhostingcom.000webhostapp.com/0.0.0.0
 address=/nelsonpto.org/0.0.0.0
+address=/nelsonsbutchers.co.uk/0.0.0.0
 address=/nelsonsilveti.com/0.0.0.0
 address=/neltac.com/0.0.0.0
 address=/nelyvos.nl/0.0.0.0
@@ -64542,7 +64577,6 @@ address=/no18balloonroom.co.uk/0.0.0.0
 address=/no1angelsescort.com/0.0.0.0
 address=/no1spinningfields.90degrees.digital/0.0.0.0
 address=/no1websitedesigner.com/0.0.0.0
-address=/no2politics.com/0.0.0.0
 address=/no70.fun/0.0.0.0
 address=/noabuseshere.top/0.0.0.0
 address=/noach.nl/0.0.0.0
@@ -65832,6 +65866,7 @@ address=/ogxbody.com/0.0.0.0
 address=/ohako.com.my/0.0.0.0
 address=/ohamburguer.com.br/0.0.0.0
 address=/ohanadev.com/0.0.0.0
+address=/ohatsbd.com/0.0.0.0
 address=/ohdratdigital.com/0.0.0.0
 address=/ohe.ie/0.0.0.0
 address=/ohelloguyzzqq.com/0.0.0.0
@@ -66136,6 +66171,7 @@ address=/omada.edu.gr/0.0.0.0
 address=/omagroup.ru/0.0.0.0
 address=/omaharefugees.com/0.0.0.0
 address=/omahduwur.com/0.0.0.0
+address=/omaia.org/0.0.0.0
 address=/omaint.ml/0.0.0.0
 address=/omalleyco-my.sharepoint.com/0.0.0.0
 address=/omalll.com/0.0.0.0
@@ -71766,6 +71802,7 @@ address=/promodigital.tk/0.0.0.0
 address=/promodont.com/0.0.0.0
 address=/promokonyara.ru/0.0.0.0
 address=/promolatinconferences.com/0.0.0.0
+address=/promolyko.com/0.0.0.0
 address=/promomitsubishitermurah.net/0.0.0.0
 address=/promonoble.com/0.0.0.0
 address=/promootzie.nl/0.0.0.0
@@ -73181,6 +73218,7 @@ address=/quickmusings.com/0.0.0.0
 address=/quickpickapp.co/0.0.0.0
 address=/quickreachmedia.com/0.0.0.0
 address=/quicksaleecuador.com/0.0.0.0
+address=/quickshine.co.ke/0.0.0.0
 address=/quickstorevn.com/0.0.0.0
 address=/quicktechsupport247.com/0.0.0.0
 address=/quicktowtowing.com/0.0.0.0
@@ -75282,6 +75320,7 @@ address=/rgclimatizacion.com/0.0.0.0
 address=/rgdecor.org/0.0.0.0
 address=/rgfloors.com.au/0.0.0.0
 address=/rgitabit.in/0.0.0.0
+address=/rgleason25s.xyz/0.0.0.0
 address=/rglgrupomedico.com.mx/0.0.0.0
 address=/rgmobilegossip.com/0.0.0.0
 address=/rgmvanijya.com/0.0.0.0
@@ -76126,6 +76165,7 @@ address=/roselvi.cl/0.0.0.0
 address=/rosemaryromero.com.br/0.0.0.0
 address=/rosemiracle.com/0.0.0.0
 address=/rosemurphy.co.uk/0.0.0.0
+address=/rosenbaum-jaida24nz.xyz/0.0.0.0
 address=/rosenfeldcapital.com/0.0.0.0
 address=/rosenlaw.cratima.com/0.0.0.0
 address=/roseperfeito.com.br/0.0.0.0
@@ -80044,6 +80084,7 @@ address=/shastri.com/0.0.0.0
 address=/shatabbytek.com/0.0.0.0
 address=/shataikok.com/0.0.0.0
 address=/shatelnews.ir/0.0.0.0
+address=/shatteredglass.io/0.0.0.0
 address=/shaukya.com/0.0.0.0
 address=/shaulla.store/0.0.0.0
 address=/shaunodonnell.com/0.0.0.0
@@ -81905,6 +81946,7 @@ address=/smartlogo.com.br/0.0.0.0
 address=/smartlync.pk/0.0.0.0
 address=/smartmadira.com/0.0.0.0
 address=/smartmassive.ru/0.0.0.0
+address=/smartmatrixs.com/0.0.0.0
 address=/smartmobilelearning.co.za/0.0.0.0
 address=/smartmoneylife.com/0.0.0.0
 address=/smartmovie.com.ua/0.0.0.0
@@ -82867,6 +82909,7 @@ address=/sosctb.com/0.0.0.0
 address=/sosenfantsburkinafaso.fr/0.0.0.0
 address=/sosexymagazine.com/0.0.0.0
 address=/sosflam.com/0.0.0.0
+address=/sosgsm.fr/0.0.0.0
 address=/sosh47.citycheb.ru/0.0.0.0
 address=/sosoab.com/0.0.0.0
 address=/sosofoto.cz/0.0.0.0
@@ -87503,6 +87546,7 @@ address=/tecnologiaoficial.com/0.0.0.0
 address=/tecnologiatech.com/0.0.0.0
 address=/tecnologiaz.com/0.0.0.0
 address=/tecnologicainformatica.com.br/0.0.0.0
+address=/tecnologyschool.com/0.0.0.0
 address=/tecnolora.com/0.0.0.0
 address=/tecnoloxia.com/0.0.0.0
 address=/tecnopc.info/0.0.0.0
@@ -90267,6 +90311,7 @@ address=/tobpm.kz/0.0.0.0
 address=/toby-warren.com/0.0.0.0
 address=/tobyetc.com/0.0.0.0
 address=/tobysherman.com/0.0.0.0
+address=/tocaima.co/0.0.0.0
 address=/tocakids.resultaweb.com.br/0.0.0.0
 address=/tocgiajojo.com/0.0.0.0
 address=/tochkae.ru/0.0.0.0
@@ -91394,6 +91439,7 @@ address=/tresjoliejewellery.com/0.0.0.0
 address=/tresnexus.com/0.0.0.0
 address=/treterhef.download/0.0.0.0
 address=/tretthing-bg.site/0.0.0.0
+address=/treutel-jamir25ju.xyz/0.0.0.0
 address=/trevellinglove.com/0.0.0.0
 address=/trevinos.net/0.0.0.0
 address=/trevorchristensen.com/0.0.0.0
@@ -94096,6 +94142,7 @@ address=/vastintegrated.com/0.0.0.0
 address=/vastraindia.com/0.0.0.0
 address=/vastralaya.shop/0.0.0.0
 address=/vastuanalyst.com/0.0.0.0
+address=/vastubless.com/0.0.0.0
 address=/vastuvidyaarchitects.com/0.0.0.0
 address=/vasudhagoodharvest.com/0.0.0.0
 address=/vasumadhi.com/0.0.0.0
@@ -95441,6 +95488,7 @@ address=/vlad.iset.ro/0.0.0.0
 address=/vladetel.org/0.0.0.0
 address=/vladimirfilin.com/0.0.0.0
 address=/vladimirfilin.ru/0.0.0.0
+address=/vladimirinternational.com/0.0.0.0
 address=/vladneta.lt/0.0.0.0
 address=/vladsever.ru/0.0.0.0
 address=/vladsp.ru/0.0.0.0
@@ -96439,6 +96487,7 @@ address=/web.eficiens.cl/0.0.0.0
 address=/web.emergingsun.com/0.0.0.0
 address=/web.emsfabrik.de/0.0.0.0
 address=/web.eng.ubu.ac.th/0.0.0.0
+address=/web.geetle.ga/0.0.0.0
 address=/web.geomegasoft.net/0.0.0.0
 address=/web.golden-goblin.com/0.0.0.0
 address=/web.gotham.com.au/0.0.0.0
@@ -97253,6 +97302,7 @@ address=/why-h.xyz/0.0.0.0
 address=/whyasksolution.com/0.0.0.0
 address=/whybowl.thebotogs.com/0.0.0.0
 address=/whyepicshop.com/0.0.0.0
+address=/whynt.xyz/0.0.0.0
 address=/whysquare.co.nz/0.0.0.0
 address=/whystudio.cn/0.0.0.0
 address=/whytech.info/0.0.0.0
@@ -98320,6 +98370,7 @@ address=/wroxra.by.files.1drv.com/0.0.0.0
 address=/wrrodrigo.com/0.0.0.0
 address=/wrtech.com.pl/0.0.0.0
 address=/wrusnollet.com/0.0.0.0
+address=/wrzucacz.pl/0.0.0.0
 address=/wrzutka.co/0.0.0.0
 address=/ws-ebavisapia01-dll.ir/0.0.0.0
 address=/ws3lfkm.com/0.0.0.0
@@ -98767,6 +98818,7 @@ address=/xh.hj46.cn/0.0.0.0
 address=/xhcmnews.com/0.0.0.0
 address=/xhd.qhv.mybluehost.me/0.0.0.0
 address=/xhencheng.tk/0.0.0.0
+address=/xherzog24pv.xyz/0.0.0.0
 address=/xhjclq.ch.files.1drv.com/0.0.0.0
 address=/xhs9a81.com/0.0.0.0
 address=/xhsdxm.com/0.0.0.0
@@ -100626,6 +100678,7 @@ address=/zafinternational.co.id/0.0.0.0
 address=/zafirotiendas.com/0.0.0.0
 address=/zagnet.pl/0.0.0.0
 address=/zagogulina.com/0.0.0.0
+address=/zagoradesertcamp.com/0.0.0.0
 address=/zagrodazbyszka.pl/0.0.0.0
 address=/zagros-shahrekord.ir/0.0.0.0
 address=/zagrosenergygroup.com/0.0.0.0
@@ -100681,6 +100734,7 @@ address=/zakodujbiznes.ml/0.0.0.0
 address=/zakopane.utazas.hu/0.0.0.0
 address=/zakopanedomki.com.pl/0.0.0.0
 address=/zakosciele66.cba.pl/0.0.0.0
+address=/zakra.tecnasulstore.com.br/0.0.0.0
 address=/zakrahgroup.com/0.0.0.0
 address=/zakriasons.co/0.0.0.0
 address=/zakromanoff.com/0.0.0.0
diff --git a/urlhaus-filter-domains-online.txt b/urlhaus-filter-domains-online.txt
index 99a1cdad..8800568e 100644
--- a/urlhaus-filter-domains-online.txt
+++ b/urlhaus-filter-domains-online.txt
@@ -1,5 +1,5 @@
 # Title: Online Malicious Domains Blocklist
-# Updated: Thu, 25 Mar 2021 12:12:40 UTC
+# Updated: Fri, 26 Mar 2021 00:12:29 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -12,7 +12,6 @@
 1.192.180.19
 1.222.140.251
 1.222.196.60
-1.24.132.118
 1.245.4.163
 1.246.222.107
 1.246.222.109
@@ -22,8 +21,10 @@
 1.246.222.153
 1.246.222.16
 1.246.222.165
+1.246.222.228
 1.246.222.232
 1.246.222.234
+1.246.222.237
 1.246.222.245
 1.246.222.249
 1.246.222.38
@@ -34,7 +35,6 @@
 1.246.222.69
 1.246.222.8
 1.246.222.80
-1.246.222.9
 1.246.222.98
 1.246.223.10
 1.246.223.103
@@ -66,23 +66,19 @@
 1.250.159.41
 1.252.102.28
 1.254.250.52
+1.58.223.96
 1.60.77.53
-1.62.195.101
 1.65.166.225
 1.82.104.89
-1.85.84.38
 100.12.184.63
 100.2.131.143
 100.8.77.4
 1008691.com
 101.108.130.108
-101.108.131.202
-101.108.133.231
 101.16.183.179
 101.16.98.170
 101.229.85.127
 101.255.36.154
-101.28.102.38
 101.28.105.132
 101.28.106.134
 101.28.145.2
@@ -93,45 +89,49 @@
 101.75.157.99
 102.130.115.14
 102.141.240.139
-103.106.29.148
 103.107.113.22
 103.113.99.79
 103.124.104.118
 103.125.218.107
 103.136.82.50
-103.139.89.205
 103.141.138.12
 103.144.36.20
 103.145.13.24
 103.146.174.208
 103.156.221.66
 103.16.145.25
+103.161.232.16
+103.207.0.134
 103.217.215.21
 103.224.200.40
 103.233.64.182
-103.235.165.183
 103.238.228.3
 103.238.228.4
 103.240.249.121
+103.4.117.26
 103.70.160.51
 103.79.112.254
+103.82.144.197
 103.82.145.111
+103.82.98.151
 103.82.98.170
-103.84.240.130
 103.84.240.228
-103.91.245.11
 103.91.245.12
+103.91.245.16
 103.91.245.17
 103.91.245.19
 103.91.245.20
+103.91.245.27
 103.91.245.3
+103.91.245.30
 103.91.245.36
+103.91.245.41
 103.91.245.46
 103.91.245.47
 103.91.245.54
 103.92.25.90
 103.92.25.95
-104.168.44.57
+104.168.98.105
 104.184.75.123
 104.33.52.85
 104.61.86.37
@@ -140,6 +140,7 @@
 106.104.193.155
 106.113.145.32
 106.113.177.60
+106.4.138.95
 107.172.134.48
 107.172.193.132
 107.172.249.148
@@ -158,8 +159,8 @@
 109.124.90.229
 109.233.196.232
 109.235.7.228
-109.248.58.238
 109.86.85.253
+109.88.185.119
 109.95.200.102
 109.95.200.230
 109.96.127.90
@@ -174,6 +175,7 @@
 110.228.195.46
 110.241.119.168
 110.241.23.107
+110.247.151.4
 110.248.124.254
 110.248.224.19
 110.248.251.194
@@ -183,22 +185,25 @@
 110.253.51.112
 110.255.101.184
 110.255.167.147
-110.35.145.127
 110.35.208.21
 110.35.209.175
-110.35.221.77
 110.35.223.92
+110.35.225.24
+110.35.233.147
 110.35.235.57
+110.35.249.21
 110.35.4.2
-110.82.195.88
 110fss.net
-111.118.124.223
+111.118.111.207
 111.118.41.173
 111.118.88.61
+111.119.245.114
 111.125.67.125
 111.160.112.142
 111.162.224.14
 111.163.50.120
+111.165.21.195
+111.165.28.234
 111.17.186.194
 111.170.84.182
 111.170.86.133
@@ -212,6 +217,7 @@
 111.185.230.136
 111.185.27.9
 111.185.48.248
+111.38.103.114
 111.38.103.122
 111.38.103.13
 111.38.103.66
@@ -234,16 +240,16 @@
 111.61.52.53
 111.73.99.162
 111.91.185.131
+111.92.63.24
 111.93.169.90
 112.105.117.227
 112.111.100.236
 112.111.108.184
 112.111.31.175
 112.122.36.108
-112.123.109.156
 112.123.200.47
-112.123.61.115
 112.132.134.106
+112.159.108.96
 112.170.124.75
 112.170.233.9
 112.186.210.211
@@ -299,10 +305,10 @@
 112.242.2.247
 112.243.115.183
 112.245.12.89
-112.245.246.253
 112.245.5.141
 112.245.8.24
 112.246.162.50
+112.246.180.49
 112.247.100.14
 112.247.121.39
 112.247.14.135
@@ -310,6 +316,7 @@
 112.247.191.118
 112.247.214.146
 112.247.240.226
+112.247.248.76
 112.247.81.173
 112.247.82.122
 112.247.89.81
@@ -318,8 +325,10 @@
 112.248.44.153
 112.249.109.217
 112.249.118.157
+112.249.206.69
 112.249.26.129
 112.249.41.142
+112.249.79.98
 112.250.102.173
 112.250.57.99
 112.251.17.5
@@ -332,6 +341,7 @@
 112.252.237.109
 112.252.239.103
 112.252.245.249
+112.252.46.212
 112.254.208.123
 112.255.38.10
 112.255.52.179
@@ -346,6 +356,7 @@
 112.27.124.119
 112.27.124.120
 112.27.124.122
+112.27.124.124
 112.27.124.127
 112.27.124.128
 112.27.124.130
@@ -361,7 +372,6 @@
 112.27.124.146
 112.27.124.149
 112.27.124.150
-112.27.124.151
 112.27.124.155
 112.27.124.158
 112.27.124.160
@@ -450,12 +460,10 @@
 112.72.153.37
 112.72.162.159
 112.72.162.49
-112.72.162.53
 112.72.175.147
 112.72.176.112
 112.72.176.84
 112.72.226.202
-112.72.231.35
 112.78.45.158
 112.80.118.16
 112.80.127.91
@@ -472,18 +480,17 @@
 112.82.227.41
 112.82.228.175
 112.86.133.125
-112.86.23.41
 112.86.253.238
 112.9.140.247
 112.93.29.211
 112.95.22.17
 112.95.23.121
 113.103.10.209
+113.104.237.52
 113.105.71.239
-113.11.95.254
-113.110.247.207
 113.116.121.167
 113.116.149.83
+113.116.150.147
 113.116.246.109
 113.116.48.217
 113.118.195.247
@@ -492,11 +499,11 @@
 113.161.58.249
 113.172.250.35
 113.179.129.99
-113.188.76.31
 113.194.133.9
 113.194.135.154
 113.195.163.26
 113.195.166.46
+113.201.24.26
 113.224.225.172
 113.226.42.250
 113.227.128.9
@@ -506,31 +513,28 @@
 113.231.93.142
 113.232.141.23
 113.232.211.182
+113.234.224.130
 113.235.116.209
 113.237.129.7
-113.245.218.18
+113.253.144.141
 113.254.169.251
 113.3.153.57
 113.3.155.199
 113.59.133.16
-113.59.136.39
-113.59.144.42
 113.59.154.21
-113.59.191.47
 113.61.204.205
+113.81.112.35
 113.86.204.13
 113.87.175.112
-113.87.32.93
+113.87.248.177
+113.88.100.120
 113.88.208.189
 113.88.232.36
+113.88.242.0
 113.88.38.232
-113.89.41.33
+113.89.245.13
 113.89.41.51
-113.92.156.196
-113.93.225.12
 114.199.204.37
-114.199.253.235
-114.223.122.19
 114.226.100.56
 114.227.156.119
 114.228.205.101
@@ -539,53 +543,62 @@
 114.229.52.14
 114.235.115.236
 114.235.42.152
-114.30.54.64
 114.79.161.94
 114.79.172.42
 115.165.216.112
+115.171.239.28
 115.193.130.126
+115.201.38.185
 115.208.101.195
+115.213.187.251
 115.223.159.80
 115.23.88.135
 115.42.47.36
+115.45.178.12
 115.48.130.181
+115.48.130.187
+115.48.135.151
 115.48.141.239
 115.48.198.142
-115.48.215.189
+115.48.200.115
 115.48.22.130
 115.48.228.176
 115.48.9.246
 115.49.100.124
-115.49.18.53
-115.49.216.150
+115.49.152.10
+115.49.242.100
 115.49.60.231
+115.49.80.117
+115.49.96.88
 115.50.1.143
 115.50.158.223
 115.50.2.251
-115.50.219.100
-115.50.22.86
+115.50.202.11
 115.50.220.156
-115.50.224.175
-115.50.230.43
-115.50.232.149
 115.50.239.222
-115.50.3.25
-115.50.56.198
-115.50.8.131
+115.50.240.230
+115.50.61.247
+115.50.64.182
 115.50.81.194
 115.51.104.85
+115.51.107.18
 115.51.123.216
 115.51.93.76
 115.52.112.200
+115.52.17.196
 115.52.19.250
 115.52.200.245
+115.52.201.231
 115.52.21.5
-115.54.192.172
-115.54.222.126
+115.52.22.162
+115.54.160.25
+115.54.212.227
 115.54.236.22
+115.54.240.173
 115.54.241.122
+115.54.70.108
 115.54.73.162
-115.55.105.163
+115.54.73.50
 115.55.144.146
 115.55.144.222
 115.55.144.42
@@ -593,58 +606,70 @@
 115.55.149.30
 115.55.178.67
 115.55.198.209
+115.55.211.41
 115.55.211.86
+115.55.3.36
 115.55.42.200
 115.55.53.51
 115.56.134.116
 115.56.134.220
+115.56.136.144
 115.56.139.122
 115.56.142.251
 115.56.143.241
 115.56.148.22
+115.56.154.147
 115.56.155.72
 115.56.156.185
+115.56.156.54
 115.56.162.173
-115.56.178.107
+115.56.177.202
 115.56.188.24
 115.56.31.54
-115.56.67.22
 115.56.86.251
 115.56.87.42
 115.56.98.205
 115.58.111.222
 115.58.119.171
+115.58.132.199
 115.58.134.143
 115.58.141.177
+115.58.167.90
+115.58.20.186
 115.58.83.233
 115.58.88.163
 115.58.93.151
 115.59.197.123
 115.59.198.165
+115.59.198.200
 115.59.210.228
+115.59.215.96
 115.59.235.229
 115.59.253.202
-115.59.26.134
 115.59.63.220
+115.59.95.247
+115.60.201.176
 115.61.107.203
-115.61.111.142
+115.61.118.201
 115.61.119.187
 115.61.119.198
 115.61.119.77
 115.61.125.184
-115.61.137.47
 115.61.180.193
 115.61.182.138
 115.61.185.246
 115.61.97.190
+115.61.97.55
+115.62.152.207
 115.62.26.39
-115.62.60.206
 115.63.135.206
+115.63.140.242
 115.63.4.244
 115.63.56.176
 115.73.3.11
 115.74.217.2
 115.75.217.79
+115.78.133.146
 115.92.174.231
 116.124.219.2
 116.127.207.224
@@ -655,18 +680,20 @@
 116.211.100.26
 116.212.142.215
 116.24.153.40
-116.72.201.93
-116.75.192.140
+116.72.202.126
+116.72.202.87
+116.72.203.143
+116.74.84.65
+116.75.194.14
 116.76.114.71
 116.88.65.131
 117.11.234.35
-117.11.95.179
 117.15.201.1
-117.192.224.243
-117.192.225.29
-117.192.226.96
-117.194.162.116
-117.194.163.237
+117.156.69.22
+117.194.160.84
+117.194.161.143
+117.194.162.121
+117.196.48.216
 117.20.204.138
 117.20.204.5
 117.20.210.52
@@ -676,39 +703,25 @@
 117.200.76.54
 117.200.76.60
 117.201.128.152
-117.202.66.23
-117.202.67.181
-117.202.67.218
-117.202.68.75
-117.213.41.18
-117.213.42.147
-117.213.42.226
-117.213.44.184
-117.213.45.119
-117.213.45.150
-117.213.45.204
-117.213.46.124
-117.213.46.243
-117.215.213.155
-117.215.215.188
-117.222.160.86
-117.222.165.221
-117.222.166.6
-117.222.169.193
-117.222.170.122
-117.222.175.220
+117.202.66.177
+117.202.68.94
+117.208.133.121
+117.222.161.68
+117.222.162.144
+117.222.163.150
+117.222.165.31
+117.222.170.189
+117.222.171.68
+117.222.172.97
 117.241.66.200
 117.241.67.68
-117.242.211.217
-117.247.204.33
-117.247.206.195
-117.248.60.21
-117.251.56.191
-117.251.56.244
-117.251.56.64
-117.251.56.73
+117.242.210.69
+117.242.211.111
+117.242.211.98
+117.251.56.135
+117.251.59.242
 117.251.60.161
-117.251.63.211
+117.251.60.69
 117.26.110.17
 117.26.235.164
 117.27.10.73
@@ -716,8 +729,11 @@
 117.63.195.140
 117.63.252.82
 117.63.53.15
+117.63.56.81
+117.86.105.110
 117.87.170.32
 117.90.78.120
+117.91.240.50
 117.93.115.242
 117.93.79.40
 118.176.104.35
@@ -734,19 +750,20 @@
 118.232.88.146
 118.232.96.150
 118.232.96.6
-118.233.165.213
 118.233.221.162
+118.233.63.194
 118.233.65.93
 118.249.136.112
 118.250.51.192
-118.38.189.207
 118.42.125.246
 118.43.180.33
 118.68.245.69
+118.75.120.136
+118.75.240.239
 118.75.50.253
 118.75.70.70
 118.79.125.92
-118.79.143.45
+118.79.164.102
 118.79.218.157
 118.79.50.203
 118.79.58.82
@@ -762,7 +779,7 @@
 119.112.22.58
 119.118.251.73
 119.119.52.202
-119.123.219.137
+119.123.175.133
 119.14.143.145
 119.147.213.57
 119.162.109.111
@@ -774,6 +791,7 @@
 119.165.107.93
 119.165.163.220
 119.165.174.63
+119.165.208.73
 119.165.241.222
 119.165.27.77
 119.165.68.145
@@ -793,6 +811,7 @@
 119.179.170.212
 119.179.27.213
 119.179.43.1
+119.179.44.141
 119.179.75.8
 119.18.38.144
 119.180.101.151
@@ -803,6 +822,7 @@
 119.180.231.79
 119.180.33.161
 119.180.80.69
+119.180.9.35
 119.180.94.80
 119.181.124.203
 119.181.43.18
@@ -829,6 +849,7 @@
 119.191.215.221
 119.191.253.206
 119.204.30.144
+119.250.129.231
 119.250.218.177
 119.251.105.221
 119.251.12.85
@@ -836,12 +857,12 @@
 119.56.131.155
 119.56.143.46
 119.56.143.71
+119.56.144.75
 119.56.148.115
 119.56.155.57
+119.56.166.36
 119.56.172.28
-119.56.175.41
 119.56.206.43
-119.56.220.170
 119.96.37.55
 119.96.70.116
 119.99.188.187
@@ -856,6 +877,7 @@
 12.207.39.227
 120.12.144.232
 120.12.153.54
+120.12.212.5
 120.142.222.22
 120.150.213.110
 120.151.248.134
@@ -900,20 +922,19 @@
 120.43.54.218
 120.50.66.60
 120.50.93.115
-120.59.245.212
 120.6.141.142
 120.6.8.11
 120.69.113.208
 120.69.131.51
 120.7.90.104
 120.85.165.141
-120.85.169.138
+120.85.173.137
 120.85.174.165
 120.85.174.175
-120.85.186.112
+120.85.174.39
+120.85.199.222
+120.85.212.45
 120.85.237.129
-120.85.239.77
-120.86.84.72
 120.9.32.51
 121.100.114.164
 121.100.96.8
@@ -941,6 +962,7 @@
 121.24.116.173
 121.25.101.86
 121.254.43.215
+121.34.150.32
 121.61.101.93
 121.61.102.1
 121.61.107.189
@@ -950,6 +972,8 @@
 122.100.150.204
 122.137.52.122
 122.160.147.53
+122.188.86.225
+122.190.19.204
 122.192.190.203
 122.194.191.57
 122.199.72.23
@@ -957,19 +981,18 @@
 122.199.83.86
 122.202.37.85
 122.202.41.23
-122.252.241.170
 122.252.250.22
 122.254.183.207
 122.254.29.37
 122.254.33.214
 123.0.240.58
 123.10.128.46
+123.10.131.225
 123.10.140.225
-123.10.210.87
+123.10.209.95
 123.10.36.124
 123.10.41.32
-123.11.1.232
-123.11.74.72
+123.10.83.136
 123.110.124.238
 123.110.124.244
 123.110.170.237
@@ -977,13 +1000,15 @@
 123.110.19.248
 123.110.200.98
 123.110.238.188
-123.12.238.89
+123.12.229.243
 123.12.3.58
+123.12.36.185
 123.128.128.205
 123.128.133.91
 123.129.84.36
 123.129.88.123
-123.130.169.45
+123.13.101.56
+123.13.30.75
 123.130.208.52
 123.130.23.110
 123.130.37.182
@@ -1000,9 +1025,9 @@
 123.135.71.150
 123.14.101.111
 123.14.150.79
+123.14.205.23
 123.14.217.22
 123.14.235.65
-123.14.248.97
 123.14.76.38
 123.14.88.195
 123.152.42.4
@@ -1013,6 +1038,7 @@
 123.159.137.101
 123.159.31.110
 123.159.8.100
+123.183.123.41
 123.191.173.88
 123.192.101.163
 123.192.194.233
@@ -1033,7 +1059,6 @@
 123.234.116.110
 123.234.184.57
 123.234.246.103
-123.235.107.135
 123.240.103.89
 123.240.181.57
 123.240.79.61
@@ -1041,39 +1066,42 @@
 123.241.184.124
 123.27.44.219
 123.28.217.23
+123.4.180.137
+123.4.185.137
 123.4.193.171
 123.4.44.217
 123.4.85.76
-123.4.88.225
 123.4.92.3
 123.5.123.162
-123.5.13.128
 123.5.178.213
+123.5.188.181
+123.5.22.220
 123.5.27.66
-123.8.253.37
+123.8.183.194
 123.8.254.172
 123.8.40.20
 123.8.41.63
 123.8.62.165
-123.9.110.119
 123.9.243.93
-123.9.245.134
 124.105.105.222
 124.129.162.169
 124.129.221.150
 124.129.76.230
 124.130.167.20
+124.130.40.31
 124.131.104.82
 124.131.130.95
 124.131.136.75
 124.131.151.135
 124.131.21.39
+124.131.26.243
 124.131.26.78
 124.131.54.33
 124.131.70.49
 124.131.72.208
 124.132.110.150
 124.135.34.49
+124.153.136.175
 124.153.236.6
 124.160.126.238
 124.163.138.104
@@ -1093,9 +1121,11 @@
 124.6.0.4
 124.7.254.85
 124.80.46.73
-124.92.132.207
 124.92.148.218
+124.95.17.41
 125.106.125.119
+125.106.252.96
+125.126.69.95
 125.128.28.161
 125.142.93.34
 125.168.10.234
@@ -1103,79 +1133,82 @@
 125.40.1.127
 125.40.107.252
 125.40.113.66
+125.40.136.25
 125.40.150.131
 125.40.16.231
 125.40.163.112
+125.40.237.130
 125.40.65.120
 125.40.73.6
 125.40.74.153
 125.40.75.22
-125.41.0.209
 125.41.106.180
 125.41.138.208
 125.41.189.235
 125.41.191.183
 125.41.196.151
-125.41.2.58
+125.41.200.189
 125.41.204.126
 125.41.205.197
-125.41.245.135
 125.41.6.192
 125.41.7.204
 125.41.80.153
 125.41.86.72
 125.41.96.53
-125.41.97.22
 125.42.124.114
+125.42.125.103
 125.42.234.197
 125.42.96.17
-125.42.96.209
 125.42.98.24
+125.43.105.157
 125.43.106.162
 125.43.112.123
 125.43.126.184
+125.43.130.232
 125.43.136.23
 125.43.177.48
+125.43.21.157
 125.43.26.36
 125.43.34.132
-125.43.5.247
 125.43.53.9
-125.43.93.164
+125.43.73.19
 125.44.168.169
+125.44.212.107
 125.44.213.216
-125.44.248.76
-125.44.29.38
+125.44.230.191
 125.44.30.143
-125.44.42.12
-125.44.61.172
+125.44.31.79
 125.44.8.227
+125.45.57.249
 125.45.65.166
+125.45.90.158
+125.46.138.117
 125.46.184.28
-125.46.203.85
 125.46.206.206
 125.47.193.134
 125.47.200.11
-125.47.207.239
 125.47.209.166
 125.47.244.201
-125.47.29.173
+125.47.252.106
+125.47.254.44
+125.47.28.217
 125.47.36.171
 125.47.45.218
 125.47.71.30
 125.47.90.82
 125.47.91.51
+125.99.220.202
 128.116.133.92
 130.255.159.133
 134.195.139.4
-134.236.252.28
 138.99.204.224
 139.159.226.180
 139.170.173.198
 139.170.174.162
+139.170.228.166
 139.216.102.151
 139.227.46.137
 14.102.17.222
-14.102.97.204
 14.136.80.242
 14.138.109.129
 14.138.109.26
@@ -1191,16 +1224,21 @@
 14.46.25.17
 14.46.98.241
 14.55.29.2
+140.237.30.113
+140.237.5.43
 142.11.216.5
 142.177.56.127
 146.71.79.230
 148.69.108.177
-149.255.15.121
+149.20.176.179
 149.255.15.180
 149.255.15.182
+149.255.15.191
+149.255.15.235
 149.255.15.87
-149.3.36.210
+149.3.85.55
 150.116.207.99
+150.129.105.61
 151.177.163.87
 151.33.230.191
 151.51.158.195
@@ -1213,10 +1251,12 @@
 153.34.135.92
 153.34.23.76
 153.34.29.28
-153.34.52.74
+153.35.111.46
 153.35.27.49
 153.36.126.35
 154.126.178.16
+154.91.1.27
+157.122.105.142
 158.101.165.14
 158.174.213.128
 158.51.125.115
@@ -1226,12 +1266,16 @@
 162.191.249.195
 162.194.28.60
 162.209.98.174
-162.212.203.250
+163.125.183.111
 163.125.195.108
-163.125.200.233
+163.125.200.72
 163.125.200.73
-163.125.203.85
-163.125.223.16
+163.125.202.174
+163.125.202.74
+163.125.203.179
+163.125.207.125
+163.125.250.202
+163.125.68.29
 163.53.206.228
 165.90.16.5
 170.78.39.3
@@ -1245,30 +1289,31 @@
 171.120.125.147
 171.121.6.162
 171.123.189.154
-171.125.114.254
 171.125.30.233
 171.125.30.93
 171.125.64.223
+171.125.65.22
 171.126.109.145
 171.34.112.42
+171.34.114.181
 171.34.179.178
 171.35.161.234
 171.35.162.156
 171.35.173.151
 171.35.174.198
+171.36.42.154
 171.38.219.189
 171.44.254.4
 172.105.36.168
 172.114.244.127
 172.245.5.185
-172.93.176.137
+172.245.5.190
 173.167.85.89
 173.169.46.85
 173.19.58.108
 173.220.222.227
 173.233.85.171
 173.235.209.70
-173.237.254.251
 173.25.113.8
 173.52.95.134
 173.52.97.25
@@ -1281,12 +1326,11 @@
 174.84.148.29
 174.96.30.156
 175.10.147.167
-175.10.48.233
-175.11.212.203
-175.11.96.155
+175.11.193.66
 175.115.241.87
 175.117.66.74
 175.145.200.216
+175.146.17.227
 175.153.144.2
 175.162.69.13
 175.169.172.216
@@ -1303,17 +1347,20 @@
 176.111.174.63
 176.111.174.66
 176.111.174.67
+176.113.161.101
 176.113.161.104
 176.113.161.113
 176.113.161.120
 176.113.161.128
 176.113.161.138
 176.113.161.59
+176.113.161.60
 176.113.161.65
 176.113.161.66
 176.113.161.84
 176.113.161.88
 176.113.161.91
+176.113.161.93
 176.113.174.139
 176.12.117.70
 176.123.4.115
@@ -1321,6 +1368,7 @@
 176.123.7.127
 176.123.9.243
 176.124.7.225
+176.221.251.147
 176.240.40.142
 176.240.84.106
 176.32.151.180
@@ -1329,90 +1377,103 @@
 177.54.82.154
 177.86.235.143
 178.124.182.187
-178.136.195.90
-178.141.210.251
+178.134.185.112
+178.141.161.129
 178.141.25.82
 178.141.57.166
 178.150.174.65
 178.165.122.141
 178.175.0.140
-178.175.1.109
+178.175.0.232
 178.175.1.247
 178.175.1.250
+178.175.1.252
 178.175.1.80
 178.175.10.108
 178.175.10.156
 178.175.10.26
+178.175.10.34
+178.175.10.42
 178.175.100.129
 178.175.100.180
 178.175.100.190
 178.175.100.223
 178.175.100.4
+178.175.100.87
 178.175.101.110
+178.175.101.207
 178.175.102.134
 178.175.102.136
 178.175.102.152
+178.175.102.221
 178.175.102.228
-178.175.102.232
 178.175.102.245
-178.175.102.81
 178.175.103.172
+178.175.103.195
 178.175.103.91
+178.175.104.106
+178.175.104.110
 178.175.104.120
 178.175.104.128
 178.175.104.153
+178.175.104.155
 178.175.104.16
-178.175.104.161
 178.175.104.169
 178.175.104.183
 178.175.104.206
-178.175.104.220
 178.175.104.49
+178.175.104.64
 178.175.104.80
 178.175.105.111
+178.175.105.125
 178.175.105.146
+178.175.105.177
 178.175.105.217
 178.175.105.245
 178.175.105.247
 178.175.105.27
+178.175.105.28
 178.175.105.49
-178.175.105.85
+178.175.105.94
 178.175.106.118
 178.175.106.18
 178.175.106.193
 178.175.106.219
+178.175.106.253
 178.175.106.37
-178.175.106.63
 178.175.106.77
 178.175.106.87
 178.175.107.0
 178.175.107.133
+178.175.107.245
 178.175.107.83
+178.175.107.86
 178.175.108.116
 178.175.108.145
 178.175.108.148
-178.175.108.16
 178.175.108.179
-178.175.108.18
+178.175.108.232
 178.175.108.67
 178.175.108.87
+178.175.108.94
 178.175.109.1
+178.175.109.127
+178.175.109.193
+178.175.109.37
 178.175.109.77
+178.175.109.78
 178.175.11.176
 178.175.11.184
 178.175.11.204
 178.175.11.57
 178.175.110.150
 178.175.110.155
-178.175.110.173
 178.175.110.214
 178.175.110.221
-178.175.110.43
 178.175.110.90
 178.175.110.97
 178.175.111.105
 178.175.111.157
-178.175.111.16
 178.175.111.190
 178.175.111.206
 178.175.111.36
@@ -1420,20 +1481,20 @@
 178.175.112.159
 178.175.112.26
 178.175.112.4
-178.175.113.130
-178.175.113.150
+178.175.112.79
+178.175.113.0
 178.175.113.171
 178.175.113.174
 178.175.113.35
+178.175.113.64
 178.175.113.85
 178.175.114.107
-178.175.114.211
 178.175.114.215
 178.175.114.234
 178.175.114.238
 178.175.114.241
+178.175.114.247
 178.175.114.254
-178.175.114.27
 178.175.114.5
 178.175.114.55
 178.175.114.63
@@ -1441,14 +1502,19 @@
 178.175.114.90
 178.175.114.99
 178.175.115.1
+178.175.115.12
 178.175.115.13
 178.175.115.142
 178.175.115.143
 178.175.115.19
+178.175.115.206
+178.175.115.208
 178.175.115.221
-178.175.115.222
 178.175.115.242
 178.175.115.35
+178.175.115.40
+178.175.116.15
+178.175.116.236
 178.175.116.48
 178.175.116.64
 178.175.116.87
@@ -1456,123 +1522,124 @@
 178.175.117.32
 178.175.117.51
 178.175.117.63
-178.175.117.90
+178.175.117.84
 178.175.118.112
+178.175.118.139
 178.175.118.192
 178.175.118.225
-178.175.118.34
 178.175.118.60
 178.175.119.205
 178.175.119.209
+178.175.119.26
 178.175.119.86
 178.175.119.88
-178.175.12.179
+178.175.12.114
 178.175.12.252
 178.175.12.53
 178.175.12.97
 178.175.120.133
 178.175.120.184
+178.175.120.196
 178.175.120.203
 178.175.120.251
 178.175.121.123
 178.175.121.155
 178.175.121.55
 178.175.121.62
+178.175.121.63
 178.175.121.68
 178.175.121.99
-178.175.122.144
 178.175.122.172
 178.175.122.245
+178.175.122.26
 178.175.122.28
 178.175.123.113
 178.175.123.2
 178.175.123.20
-178.175.123.223
+178.175.123.30
 178.175.123.56
 178.175.123.60
 178.175.124.109
 178.175.124.122
 178.175.124.131
 178.175.124.141
-178.175.124.157
-178.175.124.175
 178.175.124.211
-178.175.124.233
 178.175.124.4
 178.175.124.79
 178.175.124.89
-178.175.124.9
 178.175.125.118
 178.175.125.14
-178.175.125.143
 178.175.125.153
 178.175.125.156
 178.175.125.174
 178.175.125.219
 178.175.125.39
-178.175.125.54
-178.175.126.101
+178.175.126.124
 178.175.126.131
 178.175.126.141
 178.175.126.167
 178.175.126.220
 178.175.126.222
 178.175.126.237
-178.175.126.80
 178.175.126.83
+178.175.127.10
 178.175.127.109
 178.175.127.116
+178.175.127.129
 178.175.127.142
 178.175.127.15
 178.175.127.182
-178.175.127.212
 178.175.127.230
 178.175.127.231
 178.175.127.236
+178.175.127.238
 178.175.127.63
 178.175.127.75
+178.175.13.237
 178.175.14.106
 178.175.14.185
 178.175.14.246
-178.175.14.28
 178.175.14.60
 178.175.15.17
 178.175.15.217
+178.175.15.232
+178.175.15.246
 178.175.15.252
 178.175.15.35
+178.175.15.44
 178.175.15.45
 178.175.15.85
 178.175.16.1
 178.175.16.108
-178.175.16.121
+178.175.16.114
 178.175.16.17
 178.175.16.179
+178.175.16.193
 178.175.16.208
+178.175.16.73
 178.175.16.97
 178.175.17.176
 178.175.17.245
 178.175.18.238
-178.175.18.6
+178.175.18.27
 178.175.18.93
 178.175.19.144
 178.175.19.150
 178.175.19.163
 178.175.19.174
+178.175.19.229
 178.175.19.242
 178.175.19.44
 178.175.19.47
 178.175.2.110
 178.175.2.237
-178.175.2.245
 178.175.2.41
 178.175.2.5
-178.175.2.80
 178.175.20.117
 178.175.20.145
 178.175.20.170
 178.175.20.21
 178.175.20.225
-178.175.20.227
 178.175.20.237
 178.175.20.238
 178.175.20.24
@@ -1581,19 +1648,21 @@
 178.175.21.149
 178.175.21.184
 178.175.21.238
-178.175.21.58
 178.175.21.76
+178.175.22.207
+178.175.22.248
+178.175.23.102
 178.175.23.156
 178.175.23.250
+178.175.23.6
 178.175.24.13
 178.175.24.138
 178.175.24.15
 178.175.24.171
 178.175.24.227
-178.175.24.239
-178.175.24.251
+178.175.24.230
 178.175.25.117
-178.175.25.156
+178.175.25.169
 178.175.25.244
 178.175.25.28
 178.175.25.56
@@ -1601,17 +1670,16 @@
 178.175.25.77
 178.175.26.134
 178.175.26.164
-178.175.26.168
+178.175.26.165
+178.175.26.215
 178.175.26.219
 178.175.26.224
 178.175.26.246
-178.175.26.38
-178.175.26.69
+178.175.26.34
 178.175.27.122
 178.175.27.138
 178.175.27.14
 178.175.27.167
-178.175.27.169
 178.175.27.179
 178.175.27.199
 178.175.27.202
@@ -1619,69 +1687,66 @@
 178.175.27.225
 178.175.27.233
 178.175.27.239
-178.175.27.241
+178.175.27.32
+178.175.27.48
 178.175.27.68
 178.175.27.69
 178.175.27.84
-178.175.28.118
 178.175.28.124
-178.175.28.128
-178.175.28.167
 178.175.28.168
+178.175.28.75
 178.175.28.8
+178.175.29.12
 178.175.29.16
 178.175.29.173
 178.175.29.174
-178.175.29.184
 178.175.29.207
 178.175.3.116
+178.175.3.123
 178.175.3.130
 178.175.3.172
 178.175.3.190
+178.175.3.194
 178.175.3.196
 178.175.3.214
 178.175.3.56
 178.175.3.81
 178.175.30.0
-178.175.30.213
-178.175.30.255
 178.175.30.77
 178.175.31.211
 178.175.31.232
 178.175.31.249
 178.175.31.251
 178.175.32.0
-178.175.32.105
-178.175.32.141
 178.175.32.172
-178.175.32.196
 178.175.32.198
 178.175.32.208
 178.175.32.211
+178.175.32.229
 178.175.32.243
-178.175.32.32
+178.175.32.255
 178.175.32.42
 178.175.32.89
 178.175.33.112
-178.175.33.118
-178.175.33.151
 178.175.33.155
 178.175.33.161
 178.175.33.162
 178.175.33.170
+178.175.33.173
 178.175.33.174
 178.175.33.181
 178.175.33.2
+178.175.33.205
 178.175.33.216
 178.175.33.234
 178.175.33.236
-178.175.33.239
 178.175.33.26
+178.175.34.219
+178.175.34.5
+178.175.34.56
 178.175.34.96
-178.175.35.160
 178.175.35.21
 178.175.35.215
-178.175.35.253
 178.175.35.38
 178.175.35.83
 178.175.35.89
@@ -1690,37 +1755,39 @@
 178.175.36.102
 178.175.36.112
 178.175.36.12
-178.175.36.16
+178.175.36.127
+178.175.36.176
+178.175.36.19
 178.175.36.199
-178.175.36.200
 178.175.36.218
 178.175.36.22
 178.175.36.223
 178.175.36.33
-178.175.36.88
+178.175.36.78
 178.175.37.121
 178.175.37.135
 178.175.37.159
 178.175.37.6
 178.175.38.1
-178.175.38.126
 178.175.38.132
-178.175.38.148
 178.175.38.162
 178.175.38.165
 178.175.38.191
-178.175.38.7
+178.175.38.200
+178.175.38.53
 178.175.38.98
 178.175.39.167
+178.175.39.176
 178.175.39.245
+178.175.39.61
+178.175.4.219
 178.175.4.222
 178.175.4.42
-178.175.4.58
 178.175.4.95
 178.175.40.1
+178.175.40.145
 178.175.40.151
 178.175.40.166
-178.175.40.191
 178.175.40.199
 178.175.40.226
 178.175.40.41
@@ -1728,10 +1795,10 @@
 178.175.40.67
 178.175.40.70
 178.175.40.71
-178.175.40.73
 178.175.40.82
 178.175.41.165
 178.175.41.178
+178.175.41.200
 178.175.41.203
 178.175.41.210
 178.175.41.216
@@ -1748,74 +1815,81 @@
 178.175.43.121
 178.175.43.125
 178.175.43.147
-178.175.43.17
-178.175.43.176
-178.175.43.22
+178.175.43.16
 178.175.43.33
-178.175.43.44
-178.175.43.47
+178.175.43.34
+178.175.44.0
 178.175.44.134
 178.175.44.143
 178.175.44.155
+178.175.44.197
+178.175.44.209
 178.175.44.218
+178.175.44.219
 178.175.44.22
 178.175.44.241
+178.175.44.70
 178.175.44.89
 178.175.44.90
+178.175.44.95
 178.175.45.205
 178.175.45.221
 178.175.45.224
 178.175.45.230
+178.175.46.119
+178.175.46.132
+178.175.46.151
 178.175.46.187
 178.175.47.141
 178.175.47.151
 178.175.48.121
 178.175.48.195
 178.175.48.243
+178.175.48.76
+178.175.49.100
 178.175.49.107
+178.175.49.129
+178.175.49.138
+178.175.49.188
 178.175.49.247
 178.175.49.3
-178.175.49.98
-178.175.5.16
 178.175.5.247
 178.175.5.251
 178.175.5.70
 178.175.50.131
 178.175.50.177
+178.175.50.196
 178.175.50.201
 178.175.50.218
 178.175.50.236
 178.175.50.237
-178.175.50.47
-178.175.51.150
 178.175.51.197
 178.175.51.202
 178.175.51.223
-178.175.51.37
 178.175.51.66
 178.175.52.149
 178.175.52.161
-178.175.52.79
 178.175.53.103
-178.175.53.15
 178.175.53.186
 178.175.53.20
+178.175.53.228
 178.175.53.4
 178.175.53.5
 178.175.53.79
 178.175.54.105
 178.175.54.205
 178.175.54.214
+178.175.54.35
 178.175.54.72
 178.175.55.101
-178.175.55.111
 178.175.55.163
-178.175.55.204
+178.175.55.170
 178.175.55.216
+178.175.55.248
 178.175.55.29
 178.175.55.41
 178.175.55.77
-178.175.55.86
+178.175.55.85
 178.175.56.103
 178.175.56.196
 178.175.56.33
@@ -1824,10 +1898,8 @@
 178.175.57.141
 178.175.57.178
 178.175.57.192
-178.175.57.7
-178.175.58.117
 178.175.58.141
-178.175.58.223
+178.175.58.42
 178.175.59.142
 178.175.59.161
 178.175.59.229
@@ -1837,37 +1909,40 @@
 178.175.59.91
 178.175.6.134
 178.175.6.151
-178.175.6.154
 178.175.6.162
-178.175.6.171
-178.175.60.154
+178.175.6.72
 178.175.60.181
-178.175.60.32
-178.175.60.99
-178.175.61.151
+178.175.60.209
+178.175.61.117
 178.175.61.156
 178.175.61.219
 178.175.61.229
 178.175.61.234
 178.175.61.253
 178.175.61.40
-178.175.61.96
+178.175.61.42
+178.175.61.82
 178.175.62.110
 178.175.62.115
+178.175.62.168
+178.175.62.216
 178.175.62.43
-178.175.63.185
+178.175.62.44
+178.175.62.70
+178.175.63.194
 178.175.63.21
 178.175.63.218
 178.175.64.116
 178.175.64.12
 178.175.64.142
 178.175.64.158
+178.175.64.219
 178.175.64.30
 178.175.64.66
 178.175.65.115
-178.175.65.136
 178.175.65.171
 178.175.65.223
+178.175.65.44
 178.175.65.70
 178.175.65.95
 178.175.65.96
@@ -1878,17 +1953,15 @@
 178.175.66.199
 178.175.66.211
 178.175.66.228
-178.175.66.237
 178.175.66.93
 178.175.67.0
 178.175.67.184
-178.175.67.185
 178.175.67.201
 178.175.67.254
-178.175.67.31
+178.175.67.83
+178.175.68.1
 178.175.68.109
 178.175.68.126
-178.175.68.166
 178.175.68.170
 178.175.68.227
 178.175.68.232
@@ -1897,12 +1970,14 @@
 178.175.68.66
 178.175.68.83
 178.175.69.111
+178.175.69.112
 178.175.69.119
 178.175.69.128
 178.175.69.138
+178.175.69.148
 178.175.69.149
+178.175.69.173
 178.175.69.188
-178.175.69.205
 178.175.69.77
 178.175.7.163
 178.175.70.119
@@ -1916,64 +1991,57 @@
 178.175.71.148
 178.175.71.153
 178.175.71.185
-178.175.71.196
 178.175.71.22
+178.175.71.240
 178.175.71.55
 178.175.71.63
+178.175.71.64
 178.175.71.84
-178.175.71.89
-178.175.72.113
 178.175.72.13
 178.175.72.164
-178.175.72.173
 178.175.72.196
 178.175.72.222
-178.175.72.47
-178.175.72.75
-178.175.72.91
-178.175.72.98
-178.175.73.220
+178.175.73.211
+178.175.73.71
 178.175.74.182
 178.175.74.48
-178.175.75.135
+178.175.74.77
 178.175.75.181
 178.175.75.19
 178.175.75.209
-178.175.75.249
-178.175.75.54
 178.175.75.84
 178.175.75.87
 178.175.76.109
+178.175.76.121
 178.175.76.167
 178.175.76.187
 178.175.76.214
 178.175.76.215
 178.175.76.217
 178.175.76.24
-178.175.77.132
-178.175.77.145
 178.175.77.46
 178.175.77.47
 178.175.77.95
 178.175.78.106
-178.175.78.202
+178.175.78.118
 178.175.78.233
 178.175.78.46
 178.175.78.76
+178.175.78.97
 178.175.79.156
 178.175.79.227
-178.175.79.24
 178.175.79.247
 178.175.79.45
 178.175.79.77
 178.175.8.100
-178.175.8.165
 178.175.8.199
-178.175.8.205
 178.175.8.217
 178.175.8.254
+178.175.8.97
+178.175.80.100
+178.175.80.136
 178.175.80.237
-178.175.80.244
+178.175.80.41
 178.175.80.79
 178.175.80.86
 178.175.81.1
@@ -1982,43 +2050,47 @@
 178.175.81.152
 178.175.81.17
 178.175.81.194
-178.175.81.216
 178.175.81.226
 178.175.81.244
+178.175.81.32
 178.175.81.50
-178.175.81.82
+178.175.81.8
+178.175.82.120
 178.175.82.61
 178.175.83.147
 178.175.83.196
+178.175.83.247
 178.175.84.102
 178.175.84.109
 178.175.84.148
+178.175.84.158
 178.175.84.159
 178.175.84.215
 178.175.84.42
 178.175.85.153
-178.175.85.165
 178.175.85.183
 178.175.85.190
-178.175.85.229
+178.175.85.23
+178.175.85.81
 178.175.85.87
-178.175.85.9
 178.175.86.119
-178.175.86.218
-178.175.87.107
+178.175.86.159
+178.175.86.166
+178.175.87.108
 178.175.87.123
 178.175.87.162
 178.175.87.253
-178.175.87.90
 178.175.88.180
 178.175.88.181
-178.175.88.78
 178.175.89.130
-178.175.89.19
+178.175.89.157
+178.175.89.160
+178.175.89.169
 178.175.89.37
-178.175.89.51
-178.175.9.178
+178.175.9.106
+178.175.9.139
 178.175.9.183
+178.175.9.210
 178.175.9.215
 178.175.9.217
 178.175.9.245
@@ -2026,8 +2098,8 @@
 178.175.9.80
 178.175.9.84
 178.175.9.95
-178.175.90.115
-178.175.90.160
+178.175.90.104
+178.175.90.122
 178.175.90.178
 178.175.90.187
 178.175.90.21
@@ -2038,72 +2110,73 @@
 178.175.91.165
 178.175.91.172
 178.175.91.191
+178.175.91.223
+178.175.91.230
 178.175.91.253
-178.175.91.47
 178.175.91.58
-178.175.91.71
 178.175.91.96
 178.175.92.132
 178.175.92.186
 178.175.92.201
 178.175.92.208
 178.175.92.215
-178.175.92.224
 178.175.92.231
 178.175.92.248
 178.175.92.45
 178.175.93.143
+178.175.93.148
 178.175.93.150
 178.175.93.155
+178.175.93.171
 178.175.93.198
+178.175.93.224
 178.175.93.225
-178.175.93.245
 178.175.93.31
+178.175.93.34
 178.175.93.4
 178.175.93.45
 178.175.93.6
+178.175.93.90
 178.175.94.116
-178.175.94.184
 178.175.94.195
 178.175.94.238
+178.175.94.248
 178.175.94.40
+178.175.95.111
+178.175.95.132
 178.175.95.147
 178.175.95.227
+178.175.95.237
 178.175.95.244
-178.175.95.249
 178.175.95.4
+178.175.95.7
 178.175.95.89
-178.175.95.99
 178.175.96.13
-178.175.96.180
 178.175.96.195
-178.175.96.24
 178.175.96.6
-178.175.97.111
-178.175.97.181
-178.175.97.243
-178.175.98.140
+178.175.97.1
+178.175.97.128
+178.175.97.135
+178.175.97.162
+178.175.97.17
+178.175.97.208
 178.175.98.228
 178.175.98.254
 178.175.98.50
 178.175.98.68
-178.175.99.108
 178.175.99.123
 178.175.99.130
 178.175.99.22
 178.175.99.45
-178.175.99.75
 178.175.99.8
 178.175.99.91
 178.19.183.14
-178.205.101.33
 178.21.164.68
 178.217.8.194
 178.22.117.102
 178.222.252.130
 178.34.183.30
 178.92.246.246
-178.93.112.88
 178.95.115.33
 179.159.58.134
 179.4.187.39
@@ -2116,7 +2189,6 @@
 180.116.203.220
 180.120.149.106
 180.122.13.227
-180.125.155.69
 180.125.44.194
 180.157.66.204
 180.175.93.52
@@ -2137,7 +2209,6 @@
 181.112.218.238
 181.112.218.6
 181.143.60.163
-181.174.63.114
 181.193.107.10
 181.199.170.210
 181.199.170.222
@@ -2154,79 +2225,86 @@
 182.112.52.131
 182.113.0.79
 182.113.222.154
+182.113.233.129
 182.113.24.21
 182.114.106.207
-182.114.122.228
 182.114.202.186
-182.114.31.65
-182.114.50.124
-182.114.50.93
 182.114.64.27
-182.114.70.177
-182.114.93.165
-182.114.94.255
 182.116.101.82
-182.116.104.125
+182.116.103.81
+182.116.108.180
+182.116.108.244
 182.116.110.31
-182.116.44.70
-182.116.49.171
+182.116.119.129
 182.116.60.73
 182.116.61.252
 182.116.65.157
 182.116.65.245
 182.116.68.40
 182.116.69.37
-182.116.69.47
 182.116.94.196
+182.116.99.150
 182.116.99.17
 182.117.155.204
 182.117.25.120
 182.117.26.235
-182.117.27.150
+182.117.29.220
 182.117.29.74
 182.117.43.27
 182.118.140.117
 182.119.100.228
+182.119.13.141
 182.119.14.252
 182.119.166.208
+182.119.196.182
 182.119.211.69
 182.119.220.48
-182.119.227.82
-182.119.229.96
 182.119.236.21
+182.119.49.17
 182.119.50.155
+182.119.7.54
 182.119.81.33
 182.120.10.21
 182.120.16.22
 182.120.16.46
 182.120.37.251
 182.120.43.0
+182.120.86.248
 182.121.101.100
 182.121.109.190
+182.121.12.128
 182.121.125.170
 182.121.129.232
-182.121.131.69
 182.121.133.200
-182.121.135.160
+182.121.133.46
+182.121.134.73
 182.121.148.236
 182.121.157.221
-182.121.200.151
+182.121.165.217
+182.121.205.118
 182.121.206.132
 182.121.219.239
 182.121.233.191
 182.121.249.26
-182.121.68.100
+182.121.50.111
+182.121.78.29
 182.121.81.241
 182.121.92.113
 182.121.93.174
 182.121.98.21
 182.122.170.19
+182.122.202.37
 182.122.220.203
 182.122.229.102
 182.122.245.2
+182.122.246.187
 182.122.249.24
+182.122.251.141
+182.124.134.80
+182.124.15.108
+182.124.166.57
 182.124.188.23
-182.124.53.111
+182.124.95.139
 182.126.113.127
 182.126.117.41
 182.126.124.47
@@ -2236,22 +2314,27 @@
 182.126.139.66
 182.126.140.30
 182.126.178.187
+182.126.181.121
+182.126.241.7
+182.126.52.233
 182.126.82.29
 182.126.83.79
-182.126.87.58
+182.126.87.207
 182.126.95.209
 182.127.155.157
 182.127.166.232
 182.127.210.107
 182.127.6.12
+182.127.70.195
 182.127.78.61
-182.127.87.72
 182.127.91.161
+182.127.96.120
 182.172.36.164
-182.207.219.164
 182.233.0.252
 182.235.252.31
 182.53.197.62
+182.58.160.0
+182.59.227.125
 182.88.235.221
 183.105.104.83
 183.105.225.154
@@ -2264,7 +2347,9 @@
 183.188.151.225
 183.188.180.116
 183.188.180.68
-183.188.76.196
+183.188.188.186
+183.191.162.120
+183.83.105.21
 183.83.14.35
 183.83.15.116
 183.83.23.138
@@ -2273,6 +2358,7 @@
 183.95.147.102
 183.97.22.14
 184.164.185.41
+184.175.115.10
 184.74.149.230
 185.106.209.68
 185.107.3.8
@@ -2293,50 +2379,47 @@
 185.68.230.207
 185.81.157.186
 185.82.217.185
-185.82.217.213
 185.82.219.160
 185.82.219.161
 185.82.219.219
-185.82.219.80
 185.90.166.56
 186.151.144.85
 186.179.219.164
 186.179.243.112
 186.179.243.77
+186.179.243.91
 186.179.253.150
 186.225.120.173
 186.227.148.107
+186.232.44.86
 186.28.60.184
-186.4.125.48
+186.33.112.28
 186.73.188.132
 187.12.10.98
 187.188.124.229
 187.212.200.162
-187.56.88.170
-187.75.218.102
 188.10.21.14
 188.10.231.246
+188.113.102.18
 188.113.81.17
-188.127.224.149
 188.127.224.61
+188.127.227.173
 188.127.227.99
-188.127.230.133
 188.127.231.226
 188.127.231.55
 188.127.235.232
-188.127.235.70
+188.127.235.244
 188.127.235.71
+188.127.237.152
 188.127.254.114
 188.13.179.87
 188.138.200.32
 188.152.41.141
 188.169.178.50
-188.169.199.59
 188.169.30.30
 188.169.36.163
 188.242.167.159
 188.242.242.144
-188.81.100.83
 188.83.202.25
 188.93.233.223
 189.222.157.241
@@ -2355,14 +2438,12 @@
 190.130.15.212
 190.130.20.14
 190.141.117.41
-190.147.16.184
 190.159.240.9
 190.187.55.150
 190.210.214.130
 190.213.177.39
 190.213.226.63
 190.213.49.207
-190.214.24.194
 190.216.140.123
 190.35.225.36
 190.65.206.162
@@ -2376,13 +2457,17 @@
 192.227.185.106
 192.227.209.27
 192.227.228.67
+192.3.152.166
 192.3.73.205
 192.99.240.77
+193.142.146.25
 193.228.135.144
 193.91.131.237
+194.15.36.167
+194.15.36.202
 194.152.35.139
 194.38.20.199
-195.123.208.140
+194.87.139.10
 195.123.213.154
 195.139.126.51
 195.228.231.218
@@ -2395,12 +2480,14 @@
 197.159.2.106
 197.50.27.115
 198.23.133.218
+198.23.207.121
+198.23.213.57
 198.23.251.105
 198.46.201.76
 198.46.202.7
 1am.co.nz
 2.229.89.119
-2.37.203.65
+2.249.161.188
 2.45.111.158
 2.45.4.24
 2.55.125.182
@@ -2416,27 +2503,26 @@
 201.184.163.170
 201.184.248.190
 201.187.102.73
-201.193.17.190
+201.200.254.86
 201.203.221.20
+201.208.139.84
 201.215.84.97
 201.218.97.142
 202.107.233.41
 202.111.131.91
-202.150.176.100
 202.164.150.115
 202.166.217.54
+202.169.234.22
 202.169.234.47
 202.169.234.52
 202.169.234.56
-202.178.113.26
+202.169.234.9
 202.29.95.12
 202.4.124.58
 202.51.176.114
 202.51.191.174
 202.74.236.9
 203.109.201.243
-203.130.69.205
-203.170.105.156
 203.170.115.82
 203.189.156.107
 203.202.248.237
@@ -2451,28 +2537,25 @@
 203.82.36.34
 203.93.6.28
 204.195.116.171
-205.185.115.74
 205.185.123.217
+206.248.137.132
 206.47.41.166
 207.200.247.187
 207.44.28.234
 207.5.32.6
 208.163.58.18
-209.133.223.130
 209.141.39.50
 209.141.40.190
-209.141.40.31
 209.145.60.38
+210.102.196.200
 210.124.149.19
 210.216.152.122
 210.216.153.142
-210.57.234.131
 210.57.237.70
+210.57.245.109
 210.68.242.114
 210.96.116.236
-211.116.220.37
 211.172.11.169
-211.179.243.103
 211.187.132.204
 211.187.75.220
 211.204.215.157
@@ -2484,8 +2567,8 @@
 211.238.83.238
 211.247.113.49
 211.247.5.96
-211.32.122.110
 211.36.174.137
+211.41.197.30
 211.47.102.51
 211.51.174.149
 212.122.86.105
@@ -2499,24 +2582,22 @@
 213.14.173.117
 213.149.182.113
 213.149.190.193
+213.163.104.10
 213.163.104.12
 213.163.104.20
 213.163.104.99
 213.163.113.100
 213.163.113.199
 213.163.113.225
-213.163.113.226
-213.163.113.237
 213.163.113.51
 213.163.113.79
-213.163.114.107
-213.163.114.36
+213.163.114.80
 213.163.115.11
 213.163.115.15
 213.163.115.26
+213.163.115.33
 213.163.115.71
-213.163.116.149
-213.163.116.160
+213.163.116.132
 213.163.116.164
 213.163.116.203
 213.163.116.249
@@ -2530,10 +2611,8 @@
 213.163.126.131
 213.163.126.243
 213.163.126.60
-213.163.126.61
 213.163.126.7
-213.163.126.96
-213.163.127.178
+213.163.126.71
 213.163.127.217
 213.163.127.46
 213.189.178.163
@@ -2541,8 +2620,6 @@
 213.249.156.189
 213.27.8.6
 213.80.44.17
-213.87.87.173
-213.92.254.214
 213.92.254.52
 213.92.255.36
 213.92.255.84
@@ -2554,10 +2631,9 @@
 216.36.12.98
 217.11.75.162
 217.127.133.214
-218.104.175.64
+218.103.180.199
 218.215.243.65
 218.238.246.3
-218.255.226.166
 218.28.160.174
 218.35.207.119
 218.35.227.133
@@ -2566,38 +2642,45 @@
 218.48.135.50
 218.56.93.129
 218.57.53.55
-218.58.3.119
-218.58.3.38
 218.59.116.203
 218.72.198.15
-218.72.248.42
 218.79.103.159
 219.154.104.209
 219.154.119.145
+219.154.141.222
 219.154.182.197
 219.155.102.14
+219.155.12.221
 219.155.14.17
+219.155.170.22
+219.155.208.188
 219.155.24.246
+219.155.241.135
 219.155.26.37
-219.155.28.41
 219.155.31.15
 219.155.31.67
+219.155.37.97
 219.155.9.202
-219.155.97.226
+219.156.103.248
 219.156.21.73
-219.157.139.165
+219.156.23.29
+219.156.60.224
+219.156.9.32
 219.157.146.200
 219.157.150.91
 219.157.162.205
 219.157.17.8
-219.157.177.232
 219.157.178.201
 219.157.183.29
 219.157.202.66
-219.157.215.242
+219.157.220.170
 219.157.221.133
+219.157.223.245
+219.157.244.33
 219.157.32.244
-219.157.64.251
+219.157.50.211
+219.157.54.158
+219.157.56.46
 219.241.6.180
 219.68.1.148
 219.68.1.84
@@ -2615,34 +2698,34 @@
 220.173.160.53
 220.200.22.163
 220.71.239.115
+220.90.159.188
 221.0.16.221
 221.1.162.82
 221.124.78.15
 221.14.122.127
 221.14.182.157
 221.14.46.33
+221.14.58.5
 221.14.58.84
-221.15.124.188
+221.15.147.220
 221.15.153.17
-221.15.160.67
-221.15.194.218
-221.15.199.35
 221.15.218.173
 221.15.234.159
 221.15.234.175
+221.15.237.107
 221.15.54.237
+221.15.7.202
 221.157.191.178
 221.160.136.213
 221.160.177.104
 221.160.177.107
 221.160.177.224
 221.196.12.96
-221.208.4.71
 221.214.130.147
-221.214.146.73
 221.214.162.109
 221.214.224.184
 221.215.116.167
+221.215.172.207
 221.215.184.31
 221.215.237.220
 221.215.239.162
@@ -2657,6 +2740,7 @@
 221.3.34.43
 221.3.43.223
 221.3.68.16
+221.5.30.118
 222.108.17.64
 222.119.65.145
 222.132.125.138
@@ -2666,13 +2750,10 @@
 222.135.113.41
 222.135.219.29
 222.135.26.161
-222.136.21.126
-222.136.218.233
 222.136.231.197
 222.136.49.252
 222.137.101.251
 222.137.113.184
-222.137.120.3
 222.137.121.127
 222.137.136.241
 222.137.137.5
@@ -2684,18 +2765,26 @@
 222.137.172.250
 222.137.175.242
 222.137.186.150
+222.137.22.79
+222.137.220.94
 222.137.221.128
+222.137.49.4
 222.137.5.150
 222.137.72.146
-222.137.8.96
 222.137.81.67
+222.137.83.53
 222.138.137.188
 222.138.143.84
+222.138.189.88
 222.138.203.22
+222.138.215.161
 222.138.232.159
+222.138.232.84
+222.138.49.93
 222.138.96.79
+222.139.16.229
 222.139.59.63
-222.140.10.235
+222.140.112.150
 222.140.117.221
 222.140.161.11
 222.140.163.112
@@ -2703,27 +2792,26 @@
 222.140.209.222
 222.140.219.212
 222.140.39.66
-222.141.120.17
-222.141.147.104
 222.141.150.38
+222.141.165.180
+222.141.244.231
 222.141.40.136
-222.141.40.2
 222.141.41.155
+222.141.44.36
 222.141.45.153
-222.141.45.255
 222.141.60.251
+222.141.73.249
 222.141.85.128
 222.142.162.164
 222.142.192.66
 222.142.209.7
 222.142.65.30
-222.184.129.122
+222.179.215.189
 222.185.116.233
-222.186.20.19
 222.187.9.178
 222.211.72.66
+222.214.54.208
 222.218.220.219
-222.236.85.220
 222.238.230.7
 222.239.83.232
 222.248.64.253
@@ -2733,21 +2821,17 @@
 222.99.171.192
 223.166.117.210
 223.167.118.17
-223.175.121.249
 223.212.225.68
 223.212.234.84
 223.212.252.180
 223.212.5.29
-223.212.57.78
 223.212.73.175
-223.213.164.81
 23.125.186.135
 23.126.120.25
 23.228.143.58
 23.24.213.121
 23.243.149.13
 23.243.21.167
-23.81.246.58
 23.95.89.21
 24.103.74.180
 24.11.141.134
@@ -2774,6 +2858,7 @@
 27.105.106.201
 27.105.152.107
 27.116.84.57
+27.12.234.4
 27.12.245.238
 27.13.83.77
 27.14.211.219
@@ -2789,7 +2874,6 @@
 27.193.217.210
 27.194.149.142
 27.194.158.229
-27.194.166.45
 27.194.192.66
 27.194.210.20
 27.194.224.96
@@ -2841,14 +2925,15 @@
 27.208.166.13
 27.208.201.212
 27.208.247.130
+27.208.25.59
 27.208.34.2
 27.208.92.64
 27.209.160.222
 27.209.231.15
 27.209.60.21
-27.21.159.174
 27.210.107.125
 27.210.127.11
+27.210.146.61
 27.210.172.245
 27.210.234.28
 27.210.236.134
@@ -2857,6 +2942,8 @@
 27.213.104.201
 27.213.109.105
 27.213.109.58
+27.213.145.221
+27.213.167.175
 27.213.175.208
 27.213.220.5
 27.213.255.202
@@ -2871,6 +2958,7 @@
 27.215.38.166
 27.215.71.243
 27.215.98.242
+27.216.131.66
 27.216.144.66
 27.216.193.217
 27.216.197.193
@@ -2897,7 +2985,6 @@
 27.219.184.94
 27.219.192.223
 27.219.83.244
-27.220.243.172
 27.220.40.189
 27.220.85.168
 27.221.239.223
@@ -2909,25 +2996,27 @@
 27.223.242.164
 27.223.44.106
 27.24.28.134
-27.35.127.129
 27.35.129.198
 27.35.154.13
+27.35.16.145
 27.35.2.30
 27.35.212.124
 27.35.58.5
-27.36.143.238
-27.41.159.216
-27.41.36.15
-27.41.38.79
-27.46.45.90
-27.5.38.169
-27.5.41.251
-27.5.42.169
-27.6.196.172
+27.41.153.66
+27.41.154.31
+27.43.82.210
+27.46.45.248
+27.46.47.74
+27.5.16.243
+27.5.26.105
+27.5.26.4
+27.5.27.1
+27.5.35.127
 31.0.98.131
 31.11.51.57
 31.13.23.180
 31.154.234.3
+31.163.191.11
 31.168.124.130
 31.168.179.83
 31.168.184.59
@@ -2946,8 +3035,10 @@
 31.204.174.180
 31.210.20.138
 31.210.20.177
+31.210.20.227
 31.28.7.159
 31.30.119.23
+31.62.255.3
 32.208.157.193
 32792.prolocksmithwinterpark.com
 35.184.169.169
@@ -2959,8 +3050,6 @@
 36.251.19.88
 36.251.51.244
 36.255.90.219
-36.32.203.118
-36.32.25.158
 36.33.128.60
 36.33.160.167
 36.36.243.67
@@ -2970,7 +3059,6 @@
 36.66.139.36
 36.67.152.161
 36.89.18.133
-36.91.89.187
 36.96.187.93
 360.lcy2zzx.pw
 360down7.miiyun.cn
@@ -3008,8 +3096,8 @@
 39.72.67.64
 39.73.10.198
 39.73.163.231
-39.73.183.14
 39.73.203.225
+39.73.44.17
 39.74.104.228
 39.74.21.201
 39.74.28.89
@@ -3035,7 +3123,6 @@
 39.79.91.244
 39.79.93.171
 39.80.127.214
-39.80.188.238
 39.80.191.137
 39.80.205.255
 39.80.24.54
@@ -3052,8 +3139,10 @@
 39.84.34.217
 39.84.95.200
 39.85.54.191
+39.85.54.4
 39.86.129.233
 39.86.13.0
+39.86.151.49
 39.86.170.209
 39.86.184.164
 39.86.211.20
@@ -3064,6 +3153,7 @@
 39.86.76.9
 39.86.78.228
 39.87.63.58
+39.87.90.210
 39.87.93.109
 39.88.141.172
 39.88.155.96
@@ -3084,95 +3174,100 @@
 41.219.185.171
 41.230.31.58
 41.72.203.82
-41.76.157.2
+41.86.18.133
 41.86.18.147
 41.86.18.148
+41.86.18.165
 41.86.18.200
 41.86.18.71
-41.86.21.35
-41.86.21.40
+41.86.21.28
+41.86.21.5
+41.86.21.62
 41.86.5.103
-41.86.5.104
-41.86.5.198
-41.86.5.237
 42.176.112.72
 42.202.101.147
+42.224.122.39
 42.224.128.210
 42.224.168.142
 42.224.168.97
-42.224.170.140
+42.224.176.214
 42.224.179.49
-42.224.181.121
-42.224.183.11
 42.224.209.156
 42.224.212.124
 42.224.218.16
 42.224.233.247
 42.224.235.4
+42.224.249.8
 42.224.37.186
 42.224.37.44
 42.224.43.25
 42.224.64.34
-42.224.66.246
 42.224.70.213
 42.224.76.168
 42.224.76.198
 42.224.8.136
+42.224.90.17
 42.224.91.8
-42.225.24.101
 42.225.240.244
 42.225.250.39
-42.226.76.62
+42.225.33.31
+42.226.89.25
 42.227.179.209
-42.227.204.4
 42.227.66.88
 42.228.198.102
 42.228.60.114
 42.228.65.201
 42.228.70.126
 42.228.70.231
+42.228.75.7
 42.228.76.135
 42.230.100.114
+42.230.174.125
+42.230.219.243
 42.230.228.78
-42.230.57.145
 42.230.66.255
 42.230.82.44
 42.230.88.107
 42.230.93.169
+42.231.223.215
+42.231.244.80
 42.231.66.174
+42.231.95.195
 42.232.102.163
 42.232.170.117
 42.232.226.16
+42.233.90.183
+42.234.105.6
+42.234.162.44
 42.234.166.242
-42.234.180.136
 42.234.255.20
 42.235.124.55
-42.235.160.215
 42.235.169.85
 42.235.23.163
 42.235.66.249
-42.235.83.180
+42.235.90.32
+42.235.92.111
 42.236.148.201
 42.236.212.174
 42.236.212.83
 42.236.215.63
 42.236.236.179
+42.237.45.223
 42.237.54.162
-42.238.175.61
+42.238.175.32
 42.238.191.210
 42.238.241.239
 42.238.59.222
 42.239.192.128
-42.239.207.166
-42.239.42.135
 42.242.200.90
 42.52.180.36
 42.56.15.227
 42.61.99.155
+42.82.217.241
 42.84.14.5
 43.230.156.44
-43.230.207.204
 43.241.106.183
+43.241.106.234
 43.252.8.94
 45.112.203.218
 45.130.138.66
@@ -3184,16 +3279,20 @@
 45.14.149.204
 45.14.149.244
 45.14.149.66
-45.141.84.182
 45.141.84.184
+45.144.225.142
+45.144.225.213
 45.144.225.65
 45.148.10.47
 45.15.143.158
 45.164.140.133
-45.165.215.19
 45.176.108.116
 45.176.108.248
+45.176.110.99
+45.176.111.154
 45.176.111.16
+45.176.111.202
+45.176.111.84
 45.178.101.22
 45.201.165.164
 45.22.209.58
@@ -3207,10 +3306,8 @@
 46.172.75.231
 46.175.184.121
 46.182.173.246
-46.182.173.247
 46.20.63.218
 46.201.214.64
-46.201.38.162
 46.21.153.231
 46.214.27.4
 46.24.130.254
@@ -3242,7 +3339,6 @@
 49.68.221.252
 49.68.249.121
 49.70.15.16
-49.70.2.100
 5.181.135.114
 5.2.70.50
 5.53.146.179
@@ -3252,6 +3348,7 @@
 50.252.47.29
 51.171.146.13
 51.222.56.159
+54.180.158.181
 54.253.194.14
 54.36.114.136
 54.36.180.122
@@ -3264,9 +3361,10 @@
 58.142.166.120
 58.142.200.124
 58.143.142.142
+58.143.189.75
 58.18.103.109
+58.19.249.50
 58.217.171.157
-58.218.67.253
 58.22.212.107
 58.226.129.29
 58.229.194.122
@@ -3277,44 +3375,36 @@
 58.240.147.97
 58.241.57.237
 58.241.78.55
-58.248.112.16
-58.248.116.2
 58.248.117.188
-58.248.140.132
-58.248.142.137
-58.248.142.174
+58.248.143.173
+58.248.144.97
 58.248.149.117
-58.248.150.204
-58.248.150.244
-58.248.153.194
+58.248.149.226
 58.248.154.55
 58.248.154.66
 58.248.76.206
 58.248.79.25
-58.249.15.148
 58.249.18.244
-58.249.22.210
-58.249.72.121
+58.249.74.104
 58.249.74.124
 58.249.74.248
 58.249.77.227
-58.249.79.134
+58.249.78.155
 58.249.80.23
+58.249.80.46
 58.249.86.85
-58.249.88.207
-58.252.177.212
+58.249.87.248
+58.249.89.210
+58.249.90.206
+58.249.90.86
+58.252.176.107
 58.252.177.66
-58.252.178.167
-58.252.178.55
-58.253.14.46
-58.255.140.156
 58.255.43.163
 58.48.154.143
 58.50.178.137
 58.50.221.148
 58.72.165.153
 58.72.165.39
-58.76.151.51
 58.97.201.45
 58.97.206.33
 59.0.211.161
@@ -3322,48 +3412,18 @@
 59.151.202.3
 59.151.214.4
 59.151.237.51
-59.151.246.125
 59.29.133.229
 59.30.12.254
+59.32.97.190
 59.58.104.244
 59.58.117.226
 59.7.124.148
 59.8.35.22
-59.89.243.76
-59.92.176.136
-59.92.178.202
-59.92.18.175
-59.92.182.177
-59.92.216.255
-59.93.17.196
-59.93.17.204
-59.93.17.72
-59.93.19.11
-59.93.23.154
-59.93.23.215
-59.93.23.23
-59.93.23.7
-59.94.180.237
-59.96.36.131
-59.96.36.137
-59.96.39.91
-59.97.168.110
-59.97.170.16
-59.97.175.101
-59.97.175.96
-59.97.193.118
-59.99.137.46
-59.99.138.222
-59.99.139.252
-59.99.139.66
-59.99.141.103
-59.99.141.219
-59.99.142.43
-59.99.188.93
-59.99.41.26
-59.99.43.225
-59.99.46.7
-59.99.47.64
+59.92.182.72
+59.92.218.77
+59.92.219.28
+59.97.174.85
+59.99.47.93
 60.13.61.12
 60.14.48.221
 60.162.122.36
@@ -3402,24 +3462,24 @@
 60.220.22.89
 60.25.115.48
 60.25.76.224
-60.253.15.104
-60.253.39.88
+60.253.4.72
 60.253.42.72
-60.253.44.99
 60.253.51.127
 60.253.60.174
+60.253.8.36
 60.253.8.81
+60.254.49.59
 60.7.10.121
 60.7.136.8
 60.7.202.153
+60.7.8.43
 60.7.99.254
 61.102.243.124
+61.109.164.140
+61.141.124.123
 61.162.169.210
 61.162.55.42
-61.163.129.97
 61.164.96.98
-61.167.211.218
-61.168.139.87
 61.179.171.60
 61.179.91.194
 61.179.91.230
@@ -3429,37 +3489,42 @@
 61.213.118.28
 61.247.224.66
 61.253.94.230
-61.3.126.128
-61.3.144.90
-61.3.147.175
+61.3.124.3
+61.3.124.51
 61.47.220.169
 61.52.102.61
 61.52.103.144
 61.52.11.87
+61.52.135.192
 61.52.157.4
 61.52.159.231
 61.52.195.226
 61.52.212.191
+61.52.212.250
 61.52.243.169
 61.52.247.208
-61.52.30.49
 61.52.35.86
+61.52.39.119
 61.52.43.174
 61.52.48.112
+61.52.5.217
+61.52.63.119
+61.52.76.72
 61.52.9.166
-61.52.97.134
 61.52.99.183
 61.53.100.87
-61.53.121.19
+61.53.123.162
+61.53.125.182
 61.53.251.243
 61.53.62.169
 61.53.73.171
-61.53.74.27
 61.53.81.18
 61.53.83.14
-61.53.86.195
 61.54.172.248
-61.54.41.143
+61.54.240.20
+61.54.58.190
+61.54.58.20
+61.54.61.18
 61.54.64.104
 61.54.77.175
 61.56.180.67
@@ -3482,6 +3547,7 @@
 62.141.73.58
 62.219.131.205
 62.219.143.46
+62.219.155.61
 62.219.227.31
 62.31.126.33
 62.38.149.66
@@ -3493,16 +3559,13 @@
 65.125.128.196
 65.21.58.252
 65.26.155.131
-65.35.61.255
 66.153.233.87
-66.207.93.46
 66.229.214.115
 66.57.55.210
 66.74.7.197
 66.91.21.31
 66.97.181.196
 66.97.181.213
-67.221.107.75
 67.245.151.203
 67.3.169.223
 67.8.138.101
@@ -3541,7 +3604,7 @@
 70.33.144.248
 70.93.129.118
 71.127.148.69
-71.146.190.91
+71.19.150.93
 71.204.63.239
 71.29.48.164
 71.34.191.213
@@ -3566,7 +3629,6 @@
 74.199.84.77
 74.75.165.81
 75.127.141.52
-75.176.213.114
 75.82.36.220
 75.83.102.27
 75.99.213.61
@@ -3578,11 +3640,13 @@
 76.84.134.33
 76.95.12.137
 77.237.25.210
+77.45.183.39
 77.71.50.153
 77.71.52.220
 77.79.191.32
 77.89.203.238
 78.179.225.254
+78.186.155.18
 78.187.141.144
 78.187.240.125
 78.187.41.200
@@ -3600,7 +3664,6 @@
 79.170.31.56
 79.175.42.244
 79.21.84.63
-79.22.176.145
 79.7.170.58
 79.79.58.94
 79.8.70.162
@@ -3616,7 +3679,6 @@
 81.198.7.22
 81.213.111.60
 81.213.141.184
-81.213.166.175
 81.215.199.29
 81.218.187.113
 81.218.195.216
@@ -3660,7 +3722,7 @@
 84.210.219.208
 84.210.219.213
 84.212.219.127
-84.214.103.73
+84.224.162.170
 84.228.50.118
 84.228.95.204
 84.238.24.35
@@ -3677,12 +3739,12 @@
 85.105.208.25
 85.105.224.141
 85.105.241.2
+85.105.9.152
 85.214.149.236
 85.64.181.50
 85.74.215.180
 85.97.130.227
 85.97.195.129
-85.98.40.5
 86.35.43.220
 87.121.98.51
 87.61.89.40
@@ -3697,7 +3759,6 @@
 88.250.204.12
 88.250.226.26
 88.250.254.90
-88.37.171.141
 89.122.183.130
 89.136.197.170
 89.29.213.33
@@ -3718,11 +3779,10 @@
 91.244.169.139
 91.92.16.244
 91.98.4.181
-92.113.192.30
-92.113.195.115
 92.114.191.82
 92.241.78.114
 92.27.246.202
+92.54.237.237
 92.85.18.138
 93.171.157.73
 93.21.224.154
@@ -3747,7 +3807,6 @@
 95.170.201.34
 95.181.155.112
 95.214.52.64
-95.53.229.84
 95.54.11.179
 95.60.146.134
 95.60.6.114
@@ -3768,7 +3827,6 @@
 98.30.24.54
 99.150.245.203
 99.33.195.164
-99centsdigitals.com
 abcd.bg
 abclicks.in
 abissnet.net
@@ -3776,11 +3834,12 @@ aboveandbelow.com.au
 absoftechworld.com
 absupplies.co.uk
 abyssos.eu
+academyshademani.com
 acbick.com
 accounts.thesmarttechhub.com
 aceeprc.com.aceeprc.com
 acellr.co.uk
-aclassapart.in
+aciabogados.com
 acteon.com.ar
 activateyourdiscount.com
 activecost.com.au
@@ -3798,6 +3857,7 @@ agemn.co.za
 agenciadigitalwdys.com
 agenciatabletshouse.com.br
 agenda.gmelloinformatica.com.br
+agenmovie.xyz
 agentt.ac.ug
 agile8studio.com
 agmcarpetcare.co.uk
@@ -3809,7 +3869,6 @@ al-wahd.com
 alasdemariposas.org
 alemelektronik.com
 alena1971.es
-alertlauncher.fr
 alexdubai.com.aldiabsteel.com
 alka.institute
 allforcreative.com.au
@@ -3821,6 +3880,7 @@ amarresdeamorymaestroshechiceros.com
 amarteargentina.com.ar
 amenyan.zouri.jp
 amos524.org
+ams.alvinasschools.org.ng
 anantam.net.in
 andreelapeyre.com
 andremaraisbeleggings.co.za
@@ -3840,10 +3900,9 @@ api.sampy.io
 aplicativoparasindicato.com.br
 apoolcondo.com
 app.adsensearticle.com
-app.explicitsurveys.co.uk
 app.prerana.info
 apps.saintsoporte.com
-aras.iuc.ac
+aqv.news
 areyoulivingwell.com
 arsapetrolab.com
 artedibujoyarquitectura.com
@@ -3862,11 +3921,12 @@ avissrilanka.com
 ayamallah.com
 azmeasurement.com
 azraktours.com
-b2b.toptanakaryakit.com.tr
 backgrounds.pk
 backup.agewsage.com
 badeggdesign.com
+balealgodon.mx
 bangkok-orchids.com
+barcionstw.eastus.cloudapp.azure.com
 bary.sz4h.com
 basma.com.kw
 bausch.kr-atlas.monaxikoslykos@zytrox.tk
@@ -3875,7 +3935,6 @@ bbia.co.uk
 bcmt.elin.co.za
 bcrg.co.za
 bearcatpumps.com.cn
-beatyamerican.com
 beautincollagen.rs
 bekape.co.id
 bespokeweddings.ie
@@ -3883,6 +3942,8 @@ bestcarenepal.com
 betone.co.kr
 betycopaints.com
 beveragesmiami.solucioneslink.com
+bhavaniengineering.com
+bigbag.wootraining.certificacion.cl
 bilbosaquet.ug
 bilhen.co.za
 billing.rahitechnosoft.com
@@ -3890,11 +3951,10 @@ birdi.elin.co.za
 birminghamlink.org
 blog.callensaxen.com
 blog.oyinblogs.com
-blog.takbelit.com
 bmlifestyle.co.uk
+bnrbook.com
 bnrnews.id
 bodenstein.co.za
-bolnicaloznica.rs
 booksearch.com
 bounces.mi-fs.com
 bpo.correct.go.th
@@ -3908,23 +3968,21 @@ brightonrooms.co.uk
 brightstarshop.com
 browardinsurancemiami.solucioneslink.com
 bt2.elin.co.za
-btdapi.robotake.com
 bucrinsuranlceonlines.com
 buenavista.co
-buigiaphat.com.vn
 bullseyemedia.in
 busandvanrentalmalaysia.com
 buscascolegios.diit.cl
 business.softberg.ro
 buyingmusiconline.com
-buypropertyfast.com
 bwsr.eu
 c.oooooooooo.ga
 c0140529.ferozo.com
+caballo.com.au
 cacapavaonline.sdserver144.com.br
+calgaryautorepairservice.com
 callbury.in
 camminachetipassa.it
-campusvirtual.cepsanjuanbosco.net.pe
 cancer.educandome.co
 capitalgroup-kw.com
 capitalnewsagency.com
@@ -3937,12 +3995,10 @@ cazyacustomfurniture.com
 ccauthority.net
 cdaonline.com.ar
 cec.asso.ac-amiens.fr
-cellas.sk
 cendekiabinaaksara.com
 cespol-bote.com.mx
 cfs5.tistory.com
 ch.rmu.ac.th
-changematterscounselling.com
 chardhamdodham.com
 cheacrilnsurances.com
 chealablilitycarinsurances.com
@@ -3950,15 +4006,14 @@ chezalice.co.za
 childselect.com
 chinhdropfile.myvnc.com
 chinhdropfile80.myvnc.com
-chipmania.it
 cible-energy.com
 cifeer.net
 citycapproperty.ru
 cityglobalgospel.com
 civi.istmejia.com
 cleanbydesignllc.com
-clim34000.fr
 cloud.fc.co.mz
+clurbgolf.com
 codsambal.com
 colinde.pricesne.com
 colorpak.pl
@@ -3980,7 +4035,6 @@ creationskateboards.com
 crecerco.com
 crittersbythebay.com
 crm.notariavieitoyvelamazan.com
-crmmanivela.net
 crscorretordeimoveis.com.br
 cse-engineer.com
 csnserver.com
@@ -4027,7 +4081,6 @@ destinymc.co.za
 detorre.es
 dev-interestingtech.pantheonsite.io
 dev.sebpo.net
-dezcom.com
 dfcf.91756.cn
 dfsfcsfcdsfsdvcfsvcscv.com
 diamantenegro.mi-fs.com
@@ -4050,7 +4103,6 @@ dom.daf.free.fr
 doncedyhall.com
 donghobinhminh.com
 dongphuctop.com
-donwnloasecury.ath.cx
 dosame.com
 dosman.pl
 dovberger.com
@@ -4058,6 +4110,9 @@ down.flash-plays.com
 down.pcclear.com
 down.posti-fi-fsa.top
 down.posti-fi-fwa.top
+down.posti-fi-ij.top
+down.posti-fi-in.top
+down.posti-fi-iz.top
 down.udashi.com
 down.webbora.com
 down1.arpun.com
@@ -4074,7 +4129,6 @@ dragonsknot.com
 drbaby.com.sa
 drohnen.ensenanzainteligente.com
 drools-moved.46999.n3.nabble.com
-drrohanfonseca.com
 drsha.innovativesolutions.mobi
 dsenterprize.co.za
 dsspainting.com
@@ -4088,19 +4142,15 @@ e-commerce.saleensuporte.com.br
 e.sldov.ru
 ebruyatkin.com
 econews.treegle.org
-edelweissdecoration.com
 efficientegroup.com
 elliot.newreadermedia.net
-emaids.co.za
 en.baoend.com
 enc-tech.com
 endurotanzania.co.tz
-enkonooh.com
 ennovate.elin.co.za
 enriquecendocomconsorcio.com.br
 envios.petpienso.cl
 equimination.ee
-es.paymelist.com
 escola.probommar.org.br
 esnconsultants.com
 essentia.org.br
@@ -4112,15 +4162,14 @@ extrovertoffers.com
 f1sol.com
 familydentist.site
 farmaciasdrogaminas.com.br
-farmnatural.in
 faveraprojects.com
 fc.co.mz
 felicienne.nl
 fi.bonitastores.com
 files.martellexpress.us
 files6.uludagbilisim.com
-filmotainment.com
 final.makkahkmcc.com
+fineartgallerym.com
 fkd.derpcity.ru
 flintspin.com
 flyingbuddhadesign.com
@@ -4128,20 +4177,17 @@ fmjplastering.co.uk
 fms.buladde.or.ug
 foothills.com.br
 footweardirect.elin.co.za
-formestore.evencsoft.co
 forum.mdb.nu
 fotoobjetivo.com
 foundationrepairhoustontx.net
 foxeps.com.br
 freecnetdownload.com
-freedombookshop.tickme.lk
 freisites.com.br
 ftp.n3twork30cm.ml
 fullelectronica.com.ar
 funletters.net
 fusionfiresolutions.com
 futuregraphics.com.ar
-gahanassociates.com
 gametwogame.com
 garayvidalabogados.com
 garciadogshow.com
@@ -4149,7 +4195,6 @@ garenanow.myvnc.com
 garenanow4.myvnc.com
 gbbulls.co.uk
 gcpc.co.id.chronoscurtain.com
-gcrcorporation.com
 generaldeviales.com
 gfmodd1.webselffiles01.com
 gfold1.webselffiles01.com
@@ -4157,6 +4202,8 @@ ghettohub.co.za
 ghislain.dartois.pagesperso-orange.fr
 giadungg7.com
 giddos.ga
+gilliem.com
+girotexuniformes.com
 giteletropical.com
 globaltask.ar
 glowinmedia.co.ke
@@ -4171,10 +4218,12 @@ goldcoastoffice365.com.au
 goldcupmortgage.com
 golden-memories-funerals.yourpageserver.com
 goldmen.in
+gorecycle.fahadjutt.com
 gracejukes.com
 grupoinmare.com
 gruposelt.000webhostapp.com
 gs.monerorx.com
+guide-to-cell-phones.com
 gulfac-house.com
 gvpcdpgc.edu.in
 habbotips.free.fr
@@ -4200,6 +4249,7 @@ hitstation.nl
 hmpmall.co.kr
 hoagietesting10.com
 hoayeuthuong-my.sharepoint.com
+holmesprpmgmt.com
 homefindersolutions.com
 hongluosi.com
 hookedupboatclub.com
@@ -4211,7 +4261,6 @@ hseda.com
 hsmwebapp.com
 htownbars.com
 hubtech.co.za
-huequito.evencsoft.co
 hunggiang.vn
 husamiyahschool.com
 iam313.com
@@ -4223,6 +4272,7 @@ idvindia.com
 iesanjosemonitos.edu.co
 ikexpert.com
 ilrafrica.com
+images.jermiau.com
 imbueautoworx.co.za
 imperiumtherapy.co.za
 in-tune2016.com
@@ -4237,6 +4287,7 @@ inodesthetotaldesigners.com
 inovations.searchkero.com
 inrajahmundry.co.in
 insignificantfinecore.testmail4.repl.co
+instantindialoan.com
 instvisionmexico.edu.mx
 intellectsmart.in
 intersel-idf.org
@@ -4247,6 +4298,7 @@ ipmes.ma
 iremart.es
 iris101.co.uk
 iscamenabe.com
+ismf.com.ng
 iso-dubai.net
 israrulhaq.me
 isrorg.com
@@ -4267,7 +4319,6 @@ jhayesconsulting.com
 jiaoyuzixun.cn
 jing-da.com.tw
 jktnet.xyz
-jmcomputacion.com.ar
 jmtc.91756.cn
 jnanbharati.com
 jobs.thebeessolution.com
@@ -4276,9 +4327,7 @@ join.cl8movement.co.za
 josegene.com
 josuarochoa.com
 jpwoodfordco.com
-julietlaser.site
 jumpmanualjacobhiller.com
-jumpnjamchicago.com
 jupiter.toxsl.in
 jurgensen.newreadermedia.net
 justinscott.com.au
@@ -4300,6 +4349,7 @@ kubatoglubaklava.com.tr
 kumaralok.in
 kwanfromhongkong.com
 kz.sldov.ru
+lab18.it
 lacasadelosalebrijes.com
 ladylabonde.com
 lameguard.ru
@@ -4345,6 +4395,7 @@ lp.definerisco.com
 lp.difusodesign.com
 lp.juancamilogarciareyes.com
 lp.tecnimasdecolombia.com.co
+ltc.typoten.com
 luckybrownie.com
 luminouspneuma.com
 luxomodels.com
@@ -4353,15 +4404,15 @@ m.estudiomoros.com.ar
 madicon.co.za
 magianegramagiablancayamarres.com
 mail.bs-eiendomme.co.za
+mail.golimoapp.com
 mail.jeffsono.org
 maksi.feb.unib.ac.id
 malaya.tv
 malwarecoding.github.io
 managed.oss-cn-beijing.aliyuncs.com
+managemysalon.in
 manantialesdelnorte.uy
-manivelasst.com
 marcapinyo.ru
-marcusthepoet.com
 mario-sunjic.com
 mariobrown.net
 mariotessarollo.com
@@ -4370,7 +4421,6 @@ marketing.enexusgroup.com.au
 marksidfgs.ug
 masjidhabeebiyarazviya.mysunni.com
 materialescantu.com
-matinal-nominal.pt
 matruchhaya.co.in
 mattysplayground.com
 maxtox.com.pk
@@ -4382,6 +4432,7 @@ media-server.skyinternet.com.pk
 mediamaster.co.za
 medianews.ge
 medistaffconsulting.com
+meditreat.itwebservice.in
 meeweb.com
 megamart.afnan-amc.com
 merbay.ru
@@ -4402,7 +4453,6 @@ midlandtexasconstruction.com
 mindfulbuildingandliving.com
 mingguanwms.com
 minuevavida.org
-mirror.mypage.sk
 mis.nbcc.ac.th
 misterson.com
 mixr.at
@@ -4410,12 +4460,14 @@ mkontakt.az
 mktf.mx
 mmogollon.com.mx
 mncarteam.com
+mobile.illumetechnology.com
 modelhouseturkey.com
 modernmanna.org
 monetization.business
 moninediy.com
 mopai.sg
 motorcomunicacion.com
+msacontabil.com.br
 mtspsmjeli.sch.id
 muzimbiti.xigubo.co.mz
 mxpiqw.am.files.1drv.com
@@ -4448,8 +4500,8 @@ nhorangtreem.com
 nicolas.ug
 nidhi.iexist.in
 nikanpolimer.ir
+nilehouse.co.ug
 nilinkeji.com
-nisacooks.com
 njtiledesigncenter.com
 nobius.org
 nocalnoodle.elin.co.za
@@ -4467,10 +4519,13 @@ nyeh2o.com.au
 oakleyandfriends.co.uk
 obseques-conseils.com
 ocean.tecnasulstore.com.br
+ohe.ie
 ohsewgorgeous.co.uk
+oknoplastik.sk
 oleholeh.memangbeda.website
 olirecords.mixture.ltd
 olooom.com
+omaia.org
 omaromatic.com
 omega.az
 oms.pappai.com
@@ -4479,6 +4534,7 @@ onedigitalcard.granvizionnecorp.com
 onedrive.listifyapp.co
 online.creedglobal.in
 onlinestatis.bar
+ont.proman.id
 open.warehousesaas.co.uk
 opolis.io
 optimus.com.sg
@@ -4486,6 +4542,8 @@ optitechsa.co.za
 order.bizpeed.com
 orientgatewayltd.com
 orion445.com
+oserve.pk
+otolithenrichment.fahadjutt.com
 ottimade.com
 ourteam.searchkero.com
 ozemag.com
@@ -4507,6 +4565,7 @@ patch3.99ddd.com
 paths.elin.co.za
 paulmercier.biz
 payerrealty.com
+payments.atifsiddiqui.me
 pcsoori.com
 pd.oceaniarp.net
 perpus.onlineman7-jombang.sch.id
@@ -4519,6 +4578,7 @@ phittc.com
 photo360.kubooking.com
 photographytipsclub.com
 pink99.com
+pizzabarletta.com.br
 plasfan.ind.br
 pmglance.startwriteup.com
 pokojewewladyslawowie.pl
@@ -4528,15 +4588,13 @@ pooltablemoversdenver.net
 posmicrosystems.com
 poulman.panagiotopoulos-tours.gr
 ppdb.smk-ciptaskill.sch.id
-pptvideotemplates.com
 prestasicash.com.ar
 prestigehomeautomation.net
 prishaartcreations.com
 production.sparshims.com
-productprecise.com
-prof-dr-ahmedalmoatasem.com
 programaoperadoronline.com.br
 project.exquitec.com
+promolyko.com
 promotoradescomplica.com.br
 promoversdubai.com
 propertiq.elin.co.za
@@ -4549,7 +4607,7 @@ prueba.danielluza.com
 pujashoppe.in
 punchdialogues.com
 punjabdevelopersassociation.com.pk
-purefoe.top
+pvcprinting.co.uk
 qadir.tickfa.ir
 qatarglobalconsulting.com
 qmsled.com
@@ -4565,7 +4623,6 @@ ratemyfenancialadvisor.com
 ravenproductionsltd.com
 rc.ixiaoyang.cn
 readymmade.com
-realtheprocess.co
 redchillicrackers.com
 reifenquick.de
 relaxindulge.co.nz
@@ -4615,7 +4672,6 @@ santyago.org
 sarakem.cl
 sasystemsuk.com
 savasaachi.systems
-savingchintu.com
 scarfaceindustries.com
 scglobal.co.th
 schalke04rss.de
@@ -4623,10 +4679,8 @@ scheff.com
 schoolbustracker.softgig.co.ke
 sec-doc-w.com
 secure-doc-reader.com
-sefp-boispro.fr
 segalsmetals.elin.co.za
 sellmyphonela.com
-selltechtoday.com
 senbiaojita.com
 sentierodelviandante.ml
 serendibsourcing.com
@@ -4643,7 +4697,6 @@ shembefoundation.com
 shivakunwar.com.np
 shoblasaathitrust.org
 shooka-co.com
-shop.clarostudio.ro
 shop.goldspot.agency
 shopsofe.com
 shrushtiinfotech.com
@@ -4655,11 +4708,11 @@ siili.net
 simoneporzi.it
 simplithy.co.uk
 sindicato1ucm.cl
+sindpol.tiejuris.com.br
 sinergidwireka.com
 sipahielektrik.com
 siperb.in
 sistelligent.com
-site.sjc.co.ke
 skkksolo.beweiretail.com
 skyflyfares.com
 skyscan.com
@@ -4669,7 +4722,6 @@ smartzedu.com
 smokeandgrowrichtour.com
 smokesolutionindia.com
 sobethuacademy.com
-soft.110route.com
 soft.officelabo.net
 sohs.conceptechs.info
 solar.amazingtribe.lk
@@ -4678,11 +4730,11 @@ somcorbera.cat
 somir.com.mx
 soralapps.com
 sorteio.orgaostalita.com.br
+sosgsm.fr
 sota-france.fr
 sowingminerals.cl
 space.proactint.org
 spaceframe.mobi.space-frame.co.za
-specfloors.net
 special-key.cf
 spent.com.pl
 spetsesyachtcharter.gr
@@ -4714,6 +4766,7 @@ supermercadostia.com
 support-4-free.com
 support.clz.kr
 supportit.online
+surestdysbonescagexc.dns.army
 sw.yourpageserver.com
 sweaty.dk
 sweet-diet.com
@@ -4739,11 +4792,11 @@ taxpos.com
 tc.snpsresidential.com
 tcy.198424.com
 tdsp.yngw518.com
-tech332.synology.me
 techgms.com
 technogreen.crmmanivela.com
 technohub.searchkero.com
 tecnicaencolectores.com.mx
+tecnologyschool.com
 teduae.com
 teleargentina.com
 telescopelms.com
@@ -4751,9 +4804,9 @@ telmed.cl
 temptmag.com
 tennisafrica.com
 tentandoserfitness.000webhostapp.com
-tepresto.net.pe
 test.adventser.com
 test.letraele.es
+test.typoten.com
 test.wanepghana.org
 test1.asistencia247.com
 test1.milenial.id
@@ -4766,9 +4819,7 @@ testnew.yourpageserver.com
 teteaffiche.stephanebillon.com
 tewoerd.eu
 textile.softberg.ro
-texts.bfftexts.com
 texturesbyvinita.com
-tharringtonsponsorship.com
 thecleaningladiespdx.com
 thecreativecafe.co.uk
 thefuturelife.in
@@ -4776,12 +4827,11 @@ thehighlightinterior.com
 thehouseofpragya.com
 thekassia.co.uk
 thelaunchpadteam.com
-thelekhak.com
 thelogicalgroup.co.uk
 thesummitpc.net
 theurbantutors.com
+thewwpc.com
 thosewebbs.com
-thriveink.com
 tianangdep.com
 tickfood.tickme.lk
 tickjobs.tickme.lk
@@ -4814,7 +4864,6 @@ tsd.jxwan.com
 tulli.info
 tupperware.michaelroberge.ca
 turanggaresources.com
-tushartyagiji.digitalswagger.in
 uat.indianfilmzone.com
 ublretailerdemo.cstdevs.com
 udesk.searchkero.com
@@ -4824,7 +4873,6 @@ umwelt-kirchhof.de
 unicorpbrunei.com
 uniengrisb.com
 unisoftcc.com
-unitedpestsolutionstx.com
 unyazitelecom.com
 upcbpta.com
 urbane.dezinetimes.com
@@ -4851,17 +4899,18 @@ vitoriamodaintima.com.br
 vivationdesign.com
 viveirodoiscorregos.com.br
 vksales.com
+vladimirinternational.com
 vokasi.ub.ac.id
 vologroup.com.br
 voteyouramerica.dekitout.com
 vstsample.com
 vtube.fadlymotivator.com
 vvsskmodinationalschool.com
-wahrewah.nl
 wanepliberia.org
 wanepniger.org
 weareactum.com
 web.eng.ubu.ac.th
+web.geetle.ga
 web.geomegasoft.net
 web.newinnovationtechnology.com
 web.smarts-works.com
@@ -4875,13 +4924,12 @@ wexfashion.com
 whcms.yourpageserver.com
 whiteglovetailgate.com
 whiteresponse.com
+whynt.xyz
 wi522012.ferozo.com
 wikalen.co.za
 wildnights.co.uk
 wildtrust.mediadevstaging.com
 wimbamusica.com
-windcomtechnologies.com
-winnercircle.it
 wishesconcierge.com
 woezon.agency
 wolfgang-brodte.de
@@ -4897,7 +4945,6 @@ x2vn.com
 xia.beihaixue.com
 xixaoclothing.com
 xk.996is.com
-xmp.myracingaccounts.com
 xn--80akinnkiib6h.xn--90ais
 xn--polimerbizmimarlk-rvc.com
 ybom.urbanolab.com
@@ -4908,5 +4955,6 @@ youtubetrainingacademy.com
 yskadvisors.com
 yummyyogaudaipur.com
 yzkzixun.com
+zakra.tecnasulstore.com.br
 zytrox.tk
 zz.690tx.com
diff --git a/urlhaus-filter-domains.txt b/urlhaus-filter-domains.txt
index 67cfa0ed..a3d55739 100644
--- a/urlhaus-filter-domains.txt
+++ b/urlhaus-filter-domains.txt
@@ -1,5 +1,5 @@
 # Title: Malicious Domains Blocklist
-# Updated: Thu, 25 Mar 2021 12:12:40 UTC
+# Updated: Fri, 26 Mar 2021 00:12:29 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -1024,6 +1024,7 @@
 1.58.206.122
 1.58.206.199
 1.58.220.198
+1.58.223.96
 1.58.50.67
 1.59.181.177
 1.59.249.83
@@ -3600,6 +3601,7 @@
 103.217.116.166
 103.217.116.245
 103.217.117.108
+103.217.117.134
 103.217.119.74
 103.217.119.75
 103.217.119.76
@@ -3670,6 +3672,7 @@
 103.217.121.228
 103.217.121.23
 103.217.121.231
+103.217.121.234
 103.217.121.237
 103.217.121.238
 103.217.121.239
@@ -3735,6 +3738,7 @@
 103.217.123.2
 103.217.123.200
 103.217.123.204
+103.217.123.210
 103.217.123.213
 103.217.123.216
 103.217.123.218
@@ -5207,6 +5211,7 @@
 103.78.183.4
 103.78.183.40
 103.78.21.238
+103.78.22.157
 103.78.22.177
 103.78.22.207
 103.78.22.219
@@ -6684,6 +6689,7 @@
 104.168.151.198
 104.168.152.230
 104.168.157.45
+104.168.158.127
 104.168.158.148
 104.168.158.248
 104.168.158.38
@@ -6778,6 +6784,7 @@
 104.168.96.11
 104.168.96.168
 104.168.96.194
+104.168.98.105
 104.168.98.206
 104.168.99.220
 104.168.99.30
@@ -8390,6 +8397,7 @@
 106.36.159.125
 106.36.4.112
 106.37.121.250
+106.4.138.95
 106.4.140.29
 106.4.209.123
 106.4.241.59
@@ -10193,6 +10201,7 @@
 110.244.46.196
 110.244.48.104
 110.244.51.22
+110.247.151.4
 110.247.16.153
 110.247.16.64
 110.247.180.69
@@ -10817,6 +10826,7 @@
 111.165.186.127
 111.165.202.37
 111.165.207.179
+111.165.21.195
 111.165.210.227
 111.165.210.249
 111.165.214.179
@@ -10849,6 +10859,7 @@
 111.165.255.240
 111.165.26.73
 111.165.27.112
+111.165.28.234
 111.165.31.62
 111.165.33.132
 111.165.33.210
@@ -16984,6 +16995,7 @@
 112.246.18.70
 112.246.18.84
 112.246.18.99
+112.246.180.49
 112.246.181.139
 112.246.184.252
 112.246.184.97
@@ -17234,6 +17246,7 @@
 112.247.247.234
 112.247.248.114
 112.247.248.14
+112.247.248.76
 112.247.249.198
 112.247.249.82
 112.247.250.193
@@ -17921,6 +17934,7 @@
 112.249.205.67
 112.249.206.105
 112.249.206.52
+112.249.206.69
 112.249.206.8
 112.249.207.154
 112.249.207.198
@@ -18284,6 +18298,7 @@
 112.249.78.69
 112.249.79.230
 112.249.79.88
+112.249.79.98
 112.249.80.217
 112.249.80.53
 112.249.80.69
@@ -18566,6 +18581,7 @@
 112.252.41.80
 112.252.42.128
 112.252.43.218
+112.252.46.212
 112.252.59.78
 112.252.66.17
 112.252.66.55
@@ -20163,6 +20179,7 @@
 112.93.7.60
 112.93.89.37
 112.94.188.182
+112.94.188.230
 112.94.189.107
 112.95.12.157
 112.95.13.15
@@ -20528,6 +20545,7 @@
 113.104.237.236
 113.104.237.34
 113.104.237.36
+113.104.237.52
 113.104.237.72
 113.104.237.74
 113.104.237.83
@@ -21249,6 +21267,7 @@
 113.116.150.101
 113.116.150.110
 113.116.150.144
+113.116.150.147
 113.116.150.161
 113.116.150.176
 113.116.150.180
@@ -22454,6 +22473,7 @@
 113.118.13.222
 113.118.13.226
 113.118.13.26
+113.118.13.29
 113.118.13.44
 113.118.13.47
 113.118.13.50
@@ -23960,6 +23980,7 @@
 113.201.24.202
 113.201.24.206
 113.201.24.24
+113.201.24.26
 113.201.24.30
 113.201.24.4
 113.201.24.5
@@ -24401,6 +24422,7 @@
 113.234.185.255
 113.234.195.226
 113.234.197.125
+113.234.224.130
 113.234.224.160
 113.234.231.172
 113.234.231.202
@@ -25300,6 +25322,7 @@
 113.81.112.13
 113.81.112.159
 113.81.112.228
+113.81.112.35
 113.81.112.66
 113.81.112.72
 113.81.113.119
@@ -25821,6 +25844,7 @@
 113.87.248.159
 113.87.248.162
 113.87.248.163
+113.87.248.177
 113.87.248.181
 113.87.248.206
 113.87.248.28
@@ -26007,6 +26031,7 @@
 113.88.1.69
 113.88.100.105
 113.88.100.117
+113.88.100.120
 113.88.100.130
 113.88.100.160
 113.88.100.172
@@ -26632,6 +26657,7 @@
 113.88.241.9
 113.88.241.92
 113.88.241.98
+113.88.242.0
 113.88.242.1
 113.88.242.10
 113.88.242.116
@@ -26960,6 +26986,7 @@
 113.89.244.91
 113.89.244.93
 113.89.245.118
+113.89.245.13
 113.89.245.132
 113.89.245.144
 113.89.245.174
@@ -29688,6 +29715,7 @@
 115.171.238.92
 115.171.239.20
 115.171.239.25
+115.171.239.28
 115.171.90.159
 115.171.91.155
 115.171.91.195
@@ -29859,6 +29887,7 @@
 115.201.37.74
 115.201.37.84
 115.201.37.88
+115.201.38.185
 115.201.40.156
 115.201.40.65
 115.201.40.66
@@ -29932,6 +29961,7 @@
 115.202.187.124
 115.202.187.242
 115.202.187.61
+115.202.188.84
 115.202.210.224
 115.202.210.228
 115.202.214.217
@@ -30260,6 +30290,7 @@
 115.213.176.80
 115.213.186.121
 115.213.186.152
+115.213.187.251
 115.213.188.167
 115.213.198.25
 115.213.199.79
@@ -30753,6 +30784,7 @@
 115.48.130.177
 115.48.130.181
 115.48.130.184
+115.48.130.187
 115.48.130.193
 115.48.130.196
 115.48.130.197
@@ -30916,6 +30948,7 @@
 115.48.135.123
 115.48.135.126
 115.48.135.150
+115.48.135.151
 115.48.135.152
 115.48.135.154
 115.48.135.155
@@ -32470,6 +32503,7 @@
 115.48.200.103
 115.48.200.104
 115.48.200.114
+115.48.200.115
 115.48.200.124
 115.48.200.126
 115.48.200.134
@@ -33717,6 +33751,7 @@
 115.49.113.126
 115.49.113.59
 115.49.116.148
+115.49.116.237
 115.49.118.13
 115.49.12.164
 115.49.12.26
@@ -33834,6 +33869,7 @@
 115.49.150.203
 115.49.150.86
 115.49.151.207
+115.49.152.10
 115.49.152.116
 115.49.152.140
 115.49.152.89
@@ -34328,6 +34364,7 @@
 115.49.241.61
 115.49.241.87
 115.49.241.94
+115.49.242.100
 115.49.242.17
 115.49.242.79
 115.49.242.91
@@ -35160,6 +35197,7 @@
 115.49.79.87
 115.49.79.98
 115.49.8.244
+115.49.80.117
 115.49.80.149
 115.49.80.161
 115.49.80.74
@@ -37025,6 +37063,7 @@
 115.50.201.85
 115.50.201.87
 115.50.201.91
+115.50.202.11
 115.50.202.13
 115.50.202.131
 115.50.202.157
@@ -38459,6 +38498,7 @@
 115.50.240.216
 115.50.240.220
 115.50.240.228
+115.50.240.230
 115.50.240.237
 115.50.240.252
 115.50.240.27
@@ -39875,6 +39915,7 @@
 115.50.61.228
 115.50.61.23
 115.50.61.233
+115.50.61.247
 115.50.61.25
 115.50.61.252
 115.50.61.254
@@ -40007,6 +40048,7 @@
 115.50.64.177
 115.50.64.178
 115.50.64.179
+115.50.64.182
 115.50.64.189
 115.50.64.212
 115.50.64.229
@@ -41126,6 +41168,7 @@
 115.51.107.156
 115.51.107.163
 115.51.107.164
+115.51.107.18
 115.51.107.183
 115.51.107.193
 115.51.107.195
@@ -42443,6 +42486,7 @@
 115.52.20.97
 115.52.200.245
 115.52.201.220
+115.52.201.231
 115.52.201.254
 115.52.202.73
 115.52.204.80
@@ -42486,6 +42530,7 @@
 115.52.22.140
 115.52.22.145
 115.52.22.149
+115.52.22.162
 115.52.22.166
 115.52.22.177
 115.52.22.19
@@ -42742,6 +42787,7 @@
 115.52.35.151
 115.52.35.6
 115.52.36.27
+115.52.37.164
 115.52.38.110
 115.52.38.132
 115.52.38.182
@@ -43946,6 +43992,7 @@
 115.54.159.16
 115.54.159.206
 115.54.159.33
+115.54.160.25
 115.54.168.18
 115.54.168.190
 115.54.168.237
@@ -44732,6 +44779,7 @@
 115.54.212.205
 115.54.212.207
 115.54.212.22
+115.54.212.227
 115.54.212.233
 115.54.212.239
 115.54.212.249
@@ -45045,6 +45093,7 @@
 115.54.240.128
 115.54.240.166
 115.54.240.170
+115.54.240.173
 115.54.240.195
 115.54.240.197
 115.54.240.198
@@ -45220,6 +45269,7 @@
 115.54.69.60
 115.54.69.89
 115.54.69.9
+115.54.70.108
 115.54.70.139
 115.54.70.150
 115.54.70.161
@@ -45266,6 +45316,7 @@
 115.54.73.254
 115.54.73.37
 115.54.73.42
+115.54.73.50
 115.54.73.51
 115.54.74.109
 115.54.74.142
@@ -48107,6 +48158,7 @@
 115.55.211.247
 115.55.211.251
 115.55.211.4
+115.55.211.41
 115.55.211.48
 115.55.211.54
 115.55.211.75
@@ -48509,6 +48561,7 @@
 115.55.3.155
 115.55.3.20
 115.55.3.204
+115.55.3.36
 115.55.3.54
 115.55.30.105
 115.55.30.138
@@ -49825,6 +49878,7 @@
 115.56.136.124
 115.56.136.127
 115.56.136.141
+115.56.136.144
 115.56.136.145
 115.56.136.146
 115.56.136.154
@@ -50715,6 +50769,7 @@
 115.56.154.14
 115.56.154.142
 115.56.154.145
+115.56.154.147
 115.56.154.164
 115.56.154.17
 115.56.154.173
@@ -50832,6 +50887,7 @@
 115.56.156.30
 115.56.156.39
 115.56.156.53
+115.56.156.54
 115.56.156.55
 115.56.156.6
 115.56.156.62
@@ -51162,6 +51218,7 @@
 115.56.177.192
 115.56.177.198
 115.56.177.2
+115.56.177.202
 115.56.177.205
 115.56.177.214
 115.56.177.220
@@ -52962,6 +53019,7 @@
 115.58.132.194
 115.58.132.196
 115.58.132.197
+115.58.132.199
 115.58.132.2
 115.58.132.205
 115.58.132.211
@@ -53607,6 +53665,7 @@
 115.58.167.23
 115.58.167.50
 115.58.167.78
+115.58.167.90
 115.58.168.104
 115.58.168.117
 115.58.168.14
@@ -53746,6 +53805,7 @@
 115.58.20.147
 115.58.20.152
 115.58.20.180
+115.58.20.186
 115.58.20.193
 115.58.20.197
 115.58.20.199
@@ -55039,6 +55099,7 @@
 115.59.198.181
 115.59.198.184
 115.59.198.194
+115.59.198.200
 115.59.198.211
 115.59.198.215
 115.59.198.218
@@ -55590,6 +55651,7 @@
 115.59.215.74
 115.59.215.8
 115.59.215.95
+115.59.215.96
 115.59.215.99
 115.59.216.103
 115.59.216.106
@@ -57072,6 +57134,7 @@
 115.59.90.149
 115.59.90.155
 115.59.90.182
+115.59.90.197
 115.59.90.204
 115.59.90.22
 115.59.90.236
@@ -57194,6 +57257,7 @@
 115.60.201.105
 115.60.201.142
 115.60.201.144
+115.60.201.176
 115.60.201.181
 115.60.201.186
 115.60.201.21
@@ -57841,6 +57905,7 @@
 115.61.118.182
 115.61.118.185
 115.61.118.189
+115.61.118.201
 115.61.118.210
 115.61.118.226
 115.61.118.245
@@ -59520,6 +59585,7 @@
 115.61.97.250
 115.61.97.39
 115.61.97.46
+115.61.97.55
 115.61.97.63
 115.61.97.65
 115.61.97.70
@@ -59752,6 +59818,7 @@
 115.62.152.143
 115.62.152.144
 115.62.152.206
+115.62.152.207
 115.62.152.37
 115.62.152.55
 115.62.152.70
@@ -60266,6 +60333,7 @@
 115.63.130.140
 115.63.130.150
 115.63.130.161
+115.63.130.162
 115.63.130.169
 115.63.130.170
 115.63.130.173
@@ -60566,6 +60634,7 @@
 115.63.140.216
 115.63.140.218
 115.63.140.236
+115.63.140.242
 115.63.140.27
 115.63.140.32
 115.63.140.39
@@ -66909,6 +66978,7 @@
 115.96.87.95
 115.96.88.171
 115.96.90.226
+115.96.92.151
 115.96.94.114
 115.97.102.100
 115.97.102.102
@@ -68385,6 +68455,7 @@
 115.97.142.175
 115.97.142.176
 115.97.142.178
+115.97.142.18
 115.97.142.180
 115.97.142.182
 115.97.142.188
@@ -91410,6 +91481,7 @@
 116.24.152.157
 116.24.152.158
 116.24.152.164
+116.24.152.217
 116.24.152.245
 116.24.152.34
 116.24.152.80
@@ -94036,6 +94108,7 @@
 116.72.202.80
 116.72.202.81
 116.72.202.83
+116.72.202.87
 116.72.202.89
 116.72.202.90
 116.72.202.92
@@ -94077,6 +94150,7 @@
 116.72.203.14
 116.72.203.141
 116.72.203.142
+116.72.203.143
 116.72.203.145
 116.72.203.146
 116.72.203.148
@@ -102333,6 +102407,7 @@
 116.74.83.90
 116.74.83.94
 116.74.83.98
+116.74.84.65
 116.74.85.1
 116.74.85.131
 116.74.87.107
@@ -105657,6 +105732,7 @@
 116.75.194.137
 116.75.194.138
 116.75.194.139
+116.75.194.14
 116.75.194.140
 116.75.194.141
 116.75.194.143
@@ -107851,6 +107927,7 @@
 116.75.214.51
 116.75.214.52
 116.75.214.53
+116.75.214.56
 116.75.214.58
 116.75.214.59
 116.75.214.6
@@ -107880,6 +107957,7 @@
 116.75.214.96
 116.75.214.97
 116.75.214.98
+116.75.214.99
 116.75.215.0
 116.75.215.1
 116.75.215.100
@@ -112646,6 +112724,7 @@
 117.194.149.247
 117.194.149.250
 117.194.149.252
+117.194.149.26
 117.194.149.28
 117.194.149.33
 117.194.149.37
@@ -112990,6 +113069,7 @@
 117.194.160.8
 117.194.160.81
 117.194.160.83
+117.194.160.84
 117.194.160.85
 117.194.160.87
 117.194.160.88
@@ -116423,6 +116503,7 @@
 117.202.70.224
 117.202.70.225
 117.202.70.226
+117.202.70.227
 117.202.70.228
 117.202.70.229
 117.202.70.23
@@ -118621,6 +118702,7 @@
 117.213.11.106
 117.213.11.136
 117.213.11.205
+117.213.11.225
 117.213.11.47
 117.213.11.50
 117.213.11.8
@@ -119040,6 +119122,7 @@
 117.213.42.153
 117.213.42.154
 117.213.42.157
+117.213.42.158
 117.213.42.159
 117.213.42.16
 117.213.42.160
@@ -120079,6 +120162,7 @@
 117.213.9.58
 117.213.9.71
 117.213.9.77
+117.213.9.78
 117.214.11.249
 117.214.11.8
 117.214.242.73
@@ -120376,6 +120460,7 @@
 117.215.248.208
 117.215.248.214
 117.215.248.217
+117.215.248.223
 117.215.248.23
 117.215.248.237
 117.215.248.242
@@ -120414,6 +120499,7 @@
 117.215.249.20
 117.215.249.22
 117.215.249.221
+117.215.249.23
 117.215.249.230
 117.215.249.240
 117.215.249.241
@@ -121001,6 +121087,7 @@
 117.222.161.65
 117.222.161.66
 117.222.161.67
+117.222.161.68
 117.222.161.7
 117.222.161.70
 117.222.161.74
@@ -121269,6 +121356,7 @@
 117.222.163.148
 117.222.163.149
 117.222.163.15
+117.222.163.150
 117.222.163.151
 117.222.163.153
 117.222.163.154
@@ -121395,6 +121483,7 @@
 117.222.163.59
 117.222.163.6
 117.222.163.60
+117.222.163.61
 117.222.163.62
 117.222.163.63
 117.222.163.65
@@ -121406,6 +121495,7 @@
 117.222.163.70
 117.222.163.71
 117.222.163.72
+117.222.163.73
 117.222.163.74
 117.222.163.77
 117.222.163.78
@@ -121773,6 +121863,7 @@
 117.222.165.28
 117.222.165.29
 117.222.165.3
+117.222.165.31
 117.222.165.32
 117.222.165.33
 117.222.165.34
@@ -122220,6 +122311,7 @@
 117.222.168.114
 117.222.168.115
 117.222.168.116
+117.222.168.119
 117.222.168.122
 117.222.168.123
 117.222.168.124
@@ -122240,6 +122332,7 @@
 117.222.168.181
 117.222.168.183
 117.222.168.185
+117.222.168.186
 117.222.168.191
 117.222.168.194
 117.222.168.195
@@ -122306,6 +122399,7 @@
 117.222.169.112
 117.222.169.113
 117.222.169.114
+117.222.169.115
 117.222.169.117
 117.222.169.12
 117.222.169.124
@@ -122521,6 +122615,7 @@
 117.222.171.192
 117.222.171.202
 117.222.171.203
+117.222.171.205
 117.222.171.209
 117.222.171.217
 117.222.171.218
@@ -122669,6 +122764,7 @@
 117.222.172.9
 117.222.172.92
 117.222.172.94
+117.222.172.97
 117.222.172.98
 117.222.173.10
 117.222.173.100
@@ -124123,6 +124219,7 @@
 117.242.210.65
 117.242.210.67
 117.242.210.68
+117.242.210.69
 117.242.210.7
 117.242.210.70
 117.242.210.71
@@ -124671,6 +124768,7 @@
 117.247.200.169
 117.247.200.170
 117.247.200.172
+117.247.200.179
 117.247.200.181
 117.247.200.182
 117.247.200.185
@@ -124749,6 +124847,7 @@
 117.247.201.156
 117.247.201.158
 117.247.201.161
+117.247.201.163
 117.247.201.172
 117.247.201.175
 117.247.201.179
@@ -124870,6 +124969,7 @@
 117.247.202.31
 117.247.202.32
 117.247.202.37
+117.247.202.4
 117.247.202.46
 117.247.202.48
 117.247.202.50
@@ -124971,6 +125071,7 @@
 117.247.203.3
 117.247.203.31
 117.247.203.33
+117.247.203.38
 117.247.203.39
 117.247.203.40
 117.247.203.45
@@ -126644,6 +126745,7 @@
 117.251.59.232
 117.251.59.237
 117.251.59.24
+117.251.59.242
 117.251.59.243
 117.251.59.244
 117.251.59.246
@@ -127506,6 +127608,7 @@
 117.63.51.128
 117.63.53.15
 117.63.53.172
+117.63.56.81
 117.63.69.253
 117.63.7.177
 117.63.7.192
@@ -127569,6 +127672,7 @@
 117.85.89.213
 117.85.95.220
 117.86.1.7
+117.86.105.110
 117.86.110.91
 117.86.148.199
 117.86.155.77
@@ -127807,6 +127911,7 @@
 117.91.156.66
 117.91.172.11
 117.91.172.49
+117.91.240.50
 117.91.241.17
 117.92.177.76
 117.92.196.126
@@ -129135,6 +129240,7 @@
 118.75.114.227
 118.75.115.154
 118.75.119.214
+118.75.120.136
 118.75.120.209
 118.75.120.229
 118.75.120.98
@@ -129263,6 +129369,7 @@
 118.75.236.238
 118.75.239.142
 118.75.240.141
+118.75.240.239
 118.75.240.9
 118.75.241.204
 118.75.241.26
@@ -129574,6 +129681,7 @@
 118.79.163.61
 118.79.163.86
 118.79.163.91
+118.79.164.102
 118.79.164.108
 118.79.167.240
 118.79.167.41
@@ -130606,6 +130714,7 @@
 119.123.175.124
 119.123.175.126
 119.123.175.128
+119.123.175.133
 119.123.175.139
 119.123.175.144
 119.123.175.145
@@ -131796,6 +131905,7 @@
 119.165.207.118
 119.165.208.188
 119.165.208.216
+119.165.208.73
 119.165.209.0
 119.165.209.121
 119.165.209.127
@@ -132946,6 +133056,7 @@
 119.179.42.247
 119.179.43.1
 119.179.43.27
+119.179.44.141
 119.179.44.157
 119.179.44.192
 119.179.45.108
@@ -133421,6 +133532,7 @@
 119.180.9.183
 119.180.9.209
 119.180.9.241
+119.180.9.35
 119.180.90.121
 119.180.92.176
 119.180.92.224
@@ -135245,6 +135357,7 @@
 119.250.10.222
 119.250.117.131
 119.250.119.227
+119.250.129.231
 119.250.132.83
 119.250.166.153
 119.250.218.177
@@ -135771,6 +135884,7 @@
 120.12.211.237
 120.12.212.231
 120.12.212.234
+120.12.212.5
 120.12.213.82
 120.12.217.158
 120.12.217.9
@@ -136956,6 +137070,7 @@
 120.57.102.243
 120.57.102.246
 120.57.102.254
+120.57.102.32
 120.57.102.46
 120.57.102.5
 120.57.102.58
@@ -139438,6 +139553,7 @@
 120.82.169.73
 120.82.170.40
 120.82.170.75
+120.82.217.176
 120.82.217.197
 120.82.228.185
 120.82.38.219
@@ -139761,6 +139877,7 @@
 120.85.173.121
 120.85.173.126
 120.85.173.135
+120.85.173.137
 120.85.173.143
 120.85.173.145
 120.85.173.149
@@ -139806,6 +139923,7 @@
 120.85.174.24
 120.85.174.30
 120.85.174.38
+120.85.174.39
 120.85.174.41
 120.85.174.42
 120.85.174.45
@@ -140062,6 +140180,7 @@
 120.85.199.184
 120.85.199.19
 120.85.199.195
+120.85.199.222
 120.85.199.242
 120.85.199.247
 120.85.199.253
@@ -140183,6 +140302,7 @@
 120.85.211.82
 120.85.211.84
 120.85.211.85
+120.85.212.45
 120.85.232.107
 120.85.232.64
 120.85.234.15
@@ -140282,6 +140402,7 @@
 120.85.238.80
 120.85.238.87
 120.85.238.89
+120.85.238.97
 120.85.239.100
 120.85.239.11
 120.85.239.113
@@ -140698,6 +140819,7 @@
 121.154.163.88
 121.154.190.19
 121.154.190.232
+121.154.190.73
 121.154.226.39
 121.154.37.14
 121.154.39.26
@@ -141693,6 +141815,7 @@
 121.34.150.234
 121.34.150.251
 121.34.150.27
+121.34.150.32
 121.34.150.36
 121.34.150.43
 121.34.150.45
@@ -142486,6 +142609,7 @@
 122.188.61.157
 122.188.61.231
 122.188.61.239
+122.188.86.225
 122.189.101.23
 122.189.105.132
 122.189.105.250
@@ -142495,6 +142619,7 @@
 122.189.7.14
 122.190.115.86
 122.190.19.131
+122.190.19.204
 122.190.192.182
 122.190.192.92
 122.190.244.85
@@ -143088,6 +143213,7 @@
 123.10.131.179
 123.10.131.204
 123.10.131.223
+123.10.131.225
 123.10.131.245
 123.10.131.251
 123.10.131.47
@@ -143750,6 +143876,7 @@
 123.10.209.61
 123.10.209.65
 123.10.209.87
+123.10.209.95
 123.10.21.116
 123.10.21.172
 123.10.21.184
@@ -143794,6 +143921,7 @@
 123.10.214.114
 123.10.214.129
 123.10.214.174
+123.10.214.193
 123.10.214.25
 123.10.214.60
 123.10.214.75
@@ -144547,6 +144675,7 @@
 123.10.82.119
 123.10.82.192
 123.10.82.228
+123.10.83.136
 123.10.84.166
 123.10.84.18
 123.10.84.187
@@ -145331,6 +145460,7 @@
 123.11.174.47
 123.11.174.61
 123.11.175.108
+123.11.175.136
 123.11.175.190
 123.11.175.197
 123.11.175.227
@@ -147111,6 +147241,7 @@
 123.12.229.211
 123.12.229.232
 123.12.229.24
+123.12.229.243
 123.12.229.25
 123.12.229.252
 123.12.229.253
@@ -147528,6 +147659,7 @@
 123.12.35.198
 123.12.35.29
 123.12.36.167
+123.12.36.185
 123.12.36.193
 123.12.36.3
 123.12.36.54
@@ -148136,6 +148268,7 @@
 123.13.100.254
 123.13.101.202
 123.13.101.30
+123.13.101.56
 123.13.102.179
 123.13.102.204
 123.13.102.205
@@ -148442,6 +148575,7 @@
 123.13.30.167
 123.13.30.2
 123.13.30.219
+123.13.30.75
 123.13.31.104
 123.13.31.144
 123.13.31.175
@@ -150448,6 +150582,7 @@
 123.14.205.198
 123.14.205.212
 123.14.205.223
+123.14.205.23
 123.14.205.236
 123.14.205.241
 123.14.205.246
@@ -152259,6 +152394,7 @@
 123.183.123.153
 123.183.123.187
 123.183.123.212
+123.183.123.41
 123.183.123.5
 123.183.124.131
 123.183.124.18
@@ -153690,6 +153826,7 @@
 123.4.179.75
 123.4.179.8
 123.4.179.82
+123.4.180.137
 123.4.180.152
 123.4.180.156
 123.4.180.171
@@ -153737,6 +153874,7 @@
 123.4.184.8
 123.4.185.112
 123.4.185.12
+123.4.185.137
 123.4.185.14
 123.4.185.168
 123.4.185.220
@@ -156552,6 +156690,7 @@
 123.5.145.23
 123.5.145.233
 123.5.145.242
+123.5.145.245
 123.5.145.248
 123.5.145.42
 123.5.145.55
@@ -157748,6 +157887,7 @@
 123.5.22.110
 123.5.22.175
 123.5.22.210
+123.5.22.220
 123.5.22.221
 123.5.22.238
 123.5.22.49
@@ -158426,6 +158566,7 @@
 123.8.183.124
 123.8.183.145
 123.8.183.185
+123.8.183.194
 123.8.183.207
 123.8.183.31
 123.8.183.46
@@ -159422,6 +159563,7 @@
 123.9.103.190
 123.9.103.200
 123.9.103.23
+123.9.103.252
 123.9.103.36
 123.9.103.53
 123.9.103.61
@@ -161542,6 +161684,7 @@
 124.130.31.18
 124.130.40.15
 124.130.40.162
+124.130.40.31
 124.130.56.200
 124.130.56.42
 124.130.57.12
@@ -162185,6 +162328,7 @@
 124.131.24.86
 124.131.25.69
 124.131.26.238
+124.131.26.243
 124.131.26.78
 124.131.28.172
 124.131.28.196
@@ -163597,6 +163741,7 @@
 124.94.244.153
 124.94.57.133
 124.95.16.252
+124.95.17.41
 124.95.81.24
 124.com.ua
 124.cpanel.realwebsitesite.com
@@ -164013,6 +164158,7 @@
 125.126.66.6
 125.126.67.145
 125.126.69.198
+125.126.69.95
 125.126.71.207
 125.126.72.174
 125.126.73.123
@@ -164143,6 +164289,7 @@
 125.160.137.80
 125.160.213.219
 125.161.14.114
+125.161.70.34
 125.161.96.233
 125.162.65.174
 125.163.199.90
@@ -164928,6 +165075,7 @@
 125.40.136.22
 125.40.136.220
 125.40.136.222
+125.40.136.25
 125.40.136.252
 125.40.136.253
 125.40.136.33
@@ -165473,6 +165621,7 @@
 125.40.234.169
 125.40.234.73
 125.40.235.80
+125.40.237.130
 125.40.24.117
 125.40.24.134
 125.40.24.143
@@ -167352,6 +167501,7 @@
 125.41.200.172
 125.41.200.181
 125.41.200.188
+125.41.200.189
 125.41.200.193
 125.41.200.203
 125.41.200.210
@@ -169353,6 +169503,7 @@
 125.42.120.98
 125.42.121.101
 125.42.121.103
+125.42.121.106
 125.42.121.108
 125.42.121.109
 125.42.121.11
@@ -169652,6 +169803,7 @@
 125.42.124.88
 125.42.124.93
 125.42.124.97
+125.42.125.103
 125.42.125.107
 125.42.125.110
 125.42.125.115
@@ -170455,6 +170607,7 @@
 125.42.97.100
 125.42.97.101
 125.42.97.102
+125.42.97.103
 125.42.97.119
 125.42.97.122
 125.42.97.123
@@ -170713,6 +170866,7 @@
 125.43.105.129
 125.43.105.135
 125.43.105.149
+125.43.105.157
 125.43.105.158
 125.43.105.168
 125.43.105.172
@@ -170997,6 +171151,7 @@
 125.43.13.92
 125.43.130.108
 125.43.130.23
+125.43.130.232
 125.43.130.24
 125.43.131.111
 125.43.131.182
@@ -171345,6 +171500,7 @@
 125.43.21.146
 125.43.21.147
 125.43.21.152
+125.43.21.157
 125.43.21.159
 125.43.21.161
 125.43.21.174
@@ -174472,6 +174628,7 @@
 125.44.211.83
 125.44.211.98
 125.44.212.105
+125.44.212.107
 125.44.212.108
 125.44.212.109
 125.44.212.114
@@ -174932,6 +175089,7 @@
 125.44.230.125
 125.44.230.164
 125.44.230.176
+125.44.230.191
 125.44.230.200
 125.44.230.226
 125.44.230.244
@@ -175394,6 +175552,7 @@
 125.44.31.61
 125.44.31.64
 125.44.31.69
+125.44.31.79
 125.44.31.8
 125.44.31.82
 125.44.31.84
@@ -176646,6 +176805,7 @@
 125.45.57.231
 125.45.57.238
 125.45.57.247
+125.45.57.249
 125.45.57.35
 125.45.57.46
 125.45.57.50
@@ -177196,6 +177356,7 @@
 125.45.90.131
 125.45.90.151
 125.45.90.153
+125.45.90.158
 125.45.90.16
 125.45.90.184
 125.45.90.189
@@ -177314,6 +177475,7 @@
 125.46.137.54
 125.46.138.0
 125.46.138.10
+125.46.138.117
 125.46.138.122
 125.46.138.149
 125.46.138.151
@@ -179992,6 +180154,7 @@
 125.47.251.96
 125.47.251.98
 125.47.252.105
+125.47.252.106
 125.47.252.107
 125.47.252.109
 125.47.252.110
@@ -180209,6 +180372,7 @@
 125.47.255.94
 125.47.255.97
 125.47.28.150
+125.47.28.217
 125.47.29.173
 125.47.29.191
 125.47.32.201
@@ -182341,10 +182505,12 @@
 125.99.207.92
 125.99.212.13
 125.99.220.105
+125.99.220.202
 125.99.222.152
 125.99.222.245
 125.99.222.76
 125.99.223.227
+125.99.223.26
 125.99.224.101
 125.99.224.102
 125.99.224.106
@@ -184210,6 +184376,7 @@
 134.209.202.202
 134.209.203.101
 134.209.203.205
+134.209.203.221
 134.209.203.223
 134.209.203.70
 134.209.204.77
@@ -184717,6 +184884,7 @@
 139.170.181.68
 139.170.200.29
 139.170.206.148
+139.170.228.166
 139.170.228.217
 139.170.228.55
 139.170.230.204
@@ -186129,6 +186297,7 @@
 140.237.255.239
 140.237.28.148
 140.237.29.28
+140.237.30.113
 140.237.30.179
 140.237.30.188
 140.237.31.197
@@ -186139,6 +186308,7 @@
 140.237.4.82
 140.237.5.254
 140.237.5.41
+140.237.5.43
 140.240.100.181
 140.240.100.94
 140.240.102.181
@@ -186927,6 +187097,8 @@
 149.255.15.121
 149.255.15.180
 149.255.15.182
+149.255.15.191
+149.255.15.235
 149.255.15.87
 149.255.36.133
 149.255.36.156
@@ -187177,6 +187349,7 @@
 151.226.2.198
 151.227.42.63
 151.232.180.152
+151.232.249.222
 151.232.56.134
 151.233.52.223
 151.233.56.139
@@ -187311,6 +187484,7 @@
 152.173.25.125
 152.231.127.54
 152.231.25.253
+152.241.13.197
 152.241.13.246
 152.241.24.181
 152.241.33.96
@@ -187543,6 +187717,7 @@
 153.34.65.168
 153.34.67.119
 153.34.86.53
+153.35.111.46
 153.35.141.25
 153.35.141.60
 153.35.141.74
@@ -187743,6 +187918,7 @@
 157.119.214.172
 157.119.214.233
 157.119.215.224
+157.122.105.142
 157.122.106.12
 157.230.0.237
 157.230.1.18
@@ -189493,6 +189669,7 @@
 163.125.181.187
 163.125.181.76
 163.125.181.87
+163.125.183.111
 163.125.183.142
 163.125.183.180
 163.125.183.75
@@ -189617,6 +189794,7 @@
 163.125.200.6
 163.125.200.64
 163.125.200.70
+163.125.200.72
 163.125.200.73
 163.125.200.75
 163.125.200.76
@@ -189674,6 +189852,7 @@
 163.125.202.158
 163.125.202.159
 163.125.202.16
+163.125.202.174
 163.125.202.183
 163.125.202.186
 163.125.202.190
@@ -189691,6 +189870,7 @@
 163.125.202.4
 163.125.202.57
 163.125.202.72
+163.125.202.74
 163.125.202.8
 163.125.202.83
 163.125.202.9
@@ -189701,6 +189881,7 @@
 163.125.203.146
 163.125.203.148
 163.125.203.154
+163.125.203.179
 163.125.203.184
 163.125.203.198
 163.125.203.200
@@ -189779,6 +189960,7 @@
 163.125.207.0
 163.125.207.102
 163.125.207.116
+163.125.207.125
 163.125.207.140
 163.125.207.143
 163.125.207.158
@@ -189863,6 +190045,7 @@
 163.125.248.230
 163.125.248.254
 163.125.250.176
+163.125.250.202
 163.125.251.214
 163.125.251.225
 163.125.251.227
@@ -189884,6 +190067,7 @@
 163.125.30.28
 163.125.31.183
 163.125.34.24
+163.125.37.201
 163.125.38.226
 163.125.4.131
 163.125.4.147
@@ -189927,6 +190111,7 @@
 163.125.68.229
 163.125.68.240
 163.125.68.243
+163.125.68.29
 163.125.68.31
 163.125.68.65
 163.125.68.7
@@ -192417,6 +192602,7 @@
 171.125.65.115
 171.125.65.193
 171.125.65.202
+171.125.65.22
 171.125.66.6
 171.125.68.45
 171.125.7.181
@@ -192668,6 +192854,7 @@
 171.34.114.167
 171.34.114.179
 171.34.114.180
+171.34.114.181
 171.34.114.215
 171.34.114.217
 171.34.114.227
@@ -192879,6 +193066,7 @@
 171.36.251.189
 171.36.251.66
 171.36.41.151
+171.36.42.154
 171.36.42.159
 171.36.42.3
 171.36.42.39
@@ -193574,6 +193762,7 @@
 172.245.5.120
 172.245.5.122
 172.245.5.185
+172.245.5.190
 172.245.52.102
 172.245.52.122
 172.245.52.160
@@ -196965,6 +197154,7 @@
 175.11.193.118
 175.11.193.122
 175.11.193.157
+175.11.193.66
 175.11.193.71
 175.11.193.82
 175.11.194.130
@@ -197125,6 +197315,7 @@
 175.145.200.51
 175.146.121.210
 175.146.16.118
+175.146.17.227
 175.146.18.195
 175.146.19.126
 175.146.20.229
@@ -200175,6 +200366,7 @@
 178.141.159.159
 178.141.16.64
 178.141.160.15
+178.141.161.129
 178.141.162.124
 178.141.162.211
 178.141.162.8
@@ -200568,8 +200760,10 @@
 178.175.0.225
 178.175.0.226
 178.175.0.229
+178.175.0.232
 178.175.0.234
 178.175.0.236
+178.175.0.239
 178.175.0.241
 178.175.0.246
 178.175.0.249
@@ -200639,6 +200833,7 @@
 178.175.1.178
 178.175.1.179
 178.175.1.186
+178.175.1.187
 178.175.1.188
 178.175.1.193
 178.175.1.194
@@ -200658,6 +200853,7 @@
 178.175.1.247
 178.175.1.25
 178.175.1.250
+178.175.1.252
 178.175.1.255
 178.175.1.26
 178.175.1.28
@@ -200733,8 +200929,10 @@
 178.175.10.255
 178.175.10.26
 178.175.10.28
+178.175.10.34
 178.175.10.37
 178.175.10.41
+178.175.10.42
 178.175.10.44
 178.175.10.46
 178.175.10.50
@@ -200881,6 +201079,7 @@
 178.175.101.203
 178.175.101.204
 178.175.101.205
+178.175.101.207
 178.175.101.208
 178.175.101.209
 178.175.101.21
@@ -200989,6 +201188,7 @@
 178.175.102.216
 178.175.102.22
 178.175.102.220
+178.175.102.221
 178.175.102.223
 178.175.102.225
 178.175.102.227
@@ -201124,6 +201324,7 @@
 178.175.104.104
 178.175.104.106
 178.175.104.11
+178.175.104.110
 178.175.104.112
 178.175.104.114
 178.175.104.116
@@ -201145,6 +201346,7 @@
 178.175.104.152
 178.175.104.153
 178.175.104.154
+178.175.104.155
 178.175.104.158
 178.175.104.16
 178.175.104.161
@@ -201200,6 +201402,7 @@
 178.175.104.54
 178.175.104.59
 178.175.104.62
+178.175.104.64
 178.175.104.66
 178.175.104.69
 178.175.104.80
@@ -201228,6 +201431,7 @@
 178.175.105.121
 178.175.105.122
 178.175.105.124
+178.175.105.125
 178.175.105.130
 178.175.105.131
 178.175.105.143
@@ -201280,6 +201484,7 @@
 178.175.105.255
 178.175.105.26
 178.175.105.27
+178.175.105.28
 178.175.105.29
 178.175.105.3
 178.175.105.30
@@ -201309,6 +201514,7 @@
 178.175.105.90
 178.175.105.91
 178.175.105.93
+178.175.105.94
 178.175.105.96
 178.175.106.100
 178.175.106.102
@@ -201365,6 +201571,7 @@
 178.175.106.219
 178.175.106.22
 178.175.106.220
+178.175.106.222
 178.175.106.224
 178.175.106.226
 178.175.106.228
@@ -201380,6 +201587,7 @@
 178.175.106.25
 178.175.106.251
 178.175.106.252
+178.175.106.253
 178.175.106.27
 178.175.106.28
 178.175.106.31
@@ -201577,6 +201785,7 @@
 178.175.108.227
 178.175.108.229
 178.175.108.23
+178.175.108.232
 178.175.108.237
 178.175.108.239
 178.175.108.24
@@ -201616,6 +201825,7 @@
 178.175.108.88
 178.175.108.90
 178.175.108.93
+178.175.108.94
 178.175.108.97
 178.175.108.98
 178.175.108.99
@@ -201631,6 +201841,7 @@
 178.175.109.121
 178.175.109.123
 178.175.109.126
+178.175.109.127
 178.175.109.132
 178.175.109.134
 178.175.109.137
@@ -201656,6 +201867,7 @@
 178.175.109.19
 178.175.109.190
 178.175.109.191
+178.175.109.193
 178.175.109.195
 178.175.109.196
 178.175.109.198
@@ -201700,6 +201912,7 @@
 178.175.109.71
 178.175.109.75
 178.175.109.77
+178.175.109.78
 178.175.109.82
 178.175.109.83
 178.175.109.86
@@ -202102,6 +202315,7 @@
 178.175.112.90
 178.175.112.97
 178.175.112.99
+178.175.113.0
 178.175.113.100
 178.175.113.106
 178.175.113.112
@@ -202265,6 +202479,7 @@
 178.175.114.242
 178.175.114.244
 178.175.114.245
+178.175.114.247
 178.175.114.250
 178.175.114.251
 178.175.114.254
@@ -202314,6 +202529,7 @@
 178.175.115.112
 178.175.115.113
 178.175.115.116
+178.175.115.12
 178.175.115.125
 178.175.115.126
 178.175.115.127
@@ -202357,6 +202573,7 @@
 178.175.115.20
 178.175.115.202
 178.175.115.205
+178.175.115.206
 178.175.115.207
 178.175.115.208
 178.175.115.209
@@ -202390,6 +202607,7 @@
 178.175.115.37
 178.175.115.39
 178.175.115.4
+178.175.115.40
 178.175.115.43
 178.175.115.45
 178.175.115.46
@@ -202438,6 +202656,7 @@
 178.175.116.143
 178.175.116.145
 178.175.116.147
+178.175.116.15
 178.175.116.150
 178.175.116.152
 178.175.116.154
@@ -202472,6 +202691,7 @@
 178.175.116.226
 178.175.116.228
 178.175.116.23
+178.175.116.236
 178.175.116.237
 178.175.116.238
 178.175.116.24
@@ -202639,6 +202859,7 @@
 178.175.118.133
 178.175.118.137
 178.175.118.138
+178.175.118.139
 178.175.118.141
 178.175.118.143
 178.175.118.144
@@ -202824,6 +203045,7 @@
 178.175.12.109
 178.175.12.11
 178.175.12.111
+178.175.12.114
 178.175.12.118
 178.175.12.12
 178.175.12.123
@@ -202944,6 +203166,7 @@
 178.175.120.189
 178.175.120.191
 178.175.120.193
+178.175.120.196
 178.175.120.197
 178.175.120.20
 178.175.120.203
@@ -203169,6 +203392,7 @@
 178.175.122.246
 178.175.122.252
 178.175.122.254
+178.175.122.26
 178.175.122.27
 178.175.122.28
 178.175.122.3
@@ -203612,6 +203836,7 @@
 178.175.126.93
 178.175.126.95
 178.175.126.99
+178.175.127.10
 178.175.127.100
 178.175.127.102
 178.175.127.106
@@ -203627,6 +203852,7 @@
 178.175.127.120
 178.175.127.122
 178.175.127.125
+178.175.127.129
 178.175.127.13
 178.175.127.130
 178.175.127.133
@@ -203656,6 +203882,7 @@
 178.175.127.185
 178.175.127.19
 178.175.127.190
+178.175.127.192
 178.175.127.195
 178.175.127.197
 178.175.127.198
@@ -203678,6 +203905,7 @@
 178.175.127.231
 178.175.127.236
 178.175.127.237
+178.175.127.238
 178.175.127.24
 178.175.127.240
 178.175.127.242
@@ -203919,6 +204147,7 @@
 178.175.15.225
 178.175.15.228
 178.175.15.229
+178.175.15.232
 178.175.15.233
 178.175.15.236
 178.175.15.238
@@ -203927,6 +204156,7 @@
 178.175.15.241
 178.175.15.244
 178.175.15.245
+178.175.15.246
 178.175.15.248
 178.175.15.25
 178.175.15.250
@@ -203941,6 +204171,7 @@
 178.175.15.35
 178.175.15.37
 178.175.15.38
+178.175.15.44
 178.175.15.45
 178.175.15.47
 178.175.15.48
@@ -203969,10 +204200,12 @@
 178.175.15.97
 178.175.15.99
 178.175.16.1
+178.175.16.10
 178.175.16.108
 178.175.16.110
 178.175.16.112
 178.175.16.113
+178.175.16.114
 178.175.16.115
 178.175.16.118
 178.175.16.12
@@ -204004,6 +204237,7 @@
 178.175.16.181
 178.175.16.186
 178.175.16.189
+178.175.16.193
 178.175.16.195
 178.175.16.196
 178.175.16.205
@@ -204175,6 +204409,7 @@
 178.175.18.249
 178.175.18.250
 178.175.18.253
+178.175.18.27
 178.175.18.32
 178.175.18.42
 178.175.18.45
@@ -204246,6 +204481,7 @@
 178.175.19.224
 178.175.19.225
 178.175.19.227
+178.175.19.229
 178.175.19.232
 178.175.19.236
 178.175.19.237
@@ -204577,6 +204813,7 @@
 178.175.22.188
 178.175.22.194
 178.175.22.203
+178.175.22.207
 178.175.22.209
 178.175.22.210
 178.175.22.211
@@ -204593,6 +204830,7 @@
 178.175.22.237
 178.175.22.241
 178.175.22.245
+178.175.22.248
 178.175.22.249
 178.175.22.255
 178.175.22.32
@@ -204690,6 +204928,7 @@
 178.175.23.55
 178.175.23.56
 178.175.23.58
+178.175.23.6
 178.175.23.61
 178.175.23.69
 178.175.23.71
@@ -204755,6 +204994,7 @@
 178.175.24.222
 178.175.24.223
 178.175.24.227
+178.175.24.230
 178.175.24.232
 178.175.24.238
 178.175.24.239
@@ -204821,6 +205061,7 @@
 178.175.25.164
 178.175.25.166
 178.175.25.168
+178.175.25.169
 178.175.25.172
 178.175.25.173
 178.175.25.177
@@ -204912,6 +205153,7 @@
 178.175.26.161
 178.175.26.162
 178.175.26.164
+178.175.26.165
 178.175.26.168
 178.175.26.169
 178.175.26.17
@@ -204936,6 +205178,7 @@
 178.175.26.207
 178.175.26.211
 178.175.26.214
+178.175.26.215
 178.175.26.217
 178.175.26.218
 178.175.26.219
@@ -204959,6 +205202,7 @@
 178.175.26.3
 178.175.26.31
 178.175.26.32
+178.175.26.34
 178.175.26.36
 178.175.26.38
 178.175.26.4
@@ -205054,12 +205298,14 @@
 178.175.27.25
 178.175.27.252
 178.175.27.30
+178.175.27.32
 178.175.27.36
 178.175.27.38
 178.175.27.39
 178.175.27.4
 178.175.27.41
 178.175.27.47
+178.175.27.48
 178.175.27.49
 178.175.27.5
 178.175.27.53
@@ -205163,6 +205409,7 @@
 178.175.28.7
 178.175.28.72
 178.175.28.74
+178.175.28.75
 178.175.28.79
 178.175.28.8
 178.175.28.81
@@ -205180,6 +205427,7 @@
 178.175.29.106
 178.175.29.111
 178.175.29.114
+178.175.29.12
 178.175.29.127
 178.175.29.128
 178.175.29.130
@@ -205291,6 +205539,7 @@
 178.175.3.190
 178.175.3.192
 178.175.3.193
+178.175.3.194
 178.175.3.196
 178.175.3.199
 178.175.3.201
@@ -205375,6 +205624,7 @@
 178.175.30.178
 178.175.30.18
 178.175.30.180
+178.175.30.181
 178.175.30.183
 178.175.30.185
 178.175.30.186
@@ -205568,6 +205818,7 @@
 178.175.32.221
 178.175.32.223
 178.175.32.227
+178.175.32.229
 178.175.32.23
 178.175.32.230
 178.175.32.233
@@ -205596,6 +205847,7 @@
 178.175.32.70
 178.175.32.72
 178.175.32.77
+178.175.32.83
 178.175.32.85
 178.175.32.87
 178.175.32.89
@@ -205632,6 +205884,7 @@
 178.175.33.165
 178.175.33.167
 178.175.33.170
+178.175.33.173
 178.175.33.174
 178.175.33.177
 178.175.33.178
@@ -205644,6 +205897,7 @@
 178.175.33.198
 178.175.33.2
 178.175.33.202
+178.175.33.205
 178.175.33.209
 178.175.33.21
 178.175.33.210
@@ -205730,6 +205984,7 @@
 178.175.34.21
 178.175.34.216
 178.175.34.217
+178.175.34.219
 178.175.34.22
 178.175.34.223
 178.175.34.224
@@ -205758,6 +206013,7 @@
 178.175.34.49
 178.175.34.5
 178.175.34.53
+178.175.34.56
 178.175.34.58
 178.175.34.60
 178.175.34.61
@@ -205904,11 +206160,13 @@
 178.175.36.172
 178.175.36.173
 178.175.36.174
+178.175.36.176
 178.175.36.177
 178.175.36.182
 178.175.36.184
 178.175.36.187
 178.175.36.189
+178.175.36.19
 178.175.36.192
 178.175.36.194
 178.175.36.198
@@ -206117,6 +206375,7 @@
 178.175.38.196
 178.175.38.2
 178.175.38.20
+178.175.38.200
 178.175.38.203
 178.175.38.204
 178.175.38.206
@@ -206193,6 +206452,7 @@
 178.175.39.17
 178.175.39.174
 178.175.39.175
+178.175.39.176
 178.175.39.181
 178.175.39.183
 178.175.39.190
@@ -206287,6 +206547,7 @@
 178.175.4.215
 178.175.4.216
 178.175.4.218
+178.175.4.219
 178.175.4.220
 178.175.4.222
 178.175.4.233
@@ -206357,6 +206618,7 @@
 178.175.40.138
 178.175.40.139
 178.175.40.14
+178.175.40.145
 178.175.40.149
 178.175.40.15
 178.175.40.151
@@ -206492,6 +206754,7 @@
 178.175.41.56
 178.175.41.57
 178.175.41.6
+178.175.41.60
 178.175.41.62
 178.175.41.65
 178.175.41.66
@@ -206610,6 +206873,7 @@
 178.175.43.154
 178.175.43.157
 178.175.43.158
+178.175.43.16
 178.175.43.162
 178.175.43.163
 178.175.43.165
@@ -206651,6 +206915,7 @@
 178.175.43.30
 178.175.43.31
 178.175.43.33
+178.175.43.34
 178.175.43.37
 178.175.43.38
 178.175.43.41
@@ -206681,6 +206946,7 @@
 178.175.43.91
 178.175.43.93
 178.175.43.94
+178.175.44.0
 178.175.44.100
 178.175.44.101
 178.175.44.102
@@ -206780,6 +207046,7 @@
 178.175.44.89
 178.175.44.9
 178.175.44.90
+178.175.44.95
 178.175.45.10
 178.175.45.102
 178.175.45.107
@@ -206892,6 +207159,7 @@
 178.175.46.110
 178.175.46.114
 178.175.46.116
+178.175.46.119
 178.175.46.120
 178.175.46.124
 178.175.46.125
@@ -206904,6 +207172,7 @@
 178.175.46.145
 178.175.46.149
 178.175.46.150
+178.175.46.151
 178.175.46.152
 178.175.46.154
 178.175.46.158
@@ -207156,6 +207425,7 @@
 178.175.48.65
 178.175.48.66
 178.175.48.71
+178.175.48.76
 178.175.48.80
 178.175.48.82
 178.175.48.85
@@ -207182,6 +207452,7 @@
 178.175.49.123
 178.175.49.126
 178.175.49.127
+178.175.49.129
 178.175.49.136
 178.175.49.137
 178.175.49.138
@@ -207195,6 +207466,7 @@
 178.175.49.18
 178.175.49.180
 178.175.49.185
+178.175.49.188
 178.175.49.189
 178.175.49.19
 178.175.49.194
@@ -207382,6 +207654,7 @@
 178.175.50.233
 178.175.50.236
 178.175.50.237
+178.175.50.239
 178.175.50.248
 178.175.50.249
 178.175.50.27
@@ -207409,6 +207682,7 @@
 178.175.50.84
 178.175.50.86
 178.175.50.87
+178.175.50.9
 178.175.50.90
 178.175.50.92
 178.175.50.95
@@ -207647,6 +207921,7 @@
 178.175.53.224
 178.175.53.225
 178.175.53.227
+178.175.53.228
 178.175.53.229
 178.175.53.231
 178.175.53.233
@@ -207808,6 +208083,7 @@
 178.175.55.165
 178.175.55.167
 178.175.55.169
+178.175.55.170
 178.175.55.191
 178.175.55.192
 178.175.55.194
@@ -207855,6 +208131,7 @@
 178.175.55.70
 178.175.55.72
 178.175.55.77
+178.175.55.85
 178.175.55.86
 178.175.55.88
 178.175.55.91
@@ -208122,6 +208399,7 @@
 178.175.58.35
 178.175.58.39
 178.175.58.40
+178.175.58.42
 178.175.58.43
 178.175.58.48
 178.175.58.49
@@ -208378,6 +208656,7 @@
 178.175.60.32
 178.175.60.34
 178.175.60.36
+178.175.60.37
 178.175.60.41
 178.175.60.42
 178.175.60.46
@@ -208458,6 +208737,7 @@
 178.175.61.36
 178.175.61.37
 178.175.61.40
+178.175.61.42
 178.175.61.43
 178.175.61.45
 178.175.61.52
@@ -208515,6 +208795,7 @@
 178.175.62.209
 178.175.62.211
 178.175.62.213
+178.175.62.216
 178.175.62.219
 178.175.62.220
 178.175.62.222
@@ -208540,11 +208821,13 @@
 178.175.62.39
 178.175.62.42
 178.175.62.43
+178.175.62.44
 178.175.62.45
 178.175.62.46
 178.175.62.50
 178.175.62.51
 178.175.62.56
+178.175.62.70
 178.175.62.72
 178.175.62.74
 178.175.62.76
@@ -209041,6 +209324,7 @@
 178.175.67.78
 178.175.67.8
 178.175.67.82
+178.175.67.83
 178.175.67.84
 178.175.67.86
 178.175.67.88
@@ -209165,6 +209449,7 @@
 178.175.69.140
 178.175.69.141
 178.175.69.143
+178.175.69.148
 178.175.69.149
 178.175.69.153
 178.175.69.154
@@ -209177,6 +209462,7 @@
 178.175.69.166
 178.175.69.169
 178.175.69.171
+178.175.69.173
 178.175.69.174
 178.175.69.175
 178.175.69.182
@@ -209424,6 +209710,7 @@
 178.175.70.92
 178.175.70.93
 178.175.70.94
+178.175.71.1
 178.175.71.102
 178.175.71.103
 178.175.71.104
@@ -209517,6 +209804,7 @@
 178.175.71.59
 178.175.71.60
 178.175.71.63
+178.175.71.64
 178.175.71.65
 178.175.71.68
 178.175.71.69
@@ -209540,6 +209828,7 @@
 178.175.72.101
 178.175.72.102
 178.175.72.108
+178.175.72.109
 178.175.72.110
 178.175.72.111
 178.175.72.113
@@ -209667,6 +209956,7 @@
 178.175.73.199
 178.175.73.2
 178.175.73.21
+178.175.73.211
 178.175.73.214
 178.175.73.216
 178.175.73.219
@@ -209700,6 +209990,7 @@
 178.175.73.6
 178.175.73.68
 178.175.73.7
+178.175.73.71
 178.175.73.72
 178.175.73.76
 178.175.73.86
@@ -209904,6 +210195,7 @@
 178.175.76.11
 178.175.76.113
 178.175.76.119
+178.175.76.121
 178.175.76.124
 178.175.76.125
 178.175.76.129
@@ -210161,6 +210453,7 @@
 178.175.78.92
 178.175.78.93
 178.175.78.94
+178.175.78.97
 178.175.79.101
 178.175.79.105
 178.175.79.106
@@ -210320,7 +210613,9 @@
 178.175.8.9
 178.175.8.93
 178.175.8.94
+178.175.8.97
 178.175.80.10
+178.175.80.100
 178.175.80.103
 178.175.80.11
 178.175.80.110
@@ -210399,6 +210694,7 @@
 178.175.80.37
 178.175.80.4
 178.175.80.40
+178.175.80.41
 178.175.80.43
 178.175.80.44
 178.175.80.46
@@ -210491,6 +210787,7 @@
 178.175.81.251
 178.175.81.252
 178.175.81.30
+178.175.81.32
 178.175.81.44
 178.175.81.45
 178.175.81.49
@@ -210505,6 +210802,7 @@
 178.175.81.7
 178.175.81.70
 178.175.81.79
+178.175.81.8
 178.175.81.80
 178.175.81.82
 178.175.81.83
@@ -210525,6 +210823,7 @@
 178.175.82.115
 178.175.82.117
 178.175.82.12
+178.175.82.120
 178.175.82.122
 178.175.82.123
 178.175.82.126
@@ -210878,6 +211177,7 @@
 178.175.85.171
 178.175.85.172
 178.175.85.183
+178.175.85.184
 178.175.85.185
 178.175.85.190
 178.175.85.192
@@ -210894,6 +211194,7 @@
 178.175.85.227
 178.175.85.228
 178.175.85.229
+178.175.85.23
 178.175.85.230
 178.175.85.242
 178.175.85.243
@@ -210933,6 +211234,7 @@
 178.175.85.79
 178.175.85.8
 178.175.85.80
+178.175.85.81
 178.175.85.83
 178.175.85.87
 178.175.85.89
@@ -210960,9 +211262,11 @@
 178.175.86.146
 178.175.86.15
 178.175.86.157
+178.175.86.159
 178.175.86.160
 178.175.86.164
 178.175.86.165
+178.175.86.166
 178.175.86.167
 178.175.86.169
 178.175.86.174
@@ -211027,6 +211331,7 @@
 178.175.86.81
 178.175.86.86
 178.175.86.90
+178.175.86.92
 178.175.86.93
 178.175.86.96
 178.175.86.97
@@ -211035,6 +211340,7 @@
 178.175.87.101
 178.175.87.106
 178.175.87.107
+178.175.87.108
 178.175.87.110
 178.175.87.113
 178.175.87.115
@@ -211208,6 +211514,7 @@
 178.175.88.51
 178.175.88.52
 178.175.88.53
+178.175.88.57
 178.175.88.60
 178.175.88.64
 178.175.88.78
@@ -211244,8 +211551,11 @@
 178.175.89.150
 178.175.89.151
 178.175.89.153
+178.175.89.157
 178.175.89.159
+178.175.89.160
 178.175.89.168
+178.175.89.169
 178.175.89.171
 178.175.89.173
 178.175.89.177
@@ -211322,6 +211632,7 @@
 178.175.9.132
 178.175.9.135
 178.175.9.138
+178.175.9.139
 178.175.9.140
 178.175.9.153
 178.175.9.155
@@ -211345,6 +211656,7 @@
 178.175.9.196
 178.175.9.200
 178.175.9.21
+178.175.9.210
 178.175.9.215
 178.175.9.217
 178.175.9.220
@@ -211385,12 +211697,14 @@
 178.175.9.92
 178.175.9.95
 178.175.9.98
+178.175.90.104
 178.175.90.109
 178.175.90.11
 178.175.90.114
 178.175.90.115
 178.175.90.116
 178.175.90.119
+178.175.90.122
 178.175.90.124
 178.175.90.127
 178.175.90.128
@@ -211525,8 +211839,10 @@
 178.175.91.219
 178.175.91.22
 178.175.91.221
+178.175.91.223
 178.175.91.224
 178.175.91.23
+178.175.91.230
 178.175.91.232
 178.175.91.236
 178.175.91.237
@@ -211689,6 +212005,7 @@
 178.175.93.144
 178.175.93.145
 178.175.93.147
+178.175.93.148
 178.175.93.149
 178.175.93.15
 178.175.93.150
@@ -211717,6 +212034,7 @@
 178.175.93.219
 178.175.93.220
 178.175.93.223
+178.175.93.224
 178.175.93.225
 178.175.93.226
 178.175.93.23
@@ -211734,6 +212052,7 @@
 178.175.93.30
 178.175.93.31
 178.175.93.33
+178.175.93.34
 178.175.93.36
 178.175.93.38
 178.175.93.4
@@ -211757,6 +212076,7 @@
 178.175.93.8
 178.175.93.82
 178.175.93.89
+178.175.93.90
 178.175.93.93
 178.175.93.95
 178.175.93.96
@@ -211881,6 +212201,7 @@
 178.175.95.119
 178.175.95.122
 178.175.95.126
+178.175.95.132
 178.175.95.135
 178.175.95.136
 178.175.95.137
@@ -211922,6 +212243,7 @@
 178.175.95.228
 178.175.95.230
 178.175.95.236
+178.175.95.237
 178.175.95.238
 178.175.95.24
 178.175.95.241
@@ -212043,6 +212365,7 @@
 178.175.96.97
 178.175.96.98
 178.175.96.99
+178.175.97.1
 178.175.97.100
 178.175.97.101
 178.175.97.103
@@ -212061,6 +212384,7 @@
 178.175.97.129
 178.175.97.130
 178.175.97.132
+178.175.97.135
 178.175.97.139
 178.175.97.140
 178.175.97.141
@@ -212074,6 +212398,7 @@
 178.175.97.163
 178.175.97.167
 178.175.97.168
+178.175.97.17
 178.175.97.173
 178.175.97.175
 178.175.97.177
@@ -212258,6 +212583,7 @@
 178.175.99.222
 178.175.99.223
 178.175.99.225
+178.175.99.226
 178.175.99.230
 178.175.99.233
 178.175.99.237
@@ -214544,6 +214870,7 @@
 180.188.241.79
 180.188.241.86
 180.188.241.91
+180.188.247.140
 180.188.252.185
 180.188.252.37
 180.188.253.153
@@ -218313,6 +218640,7 @@
 182.113.232.248
 182.113.232.81
 182.113.233.120
+182.113.233.129
 182.113.233.13
 182.113.233.20
 182.113.233.3
@@ -221859,6 +222187,7 @@
 182.116.103.68
 182.116.103.76
 182.116.103.77
+182.116.103.81
 182.116.103.85
 182.116.103.90
 182.116.103.91
@@ -222127,6 +222456,7 @@
 182.116.108.177
 182.116.108.178
 182.116.108.179
+182.116.108.180
 182.116.108.182
 182.116.108.183
 182.116.108.185
@@ -222719,6 +223049,7 @@
 182.116.119.110
 182.116.119.111
 182.116.119.122
+182.116.119.129
 182.116.119.134
 182.116.119.139
 182.116.119.140
@@ -224402,6 +224733,7 @@
 182.116.99.132
 182.116.99.141
 182.116.99.142
+182.116.99.150
 182.116.99.153
 182.116.99.160
 182.116.99.17
@@ -225990,6 +226322,7 @@
 182.117.29.202
 182.117.29.212
 182.117.29.216
+182.117.29.220
 182.117.29.227
 182.117.29.228
 182.117.29.229
@@ -229116,6 +229449,7 @@
 182.119.13.107
 182.119.13.109
 182.119.13.119
+182.119.13.141
 182.119.13.148
 182.119.13.159
 182.119.13.160
@@ -230149,6 +230483,7 @@
 182.119.191.87
 182.119.191.92
 182.119.196.160
+182.119.196.182
 182.119.196.190
 182.119.199.158
 182.119.199.85
@@ -230822,6 +231157,7 @@
 182.119.227.188
 182.119.227.194
 182.119.227.199
+182.119.227.20
 182.119.227.207
 182.119.227.21
 182.119.227.245
@@ -231408,6 +231744,7 @@
 182.119.49.148
 182.119.49.162
 182.119.49.168
+182.119.49.17
 182.119.49.185
 182.119.49.207
 182.119.49.220
@@ -231915,6 +232252,7 @@
 182.119.7.3
 182.119.7.41
 182.119.7.47
+182.119.7.54
 182.119.7.73
 182.119.7.75
 182.119.7.88
@@ -233579,6 +233917,7 @@
 182.120.85.9
 182.120.86.203
 182.120.86.234
+182.120.86.248
 182.120.86.46
 182.120.87.160
 182.120.87.227
@@ -234666,6 +235005,7 @@
 182.121.133.32
 182.121.133.37
 182.121.133.41
+182.121.133.46
 182.121.133.50
 182.121.133.58
 182.121.133.72
@@ -235445,6 +235785,7 @@
 182.121.164.75
 182.121.164.85
 182.121.165.184
+182.121.165.217
 182.121.166.105
 182.121.166.123
 182.121.166.85
@@ -235833,6 +236174,7 @@
 182.121.204.99
 182.121.205.100
 182.121.205.114
+182.121.205.118
 182.121.205.124
 182.121.205.131
 182.121.205.137
@@ -237628,6 +237970,7 @@
 182.121.49.92
 182.121.49.94
 182.121.49.97
+182.121.50.111
 182.121.50.112
 182.121.50.119
 182.121.50.121
@@ -238106,6 +238449,7 @@
 182.121.78.201
 182.121.78.220
 182.121.78.27
+182.121.78.29
 182.121.78.3
 182.121.78.36
 182.121.78.42
@@ -239343,6 +239687,7 @@
 182.122.202.219
 182.122.202.229
 182.122.202.246
+182.122.202.37
 182.122.202.59
 182.122.202.62
 182.122.202.82
@@ -239745,6 +240090,7 @@
 182.122.246.167
 182.122.246.170
 182.122.246.181
+182.122.246.187
 182.122.246.190
 182.122.246.197
 182.122.246.199
@@ -239884,6 +240230,7 @@
 182.122.251.122
 182.122.251.124
 182.122.251.133
+182.122.251.141
 182.122.251.143
 182.122.251.145
 182.122.251.150
@@ -240993,6 +241340,7 @@
 182.124.134.216
 182.124.134.235
 182.124.134.75
+182.124.134.80
 182.124.134.9
 182.124.134.90
 182.124.134.96
@@ -241096,6 +241444,7 @@
 182.124.149.52
 182.124.149.67
 182.124.15.106
+182.124.15.108
 182.124.15.109
 182.124.15.111
 182.124.15.13
@@ -241201,6 +241550,7 @@
 182.124.166.2
 182.124.166.228
 182.124.166.38
+182.124.166.57
 182.124.166.6
 182.124.166.7
 182.124.167.11
@@ -243271,6 +243621,7 @@
 182.126.180.65
 182.126.180.72
 182.126.181.115
+182.126.181.121
 182.126.181.149
 182.126.181.204
 182.126.181.214
@@ -243840,6 +244191,7 @@
 182.126.241.244
 182.126.241.30
 182.126.241.42
+182.126.241.7
 182.126.241.71
 182.126.241.92
 182.126.242.10
@@ -243917,6 +244269,7 @@
 182.126.52.202
 182.126.52.214
 182.126.52.229
+182.126.52.233
 182.126.52.252
 182.126.52.47
 182.126.52.70
@@ -244509,6 +244862,7 @@
 182.126.87.20
 182.126.87.201
 182.126.87.205
+182.126.87.207
 182.126.87.209
 182.126.87.217
 182.126.87.22
@@ -248008,6 +248362,7 @@
 182.127.70.172
 182.127.70.185
 182.127.70.194
+182.127.70.195
 182.127.70.213
 182.127.70.216
 182.127.70.218
@@ -249306,6 +249661,7 @@
 182.56.115.187
 182.56.115.191
 182.56.116.121
+182.56.116.135
 182.56.116.178
 182.56.116.56
 182.56.117.14
@@ -251855,6 +252211,7 @@
 182.58.137.168
 182.58.137.66
 182.58.137.94
+182.58.160.0
 182.58.160.122
 182.58.160.252
 182.58.160.89
@@ -254352,6 +254709,7 @@
 182.59.226.71
 182.59.227.10
 182.59.227.123
+182.59.227.125
 182.59.227.130
 182.59.227.151
 182.59.227.175
@@ -257013,6 +257371,7 @@
 183.188.184.94
 183.188.186.52
 183.188.187.52
+183.188.188.186
 183.188.194.119
 183.188.194.231
 183.188.195.189
@@ -257249,6 +257608,7 @@
 183.190.24.165
 183.190.26.125
 183.190.55.62
+183.191.162.120
 183.191.204.241
 183.191.217.113
 183.191.65.166
@@ -257305,6 +257665,7 @@
 183.27.195.242
 183.28.50.158
 183.28.61.52
+183.30.202.230
 183.30.202.247
 183.30.202.59
 183.30.202.67
@@ -257434,6 +257795,7 @@
 183.83.104.44
 183.83.104.68
 183.83.105.181
+183.83.105.21
 183.83.105.228
 183.83.105.252
 183.83.105.253
@@ -258125,6 +258487,7 @@
 185.132.53.88
 185.132.53.9
 185.132.53.98
+185.133.42.86
 185.134.122.209
 185.134.123.140
 185.134.21.75
@@ -258529,6 +258892,7 @@
 185.184.221.44
 185.184.54.15
 185.185.126.123
+185.185.126.82
 185.186.142.100
 185.186.198.120
 185.186.244.186
@@ -262064,6 +262428,7 @@
 188.10.21.14
 188.10.231.246
 188.112.169.59
+188.113.102.18
 188.113.107.75
 188.113.116.133
 188.113.81.17
@@ -262217,6 +262582,7 @@
 188.166.179.28
 188.166.18.52
 188.166.19.196
+188.166.19.45
 188.166.207.182
 188.166.21.10
 188.166.21.86
@@ -264949,6 +265315,7 @@
 192.119.106.235
 192.119.106.9
 192.119.107.81
+192.119.110.168
 192.119.110.222
 192.119.110.44
 192.119.110.49
@@ -265731,6 +266098,7 @@
 194.15.36.193
 194.15.36.194
 194.15.36.196
+194.15.36.202
 194.15.36.204
 194.15.36.207
 194.15.36.208
@@ -265988,6 +266356,7 @@
 194.87.138.86
 194.87.138.88
 194.87.138.97
+194.87.139.10
 194.87.139.108
 194.87.139.110
 194.87.139.113
@@ -267653,6 +268022,7 @@
 2.238.18.160
 2.238.195.223
 2.248.2.174
+2.249.161.188
 2.249.161.196
 2.249.178.219
 2.25.93.113
@@ -268173,6 +268543,7 @@
 200.75.107.84
 200.79.152.109
 200.79.153.166
+200.8.206.151
 200.8.206.224
 200.8.23.209
 200.8.240.149
@@ -268353,6 +268724,7 @@
 201.207.235.219
 201.208.129.111
 201.208.137.75
+201.208.139.84
 201.208.153.220
 201.208.155.206
 201.208.209.28
@@ -269194,6 +269566,7 @@
 202.168.153.228
 202.169.234.10
 202.169.234.19
+202.169.234.22
 202.169.234.33
 202.169.234.36
 202.169.234.37
@@ -270235,6 +270608,7 @@
 203.114.116.37
 203.115.102.243
 203.115.73.100
+203.115.73.105
 203.115.73.107
 203.115.73.11
 203.115.73.111
@@ -270330,6 +270704,7 @@
 203.115.85.93
 203.115.91.129
 203.115.91.141
+203.115.91.232
 203.115.91.47
 203.115.91.66
 203.123.205.195
@@ -273255,6 +273630,7 @@
 206.221.176.164
 206.248.136.50
 206.248.136.6
+206.248.137.132
 206.248.139.132
 206.248.139.15
 206.248.219.15
@@ -273435,6 +273811,7 @@
 209.133.223.130
 209.14.30.121
 209.14.30.135
+209.14.30.136
 209.14.30.159
 209.14.30.161
 209.14.30.166
@@ -273443,6 +273820,7 @@
 209.14.30.205
 209.14.30.30
 209.14.30.54
+209.14.31.125
 209.14.31.162
 209.14.31.163
 209.14.31.175
@@ -273707,6 +274085,7 @@
 210.101.157.10
 210.101.157.199
 210.101.70.131
+210.102.196.200
 210.102.58.78
 210.104.187.179
 210.104.210.133
@@ -275764,6 +276143,7 @@
 218.0.88.48
 218.101.202.186
 218.101.230.26
+218.103.180.199
 218.104.175.100
 218.104.175.103
 218.104.175.109
@@ -278418,6 +278798,7 @@
 219.154.140.99
 219.154.141.138
 219.154.141.196
+219.154.141.222
 219.154.141.227
 219.154.141.242
 219.154.141.53
@@ -279260,6 +279641,7 @@
 219.155.12.205
 219.155.12.215
 219.155.12.220
+219.155.12.221
 219.155.12.40
 219.155.12.51
 219.155.12.55
@@ -279490,6 +279872,7 @@
 219.155.170.165
 219.155.170.185
 219.155.170.215
+219.155.170.22
 219.155.170.228
 219.155.170.244
 219.155.170.250
@@ -279685,6 +280068,7 @@
 219.155.207.8
 219.155.207.96
 219.155.208.145
+219.155.208.188
 219.155.208.19
 219.155.208.211
 219.155.208.212
@@ -279946,6 +280330,7 @@
 219.155.225.90
 219.155.226.130
 219.155.226.143
+219.155.226.146
 219.155.226.154
 219.155.226.188
 219.155.226.194
@@ -280142,6 +280527,7 @@
 219.155.240.86
 219.155.241.11
 219.155.241.113
+219.155.241.135
 219.155.241.137
 219.155.241.144
 219.155.241.155
@@ -280681,6 +281067,7 @@
 219.155.37.72
 219.155.37.87
 219.155.37.90
+219.155.37.97
 219.155.38.10
 219.155.38.112
 219.155.38.113
@@ -281444,6 +281831,7 @@
 219.156.103.192
 219.156.103.225
 219.156.103.236
+219.156.103.248
 219.156.103.43
 219.156.103.46
 219.156.103.84
@@ -282255,6 +282643,7 @@
 219.156.23.241
 219.156.23.245
 219.156.23.26
+219.156.23.29
 219.156.23.3
 219.156.23.41
 219.156.23.50
@@ -282398,6 +282787,7 @@
 219.156.48.185
 219.156.48.50
 219.156.49.142
+219.156.49.170
 219.156.49.172
 219.156.49.250
 219.156.5.233
@@ -282474,6 +282864,7 @@
 219.156.60.203
 219.156.60.208
 219.156.60.211
+219.156.60.224
 219.156.60.250
 219.156.60.27
 219.156.60.39
@@ -282791,6 +283182,7 @@
 219.156.9.247
 219.156.9.254
 219.156.9.27
+219.156.9.32
 219.156.9.34
 219.156.9.42
 219.156.9.48
@@ -284389,6 +284781,7 @@
 219.157.220.159
 219.157.220.163
 219.157.220.164
+219.157.220.170
 219.157.220.171
 219.157.220.177
 219.157.220.18
@@ -284474,6 +284867,7 @@
 219.157.223.24
 219.157.223.241
 219.157.223.243
+219.157.223.245
 219.157.223.29
 219.157.223.4
 219.157.223.42
@@ -284525,6 +284919,7 @@
 219.157.226.198
 219.157.226.4
 219.157.226.47
+219.157.226.79
 219.157.227.124
 219.157.227.170
 219.157.227.176
@@ -284897,6 +285292,7 @@
 219.157.244.233
 219.157.244.236
 219.157.244.254
+219.157.244.33
 219.157.244.39
 219.157.244.43
 219.157.244.61
@@ -285835,6 +286231,7 @@
 219.157.50.203
 219.157.50.208
 219.157.50.21
+219.157.50.211
 219.157.50.228
 219.157.50.233
 219.157.50.238
@@ -285994,6 +286391,7 @@
 219.157.54.150
 219.157.54.155
 219.157.54.157
+219.157.54.158
 219.157.54.159
 219.157.54.177
 219.157.54.19
@@ -286101,6 +286499,7 @@
 219.157.56.251
 219.157.56.254
 219.157.56.35
+219.157.56.46
 219.157.56.47
 219.157.56.50
 219.157.56.54
@@ -288884,6 +289283,7 @@
 221.14.56.67
 221.14.57.62
 221.14.58.27
+221.14.58.5
 221.14.58.84
 221.14.59.255
 221.14.60.146
@@ -289497,6 +289897,7 @@
 221.15.147.210
 221.15.147.214
 221.15.147.217
+221.15.147.220
 221.15.147.225
 221.15.147.227
 221.15.147.234
@@ -291309,6 +291710,7 @@
 221.15.236.92
 221.15.236.93
 221.15.236.98
+221.15.237.107
 221.15.237.109
 221.15.237.11
 221.15.237.112
@@ -292033,6 +292435,7 @@
 221.15.7.198
 221.15.7.199
 221.15.7.200
+221.15.7.202
 221.15.7.205
 221.15.7.207
 221.15.7.21
@@ -293025,6 +293428,7 @@
 221.215.170.109
 221.215.171.80
 221.215.172.192
+221.215.172.207
 221.215.172.217
 221.215.174.4
 221.215.174.59
@@ -293713,6 +294117,7 @@
 221.5.30.10
 221.5.30.100
 221.5.30.103
+221.5.30.118
 221.5.30.14
 221.5.30.140
 221.5.30.153
@@ -297260,6 +297665,7 @@
 222.137.22.42
 222.137.22.59
 222.137.22.66
+222.137.22.79
 222.137.220.10
 222.137.220.123
 222.137.220.125
@@ -297288,6 +297694,7 @@
 222.137.220.60
 222.137.220.63
 222.137.220.82
+222.137.220.94
 222.137.220.99
 222.137.221.101
 222.137.221.107
@@ -297899,6 +298306,7 @@
 222.137.49.170
 222.137.49.29
 222.137.49.30
+222.137.49.4
 222.137.49.75
 222.137.49.99
 222.137.5.102
@@ -298298,6 +298706,7 @@
 222.137.83.230
 222.137.83.39
 222.137.83.5
+222.137.83.53
 222.137.84.2
 222.137.84.240
 222.137.84.33
@@ -299840,6 +300249,7 @@
 222.138.189.219
 222.138.189.223
 222.138.189.243
+222.138.189.88
 222.138.19.110
 222.138.19.135
 222.138.19.144
@@ -300166,6 +300576,7 @@
 222.138.215.134
 222.138.215.146
 222.138.215.16
+222.138.215.161
 222.138.215.183
 222.138.215.215
 222.138.215.222
@@ -300276,6 +300687,7 @@
 222.138.224.148
 222.138.224.15
 222.138.224.163
+222.138.224.164
 222.138.224.173
 222.138.224.2
 222.138.224.228
@@ -300742,6 +301154,7 @@
 222.138.49.58
 222.138.49.67
 222.138.49.79
+222.138.49.93
 222.138.50.106
 222.138.50.237
 222.138.50.32
@@ -301164,6 +301577,7 @@
 222.139.16.143
 222.139.16.173
 222.139.16.195
+222.139.16.229
 222.139.16.236
 222.139.16.32
 222.139.16.84
@@ -301932,6 +302346,7 @@
 222.140.111.116
 222.140.111.192
 222.140.111.205
+222.140.112.150
 222.140.112.171
 222.140.112.224
 222.140.113.197
@@ -303605,6 +304020,7 @@
 222.141.164.67
 222.141.164.88
 222.141.165.116
+222.141.165.180
 222.141.165.189
 222.141.165.2
 222.141.165.214
@@ -303920,6 +304336,7 @@
 222.141.244.110
 222.141.244.147
 222.141.244.20
+222.141.244.231
 222.141.244.80
 222.141.245.10
 222.141.245.134
@@ -304584,6 +305001,7 @@
 222.141.73.184
 222.141.73.219
 222.141.73.245
+222.141.73.249
 222.141.73.38
 222.141.73.55
 222.141.73.61
@@ -306094,6 +306512,7 @@
 222.214.53.254
 222.214.53.62
 222.214.54.162
+222.214.54.208
 222.214.54.238
 222.214.55.138
 222.214.55.18
@@ -307746,6 +308165,7 @@
 27.12.232.176
 27.12.233.205
 27.12.233.96
+27.12.234.4
 27.12.235.176
 27.12.236.127
 27.12.238.202
@@ -311864,6 +312284,7 @@
 27.208.242.223
 27.208.244.172
 27.208.247.130
+27.208.25.59
 27.208.30.1
 27.208.30.87
 27.208.31.92
@@ -312151,6 +312572,7 @@
 27.210.146.49
 27.210.146.54
 27.210.146.6
+27.210.146.61
 27.210.146.89
 27.210.147.172
 27.210.147.228
@@ -312892,6 +313314,7 @@
 27.213.145.138
 27.213.145.143
 27.213.145.161
+27.213.145.221
 27.213.146.231
 27.213.147.121
 27.213.148.104
@@ -312938,6 +313361,7 @@
 27.213.166.136
 27.213.166.174
 27.213.167.154
+27.213.167.175
 27.213.167.180
 27.213.167.210
 27.213.168.16
@@ -313902,6 +314326,7 @@
 27.216.130.132
 27.216.130.185
 27.216.131.63
+27.216.131.66
 27.216.132.194
 27.216.132.221
 27.216.132.237
@@ -317796,6 +318221,7 @@
 27.41.146.252
 27.41.146.27
 27.41.146.3
+27.41.146.59
 27.41.146.63
 27.41.146.73
 27.41.146.80
@@ -317916,6 +318342,7 @@
 27.41.153.41
 27.41.153.54
 27.41.153.65
+27.41.153.66
 27.41.153.89
 27.41.153.91
 27.41.154.102
@@ -319042,6 +319469,7 @@
 27.43.151.68
 27.43.151.86
 27.43.66.61
+27.43.82.210
 27.43.92.65
 27.44.100.126
 27.44.100.242
@@ -319324,6 +319752,7 @@
 27.46.47.61
 27.46.47.69
 27.46.47.72
+27.46.47.74
 27.46.47.75
 27.46.47.76
 27.46.47.77
@@ -319413,6 +319842,7 @@
 27.5.16.236
 27.5.16.237
 27.5.16.242
+27.5.16.243
 27.5.16.244
 27.5.16.245
 27.5.16.246
@@ -319890,6 +320320,7 @@
 27.5.21.38
 27.5.21.4
 27.5.21.5
+27.5.21.53
 27.5.21.56
 27.5.21.57
 27.5.21.63
@@ -320314,6 +320745,7 @@
 27.5.26.32
 27.5.26.33
 27.5.26.37
+27.5.26.4
 27.5.26.43
 27.5.26.44
 27.5.26.47
@@ -320626,6 +321058,7 @@
 27.5.30.197
 27.5.30.20
 27.5.30.203
+27.5.30.207
 27.5.30.210
 27.5.30.212
 27.5.30.215
@@ -320932,6 +321365,7 @@
 27.5.34.169
 27.5.34.171
 27.5.34.176
+27.5.34.177
 27.5.34.182
 27.5.34.183
 27.5.34.186
@@ -320996,6 +321430,7 @@
 27.5.35.117
 27.5.35.12
 27.5.35.125
+27.5.35.127
 27.5.35.130
 27.5.35.131
 27.5.35.132
@@ -341750,6 +342185,7 @@
 31.163.189.192
 31.163.189.220
 31.163.189.254
+31.163.191.11
 31.163.57.231
 31.163.65.250
 31.164.47.38
@@ -341976,6 +342412,7 @@
 31.6.70.84
 31.6.98.137
 31.62.130.208
+31.62.255.3
 31.62.91.175
 31.63.183.192
 31.63.189.195
@@ -344023,6 +344460,7 @@
 37.187.73.85
 37.189.109.110
 37.19.48.73
+37.19.49.202
 37.19.49.206
 37.19.51.174
 37.19.52.247
@@ -345964,6 +346402,7 @@
 39.73.44.149
 39.73.44.155
 39.73.44.165
+39.73.44.17
 39.73.44.176
 39.73.44.185
 39.73.44.198
@@ -348636,6 +349075,7 @@
 39.86.150.176
 39.86.150.37
 39.86.151.106
+39.86.151.49
 39.86.151.96
 39.86.152.128
 39.86.152.130
@@ -349399,6 +349839,7 @@
 39.87.84.239
 39.87.87.117
 39.87.87.99
+39.87.90.210
 39.87.93.109
 39.87.93.54
 39.87.98.115
@@ -351781,6 +352222,7 @@
 42.224.122.3
 42.224.122.30
 42.224.122.37
+42.224.122.39
 42.224.122.41
 42.224.122.43
 42.224.122.52
@@ -353103,6 +353545,7 @@
 42.224.176.199
 42.224.176.202
 42.224.176.205
+42.224.176.214
 42.224.176.216
 42.224.176.217
 42.224.176.221
@@ -354440,6 +354883,7 @@
 42.224.249.57
 42.224.249.73
 42.224.249.76
+42.224.249.8
 42.224.249.87
 42.224.249.88
 42.224.249.92
@@ -356601,6 +357045,7 @@
 42.224.90.133
 42.224.90.151
 42.224.90.158
+42.224.90.17
 42.224.90.196
 42.224.90.240
 42.224.90.28
@@ -357802,6 +358247,7 @@
 42.225.33.162
 42.225.33.199
 42.225.33.20
+42.225.33.31
 42.225.34.174
 42.225.34.18
 42.225.34.184
@@ -358375,6 +358821,7 @@
 42.226.89.147
 42.226.89.157
 42.226.89.235
+42.226.89.25
 42.226.89.82
 42.226.90.0
 42.226.90.102
@@ -358916,6 +359363,7 @@
 42.227.176.230
 42.227.176.239
 42.227.176.90
+42.227.177.142
 42.227.177.250
 42.227.177.84
 42.227.178.10
@@ -361510,6 +361958,7 @@
 42.228.75.59
 42.228.75.63
 42.228.75.65
+42.228.75.7
 42.228.75.74
 42.228.75.79
 42.228.75.80
@@ -363420,6 +363869,7 @@
 42.230.173.51
 42.230.173.66
 42.230.174.117
+42.230.174.125
 42.230.174.161
 42.230.174.171
 42.230.174.216
@@ -364146,6 +364596,7 @@
 42.230.219.225
 42.230.219.231
 42.230.219.239
+42.230.219.243
 42.230.219.254
 42.230.219.37
 42.230.219.4
@@ -366621,6 +367072,7 @@
 42.231.223.17
 42.231.223.191
 42.231.223.209
+42.231.223.215
 42.231.223.59
 42.231.223.95
 42.231.224.122
@@ -366774,6 +367226,7 @@
 42.231.244.187
 42.231.244.189
 42.231.244.222
+42.231.244.80
 42.231.244.83
 42.231.245.111
 42.231.245.142
@@ -367192,6 +367645,7 @@
 42.231.95.136
 42.231.95.154
 42.231.95.17
+42.231.95.195
 42.231.95.210
 42.231.95.230
 42.231.95.99
@@ -369091,6 +369545,7 @@
 42.233.90.116
 42.233.90.138
 42.233.90.167
+42.233.90.183
 42.233.90.187
 42.233.90.52
 42.233.91.0
@@ -369211,6 +369666,7 @@
 42.234.105.253
 42.234.105.3
 42.234.105.33
+42.234.105.6
 42.234.105.68
 42.234.105.93
 42.234.106.110
@@ -369505,6 +369961,7 @@
 42.234.162.214
 42.234.162.4
 42.234.162.42
+42.234.162.44
 42.234.162.76
 42.234.163.119
 42.234.163.16
@@ -374059,6 +374516,7 @@
 42.235.90.245
 42.235.90.29
 42.235.90.3
+42.235.90.32
 42.235.90.46
 42.235.90.50
 42.235.90.53
@@ -375222,6 +375680,7 @@
 42.237.44.45
 42.237.44.47
 42.237.45.107
+42.237.45.223
 42.237.45.25
 42.237.45.90
 42.237.46.104
@@ -375538,6 +375997,7 @@
 42.238.109.115
 42.238.11.212
 42.238.111.149
+42.238.112.100
 42.238.112.125
 42.238.112.132
 42.238.112.32
@@ -375805,6 +376265,7 @@
 42.238.175.124
 42.238.175.14
 42.238.175.229
+42.238.175.32
 42.238.175.35
 42.238.175.61
 42.238.175.96
@@ -378688,6 +379149,7 @@
 45.144.225.118
 45.144.225.142
 45.144.225.151
+45.144.225.213
 45.144.225.65
 45.144.225.96
 45.144.29.133
@@ -385086,6 +385548,7 @@
 54.179.174.132
 54.179.179.37
 54.179.9.186
+54.180.158.181
 54.186.24.183
 54.187.210.136
 54.197.30.41
@@ -385262,6 +385725,7 @@
 58.19.163.45
 58.19.163.92
 58.19.249.100
+58.19.249.50
 58.19.250.18
 58.19.250.190
 58.19.251.10
@@ -386094,6 +386558,7 @@
 58.248.143.158
 58.248.143.164
 58.248.143.168
+58.248.143.173
 58.248.143.174
 58.248.143.176
 58.248.143.18
@@ -386122,6 +386587,7 @@
 58.248.144.180
 58.248.144.186
 58.248.144.190
+58.248.144.21
 58.248.144.216
 58.248.144.217
 58.248.144.39
@@ -386129,6 +386595,7 @@
 58.248.144.89
 58.248.144.94
 58.248.144.95
+58.248.144.97
 58.248.145.113
 58.248.145.129
 58.248.145.13
@@ -386255,6 +386722,7 @@
 58.248.149.186
 58.248.149.207
 58.248.149.214
+58.248.149.226
 58.248.149.230
 58.248.149.231
 58.248.149.240
@@ -387097,6 +387565,7 @@
 58.249.73.74
 58.249.73.90
 58.249.74.103
+58.249.74.104
 58.249.74.11
 58.249.74.118
 58.249.74.120
@@ -387123,6 +387592,7 @@
 58.249.74.9
 58.249.75.101
 58.249.75.109
+58.249.75.112
 58.249.75.125
 58.249.75.126
 58.249.75.13
@@ -387206,6 +387676,7 @@
 58.249.78.116
 58.249.78.128
 58.249.78.132
+58.249.78.155
 58.249.78.168
 58.249.78.174
 58.249.78.176
@@ -387307,6 +387778,7 @@
 58.249.80.246
 58.249.80.37
 58.249.80.38
+58.249.80.46
 58.249.80.56
 58.249.80.61
 58.249.80.63
@@ -387521,6 +387993,7 @@
 58.249.87.211
 58.249.87.222
 58.249.87.247
+58.249.87.248
 58.249.87.250
 58.249.87.253
 58.249.87.33
@@ -387585,6 +388058,7 @@
 58.249.89.169
 58.249.89.178
 58.249.89.190
+58.249.89.210
 58.249.89.213
 58.249.89.218
 58.249.89.223
@@ -387649,6 +388123,7 @@
 58.249.90.180
 58.249.90.19
 58.249.90.20
+58.249.90.206
 58.249.90.216
 58.249.90.220
 58.249.90.233
@@ -387659,6 +388134,7 @@
 58.249.90.80
 58.249.90.82
 58.249.90.84
+58.249.90.86
 58.249.90.94
 58.249.91.102
 58.249.91.11
@@ -387693,6 +388169,7 @@
 58.249.91.77
 58.249.91.98
 58.252.175.220
+58.252.176.107
 58.252.176.117
 58.252.176.12
 58.252.176.120
@@ -387961,6 +388438,7 @@
 58.255.135.21
 58.255.135.228
 58.255.135.253
+58.255.135.41
 58.255.135.48
 58.255.135.56
 58.255.135.61
@@ -388137,6 +388615,7 @@
 58.42.195.227
 58.42.198.13
 58.42.220.111
+58.46.169.21
 58.46.248.182
 58.46.248.4
 58.46.249.10
@@ -388299,6 +388778,7 @@
 58.61.51.61
 58.61.51.73
 58.61.51.97
+58.62.31.25
 58.62.80.50
 58.62.80.54
 58.62.83.182
@@ -392364,6 +392844,7 @@
 59.32.97.159
 59.32.97.187
 59.32.97.188
+59.32.97.190
 59.32.97.208
 59.32.97.217
 59.32.97.218
@@ -394236,6 +394717,7 @@
 59.92.182.7
 59.92.182.70
 59.92.182.71
+59.92.182.72
 59.92.182.74
 59.92.182.75
 59.92.182.76
@@ -394942,6 +395424,7 @@
 59.92.218.72
 59.92.218.73
 59.92.218.75
+59.92.218.77
 59.92.218.79
 59.92.218.8
 59.92.218.80
@@ -395062,6 +395545,7 @@
 59.92.219.252
 59.92.219.254
 59.92.219.26
+59.92.219.28
 59.92.219.29
 59.92.219.30
 59.92.219.31
@@ -395692,6 +396176,7 @@
 59.93.19.187
 59.93.19.189
 59.93.19.190
+59.93.19.191
 59.93.19.193
 59.93.19.194
 59.93.19.195
@@ -395866,6 +396351,7 @@
 59.93.21.110
 59.93.21.111
 59.93.21.115
+59.93.21.117
 59.93.21.121
 59.93.21.126
 59.93.21.127
@@ -397165,6 +397651,7 @@
 59.94.182.241
 59.94.182.242
 59.94.182.243
+59.94.182.244
 59.94.182.246
 59.94.182.247
 59.94.182.248
@@ -399714,6 +400201,7 @@
 59.97.169.111
 59.97.169.112
 59.97.169.113
+59.97.169.114
 59.97.169.115
 59.97.169.116
 59.97.169.117
@@ -400942,6 +401430,7 @@
 59.97.174.82
 59.97.174.83
 59.97.174.84
+59.97.174.85
 59.97.174.87
 59.97.174.89
 59.97.174.9
@@ -403353,6 +403842,7 @@
 59.99.44.249
 59.99.44.253
 59.99.44.254
+59.99.44.28
 59.99.44.29
 59.99.44.30
 59.99.44.31
@@ -404261,6 +404751,7 @@
 59.99.93.244
 59.99.93.245
 59.99.93.246
+59.99.93.248
 59.99.93.250
 59.99.93.251
 59.99.93.252
@@ -404317,6 +404808,7 @@
 59.99.93.79
 59.99.93.8
 59.99.93.80
+59.99.93.82
 59.99.93.83
 59.99.93.84
 59.99.93.85
@@ -404557,6 +405049,7 @@
 59.99.95.134
 59.99.95.135
 59.99.95.136
+59.99.95.137
 59.99.95.139
 59.99.95.14
 59.99.95.140
@@ -404566,6 +405059,7 @@
 59.99.95.146
 59.99.95.147
 59.99.95.148
+59.99.95.149
 59.99.95.15
 59.99.95.151
 59.99.95.152
@@ -406797,6 +407291,7 @@
 60.215.4.239
 60.215.4.89
 60.215.42.16
+60.215.59.108
 60.215.61.56
 60.215.63.173
 60.216.122.109
@@ -415656,6 +416151,7 @@
 60.254.49.198
 60.254.49.201
 60.254.49.215
+60.254.49.59
 60.254.49.68
 60.254.49.94
 60.254.50.240
@@ -416462,6 +416958,7 @@
 60.7.64.208
 60.7.64.243
 60.7.65.79
+60.7.8.43
 60.7.94.111
 60.7.99.254
 60.9.155.86
@@ -418674,11 +419171,13 @@
 61.3.124.244
 61.3.124.25
 61.3.124.251
+61.3.124.3
 61.3.124.33
 61.3.124.34
 61.3.124.39
 61.3.124.41
 61.3.124.46
+61.3.124.51
 61.3.124.60
 61.3.124.65
 61.3.124.71
@@ -418690,6 +419189,7 @@
 61.3.124.95
 61.3.125.102
 61.3.125.107
+61.3.125.112
 61.3.125.114
 61.3.125.119
 61.3.125.12
@@ -418785,6 +419285,7 @@
 61.3.127.124
 61.3.127.125
 61.3.127.135
+61.3.127.138
 61.3.127.149
 61.3.127.158
 61.3.127.178
@@ -419480,6 +419981,7 @@
 61.52.135.117
 61.52.135.125
 61.52.135.144
+61.52.135.192
 61.52.135.234
 61.52.135.235
 61.52.135.253
@@ -420556,6 +421058,7 @@
 61.52.212.233
 61.52.212.239
 61.52.212.244
+61.52.212.250
 61.52.212.251
 61.52.212.27
 61.52.212.30
@@ -421392,6 +421895,7 @@
 61.52.39.101
 61.52.39.109
 61.52.39.110
+61.52.39.119
 61.52.39.122
 61.52.39.132
 61.52.39.144
@@ -421699,6 +422203,7 @@
 61.52.5.192
 61.52.5.195
 61.52.5.198
+61.52.5.217
 61.52.5.226
 61.52.5.60
 61.52.50.109
@@ -422272,6 +422777,7 @@
 61.52.62.97
 61.52.63.11
 61.52.63.110
+61.52.63.119
 61.52.63.121
 61.52.63.125
 61.52.63.127
@@ -422435,6 +422941,7 @@
 61.52.76.53
 61.52.76.58
 61.52.76.59
+61.52.76.72
 61.52.76.73
 61.52.76.74
 61.52.76.87
@@ -423633,6 +424140,7 @@
 61.53.123.149
 61.53.123.154
 61.53.123.161
+61.53.123.162
 61.53.123.163
 61.53.123.168
 61.53.123.169
@@ -423719,6 +424227,7 @@
 61.53.124.215
 61.53.124.219
 61.53.124.223
+61.53.124.225
 61.53.124.227
 61.53.124.23
 61.53.124.230
@@ -426274,6 +426783,7 @@
 61.54.240.166
 61.54.240.19
 61.54.240.198
+61.54.240.20
 61.54.240.213
 61.54.240.220
 61.54.240.44
@@ -426632,10 +427142,12 @@
 61.54.58.164
 61.54.58.166
 61.54.58.172
+61.54.58.190
 61.54.58.192
 61.54.58.193
 61.54.58.197
 61.54.58.198
+61.54.58.20
 61.54.58.202
 61.54.58.211
 61.54.58.22
@@ -426694,6 +427206,7 @@
 61.54.60.242
 61.54.60.255
 61.54.60.29
+61.54.60.4
 61.54.60.43
 61.54.60.55
 61.54.60.68
@@ -426716,6 +427229,7 @@
 61.54.61.163
 61.54.61.168
 61.54.61.172
+61.54.61.18
 61.54.61.191
 61.54.61.199
 61.54.61.208
@@ -427424,6 +427938,7 @@
 62.219.131.205
 62.219.138.44
 62.219.143.46
+62.219.155.61
 62.219.163.162
 62.219.164.224
 62.219.194.210
@@ -428624,6 +429139,7 @@
 71.183.150.34
 71.187.60.8
 71.19.144.47
+71.19.150.93
 71.190.64.120
 71.190.64.189
 71.190.64.214
@@ -429532,6 +430048,7 @@
 77.45.182.113
 77.45.182.196
 77.45.183.124
+77.45.183.39
 77.45.184.77
 77.45.185.57
 77.45.185.89
@@ -431735,6 +432252,7 @@
 84.22.38.175
 84.221.143.108
 84.224.144.27
+84.224.162.170
 84.224.177.80
 84.224.213.50
 84.228.102.152
@@ -431948,6 +432466,7 @@
 85.105.77.54
 85.105.82.225
 85.105.82.94
+85.105.9.152
 85.105.98.84
 85.106.129.231
 85.106.161.174
@@ -435128,6 +435647,7 @@
 95.152.49.54
 95.152.5.232
 95.152.9.183
+95.153.241.63
 95.153.94.241
 95.154.20.231
 95.154.244.200
@@ -436600,6 +437120,7 @@ accesointerne.theworkpc.com
 access-24.jp
 access-cash.ae.org
 access-om.neomeric.us
+access-one.us
 access-to-web.com
 accessclub.jp
 accessdig.com
@@ -436777,6 +437298,7 @@ achremittanceservices.com
 acht-stuecken.de
 achuanchaolihai.cn
 aci.serabd.com
+aciabogados.com
 aciitaly.com
 acilevarkadasi.com
 acilisbalon.com
@@ -437193,6 +437715,7 @@ admin.grapejuiceofbrazil.com
 admin.greenlightcr.com
 admin.hopehorseback.org
 admin.jpcar.mystand.pt
+admin.mobilezenie.com
 admin.searchlowestprice.com
 admin.solissol.com
 admin.staging.buildsmart.io
@@ -437372,7 +437895,6 @@ adventuredsocks.com
 adventureexplorer.in
 adventurehr.com
 adventureitdate.com
-adventureits.com
 adventuremania.com
 adventurersafaris.com
 adventuresofarchibald.com
@@ -437792,6 +438314,7 @@ agenforedi.toko-abi.net
 agengarcinia5000.com
 agenity.com
 agenlama.com
+agenmovie.xyz
 agent-seo.jp
 agent.ken.by
 agent2.icu
@@ -444808,6 +445331,7 @@ barcaacademyistanbul.com
 barcelonaevent.es
 barcelonakartingcenter.com
 barchaklem.com
+barcionstw.eastus.cloudapp.azure.com
 barcla.ug
 barclaysdownloads.com
 barcoofoods.ir
@@ -447093,6 +447617,7 @@ bizzznez.com
 bj5800.com
 bjarndahl.dk
 bjbus.net
+bjconstructions.in
 bjdd.org
 bjenkins.webview.consulting
 bjenzer.com
@@ -448132,6 +448657,7 @@ bnote.novelux.com
 bnpartnersweb.com
 bnpgrup.com
 bnqzjy.cn
+bnrbook.com
 bnrnews.id
 bnsddfhjdfgvbxc.ru
 bnsgroupbd.com
@@ -448882,6 +449408,7 @@ brandzzy.com
 braner.com.ua
 branfinancial.com
 branner-chile.com
+brannon-powlowski25d.xyz
 brannudd.com
 brantech.com
 brar.aminfortgreene.com
@@ -449882,6 +450409,7 @@ buyrigrap.com
 buysellfx24.ru
 buysmart365.net
 buysmartwebmall.com
+buythebest.pk
 buytotake.online
 buytwitterlike.com
 buyuksigorta.com
@@ -451202,6 +451730,7 @@ cashonlinestore.com
 cashoutrefitips.com
 cashpickup.slmicrocredit.com
 cashslip.info
+cashtunel.com
 cashyinvestment.org
 casimiroartes.es
 casinarium.com
@@ -453774,6 +454303,7 @@ clubyourlife.ca
 clubzone.ca
 cluebazar.com
 clukva.ru
+clurbgolf.com
 clurit.com
 clusdirectory.xyz
 cluster-mixture.gq
@@ -453990,6 +454520,7 @@ coastmediagroup.com.au
 coastmedicalservice.com
 coastmotorsupply.com
 coastsignworks.com
+coastwidewaterproofing.com.au
 coatforwinter.com
 coavce.com
 cobam.xyz
@@ -456013,6 +456544,7 @@ cronicas.com.do
 cronolux.com.br
 croodly.com
 crookedchristicraddick.com
+crooks-cooper24g.xyz
 croos.org
 crope.shop
 cropfoods.com
@@ -457267,7 +457799,6 @@ dar-ltd.uk
 dar-sana.com
 darajelita.com
 daralsalam-mall.com
-daralsaqi.com
 darapartment.com
 darasrszs.online
 darassalam.ch
@@ -457376,7 +457907,6 @@ dashcenter.info
 dasheriemagazine.com
 dashfiles.tk
 dashkevichseo.ru
-dashonweb.com
 dashudance.com
 dashvaanjil.mn
 dasin-obchudek.cz
@@ -457704,6 +458234,7 @@ dboyusa.online
 dbravo.pro
 dbs-ebank.com
 dbsa-dream.com
+dbsandbox.ca
 dbsenvironmental.co.uk
 dbsgear.com
 dbsktoporder.yolasite.com
@@ -458612,6 +459143,7 @@ denlokale.nu
 denmaar.hplbusiness.com
 denmarkheating.net
 denmaytre.vn
+dennis-hill25lw.xyz
 dennis-roth.de
 dennishester.com
 dennisisasshole.com
@@ -461288,6 +461820,9 @@ down.posti-fi-fjwa.top
 down.posti-fi-fsa.top
 down.posti-fi-fsaq.top
 down.posti-fi-fwa.top
+down.posti-fi-ij.top
+down.posti-fi-in.top
+down.posti-fi-iz.top
 down.pzchao.com
 down.qm188.com
 down.qqfarmer.com.cn
@@ -463499,6 +464034,7 @@ egyptmaint.com
 egyptmotours.com
 egyptpharaohstours.com
 egyshadowmen.com
+egyutthato.eu
 egyuttkonnyebb.zolitoth.com
 egyvision.medicahealthy.net
 egywebtest.ml
@@ -464680,6 +465216,7 @@ ennaturismo.info
 ennessehospitality.id
 ennovate.elin.co.za
 eno.si
+enolil-loo.com
 enorichie.net
 enorka.info
 enosburgreading.pbworks.com
@@ -466653,6 +467190,7 @@ faithchorale.com
 faithcompassion.com
 faithconstructionltd.co.uk
 faithfight.my.id
+faithmethodistcheras.org
 faithmontessorischools.com
 faithoasis.000webhostapp.com
 faithworkx.com
@@ -467923,6 +468461,7 @@ findyourfocusph.com
 findyourvoice.ca
 fine-art-line.de
 fine.black
+fineartgallerym.com
 fineconera.com
 finefeather.info
 finefoodsfrozen.com
@@ -471551,6 +472090,7 @@ girlsphonenumbers.online
 girltalkza.co.za
 girlydesignart.com
 gironynavarro.com
+girotexuniformes.com
 girraj2016.gtranzit.com
 girrajwadi.com
 gisa.company
@@ -471640,6 +472180,7 @@ gladwynecapital.com
 glafka.com
 glambooth.nl
 glamoroushairextension.com
+glamorouspk.com
 glamour.rosolutions.com.mx
 glamourgarden-lb.com
 glamourlounge.org
@@ -472396,6 +472937,7 @@ gordondeen.net
 gordonmilktransport.com
 gordonruss.com
 gordyssensors.com
+gorecycle.fahadjutt.com
 gorenotoservisi.net
 gorestruly.com
 goretimmo.lu
@@ -473552,6 +474094,7 @@ gunesulkesi.com
 guneyaski.com
 gungazcomputer.co.ke
 gunk.insol.be
+gunma2u.com
 gunmak-com.tk
 gunnarasgeir.com
 gunnersexcavating.com
@@ -475903,6 +476446,7 @@ hollywoodremix.com
 hollywoodsmileeg.com
 holmdalehouse.co.uk
 holmesgroup-com.azurewebsites.net
+holmesprpmgmt.com
 holmnkolbas.com
 holmsater.se
 holod24.by
@@ -476596,6 +477140,7 @@ hpmamerica.com
 hpmaytinhtaophongcach.com
 hpmwqjub.com
 hpq8fa.db.files.1drv.com
+hprosacco25i.xyz
 hprpc.cn
 hps-sk.sk
 hps.nz
@@ -479172,6 +479717,7 @@ instant-resume.com
 instantbonheur.fr
 instantcashflowtoday.com.ng
 instantclients.network
+instantindialoan.com
 instanttaxsolutions.mobi
 instanttechnology.com.au
 instantworldpay.com
@@ -479996,6 +480542,7 @@ iscidavasi.com
 isciyizbiz.com
 iscleanone.com
 isclimatechangeahoax.com
+iscoegypt.com
 iscoming.ir
 iscon.com.br
 iscondisth.com
@@ -480051,7 +480598,6 @@ iskostrip.com
 iskro.textronic.info
 iskyservice.ru
 islaholics.com
-islamabadtrafficpolice.gov.pk
 islamabout.com
 islamappen.se
 islamforall.tv
@@ -481864,6 +482410,7 @@ jolly-saito-4993.sub.jp
 jollycharm.com
 jollyemma.com
 jolyscortinas.com.br
+jomansea.com
 jomar2020.com.br
 jomblo.com
 jomhermonex.com
@@ -483243,6 +483790,7 @@ kaspersky-security.com
 kasperskysecurity.club
 kasrasanatsepahan.com
 kassa.hostsites.ru
+kassandra5024d.xyz
 kassconnect.ru
 kasshmira.com
 kassohome.com.tr
@@ -483887,7 +484435,6 @@ khannamdo.com
 khannen.com.vn
 khannen.vn
 khanqahebrahimi.com
-khantil.com
 khantipong.com
 khaochills.com
 khaoden.tech
@@ -485749,6 +486296,7 @@ lab.sjworks.net
 lab.valvolari.it
 lab.ydigital.asia
 lab1.ozaki-kyousei.com
+lab18.it
 lab2.e-century.pl
 lab5.hu
 lab6.com.br
@@ -490787,6 +491335,7 @@ managegates.com
 manageitrisks.com
 management.vkims.com
 managementtop.id
+managemysalon.in
 managemyshoes.tools
 manageone.co.th
 manageprint.in
@@ -491168,6 +491717,7 @@ marecsko.hu
 marek-paysage-concept.fr
 marek.in
 marekvoprsal.cz
+marel.com.br
 marellengifts.com
 maremarius.pt
 marematto.it
@@ -492448,6 +492998,7 @@ meditationsurmesure.com
 meditec.ma
 mediterraneavacanze.com
 meditheraphy.com
+meditreat.itwebservice.in
 meditsinanarodnaya.ru
 medius.ge
 mediusvp.com
@@ -494624,6 +495175,7 @@ moitruongtunglam.com
 mojang.com.br
 mojehaftom.com
 mojewnetrza.pl
+mojno--vse.ru
 mojo-studios.co.uk
 mojorockstar.com
 mojstudent.net
@@ -495378,6 +495930,7 @@ mrpiratz.com
 mrpower.ir
 mrprintoke.com
 mrquick.co.il
+mrsambarbershop.nl
 mrsbow.com
 mrsconnect.org
 mrsdiggs.com
@@ -495978,6 +496531,7 @@ mvicente.com.br
 mvid.com
 mvidl.site
 mvisionproperties.com
+mvldesign.ca
 mvm368.com
 mvmskpd.com
 mvns.railfan.net
@@ -497312,6 +497866,7 @@ nellyvonalven.com
 nelsonhelps.com
 nelsonhostingcom.000webhostapp.com
 nelsonpto.org
+nelsonsbutchers.co.uk
 nelsonsilveti.com
 neltac.com
 nelyvos.nl
@@ -498646,7 +499201,6 @@ no18balloonroom.co.uk
 no1angelsescort.com
 no1spinningfields.90degrees.digital
 no1websitedesigner.com
-no2politics.com
 no70.fun
 noabuseshere.top
 noach.nl
@@ -499936,6 +500490,7 @@ ogxbody.com
 ohako.com.my
 ohamburguer.com.br
 ohanadev.com
+ohatsbd.com
 ohdratdigital.com
 ohe.ie
 ohelloguyzzqq.com
@@ -500240,6 +500795,7 @@ omada.edu.gr
 omagroup.ru
 omaharefugees.com
 omahduwur.com
+omaia.org
 omaint.ml
 omalleyco-my.sharepoint.com
 omalll.com
@@ -505870,6 +506426,7 @@ promodigital.tk
 promodont.com
 promokonyara.ru
 promolatinconferences.com
+promolyko.com
 promomitsubishitermurah.net
 promonoble.com
 promootzie.nl
@@ -507285,6 +507842,7 @@ quickmusings.com
 quickpickapp.co
 quickreachmedia.com
 quicksaleecuador.com
+quickshine.co.ke
 quickstorevn.com
 quicktechsupport247.com
 quicktowtowing.com
@@ -509386,6 +509944,7 @@ rgclimatizacion.com
 rgdecor.org
 rgfloors.com.au
 rgitabit.in
+rgleason25s.xyz
 rglgrupomedico.com.mx
 rgmobilegossip.com
 rgmvanijya.com
@@ -510230,6 +510789,7 @@ roselvi.cl
 rosemaryromero.com.br
 rosemiracle.com
 rosemurphy.co.uk
+rosenbaum-jaida24nz.xyz
 rosenfeldcapital.com
 rosenlaw.cratima.com
 roseperfeito.com.br
@@ -514148,6 +514708,7 @@ shastri.com
 shatabbytek.com
 shataikok.com
 shatelnews.ir
+shatteredglass.io
 shaukya.com
 shaulla.store
 shaunodonnell.com
@@ -516009,6 +516570,7 @@ smartlogo.com.br
 smartlync.pk
 smartmadira.com
 smartmassive.ru
+smartmatrixs.com
 smartmobilelearning.co.za
 smartmoneylife.com
 smartmovie.com.ua
@@ -516971,6 +517533,7 @@ sosctb.com
 sosenfantsburkinafaso.fr
 sosexymagazine.com
 sosflam.com
+sosgsm.fr
 sosh47.citycheb.ru
 sosoab.com
 sosofoto.cz
@@ -521610,6 +522173,7 @@ tecnologiaoficial.com
 tecnologiatech.com
 tecnologiaz.com
 tecnologicainformatica.com.br
+tecnologyschool.com
 tecnolora.com
 tecnoloxia.com
 tecnopc.info
@@ -524374,6 +524938,7 @@ tobpm.kz
 toby-warren.com
 tobyetc.com
 tobysherman.com
+tocaima.co
 tocakids.resultaweb.com.br
 tocgiajojo.com
 tochkae.ru
@@ -525501,6 +526066,7 @@ tresjoliejewellery.com
 tresnexus.com
 treterhef.download
 tretthing-bg.site
+treutel-jamir25ju.xyz
 trevellinglove.com
 trevinos.net
 trevorchristensen.com
@@ -528203,6 +528769,7 @@ vastintegrated.com
 vastraindia.com
 vastralaya.shop
 vastuanalyst.com
+vastubless.com
 vastuvidyaarchitects.com
 vasudhagoodharvest.com
 vasumadhi.com
@@ -529548,6 +530115,7 @@ vlad.iset.ro
 vladetel.org
 vladimirfilin.com
 vladimirfilin.ru
+vladimirinternational.com
 vladneta.lt
 vladsever.ru
 vladsp.ru
@@ -530546,6 +531114,7 @@ web.eficiens.cl
 web.emergingsun.com
 web.emsfabrik.de
 web.eng.ubu.ac.th
+web.geetle.ga
 web.geomegasoft.net
 web.golden-goblin.com
 web.gotham.com.au
@@ -531360,6 +531929,7 @@ why-h.xyz
 whyasksolution.com
 whybowl.thebotogs.com
 whyepicshop.com
+whynt.xyz
 whysquare.co.nz
 whystudio.cn
 whytech.info
@@ -532427,6 +532997,7 @@ wroxra.by.files.1drv.com
 wrrodrigo.com
 wrtech.com.pl
 wrusnollet.com
+wrzucacz.pl
 wrzutka.co
 ws-ebavisapia01-dll.ir
 ws3lfkm.com
@@ -532874,6 +533445,7 @@ xh.hj46.cn
 xhcmnews.com
 xhd.qhv.mybluehost.me
 xhencheng.tk
+xherzog24pv.xyz
 xhjclq.ch.files.1drv.com
 xhs9a81.com
 xhsdxm.com
@@ -534733,6 +535305,7 @@ zafinternational.co.id
 zafirotiendas.com
 zagnet.pl
 zagogulina.com
+zagoradesertcamp.com
 zagrodazbyszka.pl
 zagros-shahrekord.ir
 zagrosenergygroup.com
@@ -534788,6 +535361,7 @@ zakodujbiznes.ml
 zakopane.utazas.hu
 zakopanedomki.com.pl
 zakosciele66.cba.pl
+zakra.tecnasulstore.com.br
 zakrahgroup.com
 zakriasons.co
 zakromanoff.com
diff --git a/urlhaus-filter-hosts-online.txt b/urlhaus-filter-hosts-online.txt
index 715d4b15..b6d828ea 100644
--- a/urlhaus-filter-hosts-online.txt
+++ b/urlhaus-filter-hosts-online.txt
@@ -1,5 +1,5 @@
 # Title: Online Malicious Hosts Blocklist
-# Updated: Thu, 25 Mar 2021 12:12:40 UTC
+# Updated: Fri, 26 Mar 2021 00:12:29 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -19,7 +19,6 @@
 0.0.0.0 360down7.miiyun.cn
 0.0.0.0 8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com
 0.0.0.0 8poieq.bn.files.1drv.com
-0.0.0.0 99centsdigitals.com
 0.0.0.0 abcd.bg
 0.0.0.0 abclicks.in
 0.0.0.0 abissnet.net
@@ -27,11 +26,12 @@
 0.0.0.0 absoftechworld.com
 0.0.0.0 absupplies.co.uk
 0.0.0.0 abyssos.eu
+0.0.0.0 academyshademani.com
 0.0.0.0 acbick.com
 0.0.0.0 accounts.thesmarttechhub.com
 0.0.0.0 aceeprc.com.aceeprc.com
 0.0.0.0 acellr.co.uk
-0.0.0.0 aclassapart.in
+0.0.0.0 aciabogados.com
 0.0.0.0 acteon.com.ar
 0.0.0.0 activateyourdiscount.com
 0.0.0.0 activecost.com.au
@@ -49,6 +49,7 @@
 0.0.0.0 agenciadigitalwdys.com
 0.0.0.0 agenciatabletshouse.com.br
 0.0.0.0 agenda.gmelloinformatica.com.br
+0.0.0.0 agenmovie.xyz
 0.0.0.0 agentt.ac.ug
 0.0.0.0 agile8studio.com
 0.0.0.0 agmcarpetcare.co.uk
@@ -60,7 +61,6 @@
 0.0.0.0 alasdemariposas.org
 0.0.0.0 alemelektronik.com
 0.0.0.0 alena1971.es
-0.0.0.0 alertlauncher.fr
 0.0.0.0 alexdubai.com.aldiabsteel.com
 0.0.0.0 alka.institute
 0.0.0.0 allforcreative.com.au
@@ -72,6 +72,7 @@
 0.0.0.0 amarteargentina.com.ar
 0.0.0.0 amenyan.zouri.jp
 0.0.0.0 amos524.org
+0.0.0.0 ams.alvinasschools.org.ng
 0.0.0.0 anantam.net.in
 0.0.0.0 andreelapeyre.com
 0.0.0.0 andremaraisbeleggings.co.za
@@ -91,10 +92,9 @@
 0.0.0.0 aplicativoparasindicato.com.br
 0.0.0.0 apoolcondo.com
 0.0.0.0 app.adsensearticle.com
-0.0.0.0 app.explicitsurveys.co.uk
 0.0.0.0 app.prerana.info
 0.0.0.0 apps.saintsoporte.com
-0.0.0.0 aras.iuc.ac
+0.0.0.0 aqv.news
 0.0.0.0 areyoulivingwell.com
 0.0.0.0 arsapetrolab.com
 0.0.0.0 artedibujoyarquitectura.com
@@ -113,11 +113,12 @@
 0.0.0.0 ayamallah.com
 0.0.0.0 azmeasurement.com
 0.0.0.0 azraktours.com
-0.0.0.0 b2b.toptanakaryakit.com.tr
 0.0.0.0 backgrounds.pk
 0.0.0.0 backup.agewsage.com
 0.0.0.0 badeggdesign.com
+0.0.0.0 balealgodon.mx
 0.0.0.0 bangkok-orchids.com
+0.0.0.0 barcionstw.eastus.cloudapp.azure.com
 0.0.0.0 bary.sz4h.com
 0.0.0.0 basma.com.kw
 0.0.0.0 bausch.kr-atlas.monaxikoslykos@zytrox.tk
@@ -126,7 +127,6 @@
 0.0.0.0 bcmt.elin.co.za
 0.0.0.0 bcrg.co.za
 0.0.0.0 bearcatpumps.com.cn
-0.0.0.0 beatyamerican.com
 0.0.0.0 beautincollagen.rs
 0.0.0.0 bekape.co.id
 0.0.0.0 bespokeweddings.ie
@@ -134,6 +134,8 @@
 0.0.0.0 betone.co.kr
 0.0.0.0 betycopaints.com
 0.0.0.0 beveragesmiami.solucioneslink.com
+0.0.0.0 bhavaniengineering.com
+0.0.0.0 bigbag.wootraining.certificacion.cl
 0.0.0.0 bilbosaquet.ug
 0.0.0.0 bilhen.co.za
 0.0.0.0 billing.rahitechnosoft.com
@@ -141,11 +143,10 @@
 0.0.0.0 birminghamlink.org
 0.0.0.0 blog.callensaxen.com
 0.0.0.0 blog.oyinblogs.com
-0.0.0.0 blog.takbelit.com
 0.0.0.0 bmlifestyle.co.uk
+0.0.0.0 bnrbook.com
 0.0.0.0 bnrnews.id
 0.0.0.0 bodenstein.co.za
-0.0.0.0 bolnicaloznica.rs
 0.0.0.0 booksearch.com
 0.0.0.0 bounces.mi-fs.com
 0.0.0.0 bpo.correct.go.th
@@ -159,23 +160,21 @@
 0.0.0.0 brightstarshop.com
 0.0.0.0 browardinsurancemiami.solucioneslink.com
 0.0.0.0 bt2.elin.co.za
-0.0.0.0 btdapi.robotake.com
 0.0.0.0 bucrinsuranlceonlines.com
 0.0.0.0 buenavista.co
-0.0.0.0 buigiaphat.com.vn
 0.0.0.0 bullseyemedia.in
 0.0.0.0 busandvanrentalmalaysia.com
 0.0.0.0 buscascolegios.diit.cl
 0.0.0.0 business.softberg.ro
 0.0.0.0 buyingmusiconline.com
-0.0.0.0 buypropertyfast.com
 0.0.0.0 bwsr.eu
 0.0.0.0 c.oooooooooo.ga
 0.0.0.0 c0140529.ferozo.com
+0.0.0.0 caballo.com.au
 0.0.0.0 cacapavaonline.sdserver144.com.br
+0.0.0.0 calgaryautorepairservice.com
 0.0.0.0 callbury.in
 0.0.0.0 camminachetipassa.it
-0.0.0.0 campusvirtual.cepsanjuanbosco.net.pe
 0.0.0.0 cancer.educandome.co
 0.0.0.0 capitalgroup-kw.com
 0.0.0.0 capitalnewsagency.com
@@ -188,12 +187,10 @@
 0.0.0.0 ccauthority.net
 0.0.0.0 cdaonline.com.ar
 0.0.0.0 cec.asso.ac-amiens.fr
-0.0.0.0 cellas.sk
 0.0.0.0 cendekiabinaaksara.com
 0.0.0.0 cespol-bote.com.mx
 0.0.0.0 cfs5.tistory.com
 0.0.0.0 ch.rmu.ac.th
-0.0.0.0 changematterscounselling.com
 0.0.0.0 chardhamdodham.com
 0.0.0.0 cheacrilnsurances.com
 0.0.0.0 chealablilitycarinsurances.com
@@ -201,15 +198,14 @@
 0.0.0.0 childselect.com
 0.0.0.0 chinhdropfile.myvnc.com
 0.0.0.0 chinhdropfile80.myvnc.com
-0.0.0.0 chipmania.it
 0.0.0.0 cible-energy.com
 0.0.0.0 cifeer.net
 0.0.0.0 citycapproperty.ru
 0.0.0.0 cityglobalgospel.com
 0.0.0.0 civi.istmejia.com
 0.0.0.0 cleanbydesignllc.com
-0.0.0.0 clim34000.fr
 0.0.0.0 cloud.fc.co.mz
+0.0.0.0 clurbgolf.com
 0.0.0.0 codsambal.com
 0.0.0.0 colinde.pricesne.com
 0.0.0.0 colorpak.pl
@@ -231,7 +227,6 @@
 0.0.0.0 crecerco.com
 0.0.0.0 crittersbythebay.com
 0.0.0.0 crm.notariavieitoyvelamazan.com
-0.0.0.0 crmmanivela.net
 0.0.0.0 crscorretordeimoveis.com.br
 0.0.0.0 cse-engineer.com
 0.0.0.0 csnserver.com
@@ -278,7 +273,6 @@
 0.0.0.0 detorre.es
 0.0.0.0 dev-interestingtech.pantheonsite.io
 0.0.0.0 dev.sebpo.net
-0.0.0.0 dezcom.com
 0.0.0.0 dfcf.91756.cn
 0.0.0.0 dfsfcsfcdsfsdvcfsvcscv.com
 0.0.0.0 diamantenegro.mi-fs.com
@@ -301,7 +295,6 @@
 0.0.0.0 doncedyhall.com
 0.0.0.0 donghobinhminh.com
 0.0.0.0 dongphuctop.com
-0.0.0.0 donwnloasecury.ath.cx
 0.0.0.0 dosame.com
 0.0.0.0 dosman.pl
 0.0.0.0 dovberger.com
@@ -309,6 +302,9 @@
 0.0.0.0 down.pcclear.com
 0.0.0.0 down.posti-fi-fsa.top
 0.0.0.0 down.posti-fi-fwa.top
+0.0.0.0 down.posti-fi-ij.top
+0.0.0.0 down.posti-fi-in.top
+0.0.0.0 down.posti-fi-iz.top
 0.0.0.0 down.udashi.com
 0.0.0.0 down.webbora.com
 0.0.0.0 down1.arpun.com
@@ -325,7 +321,6 @@
 0.0.0.0 drbaby.com.sa
 0.0.0.0 drohnen.ensenanzainteligente.com
 0.0.0.0 drools-moved.46999.n3.nabble.com
-0.0.0.0 drrohanfonseca.com
 0.0.0.0 drsha.innovativesolutions.mobi
 0.0.0.0 dsenterprize.co.za
 0.0.0.0 dsspainting.com
@@ -339,19 +334,15 @@
 0.0.0.0 e.sldov.ru
 0.0.0.0 ebruyatkin.com
 0.0.0.0 econews.treegle.org
-0.0.0.0 edelweissdecoration.com
 0.0.0.0 efficientegroup.com
 0.0.0.0 elliot.newreadermedia.net
-0.0.0.0 emaids.co.za
 0.0.0.0 en.baoend.com
 0.0.0.0 enc-tech.com
 0.0.0.0 endurotanzania.co.tz
-0.0.0.0 enkonooh.com
 0.0.0.0 ennovate.elin.co.za
 0.0.0.0 enriquecendocomconsorcio.com.br
 0.0.0.0 envios.petpienso.cl
 0.0.0.0 equimination.ee
-0.0.0.0 es.paymelist.com
 0.0.0.0 escola.probommar.org.br
 0.0.0.0 esnconsultants.com
 0.0.0.0 essentia.org.br
@@ -363,15 +354,14 @@
 0.0.0.0 f1sol.com
 0.0.0.0 familydentist.site
 0.0.0.0 farmaciasdrogaminas.com.br
-0.0.0.0 farmnatural.in
 0.0.0.0 faveraprojects.com
 0.0.0.0 fc.co.mz
 0.0.0.0 felicienne.nl
 0.0.0.0 fi.bonitastores.com
 0.0.0.0 files.martellexpress.us
 0.0.0.0 files6.uludagbilisim.com
-0.0.0.0 filmotainment.com
 0.0.0.0 final.makkahkmcc.com
+0.0.0.0 fineartgallerym.com
 0.0.0.0 fkd.derpcity.ru
 0.0.0.0 flintspin.com
 0.0.0.0 flyingbuddhadesign.com
@@ -379,20 +369,17 @@
 0.0.0.0 fms.buladde.or.ug
 0.0.0.0 foothills.com.br
 0.0.0.0 footweardirect.elin.co.za
-0.0.0.0 formestore.evencsoft.co
 0.0.0.0 forum.mdb.nu
 0.0.0.0 fotoobjetivo.com
 0.0.0.0 foundationrepairhoustontx.net
 0.0.0.0 foxeps.com.br
 0.0.0.0 freecnetdownload.com
-0.0.0.0 freedombookshop.tickme.lk
 0.0.0.0 freisites.com.br
 0.0.0.0 ftp.n3twork30cm.ml
 0.0.0.0 fullelectronica.com.ar
 0.0.0.0 funletters.net
 0.0.0.0 fusionfiresolutions.com
 0.0.0.0 futuregraphics.com.ar
-0.0.0.0 gahanassociates.com
 0.0.0.0 gametwogame.com
 0.0.0.0 garayvidalabogados.com
 0.0.0.0 garciadogshow.com
@@ -400,7 +387,6 @@
 0.0.0.0 garenanow4.myvnc.com
 0.0.0.0 gbbulls.co.uk
 0.0.0.0 gcpc.co.id.chronoscurtain.com
-0.0.0.0 gcrcorporation.com
 0.0.0.0 generaldeviales.com
 0.0.0.0 gfmodd1.webselffiles01.com
 0.0.0.0 gfold1.webselffiles01.com
@@ -408,6 +394,8 @@
 0.0.0.0 ghislain.dartois.pagesperso-orange.fr
 0.0.0.0 giadungg7.com
 0.0.0.0 giddos.ga
+0.0.0.0 gilliem.com
+0.0.0.0 girotexuniformes.com
 0.0.0.0 giteletropical.com
 0.0.0.0 globaltask.ar
 0.0.0.0 glowinmedia.co.ke
@@ -422,10 +410,12 @@
 0.0.0.0 goldcupmortgage.com
 0.0.0.0 golden-memories-funerals.yourpageserver.com
 0.0.0.0 goldmen.in
+0.0.0.0 gorecycle.fahadjutt.com
 0.0.0.0 gracejukes.com
 0.0.0.0 grupoinmare.com
 0.0.0.0 gruposelt.000webhostapp.com
 0.0.0.0 gs.monerorx.com
+0.0.0.0 guide-to-cell-phones.com
 0.0.0.0 gulfac-house.com
 0.0.0.0 gvpcdpgc.edu.in
 0.0.0.0 habbotips.free.fr
@@ -451,6 +441,7 @@
 0.0.0.0 hmpmall.co.kr
 0.0.0.0 hoagietesting10.com
 0.0.0.0 hoayeuthuong-my.sharepoint.com
+0.0.0.0 holmesprpmgmt.com
 0.0.0.0 homefindersolutions.com
 0.0.0.0 hongluosi.com
 0.0.0.0 hookedupboatclub.com
@@ -462,7 +453,6 @@
 0.0.0.0 hsmwebapp.com
 0.0.0.0 htownbars.com
 0.0.0.0 hubtech.co.za
-0.0.0.0 huequito.evencsoft.co
 0.0.0.0 hunggiang.vn
 0.0.0.0 husamiyahschool.com
 0.0.0.0 iam313.com
@@ -474,6 +464,7 @@
 0.0.0.0 iesanjosemonitos.edu.co
 0.0.0.0 ikexpert.com
 0.0.0.0 ilrafrica.com
+0.0.0.0 images.jermiau.com
 0.0.0.0 imbueautoworx.co.za
 0.0.0.0 imperiumtherapy.co.za
 0.0.0.0 in-tune2016.com
@@ -488,6 +479,7 @@
 0.0.0.0 inovations.searchkero.com
 0.0.0.0 inrajahmundry.co.in
 0.0.0.0 insignificantfinecore.testmail4.repl.co
+0.0.0.0 instantindialoan.com
 0.0.0.0 instvisionmexico.edu.mx
 0.0.0.0 intellectsmart.in
 0.0.0.0 intersel-idf.org
@@ -498,6 +490,7 @@
 0.0.0.0 iremart.es
 0.0.0.0 iris101.co.uk
 0.0.0.0 iscamenabe.com
+0.0.0.0 ismf.com.ng
 0.0.0.0 iso-dubai.net
 0.0.0.0 israrulhaq.me
 0.0.0.0 isrorg.com
@@ -518,7 +511,6 @@
 0.0.0.0 jiaoyuzixun.cn
 0.0.0.0 jing-da.com.tw
 0.0.0.0 jktnet.xyz
-0.0.0.0 jmcomputacion.com.ar
 0.0.0.0 jmtc.91756.cn
 0.0.0.0 jnanbharati.com
 0.0.0.0 jobs.thebeessolution.com
@@ -527,9 +519,7 @@
 0.0.0.0 josegene.com
 0.0.0.0 josuarochoa.com
 0.0.0.0 jpwoodfordco.com
-0.0.0.0 julietlaser.site
 0.0.0.0 jumpmanualjacobhiller.com
-0.0.0.0 jumpnjamchicago.com
 0.0.0.0 jupiter.toxsl.in
 0.0.0.0 jurgensen.newreadermedia.net
 0.0.0.0 justinscott.com.au
@@ -551,6 +541,7 @@
 0.0.0.0 kumaralok.in
 0.0.0.0 kwanfromhongkong.com
 0.0.0.0 kz.sldov.ru
+0.0.0.0 lab18.it
 0.0.0.0 lacasadelosalebrijes.com
 0.0.0.0 ladylabonde.com
 0.0.0.0 lameguard.ru
@@ -596,6 +587,7 @@
 0.0.0.0 lp.difusodesign.com
 0.0.0.0 lp.juancamilogarciareyes.com
 0.0.0.0 lp.tecnimasdecolombia.com.co
+0.0.0.0 ltc.typoten.com
 0.0.0.0 luckybrownie.com
 0.0.0.0 luminouspneuma.com
 0.0.0.0 luxomodels.com
@@ -604,15 +596,15 @@
 0.0.0.0 madicon.co.za
 0.0.0.0 magianegramagiablancayamarres.com
 0.0.0.0 mail.bs-eiendomme.co.za
+0.0.0.0 mail.golimoapp.com
 0.0.0.0 mail.jeffsono.org
 0.0.0.0 maksi.feb.unib.ac.id
 0.0.0.0 malaya.tv
 0.0.0.0 malwarecoding.github.io
 0.0.0.0 managed.oss-cn-beijing.aliyuncs.com
+0.0.0.0 managemysalon.in
 0.0.0.0 manantialesdelnorte.uy
-0.0.0.0 manivelasst.com
 0.0.0.0 marcapinyo.ru
-0.0.0.0 marcusthepoet.com
 0.0.0.0 mario-sunjic.com
 0.0.0.0 mariobrown.net
 0.0.0.0 mariotessarollo.com
@@ -621,7 +613,6 @@
 0.0.0.0 marksidfgs.ug
 0.0.0.0 masjidhabeebiyarazviya.mysunni.com
 0.0.0.0 materialescantu.com
-0.0.0.0 matinal-nominal.pt
 0.0.0.0 matruchhaya.co.in
 0.0.0.0 mattysplayground.com
 0.0.0.0 maxtox.com.pk
@@ -633,6 +624,7 @@
 0.0.0.0 mediamaster.co.za
 0.0.0.0 medianews.ge
 0.0.0.0 medistaffconsulting.com
+0.0.0.0 meditreat.itwebservice.in
 0.0.0.0 meeweb.com
 0.0.0.0 megamart.afnan-amc.com
 0.0.0.0 merbay.ru
@@ -653,7 +645,6 @@
 0.0.0.0 mindfulbuildingandliving.com
 0.0.0.0 mingguanwms.com
 0.0.0.0 minuevavida.org
-0.0.0.0 mirror.mypage.sk
 0.0.0.0 mis.nbcc.ac.th
 0.0.0.0 misterson.com
 0.0.0.0 mixr.at
@@ -661,12 +652,14 @@
 0.0.0.0 mktf.mx
 0.0.0.0 mmogollon.com.mx
 0.0.0.0 mncarteam.com
+0.0.0.0 mobile.illumetechnology.com
 0.0.0.0 modelhouseturkey.com
 0.0.0.0 modernmanna.org
 0.0.0.0 monetization.business
 0.0.0.0 moninediy.com
 0.0.0.0 mopai.sg
 0.0.0.0 motorcomunicacion.com
+0.0.0.0 msacontabil.com.br
 0.0.0.0 mtspsmjeli.sch.id
 0.0.0.0 muzimbiti.xigubo.co.mz
 0.0.0.0 mxpiqw.am.files.1drv.com
@@ -699,8 +692,8 @@
 0.0.0.0 nicolas.ug
 0.0.0.0 nidhi.iexist.in
 0.0.0.0 nikanpolimer.ir
+0.0.0.0 nilehouse.co.ug
 0.0.0.0 nilinkeji.com
-0.0.0.0 nisacooks.com
 0.0.0.0 njtiledesigncenter.com
 0.0.0.0 nobius.org
 0.0.0.0 nocalnoodle.elin.co.za
@@ -718,10 +711,13 @@
 0.0.0.0 oakleyandfriends.co.uk
 0.0.0.0 obseques-conseils.com
 0.0.0.0 ocean.tecnasulstore.com.br
+0.0.0.0 ohe.ie
 0.0.0.0 ohsewgorgeous.co.uk
+0.0.0.0 oknoplastik.sk
 0.0.0.0 oleholeh.memangbeda.website
 0.0.0.0 olirecords.mixture.ltd
 0.0.0.0 olooom.com
+0.0.0.0 omaia.org
 0.0.0.0 omaromatic.com
 0.0.0.0 omega.az
 0.0.0.0 oms.pappai.com
@@ -730,6 +726,7 @@
 0.0.0.0 onedrive.listifyapp.co
 0.0.0.0 online.creedglobal.in
 0.0.0.0 onlinestatis.bar
+0.0.0.0 ont.proman.id
 0.0.0.0 open.warehousesaas.co.uk
 0.0.0.0 opolis.io
 0.0.0.0 optimus.com.sg
@@ -737,6 +734,8 @@
 0.0.0.0 order.bizpeed.com
 0.0.0.0 orientgatewayltd.com
 0.0.0.0 orion445.com
+0.0.0.0 oserve.pk
+0.0.0.0 otolithenrichment.fahadjutt.com
 0.0.0.0 ottimade.com
 0.0.0.0 ourteam.searchkero.com
 0.0.0.0 ozemag.com
@@ -758,6 +757,7 @@
 0.0.0.0 paths.elin.co.za
 0.0.0.0 paulmercier.biz
 0.0.0.0 payerrealty.com
+0.0.0.0 payments.atifsiddiqui.me
 0.0.0.0 pcsoori.com
 0.0.0.0 pd.oceaniarp.net
 0.0.0.0 perpus.onlineman7-jombang.sch.id
@@ -770,6 +770,7 @@
 0.0.0.0 photo360.kubooking.com
 0.0.0.0 photographytipsclub.com
 0.0.0.0 pink99.com
+0.0.0.0 pizzabarletta.com.br
 0.0.0.0 plasfan.ind.br
 0.0.0.0 pmglance.startwriteup.com
 0.0.0.0 pokojewewladyslawowie.pl
@@ -779,15 +780,13 @@
 0.0.0.0 posmicrosystems.com
 0.0.0.0 poulman.panagiotopoulos-tours.gr
 0.0.0.0 ppdb.smk-ciptaskill.sch.id
-0.0.0.0 pptvideotemplates.com
 0.0.0.0 prestasicash.com.ar
 0.0.0.0 prestigehomeautomation.net
 0.0.0.0 prishaartcreations.com
 0.0.0.0 production.sparshims.com
-0.0.0.0 productprecise.com
-0.0.0.0 prof-dr-ahmedalmoatasem.com
 0.0.0.0 programaoperadoronline.com.br
 0.0.0.0 project.exquitec.com
+0.0.0.0 promolyko.com
 0.0.0.0 promotoradescomplica.com.br
 0.0.0.0 promoversdubai.com
 0.0.0.0 propertiq.elin.co.za
@@ -800,7 +799,7 @@
 0.0.0.0 pujashoppe.in
 0.0.0.0 punchdialogues.com
 0.0.0.0 punjabdevelopersassociation.com.pk
-0.0.0.0 purefoe.top
+0.0.0.0 pvcprinting.co.uk
 0.0.0.0 qadir.tickfa.ir
 0.0.0.0 qatarglobalconsulting.com
 0.0.0.0 qmsled.com
@@ -816,7 +815,6 @@
 0.0.0.0 ravenproductionsltd.com
 0.0.0.0 rc.ixiaoyang.cn
 0.0.0.0 readymmade.com
-0.0.0.0 realtheprocess.co
 0.0.0.0 redchillicrackers.com
 0.0.0.0 reifenquick.de
 0.0.0.0 relaxindulge.co.nz
@@ -866,7 +864,6 @@
 0.0.0.0 sarakem.cl
 0.0.0.0 sasystemsuk.com
 0.0.0.0 savasaachi.systems
-0.0.0.0 savingchintu.com
 0.0.0.0 scarfaceindustries.com
 0.0.0.0 scglobal.co.th
 0.0.0.0 schalke04rss.de
@@ -874,10 +871,8 @@
 0.0.0.0 schoolbustracker.softgig.co.ke
 0.0.0.0 sec-doc-w.com
 0.0.0.0 secure-doc-reader.com
-0.0.0.0 sefp-boispro.fr
 0.0.0.0 segalsmetals.elin.co.za
 0.0.0.0 sellmyphonela.com
-0.0.0.0 selltechtoday.com
 0.0.0.0 senbiaojita.com
 0.0.0.0 sentierodelviandante.ml
 0.0.0.0 serendibsourcing.com
@@ -894,7 +889,6 @@
 0.0.0.0 shivakunwar.com.np
 0.0.0.0 shoblasaathitrust.org
 0.0.0.0 shooka-co.com
-0.0.0.0 shop.clarostudio.ro
 0.0.0.0 shop.goldspot.agency
 0.0.0.0 shopsofe.com
 0.0.0.0 shrushtiinfotech.com
@@ -906,11 +900,11 @@
 0.0.0.0 simoneporzi.it
 0.0.0.0 simplithy.co.uk
 0.0.0.0 sindicato1ucm.cl
+0.0.0.0 sindpol.tiejuris.com.br
 0.0.0.0 sinergidwireka.com
 0.0.0.0 sipahielektrik.com
 0.0.0.0 siperb.in
 0.0.0.0 sistelligent.com
-0.0.0.0 site.sjc.co.ke
 0.0.0.0 skkksolo.beweiretail.com
 0.0.0.0 skyflyfares.com
 0.0.0.0 skyscan.com
@@ -920,7 +914,6 @@
 0.0.0.0 smokeandgrowrichtour.com
 0.0.0.0 smokesolutionindia.com
 0.0.0.0 sobethuacademy.com
-0.0.0.0 soft.110route.com
 0.0.0.0 soft.officelabo.net
 0.0.0.0 sohs.conceptechs.info
 0.0.0.0 solar.amazingtribe.lk
@@ -929,11 +922,11 @@
 0.0.0.0 somir.com.mx
 0.0.0.0 soralapps.com
 0.0.0.0 sorteio.orgaostalita.com.br
+0.0.0.0 sosgsm.fr
 0.0.0.0 sota-france.fr
 0.0.0.0 sowingminerals.cl
 0.0.0.0 space.proactint.org
 0.0.0.0 spaceframe.mobi.space-frame.co.za
-0.0.0.0 specfloors.net
 0.0.0.0 special-key.cf
 0.0.0.0 spent.com.pl
 0.0.0.0 spetsesyachtcharter.gr
@@ -965,6 +958,7 @@
 0.0.0.0 support-4-free.com
 0.0.0.0 support.clz.kr
 0.0.0.0 supportit.online
+0.0.0.0 surestdysbonescagexc.dns.army
 0.0.0.0 sw.yourpageserver.com
 0.0.0.0 sweaty.dk
 0.0.0.0 sweet-diet.com
@@ -990,11 +984,11 @@
 0.0.0.0 tc.snpsresidential.com
 0.0.0.0 tcy.198424.com
 0.0.0.0 tdsp.yngw518.com
-0.0.0.0 tech332.synology.me
 0.0.0.0 techgms.com
 0.0.0.0 technogreen.crmmanivela.com
 0.0.0.0 technohub.searchkero.com
 0.0.0.0 tecnicaencolectores.com.mx
+0.0.0.0 tecnologyschool.com
 0.0.0.0 teduae.com
 0.0.0.0 teleargentina.com
 0.0.0.0 telescopelms.com
@@ -1002,9 +996,9 @@
 0.0.0.0 temptmag.com
 0.0.0.0 tennisafrica.com
 0.0.0.0 tentandoserfitness.000webhostapp.com
-0.0.0.0 tepresto.net.pe
 0.0.0.0 test.adventser.com
 0.0.0.0 test.letraele.es
+0.0.0.0 test.typoten.com
 0.0.0.0 test.wanepghana.org
 0.0.0.0 test1.asistencia247.com
 0.0.0.0 test1.milenial.id
@@ -1017,9 +1011,7 @@
 0.0.0.0 teteaffiche.stephanebillon.com
 0.0.0.0 tewoerd.eu
 0.0.0.0 textile.softberg.ro
-0.0.0.0 texts.bfftexts.com
 0.0.0.0 texturesbyvinita.com
-0.0.0.0 tharringtonsponsorship.com
 0.0.0.0 thecleaningladiespdx.com
 0.0.0.0 thecreativecafe.co.uk
 0.0.0.0 thefuturelife.in
@@ -1027,12 +1019,11 @@
 0.0.0.0 thehouseofpragya.com
 0.0.0.0 thekassia.co.uk
 0.0.0.0 thelaunchpadteam.com
-0.0.0.0 thelekhak.com
 0.0.0.0 thelogicalgroup.co.uk
 0.0.0.0 thesummitpc.net
 0.0.0.0 theurbantutors.com
+0.0.0.0 thewwpc.com
 0.0.0.0 thosewebbs.com
-0.0.0.0 thriveink.com
 0.0.0.0 tianangdep.com
 0.0.0.0 tickfood.tickme.lk
 0.0.0.0 tickjobs.tickme.lk
@@ -1065,7 +1056,6 @@
 0.0.0.0 tulli.info
 0.0.0.0 tupperware.michaelroberge.ca
 0.0.0.0 turanggaresources.com
-0.0.0.0 tushartyagiji.digitalswagger.in
 0.0.0.0 uat.indianfilmzone.com
 0.0.0.0 ublretailerdemo.cstdevs.com
 0.0.0.0 udesk.searchkero.com
@@ -1075,7 +1065,6 @@
 0.0.0.0 unicorpbrunei.com
 0.0.0.0 uniengrisb.com
 0.0.0.0 unisoftcc.com
-0.0.0.0 unitedpestsolutionstx.com
 0.0.0.0 unyazitelecom.com
 0.0.0.0 upcbpta.com
 0.0.0.0 urbane.dezinetimes.com
@@ -1102,17 +1091,18 @@
 0.0.0.0 vivationdesign.com
 0.0.0.0 viveirodoiscorregos.com.br
 0.0.0.0 vksales.com
+0.0.0.0 vladimirinternational.com
 0.0.0.0 vokasi.ub.ac.id
 0.0.0.0 vologroup.com.br
 0.0.0.0 voteyouramerica.dekitout.com
 0.0.0.0 vstsample.com
 0.0.0.0 vtube.fadlymotivator.com
 0.0.0.0 vvsskmodinationalschool.com
-0.0.0.0 wahrewah.nl
 0.0.0.0 wanepliberia.org
 0.0.0.0 wanepniger.org
 0.0.0.0 weareactum.com
 0.0.0.0 web.eng.ubu.ac.th
+0.0.0.0 web.geetle.ga
 0.0.0.0 web.geomegasoft.net
 0.0.0.0 web.newinnovationtechnology.com
 0.0.0.0 web.smarts-works.com
@@ -1126,13 +1116,12 @@
 0.0.0.0 whcms.yourpageserver.com
 0.0.0.0 whiteglovetailgate.com
 0.0.0.0 whiteresponse.com
+0.0.0.0 whynt.xyz
 0.0.0.0 wi522012.ferozo.com
 0.0.0.0 wikalen.co.za
 0.0.0.0 wildnights.co.uk
 0.0.0.0 wildtrust.mediadevstaging.com
 0.0.0.0 wimbamusica.com
-0.0.0.0 windcomtechnologies.com
-0.0.0.0 winnercircle.it
 0.0.0.0 wishesconcierge.com
 0.0.0.0 woezon.agency
 0.0.0.0 wolfgang-brodte.de
@@ -1148,7 +1137,6 @@
 0.0.0.0 xia.beihaixue.com
 0.0.0.0 xixaoclothing.com
 0.0.0.0 xk.996is.com
-0.0.0.0 xmp.myracingaccounts.com
 0.0.0.0 xn--80akinnkiib6h.xn--90ais
 0.0.0.0 xn--polimerbizmimarlk-rvc.com
 0.0.0.0 ybom.urbanolab.com
@@ -1159,5 +1147,6 @@
 0.0.0.0 yskadvisors.com
 0.0.0.0 yummyyogaudaipur.com
 0.0.0.0 yzkzixun.com
+0.0.0.0 zakra.tecnasulstore.com.br
 0.0.0.0 zytrox.tk
 0.0.0.0 zz.690tx.com
diff --git a/urlhaus-filter-hosts.txt b/urlhaus-filter-hosts.txt
index 9a4c7129..d5cc13bd 100644
--- a/urlhaus-filter-hosts.txt
+++ b/urlhaus-filter-hosts.txt
@@ -1,5 +1,5 @@
 # Title: Malicious Hosts Blocklist
-# Updated: Thu, 25 Mar 2021 12:12:40 UTC
+# Updated: Fri, 26 Mar 2021 00:12:29 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -2496,6 +2496,7 @@
 0.0.0.0 access-24.jp
 0.0.0.0 access-cash.ae.org
 0.0.0.0 access-om.neomeric.us
+0.0.0.0 access-one.us
 0.0.0.0 access-to-web.com
 0.0.0.0 accessclub.jp
 0.0.0.0 accessdig.com
@@ -2673,6 +2674,7 @@
 0.0.0.0 acht-stuecken.de
 0.0.0.0 achuanchaolihai.cn
 0.0.0.0 aci.serabd.com
+0.0.0.0 aciabogados.com
 0.0.0.0 aciitaly.com
 0.0.0.0 acilevarkadasi.com
 0.0.0.0 acilisbalon.com
@@ -3089,6 +3091,7 @@
 0.0.0.0 admin.greenlightcr.com
 0.0.0.0 admin.hopehorseback.org
 0.0.0.0 admin.jpcar.mystand.pt
+0.0.0.0 admin.mobilezenie.com
 0.0.0.0 admin.searchlowestprice.com
 0.0.0.0 admin.solissol.com
 0.0.0.0 admin.staging.buildsmart.io
@@ -3268,7 +3271,6 @@
 0.0.0.0 adventureexplorer.in
 0.0.0.0 adventurehr.com
 0.0.0.0 adventureitdate.com
-0.0.0.0 adventureits.com
 0.0.0.0 adventuremania.com
 0.0.0.0 adventurersafaris.com
 0.0.0.0 adventuresofarchibald.com
@@ -3688,6 +3690,7 @@
 0.0.0.0 agengarcinia5000.com
 0.0.0.0 agenity.com
 0.0.0.0 agenlama.com
+0.0.0.0 agenmovie.xyz
 0.0.0.0 agent-seo.jp
 0.0.0.0 agent.ken.by
 0.0.0.0 agent2.icu
@@ -10704,6 +10707,7 @@
 0.0.0.0 barcelonaevent.es
 0.0.0.0 barcelonakartingcenter.com
 0.0.0.0 barchaklem.com
+0.0.0.0 barcionstw.eastus.cloudapp.azure.com
 0.0.0.0 barcla.ug
 0.0.0.0 barclaysdownloads.com
 0.0.0.0 barcoofoods.ir
@@ -12989,6 +12993,7 @@
 0.0.0.0 bj5800.com
 0.0.0.0 bjarndahl.dk
 0.0.0.0 bjbus.net
+0.0.0.0 bjconstructions.in
 0.0.0.0 bjdd.org
 0.0.0.0 bjenkins.webview.consulting
 0.0.0.0 bjenzer.com
@@ -14028,6 +14033,7 @@
 0.0.0.0 bnpartnersweb.com
 0.0.0.0 bnpgrup.com
 0.0.0.0 bnqzjy.cn
+0.0.0.0 bnrbook.com
 0.0.0.0 bnrnews.id
 0.0.0.0 bnsddfhjdfgvbxc.ru
 0.0.0.0 bnsgroupbd.com
@@ -14778,6 +14784,7 @@
 0.0.0.0 braner.com.ua
 0.0.0.0 branfinancial.com
 0.0.0.0 branner-chile.com
+0.0.0.0 brannon-powlowski25d.xyz
 0.0.0.0 brannudd.com
 0.0.0.0 brantech.com
 0.0.0.0 brar.aminfortgreene.com
@@ -15778,6 +15785,7 @@
 0.0.0.0 buysellfx24.ru
 0.0.0.0 buysmart365.net
 0.0.0.0 buysmartwebmall.com
+0.0.0.0 buythebest.pk
 0.0.0.0 buytotake.online
 0.0.0.0 buytwitterlike.com
 0.0.0.0 buyuksigorta.com
@@ -17098,6 +17106,7 @@
 0.0.0.0 cashoutrefitips.com
 0.0.0.0 cashpickup.slmicrocredit.com
 0.0.0.0 cashslip.info
+0.0.0.0 cashtunel.com
 0.0.0.0 cashyinvestment.org
 0.0.0.0 casimiroartes.es
 0.0.0.0 casinarium.com
@@ -19670,6 +19679,7 @@
 0.0.0.0 clubzone.ca
 0.0.0.0 cluebazar.com
 0.0.0.0 clukva.ru
+0.0.0.0 clurbgolf.com
 0.0.0.0 clurit.com
 0.0.0.0 clusdirectory.xyz
 0.0.0.0 cluster-mixture.gq
@@ -19886,6 +19896,7 @@
 0.0.0.0 coastmedicalservice.com
 0.0.0.0 coastmotorsupply.com
 0.0.0.0 coastsignworks.com
+0.0.0.0 coastwidewaterproofing.com.au
 0.0.0.0 coatforwinter.com
 0.0.0.0 coavce.com
 0.0.0.0 cobam.xyz
@@ -21909,6 +21920,7 @@
 0.0.0.0 cronolux.com.br
 0.0.0.0 croodly.com
 0.0.0.0 crookedchristicraddick.com
+0.0.0.0 crooks-cooper24g.xyz
 0.0.0.0 croos.org
 0.0.0.0 crope.shop
 0.0.0.0 cropfoods.com
@@ -23163,7 +23175,6 @@
 0.0.0.0 dar-sana.com
 0.0.0.0 darajelita.com
 0.0.0.0 daralsalam-mall.com
-0.0.0.0 daralsaqi.com
 0.0.0.0 darapartment.com
 0.0.0.0 darasrszs.online
 0.0.0.0 darassalam.ch
@@ -23272,7 +23283,6 @@
 0.0.0.0 dasheriemagazine.com
 0.0.0.0 dashfiles.tk
 0.0.0.0 dashkevichseo.ru
-0.0.0.0 dashonweb.com
 0.0.0.0 dashudance.com
 0.0.0.0 dashvaanjil.mn
 0.0.0.0 dasin-obchudek.cz
@@ -23600,6 +23610,7 @@
 0.0.0.0 dbravo.pro
 0.0.0.0 dbs-ebank.com
 0.0.0.0 dbsa-dream.com
+0.0.0.0 dbsandbox.ca
 0.0.0.0 dbsenvironmental.co.uk
 0.0.0.0 dbsgear.com
 0.0.0.0 dbsktoporder.yolasite.com
@@ -24508,6 +24519,7 @@
 0.0.0.0 denmaar.hplbusiness.com
 0.0.0.0 denmarkheating.net
 0.0.0.0 denmaytre.vn
+0.0.0.0 dennis-hill25lw.xyz
 0.0.0.0 dennis-roth.de
 0.0.0.0 dennishester.com
 0.0.0.0 dennisisasshole.com
@@ -27184,6 +27196,9 @@
 0.0.0.0 down.posti-fi-fsa.top
 0.0.0.0 down.posti-fi-fsaq.top
 0.0.0.0 down.posti-fi-fwa.top
+0.0.0.0 down.posti-fi-ij.top
+0.0.0.0 down.posti-fi-in.top
+0.0.0.0 down.posti-fi-iz.top
 0.0.0.0 down.pzchao.com
 0.0.0.0 down.qm188.com
 0.0.0.0 down.qqfarmer.com.cn
@@ -29395,6 +29410,7 @@
 0.0.0.0 egyptmotours.com
 0.0.0.0 egyptpharaohstours.com
 0.0.0.0 egyshadowmen.com
+0.0.0.0 egyutthato.eu
 0.0.0.0 egyuttkonnyebb.zolitoth.com
 0.0.0.0 egyvision.medicahealthy.net
 0.0.0.0 egywebtest.ml
@@ -30576,6 +30592,7 @@
 0.0.0.0 ennessehospitality.id
 0.0.0.0 ennovate.elin.co.za
 0.0.0.0 eno.si
+0.0.0.0 enolil-loo.com
 0.0.0.0 enorichie.net
 0.0.0.0 enorka.info
 0.0.0.0 enosburgreading.pbworks.com
@@ -32549,6 +32566,7 @@
 0.0.0.0 faithcompassion.com
 0.0.0.0 faithconstructionltd.co.uk
 0.0.0.0 faithfight.my.id
+0.0.0.0 faithmethodistcheras.org
 0.0.0.0 faithmontessorischools.com
 0.0.0.0 faithoasis.000webhostapp.com
 0.0.0.0 faithworkx.com
@@ -33819,6 +33837,7 @@
 0.0.0.0 findyourvoice.ca
 0.0.0.0 fine-art-line.de
 0.0.0.0 fine.black
+0.0.0.0 fineartgallerym.com
 0.0.0.0 fineconera.com
 0.0.0.0 finefeather.info
 0.0.0.0 finefoodsfrozen.com
@@ -37447,6 +37466,7 @@
 0.0.0.0 girltalkza.co.za
 0.0.0.0 girlydesignart.com
 0.0.0.0 gironynavarro.com
+0.0.0.0 girotexuniformes.com
 0.0.0.0 girraj2016.gtranzit.com
 0.0.0.0 girrajwadi.com
 0.0.0.0 gisa.company
@@ -37536,6 +37556,7 @@
 0.0.0.0 glafka.com
 0.0.0.0 glambooth.nl
 0.0.0.0 glamoroushairextension.com
+0.0.0.0 glamorouspk.com
 0.0.0.0 glamour.rosolutions.com.mx
 0.0.0.0 glamourgarden-lb.com
 0.0.0.0 glamourlounge.org
@@ -38292,6 +38313,7 @@
 0.0.0.0 gordonmilktransport.com
 0.0.0.0 gordonruss.com
 0.0.0.0 gordyssensors.com
+0.0.0.0 gorecycle.fahadjutt.com
 0.0.0.0 gorenotoservisi.net
 0.0.0.0 gorestruly.com
 0.0.0.0 goretimmo.lu
@@ -39448,6 +39470,7 @@
 0.0.0.0 guneyaski.com
 0.0.0.0 gungazcomputer.co.ke
 0.0.0.0 gunk.insol.be
+0.0.0.0 gunma2u.com
 0.0.0.0 gunmak-com.tk
 0.0.0.0 gunnarasgeir.com
 0.0.0.0 gunnersexcavating.com
@@ -41799,6 +41822,7 @@
 0.0.0.0 hollywoodsmileeg.com
 0.0.0.0 holmdalehouse.co.uk
 0.0.0.0 holmesgroup-com.azurewebsites.net
+0.0.0.0 holmesprpmgmt.com
 0.0.0.0 holmnkolbas.com
 0.0.0.0 holmsater.se
 0.0.0.0 holod24.by
@@ -42492,6 +42516,7 @@
 0.0.0.0 hpmaytinhtaophongcach.com
 0.0.0.0 hpmwqjub.com
 0.0.0.0 hpq8fa.db.files.1drv.com
+0.0.0.0 hprosacco25i.xyz
 0.0.0.0 hprpc.cn
 0.0.0.0 hps-sk.sk
 0.0.0.0 hps.nz
@@ -45068,6 +45093,7 @@
 0.0.0.0 instantbonheur.fr
 0.0.0.0 instantcashflowtoday.com.ng
 0.0.0.0 instantclients.network
+0.0.0.0 instantindialoan.com
 0.0.0.0 instanttaxsolutions.mobi
 0.0.0.0 instanttechnology.com.au
 0.0.0.0 instantworldpay.com
@@ -45892,6 +45918,7 @@
 0.0.0.0 isciyizbiz.com
 0.0.0.0 iscleanone.com
 0.0.0.0 isclimatechangeahoax.com
+0.0.0.0 iscoegypt.com
 0.0.0.0 iscoming.ir
 0.0.0.0 iscon.com.br
 0.0.0.0 iscondisth.com
@@ -45947,7 +45974,6 @@
 0.0.0.0 iskro.textronic.info
 0.0.0.0 iskyservice.ru
 0.0.0.0 islaholics.com
-0.0.0.0 islamabadtrafficpolice.gov.pk
 0.0.0.0 islamabout.com
 0.0.0.0 islamappen.se
 0.0.0.0 islamforall.tv
@@ -47760,6 +47786,7 @@
 0.0.0.0 jollycharm.com
 0.0.0.0 jollyemma.com
 0.0.0.0 jolyscortinas.com.br
+0.0.0.0 jomansea.com
 0.0.0.0 jomar2020.com.br
 0.0.0.0 jomblo.com
 0.0.0.0 jomhermonex.com
@@ -49139,6 +49166,7 @@
 0.0.0.0 kasperskysecurity.club
 0.0.0.0 kasrasanatsepahan.com
 0.0.0.0 kassa.hostsites.ru
+0.0.0.0 kassandra5024d.xyz
 0.0.0.0 kassconnect.ru
 0.0.0.0 kasshmira.com
 0.0.0.0 kassohome.com.tr
@@ -49783,7 +49811,6 @@
 0.0.0.0 khannen.com.vn
 0.0.0.0 khannen.vn
 0.0.0.0 khanqahebrahimi.com
-0.0.0.0 khantil.com
 0.0.0.0 khantipong.com
 0.0.0.0 khaochills.com
 0.0.0.0 khaoden.tech
@@ -51645,6 +51672,7 @@
 0.0.0.0 lab.valvolari.it
 0.0.0.0 lab.ydigital.asia
 0.0.0.0 lab1.ozaki-kyousei.com
+0.0.0.0 lab18.it
 0.0.0.0 lab2.e-century.pl
 0.0.0.0 lab5.hu
 0.0.0.0 lab6.com.br
@@ -56683,6 +56711,7 @@
 0.0.0.0 manageitrisks.com
 0.0.0.0 management.vkims.com
 0.0.0.0 managementtop.id
+0.0.0.0 managemysalon.in
 0.0.0.0 managemyshoes.tools
 0.0.0.0 manageone.co.th
 0.0.0.0 manageprint.in
@@ -57064,6 +57093,7 @@
 0.0.0.0 marek-paysage-concept.fr
 0.0.0.0 marek.in
 0.0.0.0 marekvoprsal.cz
+0.0.0.0 marel.com.br
 0.0.0.0 marellengifts.com
 0.0.0.0 maremarius.pt
 0.0.0.0 marematto.it
@@ -58344,6 +58374,7 @@
 0.0.0.0 meditec.ma
 0.0.0.0 mediterraneavacanze.com
 0.0.0.0 meditheraphy.com
+0.0.0.0 meditreat.itwebservice.in
 0.0.0.0 meditsinanarodnaya.ru
 0.0.0.0 medius.ge
 0.0.0.0 mediusvp.com
@@ -60520,6 +60551,7 @@
 0.0.0.0 mojang.com.br
 0.0.0.0 mojehaftom.com
 0.0.0.0 mojewnetrza.pl
+0.0.0.0 mojno--vse.ru
 0.0.0.0 mojo-studios.co.uk
 0.0.0.0 mojorockstar.com
 0.0.0.0 mojstudent.net
@@ -61274,6 +61306,7 @@
 0.0.0.0 mrpower.ir
 0.0.0.0 mrprintoke.com
 0.0.0.0 mrquick.co.il
+0.0.0.0 mrsambarbershop.nl
 0.0.0.0 mrsbow.com
 0.0.0.0 mrsconnect.org
 0.0.0.0 mrsdiggs.com
@@ -61874,6 +61907,7 @@
 0.0.0.0 mvid.com
 0.0.0.0 mvidl.site
 0.0.0.0 mvisionproperties.com
+0.0.0.0 mvldesign.ca
 0.0.0.0 mvm368.com
 0.0.0.0 mvmskpd.com
 0.0.0.0 mvns.railfan.net
@@ -63208,6 +63242,7 @@
 0.0.0.0 nelsonhelps.com
 0.0.0.0 nelsonhostingcom.000webhostapp.com
 0.0.0.0 nelsonpto.org
+0.0.0.0 nelsonsbutchers.co.uk
 0.0.0.0 nelsonsilveti.com
 0.0.0.0 neltac.com
 0.0.0.0 nelyvos.nl
@@ -64542,7 +64577,6 @@
 0.0.0.0 no1angelsescort.com
 0.0.0.0 no1spinningfields.90degrees.digital
 0.0.0.0 no1websitedesigner.com
-0.0.0.0 no2politics.com
 0.0.0.0 no70.fun
 0.0.0.0 noabuseshere.top
 0.0.0.0 noach.nl
@@ -65832,6 +65866,7 @@
 0.0.0.0 ohako.com.my
 0.0.0.0 ohamburguer.com.br
 0.0.0.0 ohanadev.com
+0.0.0.0 ohatsbd.com
 0.0.0.0 ohdratdigital.com
 0.0.0.0 ohe.ie
 0.0.0.0 ohelloguyzzqq.com
@@ -66136,6 +66171,7 @@
 0.0.0.0 omagroup.ru
 0.0.0.0 omaharefugees.com
 0.0.0.0 omahduwur.com
+0.0.0.0 omaia.org
 0.0.0.0 omaint.ml
 0.0.0.0 omalleyco-my.sharepoint.com
 0.0.0.0 omalll.com
@@ -71766,6 +71802,7 @@
 0.0.0.0 promodont.com
 0.0.0.0 promokonyara.ru
 0.0.0.0 promolatinconferences.com
+0.0.0.0 promolyko.com
 0.0.0.0 promomitsubishitermurah.net
 0.0.0.0 promonoble.com
 0.0.0.0 promootzie.nl
@@ -73181,6 +73218,7 @@
 0.0.0.0 quickpickapp.co
 0.0.0.0 quickreachmedia.com
 0.0.0.0 quicksaleecuador.com
+0.0.0.0 quickshine.co.ke
 0.0.0.0 quickstorevn.com
 0.0.0.0 quicktechsupport247.com
 0.0.0.0 quicktowtowing.com
@@ -75282,6 +75320,7 @@
 0.0.0.0 rgdecor.org
 0.0.0.0 rgfloors.com.au
 0.0.0.0 rgitabit.in
+0.0.0.0 rgleason25s.xyz
 0.0.0.0 rglgrupomedico.com.mx
 0.0.0.0 rgmobilegossip.com
 0.0.0.0 rgmvanijya.com
@@ -76126,6 +76165,7 @@
 0.0.0.0 rosemaryromero.com.br
 0.0.0.0 rosemiracle.com
 0.0.0.0 rosemurphy.co.uk
+0.0.0.0 rosenbaum-jaida24nz.xyz
 0.0.0.0 rosenfeldcapital.com
 0.0.0.0 rosenlaw.cratima.com
 0.0.0.0 roseperfeito.com.br
@@ -80044,6 +80084,7 @@
 0.0.0.0 shatabbytek.com
 0.0.0.0 shataikok.com
 0.0.0.0 shatelnews.ir
+0.0.0.0 shatteredglass.io
 0.0.0.0 shaukya.com
 0.0.0.0 shaulla.store
 0.0.0.0 shaunodonnell.com
@@ -81905,6 +81946,7 @@
 0.0.0.0 smartlync.pk
 0.0.0.0 smartmadira.com
 0.0.0.0 smartmassive.ru
+0.0.0.0 smartmatrixs.com
 0.0.0.0 smartmobilelearning.co.za
 0.0.0.0 smartmoneylife.com
 0.0.0.0 smartmovie.com.ua
@@ -82867,6 +82909,7 @@
 0.0.0.0 sosenfantsburkinafaso.fr
 0.0.0.0 sosexymagazine.com
 0.0.0.0 sosflam.com
+0.0.0.0 sosgsm.fr
 0.0.0.0 sosh47.citycheb.ru
 0.0.0.0 sosoab.com
 0.0.0.0 sosofoto.cz
@@ -87503,6 +87546,7 @@
 0.0.0.0 tecnologiatech.com
 0.0.0.0 tecnologiaz.com
 0.0.0.0 tecnologicainformatica.com.br
+0.0.0.0 tecnologyschool.com
 0.0.0.0 tecnolora.com
 0.0.0.0 tecnoloxia.com
 0.0.0.0 tecnopc.info
@@ -90267,6 +90311,7 @@
 0.0.0.0 toby-warren.com
 0.0.0.0 tobyetc.com
 0.0.0.0 tobysherman.com
+0.0.0.0 tocaima.co
 0.0.0.0 tocakids.resultaweb.com.br
 0.0.0.0 tocgiajojo.com
 0.0.0.0 tochkae.ru
@@ -91394,6 +91439,7 @@
 0.0.0.0 tresnexus.com
 0.0.0.0 treterhef.download
 0.0.0.0 tretthing-bg.site
+0.0.0.0 treutel-jamir25ju.xyz
 0.0.0.0 trevellinglove.com
 0.0.0.0 trevinos.net
 0.0.0.0 trevorchristensen.com
@@ -94096,6 +94142,7 @@
 0.0.0.0 vastraindia.com
 0.0.0.0 vastralaya.shop
 0.0.0.0 vastuanalyst.com
+0.0.0.0 vastubless.com
 0.0.0.0 vastuvidyaarchitects.com
 0.0.0.0 vasudhagoodharvest.com
 0.0.0.0 vasumadhi.com
@@ -95441,6 +95488,7 @@
 0.0.0.0 vladetel.org
 0.0.0.0 vladimirfilin.com
 0.0.0.0 vladimirfilin.ru
+0.0.0.0 vladimirinternational.com
 0.0.0.0 vladneta.lt
 0.0.0.0 vladsever.ru
 0.0.0.0 vladsp.ru
@@ -96439,6 +96487,7 @@
 0.0.0.0 web.emergingsun.com
 0.0.0.0 web.emsfabrik.de
 0.0.0.0 web.eng.ubu.ac.th
+0.0.0.0 web.geetle.ga
 0.0.0.0 web.geomegasoft.net
 0.0.0.0 web.golden-goblin.com
 0.0.0.0 web.gotham.com.au
@@ -97253,6 +97302,7 @@
 0.0.0.0 whyasksolution.com
 0.0.0.0 whybowl.thebotogs.com
 0.0.0.0 whyepicshop.com
+0.0.0.0 whynt.xyz
 0.0.0.0 whysquare.co.nz
 0.0.0.0 whystudio.cn
 0.0.0.0 whytech.info
@@ -98320,6 +98370,7 @@
 0.0.0.0 wrrodrigo.com
 0.0.0.0 wrtech.com.pl
 0.0.0.0 wrusnollet.com
+0.0.0.0 wrzucacz.pl
 0.0.0.0 wrzutka.co
 0.0.0.0 ws-ebavisapia01-dll.ir
 0.0.0.0 ws3lfkm.com
@@ -98767,6 +98818,7 @@
 0.0.0.0 xhcmnews.com
 0.0.0.0 xhd.qhv.mybluehost.me
 0.0.0.0 xhencheng.tk
+0.0.0.0 xherzog24pv.xyz
 0.0.0.0 xhjclq.ch.files.1drv.com
 0.0.0.0 xhs9a81.com
 0.0.0.0 xhsdxm.com
@@ -100626,6 +100678,7 @@
 0.0.0.0 zafirotiendas.com
 0.0.0.0 zagnet.pl
 0.0.0.0 zagogulina.com
+0.0.0.0 zagoradesertcamp.com
 0.0.0.0 zagrodazbyszka.pl
 0.0.0.0 zagros-shahrekord.ir
 0.0.0.0 zagrosenergygroup.com
@@ -100681,6 +100734,7 @@
 0.0.0.0 zakopane.utazas.hu
 0.0.0.0 zakopanedomki.com.pl
 0.0.0.0 zakosciele66.cba.pl
+0.0.0.0 zakra.tecnasulstore.com.br
 0.0.0.0 zakrahgroup.com
 0.0.0.0 zakriasons.co
 0.0.0.0 zakromanoff.com
diff --git a/urlhaus-filter-online.tpl b/urlhaus-filter-online.tpl
index 5a4efa57..0747b9bb 100644
--- a/urlhaus-filter-online.tpl
+++ b/urlhaus-filter-online.tpl
@@ -1,6 +1,6 @@
 msFilterList
 # Title: Online Malicious Hosts Blocklist (IE)
-# Updated: Thu, 25 Mar 2021 12:12:40 UTC
+# Updated: Fri, 26 Mar 2021 00:12:29 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -22,7 +22,6 @@ msFilterList
 -d 360down7.miiyun.cn
 -d 8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com
 -d 8poieq.bn.files.1drv.com
--d 99centsdigitals.com
 -d abcd.bg
 -d abclicks.in
 -d abissnet.net
@@ -30,11 +29,12 @@ msFilterList
 -d absoftechworld.com
 -d absupplies.co.uk
 -d abyssos.eu
+-d academyshademani.com
 -d acbick.com
 -d accounts.thesmarttechhub.com
 -d aceeprc.com.aceeprc.com
 -d acellr.co.uk
--d aclassapart.in
+-d aciabogados.com
 -d acteon.com.ar
 -d activateyourdiscount.com
 -d activecost.com.au
@@ -52,6 +52,7 @@ msFilterList
 -d agenciadigitalwdys.com
 -d agenciatabletshouse.com.br
 -d agenda.gmelloinformatica.com.br
+-d agenmovie.xyz
 -d agentt.ac.ug
 -d agile8studio.com
 -d agmcarpetcare.co.uk
@@ -63,7 +64,6 @@ msFilterList
 -d alasdemariposas.org
 -d alemelektronik.com
 -d alena1971.es
--d alertlauncher.fr
 -d alexdubai.com.aldiabsteel.com
 -d alka.institute
 -d allforcreative.com.au
@@ -75,6 +75,7 @@ msFilterList
 -d amarteargentina.com.ar
 -d amenyan.zouri.jp
 -d amos524.org
+-d ams.alvinasschools.org.ng
 -d anantam.net.in
 -d andreelapeyre.com
 -d andremaraisbeleggings.co.za
@@ -94,10 +95,9 @@ msFilterList
 -d aplicativoparasindicato.com.br
 -d apoolcondo.com
 -d app.adsensearticle.com
--d app.explicitsurveys.co.uk
 -d app.prerana.info
 -d apps.saintsoporte.com
--d aras.iuc.ac
+-d aqv.news
 -d areyoulivingwell.com
 -d arsapetrolab.com
 -d artedibujoyarquitectura.com
@@ -116,11 +116,12 @@ msFilterList
 -d ayamallah.com
 -d azmeasurement.com
 -d azraktours.com
--d b2b.toptanakaryakit.com.tr
 -d backgrounds.pk
 -d backup.agewsage.com
 -d badeggdesign.com
+-d balealgodon.mx
 -d bangkok-orchids.com
+-d barcionstw.eastus.cloudapp.azure.com
 -d bary.sz4h.com
 -d basma.com.kw
 -d bausch.kr-atlas.monaxikoslykos@zytrox.tk
@@ -129,7 +130,6 @@ msFilterList
 -d bcmt.elin.co.za
 -d bcrg.co.za
 -d bearcatpumps.com.cn
--d beatyamerican.com
 -d beautincollagen.rs
 -d bekape.co.id
 -d bespokeweddings.ie
@@ -137,6 +137,8 @@ msFilterList
 -d betone.co.kr
 -d betycopaints.com
 -d beveragesmiami.solucioneslink.com
+-d bhavaniengineering.com
+-d bigbag.wootraining.certificacion.cl
 -d bilbosaquet.ug
 -d bilhen.co.za
 -d billing.rahitechnosoft.com
@@ -144,11 +146,10 @@ msFilterList
 -d birminghamlink.org
 -d blog.callensaxen.com
 -d blog.oyinblogs.com
--d blog.takbelit.com
 -d bmlifestyle.co.uk
+-d bnrbook.com
 -d bnrnews.id
 -d bodenstein.co.za
--d bolnicaloznica.rs
 -d booksearch.com
 -d bounces.mi-fs.com
 -d bpo.correct.go.th
@@ -162,23 +163,21 @@ msFilterList
 -d brightstarshop.com
 -d browardinsurancemiami.solucioneslink.com
 -d bt2.elin.co.za
--d btdapi.robotake.com
 -d bucrinsuranlceonlines.com
 -d buenavista.co
--d buigiaphat.com.vn
 -d bullseyemedia.in
 -d busandvanrentalmalaysia.com
 -d buscascolegios.diit.cl
 -d business.softberg.ro
 -d buyingmusiconline.com
--d buypropertyfast.com
 -d bwsr.eu
 -d c.oooooooooo.ga
 -d c0140529.ferozo.com
+-d caballo.com.au
 -d cacapavaonline.sdserver144.com.br
+-d calgaryautorepairservice.com
 -d callbury.in
 -d camminachetipassa.it
--d campusvirtual.cepsanjuanbosco.net.pe
 -d cancer.educandome.co
 -d capitalgroup-kw.com
 -d capitalnewsagency.com
@@ -191,12 +190,10 @@ msFilterList
 -d ccauthority.net
 -d cdaonline.com.ar
 -d cec.asso.ac-amiens.fr
--d cellas.sk
 -d cendekiabinaaksara.com
 -d cespol-bote.com.mx
 -d cfs5.tistory.com
 -d ch.rmu.ac.th
--d changematterscounselling.com
 -d chardhamdodham.com
 -d cheacrilnsurances.com
 -d chealablilitycarinsurances.com
@@ -204,15 +201,14 @@ msFilterList
 -d childselect.com
 -d chinhdropfile.myvnc.com
 -d chinhdropfile80.myvnc.com
--d chipmania.it
 -d cible-energy.com
 -d cifeer.net
 -d citycapproperty.ru
 -d cityglobalgospel.com
 -d civi.istmejia.com
 -d cleanbydesignllc.com
--d clim34000.fr
 -d cloud.fc.co.mz
+-d clurbgolf.com
 -d codsambal.com
 -d colinde.pricesne.com
 -d colorpak.pl
@@ -234,7 +230,6 @@ msFilterList
 -d crecerco.com
 -d crittersbythebay.com
 -d crm.notariavieitoyvelamazan.com
--d crmmanivela.net
 -d crscorretordeimoveis.com.br
 -d cse-engineer.com
 -d csnserver.com
@@ -281,7 +276,6 @@ msFilterList
 -d detorre.es
 -d dev-interestingtech.pantheonsite.io
 -d dev.sebpo.net
--d dezcom.com
 -d dfcf.91756.cn
 -d dfsfcsfcdsfsdvcfsvcscv.com
 -d diamantenegro.mi-fs.com
@@ -304,7 +298,6 @@ msFilterList
 -d doncedyhall.com
 -d donghobinhminh.com
 -d dongphuctop.com
--d donwnloasecury.ath.cx
 -d dosame.com
 -d dosman.pl
 -d dovberger.com
@@ -312,6 +305,9 @@ msFilterList
 -d down.pcclear.com
 -d down.posti-fi-fsa.top
 -d down.posti-fi-fwa.top
+-d down.posti-fi-ij.top
+-d down.posti-fi-in.top
+-d down.posti-fi-iz.top
 -d down.udashi.com
 -d down.webbora.com
 -d down1.arpun.com
@@ -328,7 +324,6 @@ msFilterList
 -d drbaby.com.sa
 -d drohnen.ensenanzainteligente.com
 -d drools-moved.46999.n3.nabble.com
--d drrohanfonseca.com
 -d drsha.innovativesolutions.mobi
 -d dsenterprize.co.za
 -d dsspainting.com
@@ -342,19 +337,15 @@ msFilterList
 -d e.sldov.ru
 -d ebruyatkin.com
 -d econews.treegle.org
--d edelweissdecoration.com
 -d efficientegroup.com
 -d elliot.newreadermedia.net
--d emaids.co.za
 -d en.baoend.com
 -d enc-tech.com
 -d endurotanzania.co.tz
--d enkonooh.com
 -d ennovate.elin.co.za
 -d enriquecendocomconsorcio.com.br
 -d envios.petpienso.cl
 -d equimination.ee
--d es.paymelist.com
 -d escola.probommar.org.br
 -d esnconsultants.com
 -d essentia.org.br
@@ -366,15 +357,14 @@ msFilterList
 -d f1sol.com
 -d familydentist.site
 -d farmaciasdrogaminas.com.br
--d farmnatural.in
 -d faveraprojects.com
 -d fc.co.mz
 -d felicienne.nl
 -d fi.bonitastores.com
 -d files.martellexpress.us
 -d files6.uludagbilisim.com
--d filmotainment.com
 -d final.makkahkmcc.com
+-d fineartgallerym.com
 -d fkd.derpcity.ru
 -d flintspin.com
 -d flyingbuddhadesign.com
@@ -382,20 +372,17 @@ msFilterList
 -d fms.buladde.or.ug
 -d foothills.com.br
 -d footweardirect.elin.co.za
--d formestore.evencsoft.co
 -d forum.mdb.nu
 -d fotoobjetivo.com
 -d foundationrepairhoustontx.net
 -d foxeps.com.br
 -d freecnetdownload.com
--d freedombookshop.tickme.lk
 -d freisites.com.br
 -d ftp.n3twork30cm.ml
 -d fullelectronica.com.ar
 -d funletters.net
 -d fusionfiresolutions.com
 -d futuregraphics.com.ar
--d gahanassociates.com
 -d gametwogame.com
 -d garayvidalabogados.com
 -d garciadogshow.com
@@ -403,7 +390,6 @@ msFilterList
 -d garenanow4.myvnc.com
 -d gbbulls.co.uk
 -d gcpc.co.id.chronoscurtain.com
--d gcrcorporation.com
 -d generaldeviales.com
 -d gfmodd1.webselffiles01.com
 -d gfold1.webselffiles01.com
@@ -411,6 +397,8 @@ msFilterList
 -d ghislain.dartois.pagesperso-orange.fr
 -d giadungg7.com
 -d giddos.ga
+-d gilliem.com
+-d girotexuniformes.com
 -d giteletropical.com
 -d globaltask.ar
 -d glowinmedia.co.ke
@@ -425,10 +413,12 @@ msFilterList
 -d goldcupmortgage.com
 -d golden-memories-funerals.yourpageserver.com
 -d goldmen.in
+-d gorecycle.fahadjutt.com
 -d gracejukes.com
 -d grupoinmare.com
 -d gruposelt.000webhostapp.com
 -d gs.monerorx.com
+-d guide-to-cell-phones.com
 -d gulfac-house.com
 -d gvpcdpgc.edu.in
 -d habbotips.free.fr
@@ -454,6 +444,7 @@ msFilterList
 -d hmpmall.co.kr
 -d hoagietesting10.com
 -d hoayeuthuong-my.sharepoint.com
+-d holmesprpmgmt.com
 -d homefindersolutions.com
 -d hongluosi.com
 -d hookedupboatclub.com
@@ -465,7 +456,6 @@ msFilterList
 -d hsmwebapp.com
 -d htownbars.com
 -d hubtech.co.za
--d huequito.evencsoft.co
 -d hunggiang.vn
 -d husamiyahschool.com
 -d iam313.com
@@ -477,6 +467,7 @@ msFilterList
 -d iesanjosemonitos.edu.co
 -d ikexpert.com
 -d ilrafrica.com
+-d images.jermiau.com
 -d imbueautoworx.co.za
 -d imperiumtherapy.co.za
 -d in-tune2016.com
@@ -491,6 +482,7 @@ msFilterList
 -d inovations.searchkero.com
 -d inrajahmundry.co.in
 -d insignificantfinecore.testmail4.repl.co
+-d instantindialoan.com
 -d instvisionmexico.edu.mx
 -d intellectsmart.in
 -d intersel-idf.org
@@ -501,6 +493,7 @@ msFilterList
 -d iremart.es
 -d iris101.co.uk
 -d iscamenabe.com
+-d ismf.com.ng
 -d iso-dubai.net
 -d israrulhaq.me
 -d isrorg.com
@@ -521,7 +514,6 @@ msFilterList
 -d jiaoyuzixun.cn
 -d jing-da.com.tw
 -d jktnet.xyz
--d jmcomputacion.com.ar
 -d jmtc.91756.cn
 -d jnanbharati.com
 -d jobs.thebeessolution.com
@@ -530,9 +522,7 @@ msFilterList
 -d josegene.com
 -d josuarochoa.com
 -d jpwoodfordco.com
--d julietlaser.site
 -d jumpmanualjacobhiller.com
--d jumpnjamchicago.com
 -d jupiter.toxsl.in
 -d jurgensen.newreadermedia.net
 -d justinscott.com.au
@@ -554,6 +544,7 @@ msFilterList
 -d kumaralok.in
 -d kwanfromhongkong.com
 -d kz.sldov.ru
+-d lab18.it
 -d lacasadelosalebrijes.com
 -d ladylabonde.com
 -d lameguard.ru
@@ -599,6 +590,7 @@ msFilterList
 -d lp.difusodesign.com
 -d lp.juancamilogarciareyes.com
 -d lp.tecnimasdecolombia.com.co
+-d ltc.typoten.com
 -d luckybrownie.com
 -d luminouspneuma.com
 -d luxomodels.com
@@ -607,15 +599,15 @@ msFilterList
 -d madicon.co.za
 -d magianegramagiablancayamarres.com
 -d mail.bs-eiendomme.co.za
+-d mail.golimoapp.com
 -d mail.jeffsono.org
 -d maksi.feb.unib.ac.id
 -d malaya.tv
 -d malwarecoding.github.io
 -d managed.oss-cn-beijing.aliyuncs.com
+-d managemysalon.in
 -d manantialesdelnorte.uy
--d manivelasst.com
 -d marcapinyo.ru
--d marcusthepoet.com
 -d mario-sunjic.com
 -d mariobrown.net
 -d mariotessarollo.com
@@ -624,7 +616,6 @@ msFilterList
 -d marksidfgs.ug
 -d masjidhabeebiyarazviya.mysunni.com
 -d materialescantu.com
--d matinal-nominal.pt
 -d matruchhaya.co.in
 -d mattysplayground.com
 -d maxtox.com.pk
@@ -636,6 +627,7 @@ msFilterList
 -d mediamaster.co.za
 -d medianews.ge
 -d medistaffconsulting.com
+-d meditreat.itwebservice.in
 -d meeweb.com
 -d megamart.afnan-amc.com
 -d merbay.ru
@@ -656,7 +648,6 @@ msFilterList
 -d mindfulbuildingandliving.com
 -d mingguanwms.com
 -d minuevavida.org
--d mirror.mypage.sk
 -d mis.nbcc.ac.th
 -d misterson.com
 -d mixr.at
@@ -664,12 +655,14 @@ msFilterList
 -d mktf.mx
 -d mmogollon.com.mx
 -d mncarteam.com
+-d mobile.illumetechnology.com
 -d modelhouseturkey.com
 -d modernmanna.org
 -d monetization.business
 -d moninediy.com
 -d mopai.sg
 -d motorcomunicacion.com
+-d msacontabil.com.br
 -d mtspsmjeli.sch.id
 -d muzimbiti.xigubo.co.mz
 -d mxpiqw.am.files.1drv.com
@@ -702,8 +695,8 @@ msFilterList
 -d nicolas.ug
 -d nidhi.iexist.in
 -d nikanpolimer.ir
+-d nilehouse.co.ug
 -d nilinkeji.com
--d nisacooks.com
 -d njtiledesigncenter.com
 -d nobius.org
 -d nocalnoodle.elin.co.za
@@ -721,10 +714,13 @@ msFilterList
 -d oakleyandfriends.co.uk
 -d obseques-conseils.com
 -d ocean.tecnasulstore.com.br
+-d ohe.ie
 -d ohsewgorgeous.co.uk
+-d oknoplastik.sk
 -d oleholeh.memangbeda.website
 -d olirecords.mixture.ltd
 -d olooom.com
+-d omaia.org
 -d omaromatic.com
 -d omega.az
 -d oms.pappai.com
@@ -733,6 +729,7 @@ msFilterList
 -d onedrive.listifyapp.co
 -d online.creedglobal.in
 -d onlinestatis.bar
+-d ont.proman.id
 -d open.warehousesaas.co.uk
 -d opolis.io
 -d optimus.com.sg
@@ -740,6 +737,8 @@ msFilterList
 -d order.bizpeed.com
 -d orientgatewayltd.com
 -d orion445.com
+-d oserve.pk
+-d otolithenrichment.fahadjutt.com
 -d ottimade.com
 -d ourteam.searchkero.com
 -d ozemag.com
@@ -761,6 +760,7 @@ msFilterList
 -d paths.elin.co.za
 -d paulmercier.biz
 -d payerrealty.com
+-d payments.atifsiddiqui.me
 -d pcsoori.com
 -d pd.oceaniarp.net
 -d perpus.onlineman7-jombang.sch.id
@@ -773,6 +773,7 @@ msFilterList
 -d photo360.kubooking.com
 -d photographytipsclub.com
 -d pink99.com
+-d pizzabarletta.com.br
 -d plasfan.ind.br
 -d pmglance.startwriteup.com
 -d pokojewewladyslawowie.pl
@@ -782,15 +783,13 @@ msFilterList
 -d posmicrosystems.com
 -d poulman.panagiotopoulos-tours.gr
 -d ppdb.smk-ciptaskill.sch.id
--d pptvideotemplates.com
 -d prestasicash.com.ar
 -d prestigehomeautomation.net
 -d prishaartcreations.com
 -d production.sparshims.com
--d productprecise.com
--d prof-dr-ahmedalmoatasem.com
 -d programaoperadoronline.com.br
 -d project.exquitec.com
+-d promolyko.com
 -d promotoradescomplica.com.br
 -d promoversdubai.com
 -d propertiq.elin.co.za
@@ -803,7 +802,7 @@ msFilterList
 -d pujashoppe.in
 -d punchdialogues.com
 -d punjabdevelopersassociation.com.pk
--d purefoe.top
+-d pvcprinting.co.uk
 -d qadir.tickfa.ir
 -d qatarglobalconsulting.com
 -d qmsled.com
@@ -819,7 +818,6 @@ msFilterList
 -d ravenproductionsltd.com
 -d rc.ixiaoyang.cn
 -d readymmade.com
--d realtheprocess.co
 -d redchillicrackers.com
 -d reifenquick.de
 -d relaxindulge.co.nz
@@ -869,7 +867,6 @@ msFilterList
 -d sarakem.cl
 -d sasystemsuk.com
 -d savasaachi.systems
--d savingchintu.com
 -d scarfaceindustries.com
 -d scglobal.co.th
 -d schalke04rss.de
@@ -877,10 +874,8 @@ msFilterList
 -d schoolbustracker.softgig.co.ke
 -d sec-doc-w.com
 -d secure-doc-reader.com
--d sefp-boispro.fr
 -d segalsmetals.elin.co.za
 -d sellmyphonela.com
--d selltechtoday.com
 -d senbiaojita.com
 -d sentierodelviandante.ml
 -d serendibsourcing.com
@@ -897,7 +892,6 @@ msFilterList
 -d shivakunwar.com.np
 -d shoblasaathitrust.org
 -d shooka-co.com
--d shop.clarostudio.ro
 -d shop.goldspot.agency
 -d shopsofe.com
 -d shrushtiinfotech.com
@@ -909,11 +903,11 @@ msFilterList
 -d simoneporzi.it
 -d simplithy.co.uk
 -d sindicato1ucm.cl
+-d sindpol.tiejuris.com.br
 -d sinergidwireka.com
 -d sipahielektrik.com
 -d siperb.in
 -d sistelligent.com
--d site.sjc.co.ke
 -d skkksolo.beweiretail.com
 -d skyflyfares.com
 -d skyscan.com
@@ -923,7 +917,6 @@ msFilterList
 -d smokeandgrowrichtour.com
 -d smokesolutionindia.com
 -d sobethuacademy.com
--d soft.110route.com
 -d soft.officelabo.net
 -d sohs.conceptechs.info
 -d solar.amazingtribe.lk
@@ -932,11 +925,11 @@ msFilterList
 -d somir.com.mx
 -d soralapps.com
 -d sorteio.orgaostalita.com.br
+-d sosgsm.fr
 -d sota-france.fr
 -d sowingminerals.cl
 -d space.proactint.org
 -d spaceframe.mobi.space-frame.co.za
--d specfloors.net
 -d special-key.cf
 -d spent.com.pl
 -d spetsesyachtcharter.gr
@@ -968,6 +961,7 @@ msFilterList
 -d support-4-free.com
 -d support.clz.kr
 -d supportit.online
+-d surestdysbonescagexc.dns.army
 -d sw.yourpageserver.com
 -d sweaty.dk
 -d sweet-diet.com
@@ -993,11 +987,11 @@ msFilterList
 -d tc.snpsresidential.com
 -d tcy.198424.com
 -d tdsp.yngw518.com
--d tech332.synology.me
 -d techgms.com
 -d technogreen.crmmanivela.com
 -d technohub.searchkero.com
 -d tecnicaencolectores.com.mx
+-d tecnologyschool.com
 -d teduae.com
 -d teleargentina.com
 -d telescopelms.com
@@ -1005,9 +999,9 @@ msFilterList
 -d temptmag.com
 -d tennisafrica.com
 -d tentandoserfitness.000webhostapp.com
--d tepresto.net.pe
 -d test.adventser.com
 -d test.letraele.es
+-d test.typoten.com
 -d test.wanepghana.org
 -d test1.asistencia247.com
 -d test1.milenial.id
@@ -1020,9 +1014,7 @@ msFilterList
 -d teteaffiche.stephanebillon.com
 -d tewoerd.eu
 -d textile.softberg.ro
--d texts.bfftexts.com
 -d texturesbyvinita.com
--d tharringtonsponsorship.com
 -d thecleaningladiespdx.com
 -d thecreativecafe.co.uk
 -d thefuturelife.in
@@ -1030,12 +1022,11 @@ msFilterList
 -d thehouseofpragya.com
 -d thekassia.co.uk
 -d thelaunchpadteam.com
--d thelekhak.com
 -d thelogicalgroup.co.uk
 -d thesummitpc.net
 -d theurbantutors.com
+-d thewwpc.com
 -d thosewebbs.com
--d thriveink.com
 -d tianangdep.com
 -d tickfood.tickme.lk
 -d tickjobs.tickme.lk
@@ -1068,7 +1059,6 @@ msFilterList
 -d tulli.info
 -d tupperware.michaelroberge.ca
 -d turanggaresources.com
--d tushartyagiji.digitalswagger.in
 -d uat.indianfilmzone.com
 -d ublretailerdemo.cstdevs.com
 -d udesk.searchkero.com
@@ -1078,7 +1068,6 @@ msFilterList
 -d unicorpbrunei.com
 -d uniengrisb.com
 -d unisoftcc.com
--d unitedpestsolutionstx.com
 -d unyazitelecom.com
 -d upcbpta.com
 -d urbane.dezinetimes.com
@@ -1105,17 +1094,18 @@ msFilterList
 -d vivationdesign.com
 -d viveirodoiscorregos.com.br
 -d vksales.com
+-d vladimirinternational.com
 -d vokasi.ub.ac.id
 -d vologroup.com.br
 -d voteyouramerica.dekitout.com
 -d vstsample.com
 -d vtube.fadlymotivator.com
 -d vvsskmodinationalschool.com
--d wahrewah.nl
 -d wanepliberia.org
 -d wanepniger.org
 -d weareactum.com
 -d web.eng.ubu.ac.th
+-d web.geetle.ga
 -d web.geomegasoft.net
 -d web.newinnovationtechnology.com
 -d web.smarts-works.com
@@ -1129,13 +1119,12 @@ msFilterList
 -d whcms.yourpageserver.com
 -d whiteglovetailgate.com
 -d whiteresponse.com
+-d whynt.xyz
 -d wi522012.ferozo.com
 -d wikalen.co.za
 -d wildnights.co.uk
 -d wildtrust.mediadevstaging.com
 -d wimbamusica.com
--d windcomtechnologies.com
--d winnercircle.it
 -d wishesconcierge.com
 -d woezon.agency
 -d wolfgang-brodte.de
@@ -1151,7 +1140,6 @@ msFilterList
 -d xia.beihaixue.com
 -d xixaoclothing.com
 -d xk.996is.com
--d xmp.myracingaccounts.com
 -d xn--80akinnkiib6h.xn--90ais
 -d xn--polimerbizmimarlk-rvc.com
 -d ybom.urbanolab.com
@@ -1162,5 +1150,6 @@ msFilterList
 -d yskadvisors.com
 -d yummyyogaudaipur.com
 -d yzkzixun.com
+-d zakra.tecnasulstore.com.br
 -d zytrox.tk
 -d zz.690tx.com
diff --git a/urlhaus-filter-online.txt b/urlhaus-filter-online.txt
index 9bb38bdf..8b1db68e 100644
--- a/urlhaus-filter-online.txt
+++ b/urlhaus-filter-online.txt
@@ -1,5 +1,5 @@
 ! Title: Online Malicious URL Blocklist
-! Updated: Thu, 25 Mar 2021 12:12:40 UTC
+! Updated: Fri, 26 Mar 2021 00:12:29 UTC
 ! Expires: 1 day (update frequency)
 ! Homepage: https://gitlab.com/curben/urlhaus-filter
 ! License: https://gitlab.com/curben/urlhaus-filter#license
@@ -12,7 +12,6 @@
 1.192.180.19
 1.222.140.251
 1.222.196.60
-1.24.132.118
 1.245.4.163
 1.246.222.107
 1.246.222.109
@@ -22,8 +21,10 @@
 1.246.222.153
 1.246.222.16
 1.246.222.165
+1.246.222.228
 1.246.222.232
 1.246.222.234
+1.246.222.237
 1.246.222.245
 1.246.222.249
 1.246.222.38
@@ -34,7 +35,6 @@
 1.246.222.69
 1.246.222.8
 1.246.222.80
-1.246.222.9
 1.246.222.98
 1.246.223.10
 1.246.223.103
@@ -66,23 +66,19 @@
 1.250.159.41
 1.252.102.28
 1.254.250.52
+1.58.223.96
 1.60.77.53
-1.62.195.101
 1.65.166.225
 1.82.104.89
-1.85.84.38
 100.12.184.63
 100.2.131.143
 100.8.77.4
 1008691.com
 101.108.130.108
-101.108.131.202
-101.108.133.231
 101.16.183.179
 101.16.98.170
 101.229.85.127
 101.255.36.154
-101.28.102.38
 101.28.105.132
 101.28.106.134
 101.28.145.2
@@ -93,45 +89,49 @@
 101.75.157.99
 102.130.115.14
 102.141.240.139
-103.106.29.148
 103.107.113.22
 103.113.99.79
 103.124.104.118
 103.125.218.107
 103.136.82.50
-103.139.89.205
 103.141.138.12
 103.144.36.20
 103.145.13.24
 103.146.174.208
 103.156.221.66
 103.16.145.25
+103.161.232.16
+103.207.0.134
 103.217.215.21
 103.224.200.40
 103.233.64.182
-103.235.165.183
 103.238.228.3
 103.238.228.4
 103.240.249.121
+103.4.117.26
 103.70.160.51
 103.79.112.254
+103.82.144.197
 103.82.145.111
+103.82.98.151
 103.82.98.170
-103.84.240.130
 103.84.240.228
-103.91.245.11
 103.91.245.12
+103.91.245.16
 103.91.245.17
 103.91.245.19
 103.91.245.20
+103.91.245.27
 103.91.245.3
+103.91.245.30
 103.91.245.36
+103.91.245.41
 103.91.245.46
 103.91.245.47
 103.91.245.54
 103.92.25.90
 103.92.25.95
-104.168.44.57
+104.168.98.105
 104.184.75.123
 104.33.52.85
 104.61.86.37
@@ -140,6 +140,7 @@
 106.104.193.155
 106.113.145.32
 106.113.177.60
+106.4.138.95
 107.172.134.48
 107.172.193.132
 107.172.249.148
@@ -158,8 +159,8 @@
 109.124.90.229
 109.233.196.232
 109.235.7.228
-109.248.58.238
 109.86.85.253
+109.88.185.119
 109.95.200.102
 109.95.200.230
 109.96.127.90
@@ -174,6 +175,7 @@
 110.228.195.46
 110.241.119.168
 110.241.23.107
+110.247.151.4
 110.248.124.254
 110.248.224.19
 110.248.251.194
@@ -183,22 +185,25 @@
 110.253.51.112
 110.255.101.184
 110.255.167.147
-110.35.145.127
 110.35.208.21
 110.35.209.175
-110.35.221.77
 110.35.223.92
+110.35.225.24
+110.35.233.147
 110.35.235.57
+110.35.249.21
 110.35.4.2
-110.82.195.88
 110fss.net
-111.118.124.223
+111.118.111.207
 111.118.41.173
 111.118.88.61
+111.119.245.114
 111.125.67.125
 111.160.112.142
 111.162.224.14
 111.163.50.120
+111.165.21.195
+111.165.28.234
 111.17.186.194
 111.170.84.182
 111.170.86.133
@@ -212,6 +217,7 @@
 111.185.230.136
 111.185.27.9
 111.185.48.248
+111.38.103.114
 111.38.103.122
 111.38.103.13
 111.38.103.66
@@ -234,16 +240,16 @@
 111.61.52.53
 111.73.99.162
 111.91.185.131
+111.92.63.24
 111.93.169.90
 112.105.117.227
 112.111.100.236
 112.111.108.184
 112.111.31.175
 112.122.36.108
-112.123.109.156
 112.123.200.47
-112.123.61.115
 112.132.134.106
+112.159.108.96
 112.170.124.75
 112.170.233.9
 112.186.210.211
@@ -299,10 +305,10 @@
 112.242.2.247
 112.243.115.183
 112.245.12.89
-112.245.246.253
 112.245.5.141
 112.245.8.24
 112.246.162.50
+112.246.180.49
 112.247.100.14
 112.247.121.39
 112.247.14.135
@@ -310,6 +316,7 @@
 112.247.191.118
 112.247.214.146
 112.247.240.226
+112.247.248.76
 112.247.81.173
 112.247.82.122
 112.247.89.81
@@ -318,8 +325,10 @@
 112.248.44.153
 112.249.109.217
 112.249.118.157
+112.249.206.69
 112.249.26.129
 112.249.41.142
+112.249.79.98
 112.250.102.173
 112.250.57.99
 112.251.17.5
@@ -332,6 +341,7 @@
 112.252.237.109
 112.252.239.103
 112.252.245.249
+112.252.46.212
 112.254.208.123
 112.255.38.10
 112.255.52.179
@@ -346,6 +356,7 @@
 112.27.124.119
 112.27.124.120
 112.27.124.122
+112.27.124.124
 112.27.124.127
 112.27.124.128
 112.27.124.130
@@ -361,7 +372,6 @@
 112.27.124.146
 112.27.124.149
 112.27.124.150
-112.27.124.151
 112.27.124.155
 112.27.124.158
 112.27.124.160
@@ -450,12 +460,10 @@
 112.72.153.37
 112.72.162.159
 112.72.162.49
-112.72.162.53
 112.72.175.147
 112.72.176.112
 112.72.176.84
 112.72.226.202
-112.72.231.35
 112.78.45.158
 112.80.118.16
 112.80.127.91
@@ -472,18 +480,17 @@
 112.82.227.41
 112.82.228.175
 112.86.133.125
-112.86.23.41
 112.86.253.238
 112.9.140.247
 112.93.29.211
 112.95.22.17
 112.95.23.121
 113.103.10.209
+113.104.237.52
 113.105.71.239
-113.11.95.254
-113.110.247.207
 113.116.121.167
 113.116.149.83
+113.116.150.147
 113.116.246.109
 113.116.48.217
 113.118.195.247
@@ -492,11 +499,11 @@
 113.161.58.249
 113.172.250.35
 113.179.129.99
-113.188.76.31
 113.194.133.9
 113.194.135.154
 113.195.163.26
 113.195.166.46
+113.201.24.26
 113.224.225.172
 113.226.42.250
 113.227.128.9
@@ -506,31 +513,28 @@
 113.231.93.142
 113.232.141.23
 113.232.211.182
+113.234.224.130
 113.235.116.209
 113.237.129.7
-113.245.218.18
+113.253.144.141
 113.254.169.251
 113.3.153.57
 113.3.155.199
 113.59.133.16
-113.59.136.39
-113.59.144.42
 113.59.154.21
-113.59.191.47
 113.61.204.205
+113.81.112.35
 113.86.204.13
 113.87.175.112
-113.87.32.93
+113.87.248.177
+113.88.100.120
 113.88.208.189
 113.88.232.36
+113.88.242.0
 113.88.38.232
-113.89.41.33
+113.89.245.13
 113.89.41.51
-113.92.156.196
-113.93.225.12
 114.199.204.37
-114.199.253.235
-114.223.122.19
 114.226.100.56
 114.227.156.119
 114.228.205.101
@@ -539,53 +543,62 @@
 114.229.52.14
 114.235.115.236
 114.235.42.152
-114.30.54.64
 114.79.161.94
 114.79.172.42
 115.165.216.112
+115.171.239.28
 115.193.130.126
+115.201.38.185
 115.208.101.195
+115.213.187.251
 115.223.159.80
 115.23.88.135
 115.42.47.36
+115.45.178.12
 115.48.130.181
+115.48.130.187
+115.48.135.151
 115.48.141.239
 115.48.198.142
-115.48.215.189
+115.48.200.115
 115.48.22.130
 115.48.228.176
 115.48.9.246
 115.49.100.124
-115.49.18.53
-115.49.216.150
+115.49.152.10
+115.49.242.100
 115.49.60.231
+115.49.80.117
+115.49.96.88
 115.50.1.143
 115.50.158.223
 115.50.2.251
-115.50.219.100
-115.50.22.86
+115.50.202.11
 115.50.220.156
-115.50.224.175
-115.50.230.43
-115.50.232.149
 115.50.239.222
-115.50.3.25
-115.50.56.198
-115.50.8.131
+115.50.240.230
+115.50.61.247
+115.50.64.182
 115.50.81.194
 115.51.104.85
+115.51.107.18
 115.51.123.216
 115.51.93.76
 115.52.112.200
+115.52.17.196
 115.52.19.250
 115.52.200.245
+115.52.201.231
 115.52.21.5
-115.54.192.172
-115.54.222.126
+115.52.22.162
+115.54.160.25
+115.54.212.227
 115.54.236.22
+115.54.240.173
 115.54.241.122
+115.54.70.108
 115.54.73.162
-115.55.105.163
+115.54.73.50
 115.55.144.146
 115.55.144.222
 115.55.144.42
@@ -593,58 +606,70 @@
 115.55.149.30
 115.55.178.67
 115.55.198.209
+115.55.211.41
 115.55.211.86
+115.55.3.36
 115.55.42.200
 115.55.53.51
 115.56.134.116
 115.56.134.220
+115.56.136.144
 115.56.139.122
 115.56.142.251
 115.56.143.241
 115.56.148.22
+115.56.154.147
 115.56.155.72
 115.56.156.185
+115.56.156.54
 115.56.162.173
-115.56.178.107
+115.56.177.202
 115.56.188.24
 115.56.31.54
-115.56.67.22
 115.56.86.251
 115.56.87.42
 115.56.98.205
 115.58.111.222
 115.58.119.171
+115.58.132.199
 115.58.134.143
 115.58.141.177
+115.58.167.90
+115.58.20.186
 115.58.83.233
 115.58.88.163
 115.58.93.151
 115.59.197.123
 115.59.198.165
+115.59.198.200
 115.59.210.228
+115.59.215.96
 115.59.235.229
 115.59.253.202
-115.59.26.134
 115.59.63.220
+115.59.95.247
+115.60.201.176
 115.61.107.203
-115.61.111.142
+115.61.118.201
 115.61.119.187
 115.61.119.198
 115.61.119.77
 115.61.125.184
-115.61.137.47
 115.61.180.193
 115.61.182.138
 115.61.185.246
 115.61.97.190
+115.61.97.55
+115.62.152.207
 115.62.26.39
-115.62.60.206
 115.63.135.206
+115.63.140.242
 115.63.4.244
 115.63.56.176
 115.73.3.11
 115.74.217.2
 115.75.217.79
+115.78.133.146
 115.92.174.231
 116.124.219.2
 116.127.207.224
@@ -655,18 +680,20 @@
 116.211.100.26
 116.212.142.215
 116.24.153.40
-116.72.201.93
-116.75.192.140
+116.72.202.126
+116.72.202.87
+116.72.203.143
+116.74.84.65
+116.75.194.14
 116.76.114.71
 116.88.65.131
 117.11.234.35
-117.11.95.179
 117.15.201.1
-117.192.224.243
-117.192.225.29
-117.192.226.96
-117.194.162.116
-117.194.163.237
+117.156.69.22
+117.194.160.84
+117.194.161.143
+117.194.162.121
+117.196.48.216
 117.20.204.138
 117.20.204.5
 117.20.210.52
@@ -676,39 +703,25 @@
 117.200.76.54
 117.200.76.60
 117.201.128.152
-117.202.66.23
-117.202.67.181
-117.202.67.218
-117.202.68.75
-117.213.41.18
-117.213.42.147
-117.213.42.226
-117.213.44.184
-117.213.45.119
-117.213.45.150
-117.213.45.204
-117.213.46.124
-117.213.46.243
-117.215.213.155
-117.215.215.188
-117.222.160.86
-117.222.165.221
-117.222.166.6
-117.222.169.193
-117.222.170.122
-117.222.175.220
+117.202.66.177
+117.202.68.94
+117.208.133.121
+117.222.161.68
+117.222.162.144
+117.222.163.150
+117.222.165.31
+117.222.170.189
+117.222.171.68
+117.222.172.97
 117.241.66.200
 117.241.67.68
-117.242.211.217
-117.247.204.33
-117.247.206.195
-117.248.60.21
-117.251.56.191
-117.251.56.244
-117.251.56.64
-117.251.56.73
+117.242.210.69
+117.242.211.111
+117.242.211.98
+117.251.56.135
+117.251.59.242
 117.251.60.161
-117.251.63.211
+117.251.60.69
 117.26.110.17
 117.26.235.164
 117.27.10.73
@@ -716,8 +729,11 @@
 117.63.195.140
 117.63.252.82
 117.63.53.15
+117.63.56.81
+117.86.105.110
 117.87.170.32
 117.90.78.120
+117.91.240.50
 117.93.115.242
 117.93.79.40
 118.176.104.35
@@ -734,19 +750,20 @@
 118.232.88.146
 118.232.96.150
 118.232.96.6
-118.233.165.213
 118.233.221.162
+118.233.63.194
 118.233.65.93
 118.249.136.112
 118.250.51.192
-118.38.189.207
 118.42.125.246
 118.43.180.33
 118.68.245.69
+118.75.120.136
+118.75.240.239
 118.75.50.253
 118.75.70.70
 118.79.125.92
-118.79.143.45
+118.79.164.102
 118.79.218.157
 118.79.50.203
 118.79.58.82
@@ -762,7 +779,7 @@
 119.112.22.58
 119.118.251.73
 119.119.52.202
-119.123.219.137
+119.123.175.133
 119.14.143.145
 119.147.213.57
 119.162.109.111
@@ -774,6 +791,7 @@
 119.165.107.93
 119.165.163.220
 119.165.174.63
+119.165.208.73
 119.165.241.222
 119.165.27.77
 119.165.68.145
@@ -793,6 +811,7 @@
 119.179.170.212
 119.179.27.213
 119.179.43.1
+119.179.44.141
 119.179.75.8
 119.18.38.144
 119.180.101.151
@@ -803,6 +822,7 @@
 119.180.231.79
 119.180.33.161
 119.180.80.69
+119.180.9.35
 119.180.94.80
 119.181.124.203
 119.181.43.18
@@ -829,6 +849,7 @@
 119.191.215.221
 119.191.253.206
 119.204.30.144
+119.250.129.231
 119.250.218.177
 119.251.105.221
 119.251.12.85
@@ -836,12 +857,12 @@
 119.56.131.155
 119.56.143.46
 119.56.143.71
+119.56.144.75
 119.56.148.115
 119.56.155.57
+119.56.166.36
 119.56.172.28
-119.56.175.41
 119.56.206.43
-119.56.220.170
 119.96.37.55
 119.96.70.116
 119.99.188.187
@@ -856,6 +877,7 @@
 12.207.39.227
 120.12.144.232
 120.12.153.54
+120.12.212.5
 120.142.222.22
 120.150.213.110
 120.151.248.134
@@ -900,20 +922,19 @@
 120.43.54.218
 120.50.66.60
 120.50.93.115
-120.59.245.212
 120.6.141.142
 120.6.8.11
 120.69.113.208
 120.69.131.51
 120.7.90.104
 120.85.165.141
-120.85.169.138
+120.85.173.137
 120.85.174.165
 120.85.174.175
-120.85.186.112
+120.85.174.39
+120.85.199.222
+120.85.212.45
 120.85.237.129
-120.85.239.77
-120.86.84.72
 120.9.32.51
 121.100.114.164
 121.100.96.8
@@ -941,6 +962,7 @@
 121.24.116.173
 121.25.101.86
 121.254.43.215
+121.34.150.32
 121.61.101.93
 121.61.102.1
 121.61.107.189
@@ -950,6 +972,8 @@
 122.100.150.204
 122.137.52.122
 122.160.147.53
+122.188.86.225
+122.190.19.204
 122.192.190.203
 122.194.191.57
 122.199.72.23
@@ -957,19 +981,18 @@
 122.199.83.86
 122.202.37.85
 122.202.41.23
-122.252.241.170
 122.252.250.22
 122.254.183.207
 122.254.29.37
 122.254.33.214
 123.0.240.58
 123.10.128.46
+123.10.131.225
 123.10.140.225
-123.10.210.87
+123.10.209.95
 123.10.36.124
 123.10.41.32
-123.11.1.232
-123.11.74.72
+123.10.83.136
 123.110.124.238
 123.110.124.244
 123.110.170.237
@@ -977,13 +1000,15 @@
 123.110.19.248
 123.110.200.98
 123.110.238.188
-123.12.238.89
+123.12.229.243
 123.12.3.58
+123.12.36.185
 123.128.128.205
 123.128.133.91
 123.129.84.36
 123.129.88.123
-123.130.169.45
+123.13.101.56
+123.13.30.75
 123.130.208.52
 123.130.23.110
 123.130.37.182
@@ -1000,9 +1025,9 @@
 123.135.71.150
 123.14.101.111
 123.14.150.79
+123.14.205.23
 123.14.217.22
 123.14.235.65
-123.14.248.97
 123.14.76.38
 123.14.88.195
 123.152.42.4
@@ -1013,6 +1038,7 @@
 123.159.137.101
 123.159.31.110
 123.159.8.100
+123.183.123.41
 123.191.173.88
 123.192.101.163
 123.192.194.233
@@ -1033,7 +1059,6 @@
 123.234.116.110
 123.234.184.57
 123.234.246.103
-123.235.107.135
 123.240.103.89
 123.240.181.57
 123.240.79.61
@@ -1041,39 +1066,42 @@
 123.241.184.124
 123.27.44.219
 123.28.217.23
+123.4.180.137
+123.4.185.137
 123.4.193.171
 123.4.44.217
 123.4.85.76
-123.4.88.225
 123.4.92.3
 123.5.123.162
-123.5.13.128
 123.5.178.213
+123.5.188.181
+123.5.22.220
 123.5.27.66
-123.8.253.37
+123.8.183.194
 123.8.254.172
 123.8.40.20
 123.8.41.63
 123.8.62.165
-123.9.110.119
 123.9.243.93
-123.9.245.134
 124.105.105.222
 124.129.162.169
 124.129.221.150
 124.129.76.230
 124.130.167.20
+124.130.40.31
 124.131.104.82
 124.131.130.95
 124.131.136.75
 124.131.151.135
 124.131.21.39
+124.131.26.243
 124.131.26.78
 124.131.54.33
 124.131.70.49
 124.131.72.208
 124.132.110.150
 124.135.34.49
+124.153.136.175
 124.153.236.6
 124.160.126.238
 124.163.138.104
@@ -1093,9 +1121,11 @@
 124.6.0.4
 124.7.254.85
 124.80.46.73
-124.92.132.207
 124.92.148.218
+124.95.17.41
 125.106.125.119
+125.106.252.96
+125.126.69.95
 125.128.28.161
 125.142.93.34
 125.168.10.234
@@ -1103,79 +1133,82 @@
 125.40.1.127
 125.40.107.252
 125.40.113.66
+125.40.136.25
 125.40.150.131
 125.40.16.231
 125.40.163.112
+125.40.237.130
 125.40.65.120
 125.40.73.6
 125.40.74.153
 125.40.75.22
-125.41.0.209
 125.41.106.180
 125.41.138.208
 125.41.189.235
 125.41.191.183
 125.41.196.151
-125.41.2.58
+125.41.200.189
 125.41.204.126
 125.41.205.197
-125.41.245.135
 125.41.6.192
 125.41.7.204
 125.41.80.153
 125.41.86.72
 125.41.96.53
-125.41.97.22
 125.42.124.114
+125.42.125.103
 125.42.234.197
 125.42.96.17
-125.42.96.209
 125.42.98.24
+125.43.105.157
 125.43.106.162
 125.43.112.123
 125.43.126.184
+125.43.130.232
 125.43.136.23
 125.43.177.48
+125.43.21.157
 125.43.26.36
 125.43.34.132
-125.43.5.247
 125.43.53.9
-125.43.93.164
+125.43.73.19
 125.44.168.169
+125.44.212.107
 125.44.213.216
-125.44.248.76
-125.44.29.38
+125.44.230.191
 125.44.30.143
-125.44.42.12
-125.44.61.172
+125.44.31.79
 125.44.8.227
+125.45.57.249
 125.45.65.166
+125.45.90.158
+125.46.138.117
 125.46.184.28
-125.46.203.85
 125.46.206.206
 125.47.193.134
 125.47.200.11
-125.47.207.239
 125.47.209.166
 125.47.244.201
-125.47.29.173
+125.47.252.106
+125.47.254.44
+125.47.28.217
 125.47.36.171
 125.47.45.218
 125.47.71.30
 125.47.90.82
 125.47.91.51
+125.99.220.202
 128.116.133.92
 130.255.159.133
 134.195.139.4
-134.236.252.28
 138.99.204.224
 139.159.226.180
 139.170.173.198
 139.170.174.162
+139.170.228.166
 139.216.102.151
 139.227.46.137
 14.102.17.222
-14.102.97.204
 14.136.80.242
 14.138.109.129
 14.138.109.26
@@ -1191,16 +1224,21 @@
 14.46.25.17
 14.46.98.241
 14.55.29.2
+140.237.30.113
+140.237.5.43
 142.11.216.5
 142.177.56.127
 146.71.79.230
 148.69.108.177
-149.255.15.121
+149.20.176.179
 149.255.15.180
 149.255.15.182
+149.255.15.191
+149.255.15.235
 149.255.15.87
-149.3.36.210
+149.3.85.55
 150.116.207.99
+150.129.105.61
 151.177.163.87
 151.33.230.191
 151.51.158.195
@@ -1213,10 +1251,12 @@
 153.34.135.92
 153.34.23.76
 153.34.29.28
-153.34.52.74
+153.35.111.46
 153.35.27.49
 153.36.126.35
 154.126.178.16
+154.91.1.27
+157.122.105.142
 158.101.165.14
 158.174.213.128
 158.51.125.115
@@ -1226,12 +1266,16 @@
 162.191.249.195
 162.194.28.60
 162.209.98.174
-162.212.203.250
+163.125.183.111
 163.125.195.108
-163.125.200.233
+163.125.200.72
 163.125.200.73
-163.125.203.85
-163.125.223.16
+163.125.202.174
+163.125.202.74
+163.125.203.179
+163.125.207.125
+163.125.250.202
+163.125.68.29
 163.53.206.228
 165.90.16.5
 170.78.39.3
@@ -1245,30 +1289,31 @@
 171.120.125.147
 171.121.6.162
 171.123.189.154
-171.125.114.254
 171.125.30.233
 171.125.30.93
 171.125.64.223
+171.125.65.22
 171.126.109.145
 171.34.112.42
+171.34.114.181
 171.34.179.178
 171.35.161.234
 171.35.162.156
 171.35.173.151
 171.35.174.198
+171.36.42.154
 171.38.219.189
 171.44.254.4
 172.105.36.168
 172.114.244.127
 172.245.5.185
-172.93.176.137
+172.245.5.190
 173.167.85.89
 173.169.46.85
 173.19.58.108
 173.220.222.227
 173.233.85.171
 173.235.209.70
-173.237.254.251
 173.25.113.8
 173.52.95.134
 173.52.97.25
@@ -1281,12 +1326,11 @@
 174.84.148.29
 174.96.30.156
 175.10.147.167
-175.10.48.233
-175.11.212.203
-175.11.96.155
+175.11.193.66
 175.115.241.87
 175.117.66.74
 175.145.200.216
+175.146.17.227
 175.153.144.2
 175.162.69.13
 175.169.172.216
@@ -1303,17 +1347,20 @@
 176.111.174.63
 176.111.174.66
 176.111.174.67
+176.113.161.101
 176.113.161.104
 176.113.161.113
 176.113.161.120
 176.113.161.128
 176.113.161.138
 176.113.161.59
+176.113.161.60
 176.113.161.65
 176.113.161.66
 176.113.161.84
 176.113.161.88
 176.113.161.91
+176.113.161.93
 176.113.174.139
 176.12.117.70
 176.123.4.115
@@ -1321,6 +1368,7 @@
 176.123.7.127
 176.123.9.243
 176.124.7.225
+176.221.251.147
 176.240.40.142
 176.240.84.106
 176.32.151.180
@@ -1329,90 +1377,103 @@
 177.54.82.154
 177.86.235.143
 178.124.182.187
-178.136.195.90
-178.141.210.251
+178.134.185.112
+178.141.161.129
 178.141.25.82
 178.141.57.166
 178.150.174.65
 178.165.122.141
 178.175.0.140
-178.175.1.109
+178.175.0.232
 178.175.1.247
 178.175.1.250
+178.175.1.252
 178.175.1.80
 178.175.10.108
 178.175.10.156
 178.175.10.26
+178.175.10.34
+178.175.10.42
 178.175.100.129
 178.175.100.180
 178.175.100.190
 178.175.100.223
 178.175.100.4
+178.175.100.87
 178.175.101.110
+178.175.101.207
 178.175.102.134
 178.175.102.136
 178.175.102.152
+178.175.102.221
 178.175.102.228
-178.175.102.232
 178.175.102.245
-178.175.102.81
 178.175.103.172
+178.175.103.195
 178.175.103.91
+178.175.104.106
+178.175.104.110
 178.175.104.120
 178.175.104.128
 178.175.104.153
+178.175.104.155
 178.175.104.16
-178.175.104.161
 178.175.104.169
 178.175.104.183
 178.175.104.206
-178.175.104.220
 178.175.104.49
+178.175.104.64
 178.175.104.80
 178.175.105.111
+178.175.105.125
 178.175.105.146
+178.175.105.177
 178.175.105.217
 178.175.105.245
 178.175.105.247
 178.175.105.27
+178.175.105.28
 178.175.105.49
-178.175.105.85
+178.175.105.94
 178.175.106.118
 178.175.106.18
 178.175.106.193
 178.175.106.219
+178.175.106.253
 178.175.106.37
-178.175.106.63
 178.175.106.77
 178.175.106.87
 178.175.107.0
 178.175.107.133
+178.175.107.245
 178.175.107.83
+178.175.107.86
 178.175.108.116
 178.175.108.145
 178.175.108.148
-178.175.108.16
 178.175.108.179
-178.175.108.18
+178.175.108.232
 178.175.108.67
 178.175.108.87
+178.175.108.94
 178.175.109.1
+178.175.109.127
+178.175.109.193
+178.175.109.37
 178.175.109.77
+178.175.109.78
 178.175.11.176
 178.175.11.184
 178.175.11.204
 178.175.11.57
 178.175.110.150
 178.175.110.155
-178.175.110.173
 178.175.110.214
 178.175.110.221
-178.175.110.43
 178.175.110.90
 178.175.110.97
 178.175.111.105
 178.175.111.157
-178.175.111.16
 178.175.111.190
 178.175.111.206
 178.175.111.36
@@ -1420,20 +1481,20 @@
 178.175.112.159
 178.175.112.26
 178.175.112.4
-178.175.113.130
-178.175.113.150
+178.175.112.79
+178.175.113.0
 178.175.113.171
 178.175.113.174
 178.175.113.35
+178.175.113.64
 178.175.113.85
 178.175.114.107
-178.175.114.211
 178.175.114.215
 178.175.114.234
 178.175.114.238
 178.175.114.241
+178.175.114.247
 178.175.114.254
-178.175.114.27
 178.175.114.5
 178.175.114.55
 178.175.114.63
@@ -1441,14 +1502,19 @@
 178.175.114.90
 178.175.114.99
 178.175.115.1
+178.175.115.12
 178.175.115.13
 178.175.115.142
 178.175.115.143
 178.175.115.19
+178.175.115.206
+178.175.115.208
 178.175.115.221
-178.175.115.222
 178.175.115.242
 178.175.115.35
+178.175.115.40
+178.175.116.15
+178.175.116.236
 178.175.116.48
 178.175.116.64
 178.175.116.87
@@ -1456,123 +1522,124 @@
 178.175.117.32
 178.175.117.51
 178.175.117.63
-178.175.117.90
+178.175.117.84
 178.175.118.112
+178.175.118.139
 178.175.118.192
 178.175.118.225
-178.175.118.34
 178.175.118.60
 178.175.119.205
 178.175.119.209
+178.175.119.26
 178.175.119.86
 178.175.119.88
-178.175.12.179
+178.175.12.114
 178.175.12.252
 178.175.12.53
 178.175.12.97
 178.175.120.133
 178.175.120.184
+178.175.120.196
 178.175.120.203
 178.175.120.251
 178.175.121.123
 178.175.121.155
 178.175.121.55
 178.175.121.62
+178.175.121.63
 178.175.121.68
 178.175.121.99
-178.175.122.144
 178.175.122.172
 178.175.122.245
+178.175.122.26
 178.175.122.28
 178.175.123.113
 178.175.123.2
 178.175.123.20
-178.175.123.223
+178.175.123.30
 178.175.123.56
 178.175.123.60
 178.175.124.109
 178.175.124.122
 178.175.124.131
 178.175.124.141
-178.175.124.157
-178.175.124.175
 178.175.124.211
-178.175.124.233
 178.175.124.4
 178.175.124.79
 178.175.124.89
-178.175.124.9
 178.175.125.118
 178.175.125.14
-178.175.125.143
 178.175.125.153
 178.175.125.156
 178.175.125.174
 178.175.125.219
 178.175.125.39
-178.175.125.54
-178.175.126.101
+178.175.126.124
 178.175.126.131
 178.175.126.141
 178.175.126.167
 178.175.126.220
 178.175.126.222
 178.175.126.237
-178.175.126.80
 178.175.126.83
+178.175.127.10
 178.175.127.109
 178.175.127.116
+178.175.127.129
 178.175.127.142
 178.175.127.15
 178.175.127.182
-178.175.127.212
 178.175.127.230
 178.175.127.231
 178.175.127.236
+178.175.127.238
 178.175.127.63
 178.175.127.75
+178.175.13.237
 178.175.14.106
 178.175.14.185
 178.175.14.246
-178.175.14.28
 178.175.14.60
 178.175.15.17
 178.175.15.217
+178.175.15.232
+178.175.15.246
 178.175.15.252
 178.175.15.35
+178.175.15.44
 178.175.15.45
 178.175.15.85
 178.175.16.1
 178.175.16.108
-178.175.16.121
+178.175.16.114
 178.175.16.17
 178.175.16.179
+178.175.16.193
 178.175.16.208
+178.175.16.73
 178.175.16.97
 178.175.17.176
 178.175.17.245
 178.175.18.238
-178.175.18.6
+178.175.18.27
 178.175.18.93
 178.175.19.144
 178.175.19.150
 178.175.19.163
 178.175.19.174
+178.175.19.229
 178.175.19.242
 178.175.19.44
 178.175.19.47
 178.175.2.110
 178.175.2.237
-178.175.2.245
 178.175.2.41
 178.175.2.5
-178.175.2.80
 178.175.20.117
 178.175.20.145
 178.175.20.170
 178.175.20.21
 178.175.20.225
-178.175.20.227
 178.175.20.237
 178.175.20.238
 178.175.20.24
@@ -1581,19 +1648,21 @@
 178.175.21.149
 178.175.21.184
 178.175.21.238
-178.175.21.58
 178.175.21.76
+178.175.22.207
+178.175.22.248
+178.175.23.102
 178.175.23.156
 178.175.23.250
+178.175.23.6
 178.175.24.13
 178.175.24.138
 178.175.24.15
 178.175.24.171
 178.175.24.227
-178.175.24.239
-178.175.24.251
+178.175.24.230
 178.175.25.117
-178.175.25.156
+178.175.25.169
 178.175.25.244
 178.175.25.28
 178.175.25.56
@@ -1601,17 +1670,16 @@
 178.175.25.77
 178.175.26.134
 178.175.26.164
-178.175.26.168
+178.175.26.165
+178.175.26.215
 178.175.26.219
 178.175.26.224
 178.175.26.246
-178.175.26.38
-178.175.26.69
+178.175.26.34
 178.175.27.122
 178.175.27.138
 178.175.27.14
 178.175.27.167
-178.175.27.169
 178.175.27.179
 178.175.27.199
 178.175.27.202
@@ -1619,69 +1687,66 @@
 178.175.27.225
 178.175.27.233
 178.175.27.239
-178.175.27.241
+178.175.27.32
+178.175.27.48
 178.175.27.68
 178.175.27.69
 178.175.27.84
-178.175.28.118
 178.175.28.124
-178.175.28.128
-178.175.28.167
 178.175.28.168
+178.175.28.75
 178.175.28.8
+178.175.29.12
 178.175.29.16
 178.175.29.173
 178.175.29.174
-178.175.29.184
 178.175.29.207
 178.175.3.116
+178.175.3.123
 178.175.3.130
 178.175.3.172
 178.175.3.190
+178.175.3.194
 178.175.3.196
 178.175.3.214
 178.175.3.56
 178.175.3.81
 178.175.30.0
-178.175.30.213
-178.175.30.255
 178.175.30.77
 178.175.31.211
 178.175.31.232
 178.175.31.249
 178.175.31.251
 178.175.32.0
-178.175.32.105
-178.175.32.141
 178.175.32.172
-178.175.32.196
 178.175.32.198
 178.175.32.208
 178.175.32.211
+178.175.32.229
 178.175.32.243
-178.175.32.32
+178.175.32.255
 178.175.32.42
 178.175.32.89
 178.175.33.112
-178.175.33.118
-178.175.33.151
 178.175.33.155
 178.175.33.161
 178.175.33.162
 178.175.33.170
+178.175.33.173
 178.175.33.174
 178.175.33.181
 178.175.33.2
+178.175.33.205
 178.175.33.216
 178.175.33.234
 178.175.33.236
-178.175.33.239
 178.175.33.26
+178.175.34.219
+178.175.34.5
+178.175.34.56
 178.175.34.96
-178.175.35.160
 178.175.35.21
 178.175.35.215
-178.175.35.253
 178.175.35.38
 178.175.35.83
 178.175.35.89
@@ -1690,37 +1755,39 @@
 178.175.36.102
 178.175.36.112
 178.175.36.12
-178.175.36.16
+178.175.36.127
+178.175.36.176
+178.175.36.19
 178.175.36.199
-178.175.36.200
 178.175.36.218
 178.175.36.22
 178.175.36.223
 178.175.36.33
-178.175.36.88
+178.175.36.78
 178.175.37.121
 178.175.37.135
 178.175.37.159
 178.175.37.6
 178.175.38.1
-178.175.38.126
 178.175.38.132
-178.175.38.148
 178.175.38.162
 178.175.38.165
 178.175.38.191
-178.175.38.7
+178.175.38.200
+178.175.38.53
 178.175.38.98
 178.175.39.167
+178.175.39.176
 178.175.39.245
+178.175.39.61
+178.175.4.219
 178.175.4.222
 178.175.4.42
-178.175.4.58
 178.175.4.95
 178.175.40.1
+178.175.40.145
 178.175.40.151
 178.175.40.166
-178.175.40.191
 178.175.40.199
 178.175.40.226
 178.175.40.41
@@ -1728,10 +1795,10 @@
 178.175.40.67
 178.175.40.70
 178.175.40.71
-178.175.40.73
 178.175.40.82
 178.175.41.165
 178.175.41.178
+178.175.41.200
 178.175.41.203
 178.175.41.210
 178.175.41.216
@@ -1748,74 +1815,81 @@
 178.175.43.121
 178.175.43.125
 178.175.43.147
-178.175.43.17
-178.175.43.176
-178.175.43.22
+178.175.43.16
 178.175.43.33
-178.175.43.44
-178.175.43.47
+178.175.43.34
+178.175.44.0
 178.175.44.134
 178.175.44.143
 178.175.44.155
+178.175.44.197
+178.175.44.209
 178.175.44.218
+178.175.44.219
 178.175.44.22
 178.175.44.241
+178.175.44.70
 178.175.44.89
 178.175.44.90
+178.175.44.95
 178.175.45.205
 178.175.45.221
 178.175.45.224
 178.175.45.230
+178.175.46.119
+178.175.46.132
+178.175.46.151
 178.175.46.187
 178.175.47.141
 178.175.47.151
 178.175.48.121
 178.175.48.195
 178.175.48.243
+178.175.48.76
+178.175.49.100
 178.175.49.107
+178.175.49.129
+178.175.49.138
+178.175.49.188
 178.175.49.247
 178.175.49.3
-178.175.49.98
-178.175.5.16
 178.175.5.247
 178.175.5.251
 178.175.5.70
 178.175.50.131
 178.175.50.177
+178.175.50.196
 178.175.50.201
 178.175.50.218
 178.175.50.236
 178.175.50.237
-178.175.50.47
-178.175.51.150
 178.175.51.197
 178.175.51.202
 178.175.51.223
-178.175.51.37
 178.175.51.66
 178.175.52.149
 178.175.52.161
-178.175.52.79
 178.175.53.103
-178.175.53.15
 178.175.53.186
 178.175.53.20
+178.175.53.228
 178.175.53.4
 178.175.53.5
 178.175.53.79
 178.175.54.105
 178.175.54.205
 178.175.54.214
+178.175.54.35
 178.175.54.72
 178.175.55.101
-178.175.55.111
 178.175.55.163
-178.175.55.204
+178.175.55.170
 178.175.55.216
+178.175.55.248
 178.175.55.29
 178.175.55.41
 178.175.55.77
-178.175.55.86
+178.175.55.85
 178.175.56.103
 178.175.56.196
 178.175.56.33
@@ -1824,10 +1898,8 @@
 178.175.57.141
 178.175.57.178
 178.175.57.192
-178.175.57.7
-178.175.58.117
 178.175.58.141
-178.175.58.223
+178.175.58.42
 178.175.59.142
 178.175.59.161
 178.175.59.229
@@ -1837,37 +1909,40 @@
 178.175.59.91
 178.175.6.134
 178.175.6.151
-178.175.6.154
 178.175.6.162
-178.175.6.171
-178.175.60.154
+178.175.6.72
 178.175.60.181
-178.175.60.32
-178.175.60.99
-178.175.61.151
+178.175.60.209
+178.175.61.117
 178.175.61.156
 178.175.61.219
 178.175.61.229
 178.175.61.234
 178.175.61.253
 178.175.61.40
-178.175.61.96
+178.175.61.42
+178.175.61.82
 178.175.62.110
 178.175.62.115
+178.175.62.168
+178.175.62.216
 178.175.62.43
-178.175.63.185
+178.175.62.44
+178.175.62.70
+178.175.63.194
 178.175.63.21
 178.175.63.218
 178.175.64.116
 178.175.64.12
 178.175.64.142
 178.175.64.158
+178.175.64.219
 178.175.64.30
 178.175.64.66
 178.175.65.115
-178.175.65.136
 178.175.65.171
 178.175.65.223
+178.175.65.44
 178.175.65.70
 178.175.65.95
 178.175.65.96
@@ -1878,17 +1953,15 @@
 178.175.66.199
 178.175.66.211
 178.175.66.228
-178.175.66.237
 178.175.66.93
 178.175.67.0
 178.175.67.184
-178.175.67.185
 178.175.67.201
 178.175.67.254
-178.175.67.31
+178.175.67.83
+178.175.68.1
 178.175.68.109
 178.175.68.126
-178.175.68.166
 178.175.68.170
 178.175.68.227
 178.175.68.232
@@ -1897,12 +1970,14 @@
 178.175.68.66
 178.175.68.83
 178.175.69.111
+178.175.69.112
 178.175.69.119
 178.175.69.128
 178.175.69.138
+178.175.69.148
 178.175.69.149
+178.175.69.173
 178.175.69.188
-178.175.69.205
 178.175.69.77
 178.175.7.163
 178.175.70.119
@@ -1916,64 +1991,57 @@
 178.175.71.148
 178.175.71.153
 178.175.71.185
-178.175.71.196
 178.175.71.22
+178.175.71.240
 178.175.71.55
 178.175.71.63
+178.175.71.64
 178.175.71.84
-178.175.71.89
-178.175.72.113
 178.175.72.13
 178.175.72.164
-178.175.72.173
 178.175.72.196
 178.175.72.222
-178.175.72.47
-178.175.72.75
-178.175.72.91
-178.175.72.98
-178.175.73.220
+178.175.73.211
+178.175.73.71
 178.175.74.182
 178.175.74.48
-178.175.75.135
+178.175.74.77
 178.175.75.181
 178.175.75.19
 178.175.75.209
-178.175.75.249
-178.175.75.54
 178.175.75.84
 178.175.75.87
 178.175.76.109
+178.175.76.121
 178.175.76.167
 178.175.76.187
 178.175.76.214
 178.175.76.215
 178.175.76.217
 178.175.76.24
-178.175.77.132
-178.175.77.145
 178.175.77.46
 178.175.77.47
 178.175.77.95
 178.175.78.106
-178.175.78.202
+178.175.78.118
 178.175.78.233
 178.175.78.46
 178.175.78.76
+178.175.78.97
 178.175.79.156
 178.175.79.227
-178.175.79.24
 178.175.79.247
 178.175.79.45
 178.175.79.77
 178.175.8.100
-178.175.8.165
 178.175.8.199
-178.175.8.205
 178.175.8.217
 178.175.8.254
+178.175.8.97
+178.175.80.100
+178.175.80.136
 178.175.80.237
-178.175.80.244
+178.175.80.41
 178.175.80.79
 178.175.80.86
 178.175.81.1
@@ -1982,43 +2050,47 @@
 178.175.81.152
 178.175.81.17
 178.175.81.194
-178.175.81.216
 178.175.81.226
 178.175.81.244
+178.175.81.32
 178.175.81.50
-178.175.81.82
+178.175.81.8
+178.175.82.120
 178.175.82.61
 178.175.83.147
 178.175.83.196
+178.175.83.247
 178.175.84.102
 178.175.84.109
 178.175.84.148
+178.175.84.158
 178.175.84.159
 178.175.84.215
 178.175.84.42
 178.175.85.153
-178.175.85.165
 178.175.85.183
 178.175.85.190
-178.175.85.229
+178.175.85.23
+178.175.85.81
 178.175.85.87
-178.175.85.9
 178.175.86.119
-178.175.86.218
-178.175.87.107
+178.175.86.159
+178.175.86.166
+178.175.87.108
 178.175.87.123
 178.175.87.162
 178.175.87.253
-178.175.87.90
 178.175.88.180
 178.175.88.181
-178.175.88.78
 178.175.89.130
-178.175.89.19
+178.175.89.157
+178.175.89.160
+178.175.89.169
 178.175.89.37
-178.175.89.51
-178.175.9.178
+178.175.9.106
+178.175.9.139
 178.175.9.183
+178.175.9.210
 178.175.9.215
 178.175.9.217
 178.175.9.245
@@ -2026,8 +2098,8 @@
 178.175.9.80
 178.175.9.84
 178.175.9.95
-178.175.90.115
-178.175.90.160
+178.175.90.104
+178.175.90.122
 178.175.90.178
 178.175.90.187
 178.175.90.21
@@ -2038,72 +2110,73 @@
 178.175.91.165
 178.175.91.172
 178.175.91.191
+178.175.91.223
+178.175.91.230
 178.175.91.253
-178.175.91.47
 178.175.91.58
-178.175.91.71
 178.175.91.96
 178.175.92.132
 178.175.92.186
 178.175.92.201
 178.175.92.208
 178.175.92.215
-178.175.92.224
 178.175.92.231
 178.175.92.248
 178.175.92.45
 178.175.93.143
+178.175.93.148
 178.175.93.150
 178.175.93.155
+178.175.93.171
 178.175.93.198
+178.175.93.224
 178.175.93.225
-178.175.93.245
 178.175.93.31
+178.175.93.34
 178.175.93.4
 178.175.93.45
 178.175.93.6
+178.175.93.90
 178.175.94.116
-178.175.94.184
 178.175.94.195
 178.175.94.238
+178.175.94.248
 178.175.94.40
+178.175.95.111
+178.175.95.132
 178.175.95.147
 178.175.95.227
+178.175.95.237
 178.175.95.244
-178.175.95.249
 178.175.95.4
+178.175.95.7
 178.175.95.89
-178.175.95.99
 178.175.96.13
-178.175.96.180
 178.175.96.195
-178.175.96.24
 178.175.96.6
-178.175.97.111
-178.175.97.181
-178.175.97.243
-178.175.98.140
+178.175.97.1
+178.175.97.128
+178.175.97.135
+178.175.97.162
+178.175.97.17
+178.175.97.208
 178.175.98.228
 178.175.98.254
 178.175.98.50
 178.175.98.68
-178.175.99.108
 178.175.99.123
 178.175.99.130
 178.175.99.22
 178.175.99.45
-178.175.99.75
 178.175.99.8
 178.175.99.91
 178.19.183.14
-178.205.101.33
 178.21.164.68
 178.217.8.194
 178.22.117.102
 178.222.252.130
 178.34.183.30
 178.92.246.246
-178.93.112.88
 178.95.115.33
 179.159.58.134
 179.4.187.39
@@ -2116,7 +2189,6 @@
 180.116.203.220
 180.120.149.106
 180.122.13.227
-180.125.155.69
 180.125.44.194
 180.157.66.204
 180.175.93.52
@@ -2137,7 +2209,6 @@
 181.112.218.238
 181.112.218.6
 181.143.60.163
-181.174.63.114
 181.193.107.10
 181.199.170.210
 181.199.170.222
@@ -2154,79 +2225,86 @@
 182.112.52.131
 182.113.0.79
 182.113.222.154
+182.113.233.129
 182.113.24.21
 182.114.106.207
-182.114.122.228
 182.114.202.186
-182.114.31.65
-182.114.50.124
-182.114.50.93
 182.114.64.27
-182.114.70.177
-182.114.93.165
-182.114.94.255
 182.116.101.82
-182.116.104.125
+182.116.103.81
+182.116.108.180
+182.116.108.244
 182.116.110.31
-182.116.44.70
-182.116.49.171
+182.116.119.129
 182.116.60.73
 182.116.61.252
 182.116.65.157
 182.116.65.245
 182.116.68.40
 182.116.69.37
-182.116.69.47
 182.116.94.196
+182.116.99.150
 182.116.99.17
 182.117.155.204
 182.117.25.120
 182.117.26.235
-182.117.27.150
+182.117.29.220
 182.117.29.74
 182.117.43.27
 182.118.140.117
 182.119.100.228
+182.119.13.141
 182.119.14.252
 182.119.166.208
+182.119.196.182
 182.119.211.69
 182.119.220.48
-182.119.227.82
-182.119.229.96
 182.119.236.21
+182.119.49.17
 182.119.50.155
+182.119.7.54
 182.119.81.33
 182.120.10.21
 182.120.16.22
 182.120.16.46
 182.120.37.251
 182.120.43.0
+182.120.86.248
 182.121.101.100
 182.121.109.190
+182.121.12.128
 182.121.125.170
 182.121.129.232
-182.121.131.69
 182.121.133.200
-182.121.135.160
+182.121.133.46
+182.121.134.73
 182.121.148.236
 182.121.157.221
-182.121.200.151
+182.121.165.217
+182.121.205.118
 182.121.206.132
 182.121.219.239
 182.121.233.191
 182.121.249.26
-182.121.68.100
+182.121.50.111
+182.121.78.29
 182.121.81.241
 182.121.92.113
 182.121.93.174
 182.121.98.21
 182.122.170.19
+182.122.202.37
 182.122.220.203
 182.122.229.102
 182.122.245.2
+182.122.246.187
 182.122.249.24
+182.122.251.141
+182.124.134.80
+182.124.15.108
+182.124.166.57
 182.124.188.23
-182.124.53.111
+182.124.95.139
 182.126.113.127
 182.126.117.41
 182.126.124.47
@@ -2236,22 +2314,27 @@
 182.126.139.66
 182.126.140.30
 182.126.178.187
+182.126.181.121
+182.126.241.7
+182.126.52.233
 182.126.82.29
 182.126.83.79
-182.126.87.58
+182.126.87.207
 182.126.95.209
 182.127.155.157
 182.127.166.232
 182.127.210.107
 182.127.6.12
+182.127.70.195
 182.127.78.61
-182.127.87.72
 182.127.91.161
+182.127.96.120
 182.172.36.164
-182.207.219.164
 182.233.0.252
 182.235.252.31
 182.53.197.62
+182.58.160.0
+182.59.227.125
 182.88.235.221
 183.105.104.83
 183.105.225.154
@@ -2264,7 +2347,9 @@
 183.188.151.225
 183.188.180.116
 183.188.180.68
-183.188.76.196
+183.188.188.186
+183.191.162.120
+183.83.105.21
 183.83.14.35
 183.83.15.116
 183.83.23.138
@@ -2273,6 +2358,7 @@
 183.95.147.102
 183.97.22.14
 184.164.185.41
+184.175.115.10
 184.74.149.230
 185.106.209.68
 185.107.3.8
@@ -2293,50 +2379,47 @@
 185.68.230.207
 185.81.157.186
 185.82.217.185
-185.82.217.213
 185.82.219.160
 185.82.219.161
 185.82.219.219
-185.82.219.80
 185.90.166.56
 186.151.144.85
 186.179.219.164
 186.179.243.112
 186.179.243.77
+186.179.243.91
 186.179.253.150
 186.225.120.173
 186.227.148.107
+186.232.44.86
 186.28.60.184
-186.4.125.48
+186.33.112.28
 186.73.188.132
 187.12.10.98
 187.188.124.229
 187.212.200.162
-187.56.88.170
-187.75.218.102
 188.10.21.14
 188.10.231.246
+188.113.102.18
 188.113.81.17
-188.127.224.149
 188.127.224.61
+188.127.227.173
 188.127.227.99
-188.127.230.133
 188.127.231.226
 188.127.231.55
 188.127.235.232
-188.127.235.70
+188.127.235.244
 188.127.235.71
+188.127.237.152
 188.127.254.114
 188.13.179.87
 188.138.200.32
 188.152.41.141
 188.169.178.50
-188.169.199.59
 188.169.30.30
 188.169.36.163
 188.242.167.159
 188.242.242.144
-188.81.100.83
 188.83.202.25
 188.93.233.223
 189.222.157.241
@@ -2355,14 +2438,12 @@
 190.130.15.212
 190.130.20.14
 190.141.117.41
-190.147.16.184
 190.159.240.9
 190.187.55.150
 190.210.214.130
 190.213.177.39
 190.213.226.63
 190.213.49.207
-190.214.24.194
 190.216.140.123
 190.35.225.36
 190.65.206.162
@@ -2376,13 +2457,17 @@
 192.227.185.106
 192.227.209.27
 192.227.228.67
+192.3.152.166
 192.3.73.205
 192.99.240.77
+193.142.146.25
 193.228.135.144
 193.91.131.237
+194.15.36.167
+194.15.36.202
 194.152.35.139
 194.38.20.199
-195.123.208.140
+194.87.139.10
 195.123.213.154
 195.139.126.51
 195.228.231.218
@@ -2395,12 +2480,14 @@
 197.159.2.106
 197.50.27.115
 198.23.133.218
+198.23.207.121
+198.23.213.57
 198.23.251.105
 198.46.201.76
 198.46.202.7
 1am.co.nz
 2.229.89.119
-2.37.203.65
+2.249.161.188
 2.45.111.158
 2.45.4.24
 2.55.125.182
@@ -2416,27 +2503,26 @@
 201.184.163.170
 201.184.248.190
 201.187.102.73
-201.193.17.190
+201.200.254.86
 201.203.221.20
+201.208.139.84
 201.215.84.97
 201.218.97.142
 202.107.233.41
 202.111.131.91
-202.150.176.100
 202.164.150.115
 202.166.217.54
+202.169.234.22
 202.169.234.47
 202.169.234.52
 202.169.234.56
-202.178.113.26
+202.169.234.9
 202.29.95.12
 202.4.124.58
 202.51.176.114
 202.51.191.174
 202.74.236.9
 203.109.201.243
-203.130.69.205
-203.170.105.156
 203.170.115.82
 203.189.156.107
 203.202.248.237
@@ -2451,28 +2537,25 @@
 203.82.36.34
 203.93.6.28
 204.195.116.171
-205.185.115.74
 205.185.123.217
+206.248.137.132
 206.47.41.166
 207.200.247.187
 207.44.28.234
 207.5.32.6
 208.163.58.18
-209.133.223.130
 209.141.39.50
 209.141.40.190
-209.141.40.31
 209.145.60.38
+210.102.196.200
 210.124.149.19
 210.216.152.122
 210.216.153.142
-210.57.234.131
 210.57.237.70
+210.57.245.109
 210.68.242.114
 210.96.116.236
-211.116.220.37
 211.172.11.169
-211.179.243.103
 211.187.132.204
 211.187.75.220
 211.204.215.157
@@ -2484,8 +2567,8 @@
 211.238.83.238
 211.247.113.49
 211.247.5.96
-211.32.122.110
 211.36.174.137
+211.41.197.30
 211.47.102.51
 211.51.174.149
 212.122.86.105
@@ -2499,24 +2582,22 @@
 213.14.173.117
 213.149.182.113
 213.149.190.193
+213.163.104.10
 213.163.104.12
 213.163.104.20
 213.163.104.99
 213.163.113.100
 213.163.113.199
 213.163.113.225
-213.163.113.226
-213.163.113.237
 213.163.113.51
 213.163.113.79
-213.163.114.107
-213.163.114.36
+213.163.114.80
 213.163.115.11
 213.163.115.15
 213.163.115.26
+213.163.115.33
 213.163.115.71
-213.163.116.149
-213.163.116.160
+213.163.116.132
 213.163.116.164
 213.163.116.203
 213.163.116.249
@@ -2530,10 +2611,8 @@
 213.163.126.131
 213.163.126.243
 213.163.126.60
-213.163.126.61
 213.163.126.7
-213.163.126.96
-213.163.127.178
+213.163.126.71
 213.163.127.217
 213.163.127.46
 213.189.178.163
@@ -2541,8 +2620,6 @@
 213.249.156.189
 213.27.8.6
 213.80.44.17
-213.87.87.173
-213.92.254.214
 213.92.254.52
 213.92.255.36
 213.92.255.84
@@ -2554,10 +2631,9 @@
 216.36.12.98
 217.11.75.162
 217.127.133.214
-218.104.175.64
+218.103.180.199
 218.215.243.65
 218.238.246.3
-218.255.226.166
 218.28.160.174
 218.35.207.119
 218.35.227.133
@@ -2566,38 +2642,45 @@
 218.48.135.50
 218.56.93.129
 218.57.53.55
-218.58.3.119
-218.58.3.38
 218.59.116.203
 218.72.198.15
-218.72.248.42
 218.79.103.159
 219.154.104.209
 219.154.119.145
+219.154.141.222
 219.154.182.197
 219.155.102.14
+219.155.12.221
 219.155.14.17
+219.155.170.22
+219.155.208.188
 219.155.24.246
+219.155.241.135
 219.155.26.37
-219.155.28.41
 219.155.31.15
 219.155.31.67
+219.155.37.97
 219.155.9.202
-219.155.97.226
+219.156.103.248
 219.156.21.73
-219.157.139.165
+219.156.23.29
+219.156.60.224
+219.156.9.32
 219.157.146.200
 219.157.150.91
 219.157.162.205
 219.157.17.8
-219.157.177.232
 219.157.178.201
 219.157.183.29
 219.157.202.66
-219.157.215.242
+219.157.220.170
 219.157.221.133
+219.157.223.245
+219.157.244.33
 219.157.32.244
-219.157.64.251
+219.157.50.211
+219.157.54.158
+219.157.56.46
 219.241.6.180
 219.68.1.148
 219.68.1.84
@@ -2615,34 +2698,34 @@
 220.173.160.53
 220.200.22.163
 220.71.239.115
+220.90.159.188
 221.0.16.221
 221.1.162.82
 221.124.78.15
 221.14.122.127
 221.14.182.157
 221.14.46.33
+221.14.58.5
 221.14.58.84
-221.15.124.188
+221.15.147.220
 221.15.153.17
-221.15.160.67
-221.15.194.218
-221.15.199.35
 221.15.218.173
 221.15.234.159
 221.15.234.175
+221.15.237.107
 221.15.54.237
+221.15.7.202
 221.157.191.178
 221.160.136.213
 221.160.177.104
 221.160.177.107
 221.160.177.224
 221.196.12.96
-221.208.4.71
 221.214.130.147
-221.214.146.73
 221.214.162.109
 221.214.224.184
 221.215.116.167
+221.215.172.207
 221.215.184.31
 221.215.237.220
 221.215.239.162
@@ -2657,6 +2740,7 @@
 221.3.34.43
 221.3.43.223
 221.3.68.16
+221.5.30.118
 222.108.17.64
 222.119.65.145
 222.132.125.138
@@ -2666,13 +2750,10 @@
 222.135.113.41
 222.135.219.29
 222.135.26.161
-222.136.21.126
-222.136.218.233
 222.136.231.197
 222.136.49.252
 222.137.101.251
 222.137.113.184
-222.137.120.3
 222.137.121.127
 222.137.136.241
 222.137.137.5
@@ -2684,18 +2765,26 @@
 222.137.172.250
 222.137.175.242
 222.137.186.150
+222.137.22.79
+222.137.220.94
 222.137.221.128
+222.137.49.4
 222.137.5.150
 222.137.72.146
-222.137.8.96
 222.137.81.67
+222.137.83.53
 222.138.137.188
 222.138.143.84
+222.138.189.88
 222.138.203.22
+222.138.215.161
 222.138.232.159
+222.138.232.84
+222.138.49.93
 222.138.96.79
+222.139.16.229
 222.139.59.63
-222.140.10.235
+222.140.112.150
 222.140.117.221
 222.140.161.11
 222.140.163.112
@@ -2703,27 +2792,26 @@
 222.140.209.222
 222.140.219.212
 222.140.39.66
-222.141.120.17
-222.141.147.104
 222.141.150.38
+222.141.165.180
+222.141.244.231
 222.141.40.136
-222.141.40.2
 222.141.41.155
+222.141.44.36
 222.141.45.153
-222.141.45.255
 222.141.60.251
+222.141.73.249
 222.141.85.128
 222.142.162.164
 222.142.192.66
 222.142.209.7
 222.142.65.30
-222.184.129.122
+222.179.215.189
 222.185.116.233
-222.186.20.19
 222.187.9.178
 222.211.72.66
+222.214.54.208
 222.218.220.219
-222.236.85.220
 222.238.230.7
 222.239.83.232
 222.248.64.253
@@ -2733,21 +2821,17 @@
 222.99.171.192
 223.166.117.210
 223.167.118.17
-223.175.121.249
 223.212.225.68
 223.212.234.84
 223.212.252.180
 223.212.5.29
-223.212.57.78
 223.212.73.175
-223.213.164.81
 23.125.186.135
 23.126.120.25
 23.228.143.58
 23.24.213.121
 23.243.149.13
 23.243.21.167
-23.81.246.58
 23.95.89.21
 24.103.74.180
 24.11.141.134
@@ -2774,6 +2858,7 @@
 27.105.106.201
 27.105.152.107
 27.116.84.57
+27.12.234.4
 27.12.245.238
 27.13.83.77
 27.14.211.219
@@ -2789,7 +2874,6 @@
 27.193.217.210
 27.194.149.142
 27.194.158.229
-27.194.166.45
 27.194.192.66
 27.194.210.20
 27.194.224.96
@@ -2841,14 +2925,15 @@
 27.208.166.13
 27.208.201.212
 27.208.247.130
+27.208.25.59
 27.208.34.2
 27.208.92.64
 27.209.160.222
 27.209.231.15
 27.209.60.21
-27.21.159.174
 27.210.107.125
 27.210.127.11
+27.210.146.61
 27.210.172.245
 27.210.234.28
 27.210.236.134
@@ -2857,6 +2942,8 @@
 27.213.104.201
 27.213.109.105
 27.213.109.58
+27.213.145.221
+27.213.167.175
 27.213.175.208
 27.213.220.5
 27.213.255.202
@@ -2871,6 +2958,7 @@
 27.215.38.166
 27.215.71.243
 27.215.98.242
+27.216.131.66
 27.216.144.66
 27.216.193.217
 27.216.197.193
@@ -2897,7 +2985,6 @@
 27.219.184.94
 27.219.192.223
 27.219.83.244
-27.220.243.172
 27.220.40.189
 27.220.85.168
 27.221.239.223
@@ -2909,25 +2996,27 @@
 27.223.242.164
 27.223.44.106
 27.24.28.134
-27.35.127.129
 27.35.129.198
 27.35.154.13
+27.35.16.145
 27.35.2.30
 27.35.212.124
 27.35.58.5
-27.36.143.238
-27.41.159.216
-27.41.36.15
-27.41.38.79
-27.46.45.90
-27.5.38.169
-27.5.41.251
-27.5.42.169
-27.6.196.172
+27.41.153.66
+27.41.154.31
+27.43.82.210
+27.46.45.248
+27.46.47.74
+27.5.16.243
+27.5.26.105
+27.5.26.4
+27.5.27.1
+27.5.35.127
 31.0.98.131
 31.11.51.57
 31.13.23.180
 31.154.234.3
+31.163.191.11
 31.168.124.130
 31.168.179.83
 31.168.184.59
@@ -2946,8 +3035,10 @@
 31.204.174.180
 31.210.20.138
 31.210.20.177
+31.210.20.227
 31.28.7.159
 31.30.119.23
+31.62.255.3
 32.208.157.193
 32792.prolocksmithwinterpark.com
 35.184.169.169
@@ -2959,8 +3050,6 @@
 36.251.19.88
 36.251.51.244
 36.255.90.219
-36.32.203.118
-36.32.25.158
 36.33.128.60
 36.33.160.167
 36.36.243.67
@@ -2970,7 +3059,6 @@
 36.66.139.36
 36.67.152.161
 36.89.18.133
-36.91.89.187
 36.96.187.93
 360.lcy2zzx.pw
 360down7.miiyun.cn
@@ -3008,8 +3096,8 @@
 39.72.67.64
 39.73.10.198
 39.73.163.231
-39.73.183.14
 39.73.203.225
+39.73.44.17
 39.74.104.228
 39.74.21.201
 39.74.28.89
@@ -3035,7 +3123,6 @@
 39.79.91.244
 39.79.93.171
 39.80.127.214
-39.80.188.238
 39.80.191.137
 39.80.205.255
 39.80.24.54
@@ -3052,8 +3139,10 @@
 39.84.34.217
 39.84.95.200
 39.85.54.191
+39.85.54.4
 39.86.129.233
 39.86.13.0
+39.86.151.49
 39.86.170.209
 39.86.184.164
 39.86.211.20
@@ -3064,6 +3153,7 @@
 39.86.76.9
 39.86.78.228
 39.87.63.58
+39.87.90.210
 39.87.93.109
 39.88.141.172
 39.88.155.96
@@ -3084,95 +3174,100 @@
 41.219.185.171
 41.230.31.58
 41.72.203.82
-41.76.157.2
+41.86.18.133
 41.86.18.147
 41.86.18.148
+41.86.18.165
 41.86.18.200
 41.86.18.71
-41.86.21.35
-41.86.21.40
+41.86.21.28
+41.86.21.5
+41.86.21.62
 41.86.5.103
-41.86.5.104
-41.86.5.198
-41.86.5.237
 42.176.112.72
 42.202.101.147
+42.224.122.39
 42.224.128.210
 42.224.168.142
 42.224.168.97
-42.224.170.140
+42.224.176.214
 42.224.179.49
-42.224.181.121
-42.224.183.11
 42.224.209.156
 42.224.212.124
 42.224.218.16
 42.224.233.247
 42.224.235.4
+42.224.249.8
 42.224.37.186
 42.224.37.44
 42.224.43.25
 42.224.64.34
-42.224.66.246
 42.224.70.213
 42.224.76.168
 42.224.76.198
 42.224.8.136
+42.224.90.17
 42.224.91.8
-42.225.24.101
 42.225.240.244
 42.225.250.39
-42.226.76.62
+42.225.33.31
+42.226.89.25
 42.227.179.209
-42.227.204.4
 42.227.66.88
 42.228.198.102
 42.228.60.114
 42.228.65.201
 42.228.70.126
 42.228.70.231
+42.228.75.7
 42.228.76.135
 42.230.100.114
+42.230.174.125
+42.230.219.243
 42.230.228.78
-42.230.57.145
 42.230.66.255
 42.230.82.44
 42.230.88.107
 42.230.93.169
+42.231.223.215
+42.231.244.80
 42.231.66.174
+42.231.95.195
 42.232.102.163
 42.232.170.117
 42.232.226.16
+42.233.90.183
+42.234.105.6
+42.234.162.44
 42.234.166.242
-42.234.180.136
 42.234.255.20
 42.235.124.55
-42.235.160.215
 42.235.169.85
 42.235.23.163
 42.235.66.249
-42.235.83.180
+42.235.90.32
+42.235.92.111
 42.236.148.201
 42.236.212.174
 42.236.212.83
 42.236.215.63
 42.236.236.179
+42.237.45.223
 42.237.54.162
-42.238.175.61
+42.238.175.32
 42.238.191.210
 42.238.241.239
 42.238.59.222
 42.239.192.128
-42.239.207.166
-42.239.42.135
 42.242.200.90
 42.52.180.36
 42.56.15.227
 42.61.99.155
+42.82.217.241
 42.84.14.5
 43.230.156.44
-43.230.207.204
 43.241.106.183
+43.241.106.234
 43.252.8.94
 45.112.203.218
 45.130.138.66
@@ -3184,16 +3279,20 @@
 45.14.149.204
 45.14.149.244
 45.14.149.66
-45.141.84.182
 45.141.84.184
+45.144.225.142
+45.144.225.213
 45.144.225.65
 45.148.10.47
 45.15.143.158
 45.164.140.133
-45.165.215.19
 45.176.108.116
 45.176.108.248
+45.176.110.99
+45.176.111.154
 45.176.111.16
+45.176.111.202
+45.176.111.84
 45.178.101.22
 45.201.165.164
 45.22.209.58
@@ -3207,10 +3306,8 @@
 46.172.75.231
 46.175.184.121
 46.182.173.246
-46.182.173.247
 46.20.63.218
 46.201.214.64
-46.201.38.162
 46.21.153.231
 46.214.27.4
 46.24.130.254
@@ -3242,7 +3339,6 @@
 49.68.221.252
 49.68.249.121
 49.70.15.16
-49.70.2.100
 5.181.135.114
 5.2.70.50
 5.53.146.179
@@ -3252,6 +3348,7 @@
 50.252.47.29
 51.171.146.13
 51.222.56.159
+54.180.158.181
 54.253.194.14
 54.36.114.136
 54.36.180.122
@@ -3264,9 +3361,10 @@
 58.142.166.120
 58.142.200.124
 58.143.142.142
+58.143.189.75
 58.18.103.109
+58.19.249.50
 58.217.171.157
-58.218.67.253
 58.22.212.107
 58.226.129.29
 58.229.194.122
@@ -3277,44 +3375,36 @@
 58.240.147.97
 58.241.57.237
 58.241.78.55
-58.248.112.16
-58.248.116.2
 58.248.117.188
-58.248.140.132
-58.248.142.137
-58.248.142.174
+58.248.143.173
+58.248.144.97
 58.248.149.117
-58.248.150.204
-58.248.150.244
-58.248.153.194
+58.248.149.226
 58.248.154.55
 58.248.154.66
 58.248.76.206
 58.248.79.25
-58.249.15.148
 58.249.18.244
-58.249.22.210
-58.249.72.121
+58.249.74.104
 58.249.74.124
 58.249.74.248
 58.249.77.227
-58.249.79.134
+58.249.78.155
 58.249.80.23
+58.249.80.46
 58.249.86.85
-58.249.88.207
-58.252.177.212
+58.249.87.248
+58.249.89.210
+58.249.90.206
+58.249.90.86
+58.252.176.107
 58.252.177.66
-58.252.178.167
-58.252.178.55
-58.253.14.46
-58.255.140.156
 58.255.43.163
 58.48.154.143
 58.50.178.137
 58.50.221.148
 58.72.165.153
 58.72.165.39
-58.76.151.51
 58.97.201.45
 58.97.206.33
 59.0.211.161
@@ -3322,48 +3412,18 @@
 59.151.202.3
 59.151.214.4
 59.151.237.51
-59.151.246.125
 59.29.133.229
 59.30.12.254
+59.32.97.190
 59.58.104.244
 59.58.117.226
 59.7.124.148
 59.8.35.22
-59.89.243.76
-59.92.176.136
-59.92.178.202
-59.92.18.175
-59.92.182.177
-59.92.216.255
-59.93.17.196
-59.93.17.204
-59.93.17.72
-59.93.19.11
-59.93.23.154
-59.93.23.215
-59.93.23.23
-59.93.23.7
-59.94.180.237
-59.96.36.131
-59.96.36.137
-59.96.39.91
-59.97.168.110
-59.97.170.16
-59.97.175.101
-59.97.175.96
-59.97.193.118
-59.99.137.46
-59.99.138.222
-59.99.139.252
-59.99.139.66
-59.99.141.103
-59.99.141.219
-59.99.142.43
-59.99.188.93
-59.99.41.26
-59.99.43.225
-59.99.46.7
-59.99.47.64
+59.92.182.72
+59.92.218.77
+59.92.219.28
+59.97.174.85
+59.99.47.93
 60.13.61.12
 60.14.48.221
 60.162.122.36
@@ -3402,24 +3462,24 @@
 60.220.22.89
 60.25.115.48
 60.25.76.224
-60.253.15.104
-60.253.39.88
+60.253.4.72
 60.253.42.72
-60.253.44.99
 60.253.51.127
 60.253.60.174
+60.253.8.36
 60.253.8.81
+60.254.49.59
 60.7.10.121
 60.7.136.8
 60.7.202.153
+60.7.8.43
 60.7.99.254
 61.102.243.124
+61.109.164.140
+61.141.124.123
 61.162.169.210
 61.162.55.42
-61.163.129.97
 61.164.96.98
-61.167.211.218
-61.168.139.87
 61.179.171.60
 61.179.91.194
 61.179.91.230
@@ -3429,37 +3489,42 @@
 61.213.118.28
 61.247.224.66
 61.253.94.230
-61.3.126.128
-61.3.144.90
-61.3.147.175
+61.3.124.3
+61.3.124.51
 61.47.220.169
 61.52.102.61
 61.52.103.144
 61.52.11.87
+61.52.135.192
 61.52.157.4
 61.52.159.231
 61.52.195.226
 61.52.212.191
+61.52.212.250
 61.52.243.169
 61.52.247.208
-61.52.30.49
 61.52.35.86
+61.52.39.119
 61.52.43.174
 61.52.48.112
+61.52.5.217
+61.52.63.119
+61.52.76.72
 61.52.9.166
-61.52.97.134
 61.52.99.183
 61.53.100.87
-61.53.121.19
+61.53.123.162
+61.53.125.182
 61.53.251.243
 61.53.62.169
 61.53.73.171
-61.53.74.27
 61.53.81.18
 61.53.83.14
-61.53.86.195
 61.54.172.248
-61.54.41.143
+61.54.240.20
+61.54.58.190
+61.54.58.20
+61.54.61.18
 61.54.64.104
 61.54.77.175
 61.56.180.67
@@ -3482,6 +3547,7 @@
 62.141.73.58
 62.219.131.205
 62.219.143.46
+62.219.155.61
 62.219.227.31
 62.31.126.33
 62.38.149.66
@@ -3493,16 +3559,13 @@
 65.125.128.196
 65.21.58.252
 65.26.155.131
-65.35.61.255
 66.153.233.87
-66.207.93.46
 66.229.214.115
 66.57.55.210
 66.74.7.197
 66.91.21.31
 66.97.181.196
 66.97.181.213
-67.221.107.75
 67.245.151.203
 67.3.169.223
 67.8.138.101
@@ -3541,7 +3604,7 @@
 70.33.144.248
 70.93.129.118
 71.127.148.69
-71.146.190.91
+71.19.150.93
 71.204.63.239
 71.29.48.164
 71.34.191.213
@@ -3566,7 +3629,6 @@
 74.199.84.77
 74.75.165.81
 75.127.141.52
-75.176.213.114
 75.82.36.220
 75.83.102.27
 75.99.213.61
@@ -3578,11 +3640,13 @@
 76.84.134.33
 76.95.12.137
 77.237.25.210
+77.45.183.39
 77.71.50.153
 77.71.52.220
 77.79.191.32
 77.89.203.238
 78.179.225.254
+78.186.155.18
 78.187.141.144
 78.187.240.125
 78.187.41.200
@@ -3600,7 +3664,6 @@
 79.170.31.56
 79.175.42.244
 79.21.84.63
-79.22.176.145
 79.7.170.58
 79.79.58.94
 79.8.70.162
@@ -3616,7 +3679,6 @@
 81.198.7.22
 81.213.111.60
 81.213.141.184
-81.213.166.175
 81.215.199.29
 81.218.187.113
 81.218.195.216
@@ -3660,7 +3722,7 @@
 84.210.219.208
 84.210.219.213
 84.212.219.127
-84.214.103.73
+84.224.162.170
 84.228.50.118
 84.228.95.204
 84.238.24.35
@@ -3677,12 +3739,12 @@
 85.105.208.25
 85.105.224.141
 85.105.241.2
+85.105.9.152
 85.214.149.236
 85.64.181.50
 85.74.215.180
 85.97.130.227
 85.97.195.129
-85.98.40.5
 86.35.43.220
 87.121.98.51
 87.61.89.40
@@ -3697,7 +3759,6 @@
 88.250.204.12
 88.250.226.26
 88.250.254.90
-88.37.171.141
 89.122.183.130
 89.136.197.170
 89.29.213.33
@@ -3718,11 +3779,10 @@
 91.244.169.139
 91.92.16.244
 91.98.4.181
-92.113.192.30
-92.113.195.115
 92.114.191.82
 92.241.78.114
 92.27.246.202
+92.54.237.237
 92.85.18.138
 93.171.157.73
 93.21.224.154
@@ -3747,7 +3807,6 @@
 95.170.201.34
 95.181.155.112
 95.214.52.64
-95.53.229.84
 95.54.11.179
 95.60.146.134
 95.60.6.114
@@ -3768,7 +3827,6 @@
 98.30.24.54
 99.150.245.203
 99.33.195.164
-99centsdigitals.com
 abcd.bg
 abclicks.in
 abissnet.net
@@ -3776,11 +3834,12 @@ aboveandbelow.com.au
 absoftechworld.com
 absupplies.co.uk
 abyssos.eu
+academyshademani.com
 acbick.com
 accounts.thesmarttechhub.com
 aceeprc.com.aceeprc.com
 acellr.co.uk
-aclassapart.in
+aciabogados.com
 acteon.com.ar
 activateyourdiscount.com
 activecost.com.au
@@ -3798,6 +3857,7 @@ agemn.co.za
 agenciadigitalwdys.com
 agenciatabletshouse.com.br
 agenda.gmelloinformatica.com.br
+agenmovie.xyz
 agentt.ac.ug
 agile8studio.com
 agmcarpetcare.co.uk
@@ -3809,7 +3869,6 @@ al-wahd.com
 alasdemariposas.org
 alemelektronik.com
 alena1971.es
-alertlauncher.fr
 alexdubai.com.aldiabsteel.com
 alka.institute
 allforcreative.com.au
@@ -3821,6 +3880,7 @@ amarresdeamorymaestroshechiceros.com
 amarteargentina.com.ar
 amenyan.zouri.jp
 amos524.org
+ams.alvinasschools.org.ng
 anantam.net.in
 andreelapeyre.com
 andremaraisbeleggings.co.za
@@ -3840,10 +3900,9 @@ api.sampy.io
 aplicativoparasindicato.com.br
 apoolcondo.com
 app.adsensearticle.com
-app.explicitsurveys.co.uk
 app.prerana.info
 apps.saintsoporte.com
-aras.iuc.ac
+aqv.news
 areyoulivingwell.com
 arsapetrolab.com
 artedibujoyarquitectura.com
@@ -3862,11 +3921,12 @@ avissrilanka.com
 ayamallah.com
 azmeasurement.com
 azraktours.com
-b2b.toptanakaryakit.com.tr
 backgrounds.pk
 backup.agewsage.com
 badeggdesign.com
+balealgodon.mx
 bangkok-orchids.com
+barcionstw.eastus.cloudapp.azure.com
 bary.sz4h.com
 basma.com.kw
 bausch.kr-atlas.monaxikoslykos@zytrox.tk
@@ -3875,7 +3935,6 @@ bbia.co.uk
 bcmt.elin.co.za
 bcrg.co.za
 bearcatpumps.com.cn
-beatyamerican.com
 beautincollagen.rs
 bekape.co.id
 bespokeweddings.ie
@@ -3883,6 +3942,8 @@ bestcarenepal.com
 betone.co.kr
 betycopaints.com
 beveragesmiami.solucioneslink.com
+bhavaniengineering.com
+bigbag.wootraining.certificacion.cl
 bilbosaquet.ug
 bilhen.co.za
 billing.rahitechnosoft.com
@@ -3890,11 +3951,10 @@ birdi.elin.co.za
 birminghamlink.org
 blog.callensaxen.com
 blog.oyinblogs.com
-blog.takbelit.com
 bmlifestyle.co.uk
+bnrbook.com
 bnrnews.id
 bodenstein.co.za
-bolnicaloznica.rs
 booksearch.com
 bounces.mi-fs.com
 bpo.correct.go.th
@@ -3908,23 +3968,21 @@ brightonrooms.co.uk
 brightstarshop.com
 browardinsurancemiami.solucioneslink.com
 bt2.elin.co.za
-btdapi.robotake.com
 bucrinsuranlceonlines.com
 buenavista.co
-buigiaphat.com.vn
 bullseyemedia.in
 busandvanrentalmalaysia.com
 buscascolegios.diit.cl
 business.softberg.ro
 buyingmusiconline.com
-buypropertyfast.com
 bwsr.eu
 c.oooooooooo.ga
 c0140529.ferozo.com
+caballo.com.au
 cacapavaonline.sdserver144.com.br
+calgaryautorepairservice.com
 callbury.in
 camminachetipassa.it
-campusvirtual.cepsanjuanbosco.net.pe
 cancer.educandome.co
 capitalgroup-kw.com
 capitalnewsagency.com
@@ -3937,12 +3995,10 @@ cazyacustomfurniture.com
 ccauthority.net
 cdaonline.com.ar
 cec.asso.ac-amiens.fr
-cellas.sk
 cendekiabinaaksara.com
 cespol-bote.com.mx
 cfs5.tistory.com
 ch.rmu.ac.th
-changematterscounselling.com
 chardhamdodham.com
 cheacrilnsurances.com
 chealablilitycarinsurances.com
@@ -3950,15 +4006,14 @@ chezalice.co.za
 childselect.com
 chinhdropfile.myvnc.com
 chinhdropfile80.myvnc.com
-chipmania.it
 cible-energy.com
 cifeer.net
 citycapproperty.ru
 cityglobalgospel.com
 civi.istmejia.com
 cleanbydesignllc.com
-clim34000.fr
 cloud.fc.co.mz
+clurbgolf.com
 codsambal.com
 colinde.pricesne.com
 colorpak.pl
@@ -3980,7 +4035,6 @@ creationskateboards.com
 crecerco.com
 crittersbythebay.com
 crm.notariavieitoyvelamazan.com
-crmmanivela.net
 crscorretordeimoveis.com.br
 cse-engineer.com
 csnserver.com
@@ -4027,7 +4081,6 @@ destinymc.co.za
 detorre.es
 dev-interestingtech.pantheonsite.io
 dev.sebpo.net
-dezcom.com
 dfcf.91756.cn
 dfsfcsfcdsfsdvcfsvcscv.com
 diamantenegro.mi-fs.com
@@ -4050,7 +4103,6 @@ dom.daf.free.fr
 doncedyhall.com
 donghobinhminh.com
 dongphuctop.com
-donwnloasecury.ath.cx
 dosame.com
 dosman.pl
 dovberger.com
@@ -4058,6 +4110,9 @@ down.flash-plays.com
 down.pcclear.com
 down.posti-fi-fsa.top
 down.posti-fi-fwa.top
+down.posti-fi-ij.top
+down.posti-fi-in.top
+down.posti-fi-iz.top
 down.udashi.com
 down.webbora.com
 down1.arpun.com
@@ -4074,7 +4129,6 @@ dragonsknot.com
 drbaby.com.sa
 drohnen.ensenanzainteligente.com
 drools-moved.46999.n3.nabble.com
-drrohanfonseca.com
 drsha.innovativesolutions.mobi
 dsenterprize.co.za
 dsspainting.com
@@ -4088,19 +4142,15 @@ e-commerce.saleensuporte.com.br
 e.sldov.ru
 ebruyatkin.com
 econews.treegle.org
-edelweissdecoration.com
 efficientegroup.com
 elliot.newreadermedia.net
-emaids.co.za
 en.baoend.com
 enc-tech.com
 endurotanzania.co.tz
-enkonooh.com
 ennovate.elin.co.za
 enriquecendocomconsorcio.com.br
 envios.petpienso.cl
 equimination.ee
-es.paymelist.com
 escola.probommar.org.br
 esnconsultants.com
 essentia.org.br
@@ -4112,15 +4162,14 @@ extrovertoffers.com
 f1sol.com
 familydentist.site
 farmaciasdrogaminas.com.br
-farmnatural.in
 faveraprojects.com
 fc.co.mz
 felicienne.nl
 fi.bonitastores.com
 files.martellexpress.us
 files6.uludagbilisim.com
-filmotainment.com
 final.makkahkmcc.com
+fineartgallerym.com
 fkd.derpcity.ru
 flintspin.com
 flyingbuddhadesign.com
@@ -4128,20 +4177,17 @@ fmjplastering.co.uk
 fms.buladde.or.ug
 foothills.com.br
 footweardirect.elin.co.za
-formestore.evencsoft.co
 forum.mdb.nu
 fotoobjetivo.com
 foundationrepairhoustontx.net
 foxeps.com.br
 freecnetdownload.com
-freedombookshop.tickme.lk
 freisites.com.br
 ftp.n3twork30cm.ml
 fullelectronica.com.ar
 funletters.net
 fusionfiresolutions.com
 futuregraphics.com.ar
-gahanassociates.com
 gametwogame.com
 garayvidalabogados.com
 garciadogshow.com
@@ -4149,7 +4195,6 @@ garenanow.myvnc.com
 garenanow4.myvnc.com
 gbbulls.co.uk
 gcpc.co.id.chronoscurtain.com
-gcrcorporation.com
 generaldeviales.com
 gfmodd1.webselffiles01.com
 gfold1.webselffiles01.com
@@ -4157,6 +4202,8 @@ ghettohub.co.za
 ghislain.dartois.pagesperso-orange.fr
 giadungg7.com
 giddos.ga
+gilliem.com
+girotexuniformes.com
 giteletropical.com
 globaltask.ar
 glowinmedia.co.ke
@@ -4171,10 +4218,12 @@ goldcoastoffice365.com.au
 goldcupmortgage.com
 golden-memories-funerals.yourpageserver.com
 goldmen.in
+gorecycle.fahadjutt.com
 gracejukes.com
 grupoinmare.com
 gruposelt.000webhostapp.com
 gs.monerorx.com
+guide-to-cell-phones.com
 gulfac-house.com
 gvpcdpgc.edu.in
 habbotips.free.fr
@@ -4200,6 +4249,7 @@ hitstation.nl
 hmpmall.co.kr
 hoagietesting10.com
 hoayeuthuong-my.sharepoint.com
+holmesprpmgmt.com
 homefindersolutions.com
 hongluosi.com
 hookedupboatclub.com
@@ -4211,7 +4261,6 @@ hseda.com
 hsmwebapp.com
 htownbars.com
 hubtech.co.za
-huequito.evencsoft.co
 hunggiang.vn
 husamiyahschool.com
 iam313.com
@@ -4223,6 +4272,7 @@ idvindia.com
 iesanjosemonitos.edu.co
 ikexpert.com
 ilrafrica.com
+images.jermiau.com
 imbueautoworx.co.za
 imperiumtherapy.co.za
 in-tune2016.com
@@ -4237,6 +4287,7 @@ inodesthetotaldesigners.com
 inovations.searchkero.com
 inrajahmundry.co.in
 insignificantfinecore.testmail4.repl.co
+instantindialoan.com
 instvisionmexico.edu.mx
 intellectsmart.in
 intersel-idf.org
@@ -4247,6 +4298,7 @@ ipmes.ma
 iremart.es
 iris101.co.uk
 iscamenabe.com
+ismf.com.ng
 iso-dubai.net
 israrulhaq.me
 isrorg.com
@@ -4267,7 +4319,6 @@ jhayesconsulting.com
 jiaoyuzixun.cn
 jing-da.com.tw
 jktnet.xyz
-jmcomputacion.com.ar
 jmtc.91756.cn
 jnanbharati.com
 jobs.thebeessolution.com
@@ -4276,9 +4327,7 @@ join.cl8movement.co.za
 josegene.com
 josuarochoa.com
 jpwoodfordco.com
-julietlaser.site
 jumpmanualjacobhiller.com
-jumpnjamchicago.com
 jupiter.toxsl.in
 jurgensen.newreadermedia.net
 justinscott.com.au
@@ -4300,6 +4349,7 @@ kubatoglubaklava.com.tr
 kumaralok.in
 kwanfromhongkong.com
 kz.sldov.ru
+lab18.it
 lacasadelosalebrijes.com
 ladylabonde.com
 lameguard.ru
@@ -4345,6 +4395,7 @@ lp.definerisco.com
 lp.difusodesign.com
 lp.juancamilogarciareyes.com
 lp.tecnimasdecolombia.com.co
+ltc.typoten.com
 luckybrownie.com
 luminouspneuma.com
 luxomodels.com
@@ -4353,15 +4404,15 @@ m.estudiomoros.com.ar
 madicon.co.za
 magianegramagiablancayamarres.com
 mail.bs-eiendomme.co.za
+mail.golimoapp.com
 mail.jeffsono.org
 maksi.feb.unib.ac.id
 malaya.tv
 malwarecoding.github.io
 managed.oss-cn-beijing.aliyuncs.com
+managemysalon.in
 manantialesdelnorte.uy
-manivelasst.com
 marcapinyo.ru
-marcusthepoet.com
 mario-sunjic.com
 mariobrown.net
 mariotessarollo.com
@@ -4370,7 +4421,6 @@ marketing.enexusgroup.com.au
 marksidfgs.ug
 masjidhabeebiyarazviya.mysunni.com
 materialescantu.com
-matinal-nominal.pt
 matruchhaya.co.in
 mattysplayground.com
 maxtox.com.pk
@@ -4382,6 +4432,7 @@ media-server.skyinternet.com.pk
 mediamaster.co.za
 medianews.ge
 medistaffconsulting.com
+meditreat.itwebservice.in
 meeweb.com
 megamart.afnan-amc.com
 merbay.ru
@@ -4402,7 +4453,6 @@ midlandtexasconstruction.com
 mindfulbuildingandliving.com
 mingguanwms.com
 minuevavida.org
-mirror.mypage.sk
 mis.nbcc.ac.th
 misterson.com
 mixr.at
@@ -4410,12 +4460,14 @@ mkontakt.az
 mktf.mx
 mmogollon.com.mx
 mncarteam.com
+mobile.illumetechnology.com
 modelhouseturkey.com
 modernmanna.org
 monetization.business
 moninediy.com
 mopai.sg
 motorcomunicacion.com
+msacontabil.com.br
 mtspsmjeli.sch.id
 muzimbiti.xigubo.co.mz
 mxpiqw.am.files.1drv.com
@@ -4448,8 +4500,8 @@ nhorangtreem.com
 nicolas.ug
 nidhi.iexist.in
 nikanpolimer.ir
+nilehouse.co.ug
 nilinkeji.com
-nisacooks.com
 njtiledesigncenter.com
 nobius.org
 nocalnoodle.elin.co.za
@@ -4467,10 +4519,13 @@ nyeh2o.com.au
 oakleyandfriends.co.uk
 obseques-conseils.com
 ocean.tecnasulstore.com.br
+ohe.ie
 ohsewgorgeous.co.uk
+oknoplastik.sk
 oleholeh.memangbeda.website
 olirecords.mixture.ltd
 olooom.com
+omaia.org
 omaromatic.com
 omega.az
 oms.pappai.com
@@ -4479,6 +4534,7 @@ onedigitalcard.granvizionnecorp.com
 onedrive.listifyapp.co
 online.creedglobal.in
 onlinestatis.bar
+ont.proman.id
 open.warehousesaas.co.uk
 opolis.io
 optimus.com.sg
@@ -4486,6 +4542,8 @@ optitechsa.co.za
 order.bizpeed.com
 orientgatewayltd.com
 orion445.com
+oserve.pk
+otolithenrichment.fahadjutt.com
 ottimade.com
 ourteam.searchkero.com
 ozemag.com
@@ -4507,6 +4565,7 @@ patch3.99ddd.com
 paths.elin.co.za
 paulmercier.biz
 payerrealty.com
+payments.atifsiddiqui.me
 pcsoori.com
 pd.oceaniarp.net
 perpus.onlineman7-jombang.sch.id
@@ -4519,6 +4578,7 @@ phittc.com
 photo360.kubooking.com
 photographytipsclub.com
 pink99.com
+pizzabarletta.com.br
 plasfan.ind.br
 pmglance.startwriteup.com
 pokojewewladyslawowie.pl
@@ -4528,15 +4588,13 @@ pooltablemoversdenver.net
 posmicrosystems.com
 poulman.panagiotopoulos-tours.gr
 ppdb.smk-ciptaskill.sch.id
-pptvideotemplates.com
 prestasicash.com.ar
 prestigehomeautomation.net
 prishaartcreations.com
 production.sparshims.com
-productprecise.com
-prof-dr-ahmedalmoatasem.com
 programaoperadoronline.com.br
 project.exquitec.com
+promolyko.com
 promotoradescomplica.com.br
 promoversdubai.com
 propertiq.elin.co.za
@@ -4549,7 +4607,7 @@ prueba.danielluza.com
 pujashoppe.in
 punchdialogues.com
 punjabdevelopersassociation.com.pk
-purefoe.top
+pvcprinting.co.uk
 qadir.tickfa.ir
 qatarglobalconsulting.com
 qmsled.com
@@ -4565,7 +4623,6 @@ ratemyfenancialadvisor.com
 ravenproductionsltd.com
 rc.ixiaoyang.cn
 readymmade.com
-realtheprocess.co
 redchillicrackers.com
 reifenquick.de
 relaxindulge.co.nz
@@ -4615,7 +4672,6 @@ santyago.org
 sarakem.cl
 sasystemsuk.com
 savasaachi.systems
-savingchintu.com
 scarfaceindustries.com
 scglobal.co.th
 schalke04rss.de
@@ -4623,10 +4679,8 @@ scheff.com
 schoolbustracker.softgig.co.ke
 sec-doc-w.com
 secure-doc-reader.com
-sefp-boispro.fr
 segalsmetals.elin.co.za
 sellmyphonela.com
-selltechtoday.com
 senbiaojita.com
 sentierodelviandante.ml
 serendibsourcing.com
@@ -4643,7 +4697,6 @@ shembefoundation.com
 shivakunwar.com.np
 shoblasaathitrust.org
 shooka-co.com
-shop.clarostudio.ro
 shop.goldspot.agency
 shopsofe.com
 shrushtiinfotech.com
@@ -4655,11 +4708,11 @@ siili.net
 simoneporzi.it
 simplithy.co.uk
 sindicato1ucm.cl
+sindpol.tiejuris.com.br
 sinergidwireka.com
 sipahielektrik.com
 siperb.in
 sistelligent.com
-site.sjc.co.ke
 skkksolo.beweiretail.com
 skyflyfares.com
 skyscan.com
@@ -4669,7 +4722,6 @@ smartzedu.com
 smokeandgrowrichtour.com
 smokesolutionindia.com
 sobethuacademy.com
-soft.110route.com
 soft.officelabo.net
 sohs.conceptechs.info
 solar.amazingtribe.lk
@@ -4678,11 +4730,11 @@ somcorbera.cat
 somir.com.mx
 soralapps.com
 sorteio.orgaostalita.com.br
+sosgsm.fr
 sota-france.fr
 sowingminerals.cl
 space.proactint.org
 spaceframe.mobi.space-frame.co.za
-specfloors.net
 special-key.cf
 spent.com.pl
 spetsesyachtcharter.gr
@@ -4714,6 +4766,7 @@ supermercadostia.com
 support-4-free.com
 support.clz.kr
 supportit.online
+surestdysbonescagexc.dns.army
 sw.yourpageserver.com
 sweaty.dk
 sweet-diet.com
@@ -4739,11 +4792,11 @@ taxpos.com
 tc.snpsresidential.com
 tcy.198424.com
 tdsp.yngw518.com
-tech332.synology.me
 techgms.com
 technogreen.crmmanivela.com
 technohub.searchkero.com
 tecnicaencolectores.com.mx
+tecnologyschool.com
 teduae.com
 teleargentina.com
 telescopelms.com
@@ -4751,9 +4804,9 @@ telmed.cl
 temptmag.com
 tennisafrica.com
 tentandoserfitness.000webhostapp.com
-tepresto.net.pe
 test.adventser.com
 test.letraele.es
+test.typoten.com
 test.wanepghana.org
 test1.asistencia247.com
 test1.milenial.id
@@ -4766,9 +4819,7 @@ testnew.yourpageserver.com
 teteaffiche.stephanebillon.com
 tewoerd.eu
 textile.softberg.ro
-texts.bfftexts.com
 texturesbyvinita.com
-tharringtonsponsorship.com
 thecleaningladiespdx.com
 thecreativecafe.co.uk
 thefuturelife.in
@@ -4776,12 +4827,11 @@ thehighlightinterior.com
 thehouseofpragya.com
 thekassia.co.uk
 thelaunchpadteam.com
-thelekhak.com
 thelogicalgroup.co.uk
 thesummitpc.net
 theurbantutors.com
+thewwpc.com
 thosewebbs.com
-thriveink.com
 tianangdep.com
 tickfood.tickme.lk
 tickjobs.tickme.lk
@@ -4814,7 +4864,6 @@ tsd.jxwan.com
 tulli.info
 tupperware.michaelroberge.ca
 turanggaresources.com
-tushartyagiji.digitalswagger.in
 uat.indianfilmzone.com
 ublretailerdemo.cstdevs.com
 udesk.searchkero.com
@@ -4824,7 +4873,6 @@ umwelt-kirchhof.de
 unicorpbrunei.com
 uniengrisb.com
 unisoftcc.com
-unitedpestsolutionstx.com
 unyazitelecom.com
 upcbpta.com
 urbane.dezinetimes.com
@@ -4851,17 +4899,18 @@ vitoriamodaintima.com.br
 vivationdesign.com
 viveirodoiscorregos.com.br
 vksales.com
+vladimirinternational.com
 vokasi.ub.ac.id
 vologroup.com.br
 voteyouramerica.dekitout.com
 vstsample.com
 vtube.fadlymotivator.com
 vvsskmodinationalschool.com
-wahrewah.nl
 wanepliberia.org
 wanepniger.org
 weareactum.com
 web.eng.ubu.ac.th
+web.geetle.ga
 web.geomegasoft.net
 web.newinnovationtechnology.com
 web.smarts-works.com
@@ -4875,13 +4924,12 @@ wexfashion.com
 whcms.yourpageserver.com
 whiteglovetailgate.com
 whiteresponse.com
+whynt.xyz
 wi522012.ferozo.com
 wikalen.co.za
 wildnights.co.uk
 wildtrust.mediadevstaging.com
 wimbamusica.com
-windcomtechnologies.com
-winnercircle.it
 wishesconcierge.com
 woezon.agency
 wolfgang-brodte.de
@@ -4897,7 +4945,6 @@ x2vn.com
 xia.beihaixue.com
 xixaoclothing.com
 xk.996is.com
-xmp.myracingaccounts.com
 xn--80akinnkiib6h.xn--90ais
 xn--polimerbizmimarlk-rvc.com
 ybom.urbanolab.com
@@ -4908,12 +4955,12 @@ youtubetrainingacademy.com
 yskadvisors.com
 yummyyogaudaipur.com
 yzkzixun.com
+zakra.tecnasulstore.com.br
 zytrox.tk
 zz.690tx.com
 ||2.indexsinas.me:811/64.exe$all
 ||2.indexsinas.me:811/86.exe$all
 ||2.indexsinas.me:811/c64.exe$all
-||akwer03.top/downfiles/file.exe$all
 ||amumufree.weebly.com/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe$all
 ||analogx.com/files/proxyi.exe$all
 ||bitbucket.org/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe$all
@@ -5005,84 +5052,30 @@ zz.690tx.com
 ||cloudme.com/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar$all
 ||codeload.github.com/meteoradminz/hidden-tear/zip/master$all
 ||colfincas.com/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/$all
-||d.ttr3p.com/kr.bin$all
 ||deepfreedom.org/qz0h69.pdf$all
 ||drive.google.com.it-barcelona.com/frm0reseen/prntscrnofamzorderid.jpg.exe$all
 ||drive.google.com/uc?export=download&id=0byfg0_4xbjgnwvuyev9ltuh4rmm$all
 ||drive.google.com/uc?export=download&id=13vodfxml9fg8kcnexuafh64dzmnqv8ch$all
-||drive.google.com/uc?export=download&id=14l8sj2dqo04ozum88tvuy74yfcwk5fnf$all
-||drive.google.com/uc?export=download&id=15bd1dksg4pkrxehoczi7e0uok4vblz4e$all
 ||drive.google.com/uc?export=download&id=167imxqgc8ehepa1gisxa6q6ifcjxceox$all
-||drive.google.com/uc?export=download&id=17xvn-rlhei5n9f6unuqqb_wh84u4w5cx$all
-||drive.google.com/uc?export=download&id=1_vz7veeec-juwt23g9d9wjuid2kusew7$all
 ||drive.google.com/uc?export=download&id=1a-herfdxr6xamxeabcdao0mqw9bimrig$all
 ||drive.google.com/uc?export=download&id=1aphk_vq7gtn368zxpd5bg5rv8nk0bnhn$all
-||drive.google.com/uc?export=download&id=1aqhdbelnscyjygigfopt7x_oafaqgwg1$all
-||drive.google.com/uc?export=download&id=1cf8d3ljsfn3toddczqtkkbhrd5g00cjg$all
 ||drive.google.com/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben$all
-||drive.google.com/uc?export=download&id=1cynoc3t9rp-xvso3jcmx_prwppp8u-dv$all
-||drive.google.com/uc?export=download&id=1d8fykmpewc_4yurihjh_cdehkdp_nuik$all
-||drive.google.com/uc?export=download&id=1dgcin9vevl9f63cbhbkmc_gpa2b0zlrh$all
-||drive.google.com/uc?export=download&id=1do7c-fjuscbueu0un2dbxe3-pnwdufb_$all
 ||drive.google.com/uc?export=download&id=1eqnvgn0qkunp7t6crk8oj7_e7rh5qxwi$all
-||drive.google.com/uc?export=download&id=1f3kxfcvbpaaexgnchpvmyoxkcdmickjj$all
-||drive.google.com/uc?export=download&id=1gsmk1t_yigh7jablxkuhbmmh93vwgikb$all
-||drive.google.com/uc?export=download&id=1hmud67vsl-shqddzpxniqmyj92iynyis$all
-||drive.google.com/uc?export=download&id=1ik-x4_bsr5dbocs9j1ryg1ybw75fqu8t$all
 ||drive.google.com/uc?export=download&id=1in-rhdrss2qsjqj8xffb1hbwi9znp4je$all
 ||drive.google.com/uc?export=download&id=1iwc-lf99neesk6mvvo2al4futbmyoiev$all
 ||drive.google.com/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr$all
-||drive.google.com/uc?export=download&id=1jgykopezccdq3q5qprmkl1zdl1auymkq$all
-||drive.google.com/uc?export=download&id=1lplk8rixxuboakkmut_qgzn92bkoulna$all
-||drive.google.com/uc?export=download&id=1mug8m5o6kl_bx68x8cuxmzhn0gxnc7ki$all
 ||drive.google.com/uc?export=download&id=1n8o4hbvi7o9ks9jqhofny7okposfaz4y$all
-||drive.google.com/uc?export=download&id=1nindqtjvyyzz-qk-hqa9gls5ccwhys-e$all
 ||drive.google.com/uc?export=download&id=1nio_cdsggt4zv1kdrpubrfpd0pzsyffd$all
-||drive.google.com/uc?export=download&id=1nsyqwodoi1t9-i29arbxwe7fkafjydsz$all
-||drive.google.com/uc?export=download&id=1nwctbvlr_1bewpvgdbmuhnny-zi6kp1l$all
-||drive.google.com/uc?export=download&id=1o2dcrdwgu91moicmterbx9avcl9cavy1$all
-||drive.google.com/uc?export=download&id=1o4lh97cmfnztr_hkocnwiucy5l6oskpy$all
 ||drive.google.com/uc?export=download&id=1oabvvnazifkxktvt-izbcdqpb7dm6nrw$all
-||drive.google.com/uc?export=download&id=1oys1nkexzsuci6pfghowlbpwaw-_btxk$all
 ||drive.google.com/uc?export=download&id=1prxtn1juykhcr_9ilw-vtirv5anyeoej$all
-||drive.google.com/uc?export=download&id=1pzywywxrwl2plk82nuodgvmcckpzrufb$all
-||drive.google.com/uc?export=download&id=1q0uxhnzfs4j91rxz5x45iov8tjkomsgr$all
-||drive.google.com/uc?export=download&id=1q9vzzhu-n9cu8ixdginpzaxxgvb1lrjv$all
-||drive.google.com/uc?export=download&id=1qk8_jouqbnrfkky7x1aqunudfyl6fjii$all
-||drive.google.com/uc?export=download&id=1qxv3i0dwy_cdx2bm1lqx6ef0qjwmhbpk$all
-||drive.google.com/uc?export=download&id=1qzmi4jvter0_cwexcp4grjhxvr7lep5k$all
-||drive.google.com/uc?export=download&id=1r-kstukxtxjqxlwypgd764dw-puj_7fz$all
-||drive.google.com/uc?export=download&id=1r-zn6o95qzworq8e4fhz637bfuoxayby$all
-||drive.google.com/uc?export=download&id=1rcykjynwhlc487sn1vwcsmjse_ctlrox$all
-||drive.google.com/uc?export=download&id=1rdxnm_kxegbwlojlucu4qiff7kyax3oi$all
-||drive.google.com/uc?export=download&id=1s9tu6akdxquy7cezquljtb2yarci99ab$all
-||drive.google.com/uc?export=download&id=1serasql3bw7nc-sllzyrishnhodmefyf$all
-||drive.google.com/uc?export=download&id=1shuxviwx167elbuz8mfcjc2bk99zzov_$all
-||drive.google.com/uc?export=download&id=1sjzynfvpwdcwsr1p3w_q8-6ktsqiwadx$all
-||drive.google.com/uc?export=download&id=1sogqqdapgyioillf7u62widsprhw3cjh$all
 ||drive.google.com/uc?export=download&id=1t1bd_itjnhsmozdl9was0gouehujm1fn$all
-||drive.google.com/uc?export=download&id=1tfra7fzrjl2vdj73hcmcru5ynuqmz61g$all
 ||drive.google.com/uc?export=download&id=1tsmbsikhechaqedk6nktlfzasus_tghw$all
-||drive.google.com/uc?export=download&id=1ur9qebooqc-mjcdzn9wcbavocumdlosm$all
 ||drive.google.com/uc?export=download&id=1uvtmu3-hcryp3rskqnpkiodcjuchtz55$all
-||drive.google.com/uc?export=download&id=1v4ima0sfnmboxmyoklp4g0_uehaj22x2$all
 ||drive.google.com/uc?export=download&id=1vevblftithattyguwyjot1p0wptg7l5t$all
-||drive.google.com/uc?export=download&id=1vl9gje5llm7ja3dadct9okr6bzbmijc3$all
-||drive.google.com/uc?export=download&id=1vvvujegfrgey39w6y3ybwpptl1guwf8a$all
-||drive.google.com/uc?export=download&id=1ws2ptumptku-imi9sv_k5g4fhsx30gnl$all
-||drive.google.com/uc?export=download&id=1wtxdbb1fm9ozinx09a63-o-tn4ssgzpw$all
-||drive.google.com/uc?export=download&id=1xbeqbw67xz4iqpu8dgmdrlkpa6kzotes$all
-||drive.google.com/uc?export=download&id=1xdpxbb9gifdrugqxmg2_06xygbfq-x2k$all
 ||drive.google.com/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e$all
-||drive.google.com/uc?export=download&id=1xu9wvl5ktadwfxd94dicuej6y_j6kf8-$all
 ||drive.google.com/uc?export=download&id=1yawygcfjs9inzoiwagqfcn3utaywxmwi$all
-||drive.google.com/uc?export=download&id=1ycggxvacywdkt3jvqbpxpz9cyjcwvl_c$all
 ||drive.google.com/uc?export=download&id=1yhflwpk3yeyrdhlhanctlind-5j24iwv$all
-||drive.google.com/uc?export=download&id=1ys9rupdqvnhvrngizxfzstzcos0dlx-u$all
-||drive.google.com/uc?export=download&id=1z6wmqtnaa-jtpm5bqkb3ebi_btjcvmat$all
 ||drive.google.com/uc?export=download&id=1zbclvhabervgfryoyqklo4_oe6icd8sr$all
-||drive.google.com/uc?export=download&id=1zor7cinphnazfkldkthucb2h8jthlh9d$all
-||drive.google.com/uc?export=download&id=1zsghzos5foggoqxq6w12xeqvanhccdyk$all
 ||drive.google.com/uc?id=148pt6v0nlg8yoim7w6in7dpixkzaacbg&export=download&authuser=0$all
 ||drpamelageorge.com/wp-includes/1zilg/$all
 ||drpamelageorge.com/wp-includes/qcgfmfvh/$all
@@ -5110,11 +5103,13 @@ zz.690tx.com
 ||jointings.org/eng/wp-content/plugins/featurific-for-wordpress/1$all
 ||jointings.org/eng/wp-content/plugins/featurific-for-wordpress/2$all
 ||jointings.org/eng/wp-content/plugins/featurific-for-wordpress/3$all
+||justlficante.mediafire.com/file/jl01o54yy09qrzg/fac215.tgz/file$all
 ||karmakoincodes.weebly.com/uploads/3/2/8/8/3288864/karma_koin_codes.exe$all
 ||kotakwarna.co.id/dg/etrac/nf4emwz/$all
 ||kuaizip.com/down/affiliate/kuaizip_setup_10029.exe$all
 ||linuxforensicsbook.com.s3.amazonaws.com/linuxforensicscode.zip$all
 ||minpic.de/k/big5/1giof6/$all
+||morrobaydrugandgift.com/wp-contentbak/t9m/$all
 ||my.cloudme.com/v1/ws2/:gianni1962/:ie6setup/ie6setup.exe$all
 ||nch.com.au/components/aacenc.exe$all
 ||nch.com.au/components/doxillionsetup.exe$all
@@ -5127,6 +5122,7 @@ zz.690tx.com
 ||onedrive.live.com/download?&resid=b4c15a27928f663b!229&authkey=aiarm61fwmd_npe$all
 ||onedrive.live.com/download?&resid=b4c15a27928f663b!230&authkey=ancu1eabetiubzg$all
 ||onedrive.live.com/download?&resid=b4c15a27928f663b!231&authkey=ai9h3sk_luxran0$all
+||onedrive.live.com/download?&resid=c127f9e0fb7cbbea!214&authkey=aat73nvghhjdr9g$all
 ||onedrive.live.com/download?authkey=!aase4ma0-vo_cls&cid=4df11eda676a355f&resid=4df11eda676a355f!140$all
 ||onedrive.live.com/download?authkey=!akd6uxvljtlvpxu&cid=4df11eda676a355f&resid=4df11eda676a355f!130$all
 ||onedrive.live.com/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135$all
@@ -5145,14 +5141,13 @@ zz.690tx.com
 ||onedrive.live.com/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw$all
 ||onedrive.live.com/download?cid=03286724f74117f9&resid=3286724f74117f9!1179&authkey=acr-_rvrgp39kk4$all
 ||onedrive.live.com/download?cid=03286724f74117f9&resid=3286724f74117f9%211179&authkey=acr-_rvrgp39kk4$all
-||onedrive.live.com/download?cid=032ce380af7ab389&resid=32ce380af7ab389!210&authkey=akcynbtc0h3ui7e$all
-||onedrive.live.com/download?cid=032ce380af7ab389&resid=32ce380af7ab389%21210&authkey=akcynbtc0h3ui7e$all
 ||onedrive.live.com/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48$all
 ||onedrive.live.com/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq$all
 ||onedrive.live.com/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg$all
 ||onedrive.live.com/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw$all
 ||onedrive.live.com/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq$all
 ||onedrive.live.com/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!273&authkey=ae2m69e5nu3rrea$all
+||onedrive.live.com/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!274&authkey=acqg0akutoxdpgo$all
 ||onedrive.live.com/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21273&authkey=ae2m69e5nu3rrea$all
 ||onedrive.live.com/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21274&authkey=acqg0akutoxdpgo$all
 ||onedrive.live.com/download?cid=0e26b39babdbf63c&resid=e26b39babdbf63c%21137&authkey=anshbgxg1_qa2h4$all
@@ -5164,8 +5159,10 @@ zz.690tx.com
 ||onedrive.live.com/download?cid=115bffdddaa40942&resid=115bffdddaa40942%21540&authkey=aamhnqgfdtdsoxk$all
 ||onedrive.live.com/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a$all
 ||onedrive.live.com/download?cid=13b301f1cb48f8cd&resid=13b301f1cb48f8cd%21106&authkey=aiae3olcs4lulz4$all
+||onedrive.live.com/download?cid=14f52af71b98dbc5&resid=14f52af71b98dbc5%212449&authkey=anfs_n5cs1noojo$all
 ||onedrive.live.com/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte$all
 ||onedrive.live.com/download?cid=165468846f076ee7&resid=165468846f076ee7%21118&authkey=antash3ig98aqte$all
+||onedrive.live.com/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f%21286&authkey=almwisomhv3c0zc$all
 ||onedrive.live.com/download?cid=174a158b69387a7e&resid=174a158b69387a7e!348&authkey=ahnjoxa4ufoxa54$all
 ||onedrive.live.com/download?cid=174a158b69387a7e&resid=174a158b69387a7e%21348&authkey=ahnjoxa4ufoxa54$all
 ||onedrive.live.com/download?cid=18418adacefed6e2&resid=18418adacefed6e2!126&authkey=ad4yflrisq6d82g$all
@@ -5181,10 +5178,6 @@ zz.690tx.com
 ||onedrive.live.com/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg$all
 ||onedrive.live.com/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4$all
 ||onedrive.live.com/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c$all
-||onedrive.live.com/download?cid=2184cd6093fdd997&resid=2184cd6093fdd997!136&authkey=agsnq9l7ncf4p-w$all
-||onedrive.live.com/download?cid=2184cd6093fdd997&resid=2184cd6093fdd997!137&authkey=aawcijw8fv4m-8g$all
-||onedrive.live.com/download?cid=2184cd6093fdd997&resid=2184cd6093fdd997%21136&authkey=agsnq9l7ncf4p-w$all
-||onedrive.live.com/download?cid=2184cd6093fdd997&resid=2184cd6093fdd997%21137&authkey=aawcijw8fv4m-8g$all
 ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!123&authkey=am1rcmkppbht8v0$all
 ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!124&authkey=am5sltharf-j_cc$all
 ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!125&authkey=acgvgbbuowodg4c$all
@@ -5217,6 +5210,8 @@ zz.690tx.com
 ||onedrive.live.com/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21115&authkey=aglznnsx71tbe9e$all
 ||onedrive.live.com/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37!183&authkey=akon9i9zzhusiuk$all
 ||onedrive.live.com/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37%21183&authkey=akon9i9zzhusiuk$all
+||onedrive.live.com/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6!161&authkey=aovldmsenzzpjrw$all
+||onedrive.live.com/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6%21161&authkey=aovldmsenzzpjrw$all
 ||onedrive.live.com/download?cid=2f01a497b687285e&resid=2f01a497b687285e!734&authkey=aiumuxtp3phppy4$all
 ||onedrive.live.com/download?cid=2f01a497b687285e&resid=2f01a497b687285e%21734&authkey=aiumuxtp3phppy4$all
 ||onedrive.live.com/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!116&authkey=!abwledjhfsqwap4$all
@@ -5239,8 +5234,6 @@ zz.690tx.com
 ||onedrive.live.com/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0$all
 ||onedrive.live.com/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa$all
 ||onedrive.live.com/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa$all
-||onedrive.live.com/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c!139&authkey=ap4bbakgkikau-a$all
-||onedrive.live.com/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c%21139&authkey=ap4bbakgkikau-a$all
 ||onedrive.live.com/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!198&authkey=acyz0gbpl6bp9mo$all
 ||onedrive.live.com/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!199&authkey=admaszabh84m8ou$all
 ||onedrive.live.com/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e%21198&authkey=acyz0gbpl6bp9mo$all
@@ -5250,21 +5243,6 @@ zz.690tx.com
 ||onedrive.live.com/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21152&authkey=am09sv26njxzyn0$all
 ||onedrive.live.com/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21153&authkey=ajs0jkoeqkqjrze$all
 ||onedrive.live.com/download?cid=3a1715e2cb964f25&resid=3a1715e2cb964f25%213713&authkey=aortxmfnibnoqkk$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237!963&authkey=aewqwrtr9szefem$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237!965&authkey=aaayllvoxl-rbdi$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237!966&authkey=apsg26pur_hpk6k$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237!971&authkey=amfm0a4mjjup0o8$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237!973&authkey=acfwvefa0v7myb4$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237!975&authkey=ajreyx8ik2l5uxm$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237!976&authkey=alpmp7w4cfupsvu$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237!977&authkey=adju1b_cnsxdxni$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21965&authkey=aaayllvoxl-rbdi$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21966&authkey=apsg26pur_hpk6k$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21971&authkey=amfm0a4mjjup0o8$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21975&authkey=ajreyx8ik2l5uxm$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21976&authkey=alpmp7w4cfupsvu$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21977&authkey=adju1b_cnsxdxni$all
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21978&authkey=agg7tntwzgctq7s$all
 ||onedrive.live.com/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21432&authkey=aa_npsupyqb2kge$all
 ||onedrive.live.com/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21435&authkey=admsjhgpkbtcqzs$all
 ||onedrive.live.com/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog$all
@@ -5431,6 +5409,7 @@ zz.690tx.com
 ||onedrive.live.com/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w$all
 ||onedrive.live.com/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta$all
 ||onedrive.live.com/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21117&authkey=aivf1ddcvvu22em$all
+||onedrive.live.com/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb!211&authkey=anxavz-oaf9pv_c$all
 ||onedrive.live.com/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21210&authkey=agpl0pgvft8faaa$all
 ||onedrive.live.com/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21211&authkey=anxavz-oaf9pv_c$all
 ||onedrive.live.com/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto$all
@@ -5471,7 +5450,6 @@ zz.690tx.com
 ||onedrive.live.com/download?cid=8ca507baa15fdb5c&resid=8ca507baa15fdb5c!213&authkey=acyrjlhflcrypae$all
 ||onedrive.live.com/download?cid=8ffd8cbd6540c065&resid=8ffd8cbd6540c065!822&authkey=acfj7bbrmktj1i0$all
 ||onedrive.live.com/download?cid=907247dc330a3f33&resid=907247dc330a3f33!243&authkey=aeiqd4ihuqopwm8$all
-||onedrive.live.com/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21276&authkey=afig5wsljtdc33s$all
 ||onedrive.live.com/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my$all
 ||onedrive.live.com/download?cid=914146ba02b70d25&resid=914146ba02b70d25!130&authkey=ais_g9dqoddonsc$all
 ||onedrive.live.com/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby$all
@@ -5514,7 +5492,6 @@ zz.690tx.com
 ||onedrive.live.com/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8$all
 ||onedrive.live.com/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq$all
 ||onedrive.live.com/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq$all
-||onedrive.live.com/download?cid=9fb622acb27482ef&resid=9fb622acb27482ef%211197&authkey=aeacibxy2zlyxro$all
 ||onedrive.live.com/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o$all
 ||onedrive.live.com/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4$all
 ||onedrive.live.com/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi$all
@@ -5531,7 +5508,6 @@ zz.690tx.com
 ||onedrive.live.com/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21!6053&authkey=agfh0ahstj7rrki$all
 ||onedrive.live.com/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21%216053&authkey=agfh0ahstj7rrki$all
 ||onedrive.live.com/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fi$all
-||onedrive.live.com/download?cid=a76c2c9b2bbef5ec&resid=a76c2c9b2bbef5ec%21141&authkey=akcfuxzfafd_c9c$all
 ||onedrive.live.com/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21414&authkey=akf9uwwkitvhrvc$all
 ||onedrive.live.com/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21415&authkey=ag_5kthuezprnoy$all
 ||onedrive.live.com/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21416&authkey=airlma-pycgfkyc$all
@@ -5635,12 +5611,14 @@ zz.690tx.com
 ||onedrive.live.com/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211030&authkey=aeqnasuksxccax4$all
 ||onedrive.live.com/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211031&authkey=acxtarrhbwrqt20$all
 ||onedrive.live.com/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211032&authkey=aemitbkn-vma9yk$all
+||onedrive.live.com/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211033&authkey=abiydifgst6musa$all
 ||onedrive.live.com/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211035&authkey=ahd_ichsrf8ok_u$all
 ||onedrive.live.com/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!191&authkey=ajl2uegqunsgc3q$all
 ||onedrive.live.com/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!192&authkey=acd_hx4bka3z0nw$all
 ||onedrive.live.com/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21191&authkey=ajl2uegqunsgc3q$all
 ||onedrive.live.com/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21192&authkey=acd_hx4bka3z0nw$all
 ||onedrive.live.com/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy$all
+||onedrive.live.com/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21107&authkey=alo4lep7wht05na$all
 ||onedrive.live.com/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21109&authkey=adnbm6mekgzvvh8$all
 ||onedrive.live.com/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!141&authkey=alya4infudqs53o$all
 ||onedrive.live.com/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!142&authkey=aiemnxi-s-5vrz0$all
@@ -5675,8 +5653,6 @@ zz.690tx.com
 ||onedrive.live.com/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21350&authkey=ao-vuexoihzj7da$all
 ||onedrive.live.com/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2!142&authkey=ais88uad5aom6qu$all
 ||onedrive.live.com/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2%21142&authkey=ais88uad5aom6qu$all
-||onedrive.live.com/download?cid=e86539a3497e46a2&resid=e86539a3497e46a2!120&authkey=amd6o5flalahjsy$all
-||onedrive.live.com/download?cid=e86539a3497e46a2&resid=e86539a3497e46a2%21120&authkey=amd6o5flalahjsy$all
 ||onedrive.live.com/download?cid=e97110434470423e&resid=e97110434470423e%21113&authkey=afowclex54if0g0$all
 ||onedrive.live.com/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw$all
 ||onedrive.live.com/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw$all
diff --git a/urlhaus-filter-snort2-online.rules b/urlhaus-filter-snort2-online.rules
index 96a2997c..e57d3f25 100644
--- a/urlhaus-filter-snort2-online.rules
+++ b/urlhaus-filter-snort2-online.rules
@@ -1,5 +1,5 @@
 # Title: Online Malicious URL Snort2 Ruleset
-# Updated: Thu, 25 Mar 2021 12:12:40 UTC
+# Updated: Fri, 26 Mar 2021 00:12:29 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -12,29 +12,29 @@ alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.192.180.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000006; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.222.140.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000007; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.222.196.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000008; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.24.132.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000009; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.245.4.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000010; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000011; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000012; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000013; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000014; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000015; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100000016; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100000017; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000018; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.245.4.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000009; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000010; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000011; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000012; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000013; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000014; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100000015; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100000016; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000017; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000018; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000019; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100000020; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100000021; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000022; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000023; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000024; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000025; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000026; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000027; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000028; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000029; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000030; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000031; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000021; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100000022; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000023; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000024; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000025; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000026; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000027; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000028; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000029; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000030; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000031; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.222.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000032; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000033; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.246.223.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000034; rev:1;)
@@ -66,72 +66,72 @@ alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.250.159.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000060; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.252.102.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000061; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.254.250.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000062; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.60.77.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000063; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.62.195.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100000064; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.58.223.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000063; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.60.77.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000064; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.65.166.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100000065; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.82.104.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000066; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1.85.84.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000067; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"100.12.184.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100000068; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"100.2.131.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000069; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"100.8.77.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000070; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1008691.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100000071; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.108.130.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000072; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.108.131.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000073; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.108.133.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100000074; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.16.183.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100000075; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.16.98.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000076; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.229.85.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000077; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.255.36.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100000078; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.28.102.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000079; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.28.105.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000080; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.28.106.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000081; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.28.145.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000082; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.28.76.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000083; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.30.128.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000084; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.64.119.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000085; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.64.161.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100000086; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.75.157.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000087; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.130.115.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000088; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.141.240.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000089; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.106.29.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100000090; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.107.113.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000091; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.113.99.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000092; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.124.104.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000093; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.125.218.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000094; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.136.82.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000095; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.139.89.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100000096; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.141.138.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000097; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.144.36.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100000098; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.145.13.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100000099; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.146.174.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100000100; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.156.221.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100000101; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.16.145.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000102; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.217.215.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000103; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.224.200.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100000104; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.233.64.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000105; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.235.165.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100000106; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.238.228.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100000107; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.238.228.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000108; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.240.249.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000109; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.70.160.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000110; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.79.112.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000111; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.82.145.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100000112; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.82.98.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000113; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.84.240.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000114; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.84.240.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000115; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100000116; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000117; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000118; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000119; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100000120; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100000121; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000122; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"100.12.184.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100000067; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"100.2.131.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000068; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"100.8.77.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000069; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1008691.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100000070; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.108.130.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000071; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.16.183.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100000072; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.16.98.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000073; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.229.85.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000074; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.255.36.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100000075; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.28.105.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000076; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.28.106.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000077; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.28.145.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000078; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.28.76.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000079; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.30.128.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000080; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.64.119.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000081; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.64.161.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100000082; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"101.75.157.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000083; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.130.115.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000084; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"102.141.240.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000085; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.107.113.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000086; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.113.99.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000087; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.124.104.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000088; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.125.218.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000089; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.136.82.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000090; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.141.138.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000091; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.144.36.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100000092; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.145.13.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100000093; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.146.174.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100000094; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.156.221.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100000095; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.16.145.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000096; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.161.232.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100000097; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.207.0.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000098; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.217.215.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000099; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.224.200.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100000100; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.233.64.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000101; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.238.228.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100000102; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.238.228.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000103; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.240.249.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000104; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.4.117.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000105; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.70.160.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000106; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.79.112.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000107; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.82.144.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100000108; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.82.145.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100000109; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.82.98.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000110; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.82.98.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000111; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.84.240.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000112; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000113; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100000114; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000115; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000116; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100000117; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000118; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100000119; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100000120; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000121; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000122; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000123; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100000124; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.91.245.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000125; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.92.25.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000126; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.92.25.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000127; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.168.44.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000128; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.168.98.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100000128; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.184.75.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000129; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.33.52.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000130; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.61.86.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000131; rev:1;)
@@ -140,5638 +140,5614 @@ alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.104.193.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000134; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.113.145.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100000135; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.113.177.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000136; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.172.134.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100000137; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.172.193.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000138; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.172.249.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100000139; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.173.155.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000140; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.174.144.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000141; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.175.197.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000142; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.181.136.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000143; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.194.242.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000144; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.219.185.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000145; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.220.119.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000146; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.221.96.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000147; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"108.190.201.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000148; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"108.190.250.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100000149; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"108.55.199.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100000150; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.104.151.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000151; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.124.90.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000152; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.233.196.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000153; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.235.7.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000154; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.248.58.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000155; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.4.138.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000137; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.172.134.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100000138; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.172.193.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000139; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.172.249.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100000140; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.173.155.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000141; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.174.144.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000142; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.175.197.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000143; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.181.136.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000144; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.194.242.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000145; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.219.185.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000146; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.220.119.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000147; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.221.96.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000148; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"108.190.201.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000149; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"108.190.250.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100000150; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"108.55.199.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100000151; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.104.151.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000152; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.124.90.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000153; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.233.196.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000154; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.235.7.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000155; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.86.85.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000156; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.95.200.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100000157; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.95.200.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000158; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.96.127.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000159; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.96.57.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100000160; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.99.37.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100000161; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"10abcabc0.cf"; content:"Host"; http_header; classtype:trojan-activity; sid:100000162; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.10.58.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000163; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.12.123.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100000164; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.14.58.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000165; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.187.229.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000166; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.228.190.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000167; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.228.195.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000168; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.241.119.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000169; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.241.23.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000170; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.248.124.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000171; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.248.224.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000172; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.248.251.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000173; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.251.10.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000174; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.253.103.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000175; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.253.213.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000176; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.253.51.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000177; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.255.101.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000178; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.255.167.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000179; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.145.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000180; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.208.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000181; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.209.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000182; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.221.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000183; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.88.185.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100000157; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.95.200.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100000158; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.95.200.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000159; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.96.127.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000160; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.96.57.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100000161; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"109.99.37.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100000162; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"10abcabc0.cf"; content:"Host"; http_header; classtype:trojan-activity; sid:100000163; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.10.58.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000164; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.12.123.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100000165; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.14.58.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000166; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.187.229.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000167; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.228.190.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000168; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.228.195.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000169; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.241.119.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000170; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.241.23.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000171; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.247.151.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000172; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.248.124.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000173; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.248.224.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000174; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.248.251.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000175; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.251.10.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000176; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.253.103.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000177; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.253.213.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000178; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.253.51.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000179; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.255.101.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000180; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.255.167.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000181; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.208.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000182; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.209.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000183; rev:1;)
 alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.223.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100000184; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.235.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000185; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.4.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000186; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.82.195.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100000187; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110fss.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100000188; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.118.124.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100000189; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.118.41.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000190; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.118.88.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100000191; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.125.67.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100000192; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.160.112.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000193; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.162.224.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000194; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.163.50.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000195; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.17.186.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000196; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.170.84.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000197; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.170.86.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000198; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.172.164.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100000199; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.176.182.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000200; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.179.153.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000201; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.179.243.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100000202; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.182.232.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000203; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.177.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000204; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.23.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000205; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.230.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000206; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.27.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000207; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.48.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100000208; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.103.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000209; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.103.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100000210; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.103.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100000211; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.104.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000212; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.104.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000213; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.106.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000214; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.106.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000215; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.106.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100000216; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.121.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000217; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.121.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100000218; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.121.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000219; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.123.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000220; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.123.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000221; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.123.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100000222; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.123.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000223; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.123.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000224; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.26.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000225; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.26.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000226; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.8.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100000227; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.61.52.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000228; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.73.99.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000229; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.91.185.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100000230; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.93.169.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000231; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.105.117.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000232; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.111.100.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100000233; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.111.108.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000234; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.111.31.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000235; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.122.36.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000236; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.123.109.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100000237; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.123.200.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100000238; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.123.61.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000239; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.132.134.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100000240; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.170.124.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000241; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.170.233.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000242; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.186.210.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100000243; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.186.96.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100000244; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.187.91.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100000245; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.214.127.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000246; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.187.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000247; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.236.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000248; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.43.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000249; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.52.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100000250; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.82.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000251; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.118.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000252; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.176.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100000253; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.195.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100000254; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.202.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100000255; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.205.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000256; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.47.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000257; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.67.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000258; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.92.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000259; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.228.100.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100000260; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.228.180.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000261; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.228.79.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000262; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.228.79.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100000263; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.229.178.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000264; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.229.188.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000265; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.229.199.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000266; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.234.134.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000267; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.234.16.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100000268; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.234.194.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000269; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.234.216.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000270; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.234.218.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000271; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.235.149.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000272; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.235.188.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100000273; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.236.126.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000274; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.236.171.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000275; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.236.228.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000276; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.141.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100000277; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.144.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100000278; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.197.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000279; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.230.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100000280; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.75.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100000281; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.89.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100000282; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.143.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000283; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.17.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000284; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.190.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000285; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.194.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000286; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.227.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000287; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.73.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100000288; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.240.184.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000289; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.240.216.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000290; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.242.106.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000291; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.242.18.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000292; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.242.2.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000293; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.243.115.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100000294; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.245.12.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000295; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.245.246.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000296; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.245.5.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000297; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.245.8.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100000298; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.246.162.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000299; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.100.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000300; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.121.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100000301; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.14.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000302; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.161.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000303; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.191.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000304; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.214.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000305; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.240.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100000306; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.81.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000307; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.82.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000308; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.89.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100000309; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.248.148.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000310; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.248.197.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000311; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.248.44.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100000312; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.109.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000313; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.118.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100000314; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.26.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100000315; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.41.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000316; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.250.102.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000317; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.250.57.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000318; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.251.17.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000319; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.251.218.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100000320; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.251.23.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000321; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.136.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000322; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.199.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000323; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.221.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000324; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.236.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100000325; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.237.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000326; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.239.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000327; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.245.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000328; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.254.208.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000329; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.255.38.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000330; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.255.52.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100000331; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.255.8.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000332; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.121.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000333; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.123.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100000334; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000335; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000336; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100000337; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000338; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100000339; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100000340; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000341; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000342; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000343; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000344; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000345; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100000346; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000347; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000348; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000349; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000350; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100000351; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000352; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000353; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000354; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000355; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000356; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000357; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000358; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000359; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100000360; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100000361; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000362; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000363; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000364; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000365; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100000366; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100000367; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000368; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100000369; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000370; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100000371; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000372; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.126.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000373; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.127.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000374; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.80.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000375; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.80.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000376; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.80.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000377; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.82.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100000378; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.83.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000379; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.83.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000380; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.87.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100000381; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.88.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100000382; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.91.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000383; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.91.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000384; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000385; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100000386; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100000387; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000388; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000389; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000390; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100000391; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100000392; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000393; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100000394; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000395; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100000396; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100000397; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000398; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000399; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100000400; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000401; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000402; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000403; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000404; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000405; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000406; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000407; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.100.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000408; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000409; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100000410; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100000411; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100000412; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000413; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000414; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000415; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000416; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000417; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000418; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000419; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000420; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000421; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000422; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000423; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100000424; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100000425; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.35.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000426; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.38.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100000427; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.38.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000428; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000429; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100000430; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000431; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000432; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000433; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000434; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000435; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000436; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000437; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000438; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.31.211.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000439; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.53.224.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000440; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.53.227.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000441; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.53.227.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100000442; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.65.53.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000443; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.153.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000444; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.162.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100000445; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.162.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100000446; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.162.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000447; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.175.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000448; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.176.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000449; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.176.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000450; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.226.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000451; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.231.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000452; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.78.45.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100000453; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.80.118.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100000454; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.80.127.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000455; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.80.215.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100000456; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.81.161.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000457; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.81.199.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100000458; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.81.49.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000459; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.131.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100000460; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.141.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000461; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.146.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000462; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.148.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000463; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.18.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100000464; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.224.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000465; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.227.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000466; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.228.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000467; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.86.133.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100000468; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.86.23.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000469; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.86.253.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000470; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.9.140.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000471; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.93.29.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100000472; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.95.22.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000473; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.95.23.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000474; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.103.10.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100000475; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.105.71.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100000476; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.11.95.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000477; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.110.247.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000478; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.116.121.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100000479; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.116.149.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100000480; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.116.246.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000481; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.116.48.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000482; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.118.195.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000483; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.122.238.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100000484; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.122.59.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000485; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.161.58.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000486; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.172.250.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000487; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.179.129.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000488; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.188.76.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100000489; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.194.133.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000490; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.194.135.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100000491; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.195.163.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000492; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.195.166.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000493; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.224.225.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100000494; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.226.42.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000495; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.227.128.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000496; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.227.169.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000497; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.227.35.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000498; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.231.211.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100000499; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.231.93.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000500; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.232.141.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000501; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.232.211.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000502; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.235.116.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100000503; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.237.129.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100000504; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.245.218.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000505; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.254.169.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000506; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.3.153.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000507; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.3.155.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100000508; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.133.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100000509; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.136.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100000510; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.144.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000511; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.154.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000512; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.191.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100000513; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.61.204.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100000514; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.86.204.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100000515; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.87.175.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000516; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.87.32.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000517; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.88.208.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100000518; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.88.232.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000519; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.88.38.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000520; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.89.41.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000521; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.89.41.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000522; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.92.156.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100000523; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.93.225.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000524; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.199.204.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000525; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.199.253.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000526; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.223.122.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000527; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.226.100.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000528; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.227.156.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100000529; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.228.205.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100000530; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.228.242.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000531; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.229.165.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000532; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.229.52.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000533; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.235.115.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100000534; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.235.42.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100000535; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.30.54.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100000536; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.79.161.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000537; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.79.172.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000538; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.165.216.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000539; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.193.130.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100000540; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.208.101.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000541; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.223.159.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000542; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.23.88.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000543; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.42.47.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000544; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.48.130.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100000545; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.48.141.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100000546; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.48.198.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000547; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.48.215.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100000548; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.48.22.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000549; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.48.228.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100000550; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.48.9.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100000551; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.49.100.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100000552; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.49.18.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000553; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.49.216.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000554; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.49.60.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100000555; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.1.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000556; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.158.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100000557; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.2.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000558; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.219.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100000559; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.22.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100000560; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.220.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100000561; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.224.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000562; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.230.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000563; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.232.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000564; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.239.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000565; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.3.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000566; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.56.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000567; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.8.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100000568; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.81.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000569; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.51.104.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000570; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.51.123.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100000571; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.51.93.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100000572; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.52.112.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000573; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.52.19.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000574; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.52.200.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100000575; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.52.21.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000576; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.54.192.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100000577; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.54.222.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100000578; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.54.236.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000579; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.54.241.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000580; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.54.73.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000581; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.105.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000582; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.144.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000583; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.144.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000584; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.144.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000585; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.145.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000586; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.149.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100000587; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.178.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100000588; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.198.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100000589; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.211.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100000590; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.42.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000591; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.53.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000592; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.134.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100000593; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.134.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100000594; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.139.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000595; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.142.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000596; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.143.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100000597; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.148.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000598; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.155.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100000599; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.156.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000600; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.162.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000601; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.178.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100000602; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.188.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100000603; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.31.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000604; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.67.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000605; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.86.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000606; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.87.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000607; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.98.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100000608; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.111.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000609; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.119.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100000610; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.134.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000611; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.141.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000612; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.83.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100000613; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.88.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000614; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.93.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000615; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.197.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000616; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.198.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000617; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.210.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000618; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.235.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000619; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.253.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000620; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.26.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000621; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.63.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100000622; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.107.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000623; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.111.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000624; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.119.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100000625; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.119.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000626; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.119.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000627; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.125.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000628; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.137.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100000629; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.180.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000630; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.182.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100000631; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.185.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100000632; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.97.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000633; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.62.26.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100000634; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.62.60.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000635; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.63.135.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000636; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.63.4.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000637; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.63.56.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100000638; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.73.3.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100000639; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.74.217.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000640; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.75.217.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000641; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.92.174.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100000642; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.124.219.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000643; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.127.207.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100000644; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.149.119.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000645; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.2.100.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100000646; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.2.66.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100000647; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.206.164.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000648; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.211.100.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000649; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.212.142.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000650; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.24.153.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100000651; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.72.201.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000652; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.75.192.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100000653; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.76.114.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000654; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.88.65.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100000655; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.11.234.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000656; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.11.95.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100000657; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.15.201.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100000658; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.192.224.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000659; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.192.225.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100000660; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.192.226.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000661; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.194.162.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100000662; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.194.163.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000663; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.204.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100000664; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.204.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000665; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.210.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000666; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.220.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100000667; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.236.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000668; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.243.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100000669; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.200.76.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000670; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.200.76.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000671; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.201.128.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100000672; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.202.66.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000673; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.202.67.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100000674; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.202.67.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100000675; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.202.68.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000676; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.213.41.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000677; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.213.42.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000678; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.213.42.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100000679; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.213.44.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000680; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.213.45.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100000681; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.213.45.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000682; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.213.45.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100000683; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.213.46.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100000684; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.213.46.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000685; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.215.213.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000686; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.215.215.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100000687; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.222.160.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100000688; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.222.165.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100000689; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.222.166.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000690; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.222.169.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000691; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.222.170.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000692; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.222.175.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100000693; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.241.66.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000694; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.241.67.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100000695; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.242.211.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000696; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.247.204.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000697; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.247.206.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000698; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.248.60.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000699; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.251.56.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100000700; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.251.56.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000701; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.251.56.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100000702; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.251.56.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000703; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.251.60.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000704; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.251.63.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100000705; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.26.110.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000706; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.26.235.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000707; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.27.10.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000708; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.63.113.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000709; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.63.195.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100000710; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.63.252.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100000711; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.63.53.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100000712; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.87.170.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100000713; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.90.78.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000714; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.93.115.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100000715; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.93.79.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100000716; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.176.104.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000717; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.176.157.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100000718; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.176.7.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000719; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.211.38.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000720; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.223.32.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000721; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.223.5.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000722; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.223.72.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000723; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.128.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000724; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.208.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000725; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.209.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000726; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.214.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100000727; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.88.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000728; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.96.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000729; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.96.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000730; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.233.165.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100000731; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.233.221.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000732; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.233.65.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000733; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.249.136.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000734; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.250.51.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100000735; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.38.189.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000736; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.42.125.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100000737; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.43.180.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000738; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.68.245.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000739; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.75.50.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000740; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.75.70.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100000741; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.125.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100000742; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.143.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000743; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.218.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100000744; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.50.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000745; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.58.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100000746; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.73.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000747; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.83.79.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000748; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.99.179.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000749; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.99.183.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000750; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.99.239.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000751; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.100.40.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000752; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.108.188.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000753; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.108.252.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000754; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.109.34.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100000755; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.112.22.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000756; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.118.251.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000757; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.119.52.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000758; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.123.219.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100000759; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.14.143.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100000760; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.147.213.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000761; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.162.109.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100000762; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.163.144.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100000763; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.163.93.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100000764; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.164.18.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000765; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.164.31.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100000766; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.164.74.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100000767; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.107.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000768; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.163.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100000769; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.174.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100000770; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.241.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000771; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.27.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000772; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.68.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100000773; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.166.170.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100000774; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.166.19.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000775; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.166.97.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000776; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.167.1.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100000777; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.167.2.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100000778; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.167.26.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000779; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.167.63.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000780; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.176.231.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000781; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.178.201.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100000782; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.178.248.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000783; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.178.249.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100000784; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.157.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100000785; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.16.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000786; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.170.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000787; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.27.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100000788; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.43.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100000789; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.75.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000790; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.18.38.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000791; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.101.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000792; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.106.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000793; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.108.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000794; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.108.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000795; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.11.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100000796; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.231.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000797; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.33.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000798; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.80.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000799; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.94.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000800; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.181.124.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000801; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.181.43.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000802; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.183.109.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000803; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.183.115.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000804; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.183.9.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100000805; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.184.14.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000806; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.184.172.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100000807; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.184.172.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000808; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.185.102.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000809; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.185.237.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000810; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.185.39.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100000811; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.185.43.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000812; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.186.22.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100000813; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.187.195.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000814; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.187.220.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000815; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.187.62.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000816; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.189.137.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000817; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.189.227.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000818; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.190.211.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000819; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.190.240.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000820; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.150.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000821; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.187.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000822; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.215.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100000823; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.253.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000824; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.204.30.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000825; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.250.218.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000826; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.251.105.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100000827; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.251.12.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000828; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.251.14.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000829; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.131.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000830; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.143.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000831; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.143.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000832; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.148.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000833; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.155.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000834; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.172.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000835; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.175.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000836; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.206.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000837; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.220.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000838; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.96.37.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000839; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.96.70.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100000840; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.99.188.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100000841; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.99.190.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100000842; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.99.232.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100000843; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.132.113.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000844; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.15.69.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100000845; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000846; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100000847; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000848; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000849; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.207.39.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000850; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.12.144.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000851; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.12.153.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000852; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.142.222.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000853; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.150.213.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000854; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.151.248.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000855; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000856; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000857; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100000858; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100000859; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100000860; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000861; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000862; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100000863; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100000864; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100000865; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000866; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100000867; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100000868; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000869; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100000870; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000871; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100000872; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000873; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000874; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100000875; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000876; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100000877; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100000878; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000879; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100000880; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000881; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100000882; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.93.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000883; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.121.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000884; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000885; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100000886; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100000887; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000888; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000889; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000890; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.127.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100000891; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.99.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000892; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.210.89.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000893; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.43.54.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100000894; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.50.66.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000895; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.50.93.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000896; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.59.245.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000897; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.6.141.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000898; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.6.8.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100000899; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.69.113.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100000900; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.69.131.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000901; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.7.90.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100000902; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.165.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000903; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.169.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100000904; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.174.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000905; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.174.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000906; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.186.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000907; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.237.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100000908; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.239.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000909; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.86.84.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100000910; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.9.32.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000911; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.100.114.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000912; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.100.96.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000913; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.121.44.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000914; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.123.53.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000915; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.127.155.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100000916; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.141.11.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000917; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.15.142.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100000918; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.151.78.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000919; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.159.22.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000920; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.16.155.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000921; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.17.103.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100000922; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.170.234.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000923; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.185.31.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000924; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.190.36.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000925; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.205.229.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000926; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.225.11.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000927; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.226.82.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000928; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.23.18.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000929; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.230.171.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000930; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.231.103.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000931; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.237.225.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000932; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.238.175.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100000933; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.239.15.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000934; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.24.116.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000935; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.25.101.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100000936; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.254.43.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000937; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.61.101.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000938; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.61.102.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100000939; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.61.107.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100000940; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.61.97.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000941; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.61.98.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000942; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.88.99.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100000943; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.100.150.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100000944; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.137.52.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000945; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.160.147.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000946; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.192.190.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000947; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.194.191.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000948; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.199.72.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000949; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.199.79.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000950; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.199.83.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100000951; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.202.37.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000952; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.202.41.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000953; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.252.241.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000954; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.252.250.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000955; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.254.183.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000956; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.254.29.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000957; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.254.33.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100000958; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.0.240.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000959; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.10.128.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000960; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.10.140.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100000961; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.10.210.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100000962; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.10.36.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100000963; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.10.41.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100000964; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.11.1.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000965; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.11.74.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100000966; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.124.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000967; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.124.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000968; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.170.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000969; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.182.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100000970; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.19.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100000971; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.200.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000972; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.238.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100000973; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.12.238.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000974; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.12.3.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000975; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.128.128.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100000976; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.128.133.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000977; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.129.84.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000978; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.129.88.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000979; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.169.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000980; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.208.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000981; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.23.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000982; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.37.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000983; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.61.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100000984; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.131.186.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000985; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.132.219.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000986; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.133.125.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000987; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.133.144.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100000988; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.133.98.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000989; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.134.14.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000990; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.134.50.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100000991; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.135.157.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000992; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.135.39.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000993; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.135.71.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000994; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.101.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100000995; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.150.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000996; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.217.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000997; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.235.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100000998; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.248.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100000999; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.76.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100001000; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.88.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100001001; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.152.42.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001002; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.152.43.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100001003; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.154.94.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001004; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.155.118.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001005; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.156.136.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100001006; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.159.137.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100001007; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.159.31.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001008; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.159.8.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100001009; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.191.173.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100001010; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.192.101.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001011; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.192.194.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001012; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.193.149.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100001013; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.193.53.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001014; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.235.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001015; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.35.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100001016; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.52.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001017; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.60.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001018; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.195.112.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100001019; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.195.184.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001020; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.195.98.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001021; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.212.29.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100001022; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.213.225.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001023; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.233.130.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001024; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.233.152.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100001025; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.234.100.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001026; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.234.116.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001027; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.234.184.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001028; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.234.246.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100001029; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.235.107.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001030; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.240.103.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001031; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.240.181.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001032; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.240.79.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100001033; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.241.148.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001034; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.241.184.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100001035; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.27.44.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001036; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.28.217.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001037; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.193.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001038; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.44.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100001039; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.85.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100001040; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.88.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001041; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.92.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001042; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.5.123.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001043; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.5.13.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001044; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.5.178.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100001045; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.5.27.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001046; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.8.253.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001047; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.8.254.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001048; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.8.40.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001049; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.8.41.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001050; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.8.62.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001051; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.9.110.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100001052; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.9.243.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001053; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.9.245.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001054; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.105.105.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100001055; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.129.162.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001056; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.129.221.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001057; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.129.76.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001058; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.130.167.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001059; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.104.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001060; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.130.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001061; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.136.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001062; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.151.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001063; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.21.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100001064; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.26.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100001065; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.54.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001066; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.70.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001067; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.72.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001068; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.132.110.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001069; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.135.34.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001070; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.153.236.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001071; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.160.126.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001072; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.138.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100001073; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.167.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001074; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.65.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001075; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.72.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100001076; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.77.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001077; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.90.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001078; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.165.123.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001079; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.167.186.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001080; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.187.111.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100001081; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.199.56.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001082; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.226.24.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100001083; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.230.174.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001084; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.234.6.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001085; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.5.92.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001086; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.6.0.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001087; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.7.254.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001088; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.80.46.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100001089; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.92.132.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001090; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.92.148.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001091; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.106.125.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100001092; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.128.28.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001093; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.142.93.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001094; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.168.10.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001095; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.191.113.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001096; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.1.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100001097; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.107.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001098; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.113.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001099; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.150.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001100; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.16.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001101; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.163.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001102; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.65.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100001103; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.73.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001104; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.74.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001105; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.75.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001106; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.0.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001107; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.106.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001108; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.138.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001109; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.189.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100001110; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.191.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100001111; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.196.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001112; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.2.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001113; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.204.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100001114; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.205.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001115; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.245.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001116; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.6.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001117; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.7.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001118; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.80.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001119; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.86.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100001120; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.96.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100001121; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.97.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001122; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.42.124.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100001123; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.42.234.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001124; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.42.96.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100001125; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.42.96.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001126; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.42.98.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100001127; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.106.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001128; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.112.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100001129; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.126.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001130; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.136.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001131; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.177.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100001132; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.26.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001133; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.34.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001134; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.5.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100001135; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.53.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100001136; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.93.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100001137; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.168.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001138; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.213.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100001139; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.248.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100001140; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.29.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100001141; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.30.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001142; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.42.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100001143; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.61.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001144; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.8.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001145; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.45.65.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001146; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.46.184.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001147; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.46.203.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001148; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.46.206.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100001149; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.193.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001150; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.200.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100001151; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.207.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100001152; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.209.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001153; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.244.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100001154; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.29.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100001155; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.36.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001156; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.45.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001157; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.71.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100001158; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.90.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001159; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.91.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001160; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"128.116.133.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100001161; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"130.255.159.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001162; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"134.195.139.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001163; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"134.236.252.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001164; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"138.99.204.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100001165; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.159.226.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001166; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.170.173.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001167; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.170.174.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001168; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.216.102.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001169; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.227.46.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100001170; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.102.17.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100001171; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.102.97.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001172; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.136.80.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001173; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.138.109.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100001174; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.138.109.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001175; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.138.8.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001176; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.138.8.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001177; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.155.220.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100001178; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.155.223.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001179; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.169.164.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001180; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.189.247.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001181; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.205.201.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001182; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.37.222.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001183; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.45.127.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001184; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.46.25.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100001185; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.46.98.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100001186; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.55.29.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001187; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"142.11.216.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001188; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"142.177.56.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100001189; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"146.71.79.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001190; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"148.69.108.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100001191; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001192; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001193; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001194; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001195; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.3.36.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100001196; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"150.116.207.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100001197; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"151.177.163.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001198; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"151.33.230.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001199; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"151.51.158.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100001200; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"151.73.124.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001201; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.101.225.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001202; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.101.234.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001203; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.3.123.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001204; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.3.43.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100001205; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.3.44.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100001206; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.34.135.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100001207; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.34.23.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100001208; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.34.29.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001209; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.34.52.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001210; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.35.27.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001211; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.36.126.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001212; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"154.126.178.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001213; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"158.101.165.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001214; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"158.174.213.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001215; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"158.51.125.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001216; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"159.224.74.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001217; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.191.165.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001218; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.191.205.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100001219; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.191.249.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100001220; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.194.28.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001221; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.209.98.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001222; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.212.203.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001223; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.195.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100001224; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.200.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001225; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.200.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100001226; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.203.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001227; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.223.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001228; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.53.206.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001229; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"165.90.16.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001230; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"170.78.39.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001231; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"170.81.238.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001232; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.118.18.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001233; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.118.210.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100001234; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.119.217.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001235; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.119.218.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001236; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.119.219.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001237; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.119.255.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001238; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.120.125.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001239; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.121.6.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001240; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.123.189.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100001241; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.125.114.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100001242; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.125.30.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001243; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.125.30.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001244; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.125.64.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001245; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.126.109.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100001246; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.34.112.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001247; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.34.179.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001248; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.35.161.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001249; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.35.162.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100001250; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.35.173.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001251; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.35.174.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001252; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.38.219.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100001253; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.44.254.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001254; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.105.36.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100001255; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.114.244.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100001256; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.245.5.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100001257; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.93.176.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100001258; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.167.85.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001259; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.169.46.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001260; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.19.58.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100001261; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.220.222.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001262; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.233.85.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001263; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.235.209.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001264; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.237.254.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100001265; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.25.113.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100001266; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.52.95.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001267; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.52.97.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100001268; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.56.119.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100001269; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.56.92.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001270; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.106.33.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001271; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.48.181.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001272; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.73.246.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100001273; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.81.78.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001274; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.84.148.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100001275; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.96.30.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100001276; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.10.147.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001277; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.10.48.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001278; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.11.212.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001279; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.11.96.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001280; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.115.241.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001281; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.117.66.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001282; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.145.200.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100001283; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.153.144.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001284; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.162.69.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100001285; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.169.172.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100001286; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.173.196.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001287; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.174.93.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001288; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.199.33.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001289; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.201.104.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001290; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.208.230.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100001291; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.212.6.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001292; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.42.46.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001293; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.9.24.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001294; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001295; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001296; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001297; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001298; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100001299; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100001300; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100001301; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100001302; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001303; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001304; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001305; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001306; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001307; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100001308; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100001309; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100001310; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.174.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001311; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.12.117.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001312; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.123.4.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001313; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.123.7.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001314; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.123.7.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100001315; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.123.9.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001316; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.124.7.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001317; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.240.40.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100001318; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.240.84.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001319; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.32.151.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001320; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.229.64.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001321; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.44.61.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001322; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.54.82.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100001323; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.86.235.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001324; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.124.182.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100001325; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.136.195.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100001326; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.141.210.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100001327; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.141.25.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001328; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.141.57.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001329; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.150.174.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001330; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.165.122.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001331; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.0.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100001332; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001333; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100001334; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001335; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100001336; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.10.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100001337; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.10.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100001338; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.10.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001339; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100001340; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001341; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001342; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001343; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001344; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.101.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001345; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001346; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100001347; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100001348; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001349; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100001350; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001351; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100001352; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.103.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001353; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.103.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100001354; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100001355; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001356; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001357; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001358; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001359; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001360; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100001361; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100001362; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001363; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001364; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100001365; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100001366; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100001367; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100001368; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001369; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100001370; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001371; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001372; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001373; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001374; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001375; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100001376; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001377; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001378; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001379; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001380; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001381; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001382; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001383; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001384; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100001385; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100001386; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100001387; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001388; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001389; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001390; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100001391; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001392; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.109.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001393; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.109.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001394; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100001395; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001396; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001397; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001398; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001399; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001400; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100001401; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100001402; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100001403; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100001404; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100001405; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100001406; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001407; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001408; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001409; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001410; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100001411; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001412; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100001413; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001414; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001415; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001416; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.113.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001417; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.113.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001418; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.113.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001419; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.113.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001420; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.113.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001421; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.113.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001422; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001423; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001424; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001425; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001426; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001427; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100001428; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100001429; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001430; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001431; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100001432; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001433; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001434; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100001435; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100001436; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001437; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100001438; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100001439; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001440; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100001441; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100001442; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100001443; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001444; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001445; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.116.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100001446; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.116.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001447; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.116.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001448; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.117.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001449; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.117.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100001450; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.117.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001451; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.117.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001452; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.117.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100001453; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001454; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001455; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001456; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001457; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001458; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100001459; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001460; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100001461; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100001462; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001463; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001464; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100001465; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100001466; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.120.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001467; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.120.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001468; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.120.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001469; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.120.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100001470; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100001471; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001472; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100001473; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100001474; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100001475; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100001476; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100001477; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001478; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001479; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001480; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100001481; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001482; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001483; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001484; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001485; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001486; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001487; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001488; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001489; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001490; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001491; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100001492; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001493; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001494; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001495; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001496; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001497; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100001498; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001499; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001500; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001501; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001502; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100001503; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001504; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001505; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100001506; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001507; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100001508; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001509; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001510; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001511; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001512; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100001513; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001514; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100001515; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001516; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001517; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100001518; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100001519; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100001520; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001521; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001522; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001523; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001524; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001525; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001526; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001527; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.14.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001528; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.14.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100001529; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.14.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001530; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.14.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001531; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.14.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001532; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100001533; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100001534; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001535; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001536; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100001537; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001538; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001539; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100001540; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001541; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100001542; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001543; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001544; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100001545; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.17.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100001546; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.17.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001547; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.18.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001548; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.18.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001549; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.18.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001550; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100001551; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001552; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001553; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001554; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001555; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100001556; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001557; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001558; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001559; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001560; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001561; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001562; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100001563; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100001564; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100001565; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001566; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100001567; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001568; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001569; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001570; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001571; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100001572; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100001573; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001574; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001575; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001576; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001577; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001578; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100001579; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.23.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100001580; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.23.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001581; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100001582; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001583; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100001584; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001585; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001586; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100001587; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100001588; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100001589; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100001590; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001591; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001592; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001593; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001594; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001595; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001596; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100001597; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100001598; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001599; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100001600; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001601; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100001602; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100001603; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001604; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001605; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001606; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001607; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001608; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001609; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001610; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100001611; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001612; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001613; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001614; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100001615; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100001616; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100001617; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100001618; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100001619; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.28.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001620; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.28.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100001621; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.28.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001622; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.28.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001623; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.28.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100001624; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.28.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100001625; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001626; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100001627; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001628; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001629; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001630; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100001631; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001632; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001633; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001634; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001635; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100001636; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001637; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100001638; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001639; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100001640; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100001641; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001642; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.31.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001643; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.31.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100001644; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.31.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100001645; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.31.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100001646; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001647; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001648; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001649; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001650; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001651; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001652; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001653; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001654; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001655; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100001656; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001657; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001658; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001659; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001660; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001661; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001662; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001663; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001664; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001665; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001666; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100001667; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001668; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100001669; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001670; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001671; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100001672; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001673; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.34.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001674; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.35.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100001675; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.35.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100001676; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.35.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001677; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.35.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100001678; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.35.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100001679; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.35.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001680; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.35.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001681; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001682; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001683; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100001684; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001685; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100001686; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001687; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001688; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100001689; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001690; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001691; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001692; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001693; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100001694; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001695; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001696; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001697; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001698; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001699; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100001700; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001701; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100001702; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001703; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001704; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001705; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001706; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001707; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.39.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001708; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.39.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001709; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100001710; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001711; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001712; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001713; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001714; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001715; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001716; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001717; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001718; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100001719; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001720; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001721; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100001722; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001723; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100001724; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100001725; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001726; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001727; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001728; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001729; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100001730; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100001731; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001732; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001733; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001734; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001735; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100001736; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001737; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100001738; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001739; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001740; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001741; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001742; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100001743; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001744; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100001745; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100001746; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001747; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001748; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100001749; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001750; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001751; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001752; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001753; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001754; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001755; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100001756; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001757; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100001758; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.45.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100001759; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.45.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100001760; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.45.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100001761; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.45.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001762; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100001763; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001764; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001765; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.48.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001766; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.48.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100001767; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.48.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001768; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001769; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100001770; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001771; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001772; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.5.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001773; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.5.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100001774; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.5.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100001775; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.5.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001776; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001777; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100001778; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100001779; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001780; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001781; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001782; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001783; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.51.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001784; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.51.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001785; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.51.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100001786; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.51.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001787; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.51.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001788; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.51.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001789; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001790; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001791; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001792; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100001793; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100001794; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001795; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001796; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001797; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001798; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001799; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001800; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100001801; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100001802; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100001803; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100001804; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100001805; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001806; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001807; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100001808; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100001809; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001810; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001811; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100001812; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100001813; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001814; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001815; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001816; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001817; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.57.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001818; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.57.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001819; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.57.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001820; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.57.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001821; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.58.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100001822; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.58.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001823; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.58.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001824; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100001825; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001826; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100001827; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001828; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001829; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001830; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100001831; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001832; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001833; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100001834; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001835; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001836; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.60.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100001837; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.60.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100001838; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.60.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100001839; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.60.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100001840; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001841; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100001842; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001843; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100001844; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001845; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100001846; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100001847; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001848; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001849; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001850; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100001851; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.63.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100001852; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.63.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100001853; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.63.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001854; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100001855; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100001856; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100001857; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100001858; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100001859; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001860; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.65.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001861; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.65.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100001862; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.65.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001863; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.65.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001864; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.65.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001865; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.65.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001866; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.65.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001867; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001868; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001869; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100001870; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001871; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001872; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001873; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001874; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001875; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001876; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001877; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001878; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100001879; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100001880; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100001881; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001882; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001883; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100001884; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001885; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001886; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001887; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100001888; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100001889; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100001890; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001891; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001892; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100001893; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100001894; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001895; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001896; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001897; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100001898; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100001899; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001900; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.7.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001901; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100001902; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100001903; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001904; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001905; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100001906; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100001907; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100001908; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001909; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100001910; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001911; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100001912; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001913; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001914; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100001915; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001916; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100001917; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001918; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100001919; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100001920; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100001921; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100001922; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001923; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100001924; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001925; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001926; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100001927; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001928; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.73.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001929; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.74.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001930; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.74.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100001931; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.75.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001932; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.75.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100001933; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.75.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100001934; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.75.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001935; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.75.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100001936; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.75.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001937; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.75.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100001938; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.75.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001939; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001940; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001941; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100001942; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100001943; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001944; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100001945; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100001946; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.77.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001947; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.77.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100001948; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.77.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001949; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.77.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001950; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.77.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001951; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001952; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100001953; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001954; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001955; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100001956; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.79.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100001957; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.79.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001958; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.79.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100001959; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.79.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100001960; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.79.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100001961; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.79.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001962; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.8.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100001963; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.8.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001964; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.8.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001965; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.8.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100001966; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.8.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100001967; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.8.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100001968; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001969; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001970; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001971; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100001972; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001973; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001974; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100001975; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100001976; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100001977; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001978; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100001979; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100001980; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001981; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100001982; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001983; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.82.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100001984; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.83.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001985; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.83.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001986; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100001987; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001988; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100001989; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001990; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001991; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001992; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001993; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001994; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100001995; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001996; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100001997; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001998; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100001999; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.86.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100002000; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.86.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100002001; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002002; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100002003; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002004; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100002005; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100002006; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002007; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100002008; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100002009; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.89.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002010; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.89.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100002011; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.89.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100002012; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.89.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100002013; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100002014; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100002015; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100002016; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002017; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100002018; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100002019; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100002020; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002021; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100002022; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002023; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100002024; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100002025; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100002026; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100002027; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100002028; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100002029; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100002030; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100002031; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100002032; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100002033; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100002034; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100002035; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100002036; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002037; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100002038; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002039; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100002040; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100002041; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100002042; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100002043; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100002044; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100002045; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100002046; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100002047; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100002048; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100002049; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100002050; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100002051; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100002052; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100002053; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100002054; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100002055; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100002056; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100002057; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100002058; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100002059; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100002060; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100002061; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100002062; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100002063; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100002064; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100002065; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002066; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100002067; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100002068; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100002069; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100002070; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.96.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100002071; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.96.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002072; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.96.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100002073; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.96.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100002074; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.96.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100002075; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.97.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100002076; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.97.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100002077; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.97.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100002078; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.98.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100002079; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.98.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100002080; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.98.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100002081; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.98.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100002082; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.98.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100002083; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100002084; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100002085; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002086; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002087; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100002088; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100002089; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100002090; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100002091; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.19.183.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100002092; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.205.101.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002093; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.21.164.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100002094; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.217.8.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002095; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.22.117.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100002096; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.222.252.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002097; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.34.183.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100002098; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.92.246.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100002099; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.93.112.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100002100; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.95.115.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002101; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.159.58.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100002102; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.4.187.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100002103; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.48.156.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002104; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.60.84.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002105; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.99.210.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100002106; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.109.36.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002107; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.111.101.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100002108; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.114.111.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100002109; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.116.203.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002110; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.120.149.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100002111; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.122.13.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100002112; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.125.155.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100002113; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.125.44.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002114; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.157.66.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100002115; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.175.93.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100002116; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.105.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002117; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.110.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100002118; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.165.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100002119; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.214.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100002120; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.34.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100002121; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.96.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100002122; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.177.104.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100002123; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.177.242.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100002124; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.218.5.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100002125; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.248.80.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100002126; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.66.111.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002127; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.66.53.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100002128; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.94.170.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002129; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.112.138.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100002130; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.112.218.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100002131; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.112.218.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100002132; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.143.60.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002133; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.174.63.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100002134; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.193.107.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100002135; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.199.170.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100002136; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.199.170.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100002137; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.199.170.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100002138; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.199.170.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100002139; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.210.45.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002140; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.215.47.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002141; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.224.242.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100002142; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.49.236.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100002143; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.49.59.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002144; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.112.0.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002145; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.112.15.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100002146; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.112.39.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100002147; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.112.52.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100002148; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.113.0.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100002149; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.113.222.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100002150; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.113.24.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100002151; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.106.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100002152; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.122.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100002153; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.202.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100002154; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.31.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100002155; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.50.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100002156; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.50.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100002157; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.64.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100002158; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.70.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100002159; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.93.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100002160; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.94.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100002161; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.101.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002162; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.104.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100002163; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.110.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100002164; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.44.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100002165; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.49.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100002166; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.60.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100002167; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.61.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002168; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.65.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100002169; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.65.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100002170; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.68.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100002171; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.69.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100002172; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.69.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100002173; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.94.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100002174; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.99.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002175; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.155.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100002176; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.25.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100002177; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.26.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100002178; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.27.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100002179; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.29.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002180; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.43.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100002181; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.118.140.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100002182; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.100.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100002183; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.14.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002184; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.166.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100002185; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.211.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100002186; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.220.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100002187; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.227.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002188; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.229.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002189; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.236.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100002190; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.50.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100002191; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.81.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002192; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.10.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100002193; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.16.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002194; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.16.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100002195; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.37.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100002196; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.43.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100002197; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.101.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100002198; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.109.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100002199; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.125.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100002200; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.129.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100002201; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.131.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100002202; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.133.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100002203; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.135.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100002204; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.148.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100002205; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.157.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100002206; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.200.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100002207; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.206.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100002208; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.219.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100002209; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.233.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100002210; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.249.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100002211; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.68.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100002212; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.81.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100002213; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.92.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100002214; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.93.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100002215; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.98.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100002216; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.122.170.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100002217; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.122.220.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002218; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.122.229.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100002219; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.122.245.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100002220; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.122.249.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100002221; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.124.188.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100002222; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.124.53.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100002223; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.113.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100002224; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.117.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002225; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.124.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100002226; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.126.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002227; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.127.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100002228; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.139.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100002229; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.139.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002230; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.140.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100002231; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.178.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100002232; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.82.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100002233; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.83.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100002234; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.87.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002235; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.95.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100002236; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.155.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100002237; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.166.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100002238; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.210.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002239; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.6.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100002240; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.78.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100002241; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.87.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100002242; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.91.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100002243; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.172.36.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002244; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.207.219.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002245; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.233.0.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002246; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.235.252.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100002247; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.53.197.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100002248; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.88.235.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100002249; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.105.104.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100002250; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.105.225.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100002251; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.109.169.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100002252; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.11.238.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100002253; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.136.252.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100002254; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.150.138.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100002255; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.16.208.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100002256; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.187.163.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100002257; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.188.151.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100002258; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.188.180.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100002259; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.188.180.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100002260; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.188.76.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100002261; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.83.14.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100002262; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.83.15.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100002263; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.83.23.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100002264; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.83.99.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002265; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.92.195.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100002266; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.95.147.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100002267; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.97.22.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100002268; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"184.164.185.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002269; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"184.74.149.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100002270; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.106.209.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100002271; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.107.3.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100002272; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.172.110.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100002273; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.181.10.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100002274; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.200.241.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100002275; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100002276; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100002277; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002278; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100002279; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.219.133.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100002280; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.221.3.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002281; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.228.141.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002282; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.239.243.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002283; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.26.113.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100002284; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.43.19.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100002285; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.55.1.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100002286; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.68.230.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100002287; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.81.157.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100002288; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.217.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100002289; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.217.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100002290; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100002291; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100002292; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100002293; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100002294; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.90.166.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100002295; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.151.144.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100002296; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.219.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002297; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.243.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100002298; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.243.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002299; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.253.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100002300; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.225.120.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100002301; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.227.148.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002302; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.28.60.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100002303; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.4.125.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100002304; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.73.188.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100002305; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.12.10.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100002306; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.188.124.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100002307; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.212.200.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002308; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.56.88.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100002309; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.75.218.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100002310; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.10.21.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100002311; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.10.231.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100002312; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.113.81.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002313; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.127.224.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100002314; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.127.224.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100002315; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.127.227.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100002316; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.127.230.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100002317; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.127.231.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100002318; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.127.231.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100002319; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.127.235.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100002320; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.127.235.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100002321; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.127.235.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100002322; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.127.254.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100002323; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.13.179.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100002324; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.138.200.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100002325; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.152.41.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100002326; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.169.178.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100002327; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.169.199.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100002328; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.169.30.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100002329; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.169.36.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002330; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.242.167.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100002331; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.242.242.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100002332; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.81.100.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100002333; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.83.202.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100002334; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.93.233.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100002335; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"189.222.157.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100002336; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"19.dbstrony.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002337; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.0.42.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100002338; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.110.161.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002339; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.111.151.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002340; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.119.207.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002341; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.12.99.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002342; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.121.194.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002343; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100002344; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100002345; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100002346; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002347; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002348; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.130.15.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100002349; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.130.20.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100002350; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.141.117.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002351; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.147.16.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100002352; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.159.240.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100002353; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.187.55.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100002354; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.210.214.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002355; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.213.177.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100002356; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.213.226.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100002357; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.213.49.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100002358; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.214.24.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002359; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.216.140.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100002360; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.35.225.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002361; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.65.206.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002362; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.92.4.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100002363; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.98.37.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100002364; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.98.37.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100002365; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.98.41.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002366; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"191.255.248.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002367; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.210.175.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002368; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.210.241.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100002369; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.185.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100002370; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.209.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100002371; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.228.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100002372; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.3.73.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100002373; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.99.240.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002374; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"193.228.135.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100002375; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"193.91.131.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100002376; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.152.35.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100002377; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.38.20.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100002378; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.123.208.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100002379; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.123.213.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100002380; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.139.126.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100002381; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.228.231.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100002382; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.24.94.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100002383; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.64.163.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100002384; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.202.26.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100002385; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.218.48.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002386; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.221.148.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100002387; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.221.166.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002388; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"197.159.2.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100002389; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"197.50.27.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002390; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.133.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100002391; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.251.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100002392; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.46.201.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100002393; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.46.202.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002394; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1am.co.nz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002395; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.229.89.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100002396; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.37.203.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100002397; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.45.111.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100002398; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.45.4.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100002399; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.55.125.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100002400; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.55.92.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100002401; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.83.152.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100002402; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"20.dbstrony.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002403; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.105.167.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100002404; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.111.189.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100002405; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.194.4.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100002406; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.2.161.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100002407; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.30.132.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100002408; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.142.147.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100002409; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.184.163.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100002410; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.184.248.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100002411; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.187.102.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100002412; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.193.17.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100002413; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.203.221.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100002414; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.215.84.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100002415; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.218.97.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100002416; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.107.233.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002417; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.111.131.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100002418; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.150.176.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100002419; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.164.150.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002420; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.166.217.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100002421; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.169.234.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100002422; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.169.234.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100002423; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.169.234.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100002424; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.178.113.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100002425; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.29.95.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100002426; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.4.124.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002427; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.51.176.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100002428; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.51.191.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100002429; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.74.236.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100002430; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.109.201.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100002431; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.130.69.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100002432; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.170.105.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100002433; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.170.115.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002434; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.189.156.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002435; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.202.248.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100002436; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.204.232.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002437; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.229.21.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100002438; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.236.190.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100002439; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.238.86.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100002440; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.70.166.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002441; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.77.80.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100002442; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.80.119.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002443; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.80.171.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100002444; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.82.36.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100002445; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.93.6.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100002446; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"204.195.116.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100002447; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"205.185.115.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002448; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"205.185.123.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002449; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"206.47.41.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002450; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"207.200.247.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100002451; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"207.44.28.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100002452; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"207.5.32.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100002453; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"208.163.58.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002454; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.133.223.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002455; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.141.39.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100002456; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.141.40.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100002457; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.141.40.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100002458; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.145.60.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100002459; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.124.149.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100002460; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.216.152.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100002461; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.216.153.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100002462; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.57.234.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100002463; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.57.237.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100002464; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.68.242.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100002465; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.96.116.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100002466; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.116.220.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100002467; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.172.11.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100002468; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.179.243.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100002469; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.187.132.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100002470; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.187.75.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002471; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.204.215.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100002472; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.210.66.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100002473; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.210.93.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100002474; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.216.66.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100002475; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.237.114.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002476; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.237.120.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100002477; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.238.83.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100002478; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.247.113.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100002479; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.247.5.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002480; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.32.122.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100002481; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.36.174.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100002482; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.47.102.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100002483; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.51.174.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100002484; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.122.86.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100002485; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.143.227.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002486; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.156.215.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100002487; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.46.197.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100002488; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.56.197.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100002489; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.119.74.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100002490; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.123.206.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100002491; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.135.178.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100002492; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.14.173.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100002493; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.149.182.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100002494; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.149.190.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100002495; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.104.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100002496; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.104.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100002497; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.104.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100002498; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100002499; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100002500; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100002501; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100002502; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100002503; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100002504; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100002505; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.114.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002506; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.114.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002507; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100002508; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100002509; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100002510; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100002511; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.116.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100002512; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.116.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100002513; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.116.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002514; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.116.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002515; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.116.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100002516; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.116.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002517; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.116.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100002518; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.117.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100002519; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.118.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100002520; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.118.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100002521; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.118.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100002522; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.119.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100002523; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100002524; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100002525; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100002526; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100002527; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002528; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002529; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.127.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100002530; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.127.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002531; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.127.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100002532; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.189.178.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002533; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.240.218.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100002534; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.249.156.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100002535; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.27.8.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100002536; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.80.44.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002537; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.87.87.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100002538; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.92.254.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100002539; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.92.254.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100002540; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.92.255.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002541; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.92.255.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002542; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.12.93.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100002543; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.127.185.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100002544; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.170.240.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100002545; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.183.54.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100002546; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.24.72.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100002547; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.36.12.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100002548; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"217.11.75.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002549; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"217.127.133.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100002550; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.104.175.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100002551; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.215.243.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100002552; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.238.246.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100002553; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.255.226.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002554; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.28.160.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100002555; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.207.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100002556; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.227.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100002557; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.68.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100002558; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.81.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100002559; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.48.135.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100002560; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.56.93.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100002561; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.57.53.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100002562; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.58.3.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100002563; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.58.3.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100002564; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.59.116.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002565; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.72.198.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100002566; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.72.248.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002567; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.79.103.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100002568; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.104.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100002569; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.119.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100002570; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.182.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100002571; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.102.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100002572; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.14.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002573; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.24.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100002574; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.26.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100002575; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.28.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002576; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.31.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100002577; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.31.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100002578; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.9.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100002579; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.97.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100002580; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.156.21.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100002581; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.139.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100002582; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.146.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100002583; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.150.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100002584; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.162.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100002585; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.17.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100002586; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.177.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100002587; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.178.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100002588; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.183.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100002589; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.202.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002590; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.215.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100002591; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.221.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100002592; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.32.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002593; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.64.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100002594; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.241.6.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002595; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.1.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100002596; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.1.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002597; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.163.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002598; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.171.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100002599; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.245.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100002600; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.251.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100002601; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.5.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100002602; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.69.71.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100002603; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.80.217.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100002604; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.85.145.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002605; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"21robo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002606; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.118.168.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100002607; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.126.237.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002608; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.173.160.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100002609; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.200.22.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002610; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.71.239.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002611; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.0.16.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100002612; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.1.162.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002613; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.124.78.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100002614; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.14.122.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100002615; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.14.182.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100002616; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.14.46.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002617; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.14.58.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002618; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.124.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100002619; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.153.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002620; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.160.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100002621; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.194.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100002622; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.199.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100002623; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.218.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100002624; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.234.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100002625; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.234.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100002626; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.54.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100002627; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.157.191.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100002628; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.160.136.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100002629; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.160.177.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100002630; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.160.177.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002631; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.160.177.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100002632; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.196.12.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002633; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.208.4.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100002634; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.214.130.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100002635; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.214.146.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100002636; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.214.162.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002637; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.214.224.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100002638; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.116.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100002639; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.184.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100002640; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.237.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002641; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.239.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002642; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.252.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100002643; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.8.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100002644; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.232.1.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002645; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.232.179.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100002646; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.235.137.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002647; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.235.142.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100002648; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.112.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100002649; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.32.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100002650; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.34.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100002651; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.43.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100002652; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.68.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100002653; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.108.17.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100002654; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.119.65.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100002655; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.132.125.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100002656; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.133.102.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100002657; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.133.103.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100002658; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.133.105.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100002659; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.135.113.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002660; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.135.219.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100002661; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.135.26.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100002662; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.136.21.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100002663; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.136.218.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100002664; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.136.231.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100002665; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.136.49.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002666; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.101.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100002667; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.113.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100002668; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.120.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100002669; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.121.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100002670; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.136.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100002671; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.137.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100002672; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.137.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100002673; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.138.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002674; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.139.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100002675; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.148.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100002676; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.152.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100002677; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.172.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100002678; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.175.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100002679; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.186.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100002680; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.221.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100002681; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.5.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100002682; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.72.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100002683; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.8.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002684; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.81.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100002685; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.137.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100002686; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.143.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002687; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.203.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002688; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.232.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100002689; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.96.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100002690; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.139.59.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100002691; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.10.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100002692; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.117.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100002693; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.161.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100002694; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.163.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100002695; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.17.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100002696; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.209.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100002697; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.219.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100002698; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.39.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002699; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.120.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002700; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.147.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100002701; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.150.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100002702; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.40.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100002703; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.40.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100002704; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.41.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100002705; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.45.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100002706; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.45.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100002707; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.60.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100002708; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.85.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100002709; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.142.162.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002710; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.142.192.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002711; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.142.209.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002712; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.142.65.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100002713; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.184.129.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100002714; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.185.116.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100002715; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.186.20.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100002716; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.187.9.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100002717; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.211.72.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002718; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.218.220.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100002719; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.236.85.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002720; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.238.230.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002721; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.239.83.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100002722; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.248.64.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100002723; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.64.16.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100002724; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.83.150.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100002725; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.92.9.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100002726; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.99.171.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100002727; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.166.117.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100002728; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.167.118.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002729; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.175.121.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100002730; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.212.225.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100002731; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.212.234.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002732; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.212.252.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002733; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.212.5.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100002734; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.212.57.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100002735; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.212.73.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100002736; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.213.164.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100002737; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.125.186.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100002738; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.126.120.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100002739; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.228.143.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002740; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.24.213.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100002741; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.243.149.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100002742; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.243.21.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100002743; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.81.246.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002744; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.95.89.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100002745; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.103.74.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002746; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.11.141.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100002747; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.119.158.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002748; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.137.147.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100002749; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.152.235.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100002750; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.158.25.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100002751; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.176.206.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100002752; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.184.1.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002753; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.192.191.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002754; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.225.114.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100002755; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.227.190.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100002756; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.35.245.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100002757; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.39.181.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002758; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.39.34.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100002759; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.42.229.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100002760; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.45.4.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100002761; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.51.91.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100002762; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.53.163.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100002763; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.53.163.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100002764; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.dbstrony.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002765; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.1.245.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100002766; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.1.245.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002767; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.105.106.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100002768; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.105.152.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002769; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.116.84.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100002770; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.12.245.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100002771; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.13.83.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002772; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.14.211.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100002773; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.141.218.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002774; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.147.29.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100002775; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.147.40.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100002776; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.153.132.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002777; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.153.207.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100002778; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.184.244.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100002779; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.184.54.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100002780; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.187.248.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002781; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.193.196.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100002782; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.193.217.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100002783; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.194.149.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100002784; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.194.158.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100002785; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.194.166.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100002786; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.194.192.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002787; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.194.210.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100002788; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.194.224.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002789; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.197.17.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100002790; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.197.22.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002791; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.197.23.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100002792; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.197.24.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100002793; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.199.232.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100002794; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.199.3.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002795; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.199.34.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100002796; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.200.140.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100002797; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.200.23.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100002798; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.200.32.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100002799; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.202.182.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100002800; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.202.21.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100002801; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.202.66.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100002802; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.102.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100002803; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.126.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002804; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.154.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100002805; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.165.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100002806; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.185.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002807; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.185.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100002808; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.213.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100002809; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.234.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100002810; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.246.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002811; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.255.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002812; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.28.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002813; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.4.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100002814; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.54.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002815; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.87.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100002816; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.94.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100002817; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.204.253.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002818; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.205.178.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100002819; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.136.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100002820; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.14.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100002821; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.148.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100002822; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.154.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100002823; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.185.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100002824; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.26.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100002825; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.81.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002826; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.83.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100002827; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.97.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100002828; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.207.155.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100002829; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.207.194.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100002830; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.207.199.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002831; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.152.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100002832; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.160.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100002833; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.164.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002834; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.166.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100002835; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.201.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100002836; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.247.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002837; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.34.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100002838; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.92.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100002839; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.209.160.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100002840; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.209.231.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100002841; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.209.60.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100002842; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.21.159.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100002843; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.107.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100002844; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.127.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100002845; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.172.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100002846; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.234.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100002847; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.236.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100002848; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.63.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100002849; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.211.251.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002850; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.104.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100002851; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.109.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100002852; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.109.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002853; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.175.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100002854; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.220.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100002855; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.255.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100002856; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.255.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100002857; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.84.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002858; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.214.37.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100002859; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.139.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100002860; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.190.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100002861; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.212.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100002862; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.253.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100002863; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.34.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100002864; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.38.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002865; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.71.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100002866; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.98.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100002867; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.144.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002868; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.193.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002869; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.197.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100002870; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.225.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100002871; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.234.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100002872; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.46.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100002873; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.58.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100002874; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.95.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100002875; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.217.120.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100002876; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.217.133.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100002877; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.217.155.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100002878; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.217.191.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002879; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.217.31.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100002880; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.217.76.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100002881; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.218.180.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100002882; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.218.219.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100002883; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.218.248.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100002884; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.132.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100002885; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.151.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100002886; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.160.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100002887; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.172.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100002888; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.173.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002889; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.176.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100002890; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.184.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100002891; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.192.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100002892; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.83.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002893; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.220.243.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100002894; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.220.40.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100002895; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.220.85.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100002896; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.221.239.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100002897; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.222.241.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100002898; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.222.249.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100002899; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.222.249.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100002900; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.222.42.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100002901; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.222.50.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100002902; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.223.242.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002903; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.223.44.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100002904; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.24.28.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100002905; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.127.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100002906; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.129.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100002907; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.154.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100002908; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.2.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100002909; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.212.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100002910; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.58.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100002911; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.36.143.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100002912; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.41.159.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100002913; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.41.36.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100002914; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.41.38.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100002915; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.46.45.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100002916; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.5.38.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100002917; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.5.41.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100002918; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.5.42.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100002919; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.6.196.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100002920; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.0.98.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100002921; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.11.51.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100002922; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.13.23.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002923; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.154.234.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100002924; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.124.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002925; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.179.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100002926; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.184.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100002927; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.191.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100002928; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.194.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100002929; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.216.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100002930; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.219.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100002931; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.24.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002932; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.30.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100002933; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.60.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100002934; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.63.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002935; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.65.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100002936; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.94.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100002937; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.179.201.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100002938; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.195.84.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100002939; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.204.174.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002940; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.210.20.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100002941; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.210.20.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100002942; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.28.7.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100002943; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.30.119.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100002944; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"32.208.157.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100002945; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"32792.prolocksmithwinterpark.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002946; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"35.184.169.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100002947; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.108.231.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100002948; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.109.132.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100002949; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.250.203.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100002950; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.157.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100002951; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.18.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002952; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.19.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100002953; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.51.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002954; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.255.90.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100002955; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.32.203.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100002956; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.32.25.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100002957; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.33.128.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100002958; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.33.160.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100002959; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.36.243.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100002960; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.66.105.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100002961; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.66.111.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002962; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.66.133.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100002963; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.66.139.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002964; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.67.152.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100002965; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.89.18.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100002966; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.91.89.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100002967; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.96.187.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100002968; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"360.lcy2zzx.pw"; content:"Host"; http_header; classtype:trojan-activity; sid:100002969; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"360down7.miiyun.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100002970; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.222.98.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100002971; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.233.60.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100002972; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.34.179.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100002973; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.34.180.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100002974; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.44.238.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100002975; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.49.229.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100002976; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.49.230.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100002977; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.52.117.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100002978; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.54.14.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002979; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"38.77.14.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100002980; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"38.81.149.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100002981; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.113.245.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100002982; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.113.98.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100002983; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.114.137.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100002984; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.117.31.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002985; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.162.104.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100002986; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.64.28.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100002987; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.65.171.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100002988; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.65.196.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100002989; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.65.59.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100002990; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.66.129.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002991; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.66.85.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100002992; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.104.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100002993; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.125.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100002994; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.146.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100002995; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.148.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002996; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.92.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100002997; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.68.124.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100002998; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.68.249.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100002999; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.72.130.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100003000; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.72.167.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100003001; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.72.67.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100003002; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.10.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100003003; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.163.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003004; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.183.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100003005; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.203.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100003006; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.74.104.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100003007; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.74.21.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100003008; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.74.28.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100003009; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.74.31.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100003010; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.74.68.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100003011; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.76.194.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100003012; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.76.79.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100003013; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.76.97.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100003014; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.113.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100003015; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.114.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100003016; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.136.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100003017; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.14.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100003018; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.150.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100003019; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.197.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100003020; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.209.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100003021; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.94.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100003022; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.95.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100003023; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.107.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100003024; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.166.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100003025; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.218.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100003026; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.62.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100003027; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.90.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100003028; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.91.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100003029; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.93.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100003030; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.127.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100003031; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.188.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100003032; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.191.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100003033; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.205.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100003034; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.24.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100003035; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.34.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100003036; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.36.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100003037; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.124.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100003038; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.130.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100003039; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.251.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100003040; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.27.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100003041; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.29.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003042; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.82.86.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100003043; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.83.94.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100003044; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.84.157.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100003045; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.84.34.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100003046; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.84.95.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100003047; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.85.54.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100003048; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.129.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100003049; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.13.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100003050; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.170.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100003051; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.184.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100003052; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.211.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100003053; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.234.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100003054; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.248.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100003055; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.60.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100003056; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.66.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100003057; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.76.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100003058; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.78.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100003059; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.87.63.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003060; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.87.93.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100003061; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.141.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100003062; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.155.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100003063; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.233.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100003064; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.39.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100003065; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.41.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100003066; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.67.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100003067; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.72.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100003068; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.146.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100003069; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.146.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100003070; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.157.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100003071; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.63.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100003072; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.90.86.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100003073; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.139.209.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100003074; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.165.130.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100003075; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.190.63.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100003076; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.193.192.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100003077; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.219.185.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100003078; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.230.31.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003079; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.72.203.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100003080; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.76.157.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100003081; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.18.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100003082; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.18.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100003083; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.18.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100003084; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.18.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100003085; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.21.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100003086; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.21.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100003087; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.5.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100003088; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.5.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100003089; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.5.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100003090; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.5.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100003091; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.176.112.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100003092; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.202.101.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100003093; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.128.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100003094; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.168.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100003095; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.168.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100003096; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.170.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100003097; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.179.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100003098; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.181.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100003099; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.183.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100003100; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.209.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100003101; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.212.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100003102; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.218.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100003103; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.233.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100003104; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.235.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100003105; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.37.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100003106; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.37.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100003107; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.43.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100003108; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.64.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100003109; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.66.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100003110; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.70.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100003111; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.76.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100003112; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.76.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100003113; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.8.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100003114; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.91.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100003115; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.225.24.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100003116; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.225.240.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100003117; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.225.250.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100003118; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.226.76.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100003119; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.227.179.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100003120; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.227.204.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100003121; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.227.66.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100003122; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.198.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100003123; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.60.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100003124; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.65.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100003125; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.70.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100003126; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.70.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003127; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.76.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100003128; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.230.100.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100003129; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.230.228.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100003130; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.230.57.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100003131; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.230.66.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100003132; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.230.82.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100003133; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.230.88.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100003134; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.230.93.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100003135; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.231.66.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100003136; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.232.102.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100003137; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.232.170.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100003138; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.232.226.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100003139; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.234.166.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100003140; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.234.180.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100003141; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.234.255.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100003142; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.235.124.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100003143; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.235.160.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100003144; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.235.169.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100003145; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.235.23.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100003146; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.235.66.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100003147; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.235.83.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100003148; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.236.148.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100003149; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.236.212.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100003150; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.236.212.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100003151; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.236.215.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100003152; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.236.236.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100003153; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.237.54.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100003154; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.238.175.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100003155; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.238.191.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100003156; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.238.241.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100003157; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.238.59.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100003158; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.239.192.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100003159; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.239.207.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100003160; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.239.42.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100003161; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.242.200.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100003162; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.52.180.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100003163; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.56.15.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100003164; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.61.99.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100003165; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.84.14.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100003166; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"43.230.156.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100003167; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"43.230.207.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100003168; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"43.241.106.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100003169; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"43.252.8.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100003170; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.112.203.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100003171; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.130.138.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100003172; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.133.1.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100003173; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.133.1.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100003174; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.133.203.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100003175; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.135.134.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100003176; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.14.149.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100003177; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.14.149.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100003178; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.14.149.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100003179; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.14.149.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100003180; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.141.84.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100003181; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.141.84.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100003182; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100003183; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.148.10.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100003184; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.15.143.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100003185; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.164.140.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100003186; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.165.215.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100003187; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.108.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100003188; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.108.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100003189; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.111.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100003190; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.178.101.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100003191; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.201.165.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100003192; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.22.209.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003193; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.23.22.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100003194; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.27.253.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100003195; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.33.112.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100003196; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.51.104.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100003197; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.81.235.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100003198; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.9.148.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100003199; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.151.155.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100003200; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.172.75.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003201; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.175.184.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100003202; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.182.173.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100003203; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.182.173.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100003204; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.20.63.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100003205; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.201.214.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100003206; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.201.38.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100003207; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.21.153.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003208; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.214.27.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100003209; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.24.130.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003210; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.243.179.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100003211; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.249.33.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100003212; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.25.242.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100003213; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.42.118.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100003214; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.42.86.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100003215; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.97.76.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100003216; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.145.152.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100003217; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.151.23.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100003218; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.157.97.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100003219; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.16.131.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100003220; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.197.0.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100003221; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.21.202.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100003222; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.223.167.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100003223; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.46.231.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100003224; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.142.162.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100003225; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.142.87.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100003226; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.143.43.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100003227; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.156.35.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100003228; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.158.201.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100003229; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.159.20.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100003230; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.159.21.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100003231; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.174.182.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100003232; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.213.170.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100003233; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.213.178.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100003234; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.213.179.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100003235; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.68.221.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100003236; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.68.249.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100003237; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.70.15.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100003238; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.70.2.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100003239; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.181.135.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100003240; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.2.70.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100003241; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.53.146.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100003242; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.8.10.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100003243; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.115.174.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100003244; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.121.91.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100003245; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.252.47.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100003246; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"51.171.146.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100003247; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"51.222.56.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100003248; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"54.253.194.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100003249; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"54.36.114.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100003250; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"54.36.180.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100003251; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"54.37.93.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100003252; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.114.246.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100003253; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.115.162.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100003254; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.115.174.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100003255; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.125.191.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100003256; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.126.247.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100003257; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.142.166.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100003258; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.142.200.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100003259; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.143.142.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100003260; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.18.103.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100003261; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.217.171.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100003262; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.218.67.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100003263; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.22.212.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100003264; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.226.129.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100003265; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.229.194.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100003266; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.23.245.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100003267; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.230.89.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100003268; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.232.155.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100003269; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.238.42.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100003270; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.240.147.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100003271; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.241.57.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100003272; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.241.78.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100003273; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.112.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100003274; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.116.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100003275; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.117.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100003276; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.140.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100003277; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.142.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100003278; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.142.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100003279; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.149.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100003280; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.150.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100003281; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.150.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100003282; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.153.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100003283; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.154.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100003284; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.154.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100003285; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.76.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100003286; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.79.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100003287; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.15.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100003288; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.18.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100003289; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.22.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100003290; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.72.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100003291; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.74.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100003292; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.74.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100003293; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.77.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100003294; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.79.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100003295; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.80.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100003296; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.86.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100003297; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.88.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100003298; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.252.177.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100003299; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.252.177.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100003300; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.252.178.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100003301; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.252.178.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100003302; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.253.14.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100003303; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.255.140.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100003304; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.255.43.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100003305; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.48.154.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100003306; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.50.178.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100003307; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.50.221.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100003308; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.72.165.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100003309; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.72.165.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100003310; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.76.151.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100003311; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.97.201.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100003312; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.97.206.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100003313; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.0.211.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100003314; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.102.168.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100003315; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.151.202.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100003316; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.151.214.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100003317; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.151.237.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100003318; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.151.246.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100003319; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.29.133.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100003320; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.30.12.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003321; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.58.104.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100003322; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.58.117.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100003323; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.7.124.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100003324; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.8.35.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100003325; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.89.243.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100003326; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.92.176.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100003327; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.92.178.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100003328; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.92.18.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100003329; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.92.182.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100003330; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.92.216.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100003331; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.93.17.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100003332; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.93.17.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100003333; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.93.17.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100003334; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.93.19.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100003335; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.93.23.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100003336; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.93.23.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100003337; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.93.23.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100003338; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.93.23.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100003339; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.94.180.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100003340; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.96.36.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100003341; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.96.36.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100003342; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.96.39.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100003343; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.97.168.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100003344; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.97.170.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100003345; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.97.175.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100003346; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.97.175.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100003347; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.97.193.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100003348; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.99.137.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100003349; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.99.138.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100003350; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.99.139.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100003351; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.99.139.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100003352; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.99.141.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100003353; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.99.141.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100003354; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.99.142.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100003355; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.99.188.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100003356; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.99.41.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100003357; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.99.43.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100003358; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.99.46.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100003359; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.99.47.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100003360; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.13.61.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100003361; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.14.48.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100003362; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.162.122.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100003363; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.162.160.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100003364; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.164.130.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100003365; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.17.12.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100003366; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.176.249.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100003367; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.20.217.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100003368; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.208.135.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100003369; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.122.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100003370; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.186.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100003371; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.216.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100003372; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.33.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100003373; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.211.19.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100003374; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.211.6.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100003375; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.211.7.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100003376; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.100.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100003377; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.162.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100003378; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.206.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100003379; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.218.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100003380; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.220.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100003381; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.23.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100003382; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.254.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100003383; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.213.162.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100003384; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.213.58.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100003385; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.213.83.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100003386; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.214.93.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100003387; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.215.165.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100003388; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.215.195.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100003389; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.215.207.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100003390; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.215.219.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100003391; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.215.4.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100003392; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.216.95.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100003393; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.217.177.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100003394; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.217.86.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100003395; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.220.22.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100003396; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.25.115.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100003397; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.25.76.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100003398; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.15.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100003399; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.39.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100003400; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.42.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100003401; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.44.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100003402; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.51.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100003403; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.60.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100003404; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.8.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100003405; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.7.10.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100003406; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.7.136.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100003407; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.7.202.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100003408; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.7.99.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003409; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.102.243.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100003410; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.162.169.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100003411; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.162.55.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100003412; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.163.129.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100003413; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.164.96.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100003414; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.167.211.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100003415; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.168.139.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100003416; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.179.171.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100003417; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.179.91.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100003418; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.179.91.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100003419; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.179.93.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100003420; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.18.112.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100003421; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.192.73.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100003422; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.213.118.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100003423; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.247.224.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100003424; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.253.94.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100003425; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.3.126.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100003426; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.3.144.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100003427; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.3.147.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100003428; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.47.220.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100003429; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.102.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100003430; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.103.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100003431; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.11.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100003432; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.157.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100003433; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.159.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003434; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.195.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100003435; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.212.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100003436; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.243.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100003437; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.247.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100003438; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.30.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100003439; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.35.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100003440; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.43.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100003441; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.48.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100003442; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.9.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100003443; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.97.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100003444; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.99.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100003445; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.100.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100003446; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.121.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100003447; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.251.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100003448; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.62.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100003449; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.73.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100003450; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.74.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100003451; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.81.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100003452; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.83.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100003453; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.86.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100003454; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.172.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100003455; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.41.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100003456; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.64.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100003457; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.77.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100003458; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.56.180.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100003459; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.56.181.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100003460; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.57.96.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100003461; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.58.170.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100003462; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.58.73.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100003463; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.61.218.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100003464; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.65.172.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100003465; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.0.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100003466; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.104.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100003467; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.110.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100003468; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.132.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100003469; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.132.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100003470; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.255.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100003471; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.45.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100003472; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.98.144.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100003473; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.1.98.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100003474; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.117.124.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100003475; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.141.73.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003476; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.219.131.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100003477; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.219.143.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100003478; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.219.227.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100003479; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.31.126.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100003480; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.38.149.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100003481; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.38.222.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100003482; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.43.207.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100003483; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.90.165.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100003484; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"63.245.122.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100003485; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"64.233.154.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100003486; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.125.128.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100003487; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.21.58.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100003488; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.26.155.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100003489; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.35.61.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100003490; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.153.233.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100003491; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.207.93.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100003492; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.229.214.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100003493; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.57.55.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100003494; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.74.7.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100003495; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.91.21.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100003496; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.97.181.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100003497; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.97.181.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100003498; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.221.107.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100003499; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.245.151.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100003500; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.3.169.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100003501; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.8.138.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100003502; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.81.98.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100003503; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.82.242.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100003504; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.83.49.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100003505; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.84.138.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100003506; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.148.103.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100003507; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.151.244.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100003508; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.174.182.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100003509; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.175.107.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100003510; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.188.144.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100003511; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.204.88.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100003512; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.205.106.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100003513; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.205.119.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100003514; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.78.33.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100003515; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.115.37.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100003516; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.120.237.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100003517; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.123.245.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100003518; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.124.231.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100003519; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.127.214.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100003520; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.146.232.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100003521; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.165.173.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100003522; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.196.158.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100003523; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.222.157.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100003524; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.229.0.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100003525; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.63.73.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100003526; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.75.115.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100003527; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.75.227.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100003528; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.76.240.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100003529; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.115.31.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100003530; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.118.240.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100003531; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.167.10.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100003532; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.236.190.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100003533; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.25.5.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100003534; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.33.144.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100003535; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.93.129.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100003536; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.127.148.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100003537; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.146.190.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100003538; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.204.63.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100003539; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.29.48.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100003540; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.34.191.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100003541; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.40.234.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100003542; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.43.2.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100003543; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.43.235.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100003544; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.47.133.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003545; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.71.60.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100003546; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.85.106.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100003547; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.17.22.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100003548; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.186.139.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100003549; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.189.180.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100003550; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.214.69.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100003551; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.229.230.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100003552; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.229.35.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100003553; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.31.40.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100003554; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"73.204.216.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100003555; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.101.1.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100003556; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.108.224.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100003557; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.194.117.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100003558; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.195.115.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100003559; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.199.84.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100003560; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.75.165.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100003561; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"75.127.141.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100003562; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"75.176.213.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100003563; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"75.82.36.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100003564; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"75.83.102.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100003565; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"75.99.213.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100003566; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.108.199.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100003567; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.170.11.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100003568; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.178.22.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100003569; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.250.199.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100003570; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.254.129.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100003571; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.84.134.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100003572; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.95.12.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100003573; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.237.25.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100003574; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.71.50.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100003575; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.71.52.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100003576; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.79.191.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100003577; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.89.203.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100003578; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.179.225.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003579; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.187.141.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100003580; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.187.240.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100003581; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.187.41.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100003582; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.188.168.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100003583; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.188.188.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100003584; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.189.104.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100003585; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.189.176.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100003586; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.23.172.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100003587; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.72.231.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100003588; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.8.225.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100003589; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.11.195.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100003590; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.13.49.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100003591; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.130.253.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100003592; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.147.123.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100003593; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.170.31.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100003594; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.175.42.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100003595; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.21.84.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100003596; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.22.176.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100003597; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.7.170.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003598; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.79.58.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100003599; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.8.70.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100003600; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.9.88.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100003601; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.107.89.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100003602; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.19.101.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100003603; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.211.181.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100003604; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.217.12.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100003605; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.99.128.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100003606; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.136.146.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100003607; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.165.44.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100003608; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.191.40.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003609; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.198.7.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100003610; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.213.111.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100003611; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.213.141.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100003612; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.213.166.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100003613; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.215.199.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100003614; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.218.187.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100003615; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.218.195.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100003616; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.237.128.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100003617; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.246.225.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100003618; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.92.36.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100003619; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.103.108.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100003620; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.135.196.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100003621; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.166.212.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100003622; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.166.85.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100003623; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.207.61.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100003624; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.209.250.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100003625; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.211.156.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100003626; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.62.110.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100003627; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.62.53.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100003628; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.138.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100003629; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.139.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100003630; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.154.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100003631; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.187.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100003632; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.100.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100003633; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.106.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100003634; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.108.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100003635; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.131.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100003636; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.19.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100003637; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.197.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003638; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.215.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100003639; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.232.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100003640; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.234.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100003641; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.246.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100003642; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.28.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100003643; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.4.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100003644; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.55.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100003645; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.73.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100003646; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.9.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100003647; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.98.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100003648; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.165.237.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100003649; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.234.147.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100003650; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.234.218.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100003651; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.242.253.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100003652; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.252.9.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100003653; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.210.219.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100003654; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.210.219.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100003655; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.212.219.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100003656; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.214.103.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100003657; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.228.50.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100003658; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.228.95.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100003659; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.238.24.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100003660; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.247.83.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100003661; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.254.39.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100003662; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.33.111.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100003663; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.38.152.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100003664; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.40.127.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100003665; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.42.20.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100003666; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003667; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.11.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100003668; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.123.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100003669; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.135.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100003670; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.208.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100003671; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.224.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100003672; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.241.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100003673; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.214.149.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100003674; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.64.181.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100003675; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.74.215.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100003676; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.97.130.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100003677; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.97.195.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100003678; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.98.40.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100003679; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"86.35.43.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100003680; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"87.121.98.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100003681; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"87.61.89.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100003682; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.119.171.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100003683; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.2.208.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100003684; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.2.219.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100003685; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.225.222.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100003686; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.247.96.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100003687; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.248.136.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003688; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.248.51.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100003689; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.249.244.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100003690; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.250.204.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100003691; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.250.226.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100003692; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.250.254.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100003693; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.37.171.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100003694; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.122.183.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100003695; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.136.197.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100003696; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.29.213.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100003697; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.35.62.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100003698; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.40.85.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100003699; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.40.87.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100003700; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"8poieq.bn.files.1drv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003701; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"90.152.144.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100003702; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.177.139.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100003703; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.187.103.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100003704; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.212.150.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100003705; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.212.150.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100003706; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.217.104.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100003707; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.233.112.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100003708; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.234.60.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100003709; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.239.168.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100003710; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.244.114.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100003711; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.244.169.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100003712; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.92.16.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100003713; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.98.4.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100003714; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.113.192.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100003715; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.113.195.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100003716; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.114.191.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100003717; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.241.78.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100003718; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.27.246.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100003719; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.85.18.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100003720; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.171.157.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100003721; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.21.224.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100003722; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.39.115.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100003723; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.41.137.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100003724; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.41.182.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100003725; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.41.206.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100003726; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.57.43.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100003727; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.73.99.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100003728; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.136.69.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100003729; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.143.53.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100003730; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.154.17.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100003731; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.154.82.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100003732; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.200.16.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100003733; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.224.83.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100003734; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.43.139.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100003735; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.53.120.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100003736; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.132.129.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100003737; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.154.20.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003738; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.158.19.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100003739; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.170.113.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100003740; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.170.201.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100003741; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.181.155.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100003742; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.214.52.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100003743; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.53.229.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100003744; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.54.11.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100003745; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.60.146.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100003746; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.60.6.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100003747; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.66.196.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100003748; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.9.120.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100003749; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"96.239.73.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100003750; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"96.47.147.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100003751; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"97.68.140.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003752; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"97.96.199.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100003753; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.0.210.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100003754; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.0.239.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100003755; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.113.239.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100003756; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.116.72.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100003757; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.128.147.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100003758; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.178.242.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100003759; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.249.236.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100003760; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.28.200.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100003761; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.30.24.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100003762; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"99.150.245.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100003763; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"99.33.195.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100003764; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"99centsdigitals.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003765; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abcd.bg"; content:"Host"; http_header; classtype:trojan-activity; sid:100003766; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abclicks.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003767; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abissnet.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003768; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aboveandbelow.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003769; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"absoftechworld.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003770; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"absupplies.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003771; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abyssos.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003772; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"acbick.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003773; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"accounts.thesmarttechhub.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003774; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aceeprc.com.aceeprc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003775; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"acellr.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003776; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aclassapart.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003777; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"acteon.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100003778; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"activateyourdiscount.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003779; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"activecost.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003780; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"adamorinmusic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003781; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"addahealingmusic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003782; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"adithimedia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003783; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"adithimedia.memengers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003784; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"admin.erapor.smk-alasror.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003785; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"admin.gentbcn.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003786; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"admin.grandoceanvilla.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003787; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"adventureexplorer.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003788; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aeropilates.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003789; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"afrimedspecialist.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003790; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agemn.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003791; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agenciadigitalwdys.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003792; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agenciatabletshouse.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003793; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agenda.gmelloinformatica.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003794; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agentt.ac.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100003795; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agile8studio.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003796; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agmcarpetcare.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003797; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aiqtest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003798; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ajpharmaholding.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003799; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ajstudiollc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003800; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aktyd05.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100003801; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"al-wahd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003802; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alasdemariposas.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003803; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alemelektronik.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003804; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alena1971.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100003805; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alertlauncher.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003806; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alexdubai.com.aldiabsteel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003807; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alka.institute"; content:"Host"; http_header; classtype:trojan-activity; sid:100003808; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"allforcreative.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003809; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alltheway.travel"; content:"Host"; http_header; classtype:trojan-activity; sid:100003810; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alpaylar.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003811; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"am-concepts.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100003812; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amamontajes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003813; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amarresdeamorymaestroshechiceros.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003814; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amarteargentina.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100003815; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amenyan.zouri.jp"; content:"Host"; http_header; classtype:trojan-activity; sid:100003816; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amos524.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003817; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anantam.net.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003818; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andreelapeyre.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003819; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andremaraisbeleggings.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003820; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andres.ac.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100003821; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andres.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100003822; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andreshconcejal.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003823; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"angelazgheibld.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003824; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"angelsdetour.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003825; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"angloteste.bigprime.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003826; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anhung1102.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100003827; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anysbergbiltong.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003828; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"apartamentoscitta.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003829; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"api-ms.cobainaja.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003830; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"api.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003831; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"api.quocbao.biz"; content:"Host"; http_header; classtype:trojan-activity; sid:100003832; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"api.sampy.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100003833; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aplicativoparasindicato.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003834; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"apoolcondo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003835; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"app.adsensearticle.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003836; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"app.explicitsurveys.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003837; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"app.prerana.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100003838; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"apps.saintsoporte.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003839; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aras.iuc.ac"; content:"Host"; http_header; classtype:trojan-activity; sid:100003840; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"areyoulivingwell.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003841; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"arsapetrolab.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003842; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"artedibujoyarquitectura.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003843; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ask-regard.call-save.biz"; content:"Host"; http_header; classtype:trojan-activity; sid:100003844; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"atfile.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003845; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"athenacapsg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003846; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"atlasconcreteworks.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003847; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"attach.66rpg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003848; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"atteuqpotentialunlimited.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003849; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"augustair.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003850; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aulist.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003851; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"australiafashions.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003852; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"automaticrefreshments.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003853; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"avadhanagames.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003854; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"avissrilanka.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003855; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ayamallah.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003856; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"azmeasurement.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003857; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"azraktours.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003858; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"b2b.toptanakaryakit.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003859; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"backgrounds.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003860; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"backup.agewsage.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003861; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"badeggdesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003862; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bangkok-orchids.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003863; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bary.sz4h.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003864; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"basma.com.kw"; content:"Host"; http_header; classtype:trojan-activity; sid:100003865; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bausch.kr-atlas.monaxikoslykos@zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003866; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bavhome.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003867; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bbia.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003868; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bcmt.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003869; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bcrg.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003870; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bearcatpumps.com.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100003871; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"beatyamerican.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003872; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"beautincollagen.rs"; content:"Host"; http_header; classtype:trojan-activity; sid:100003873; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bekape.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003874; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bespokeweddings.ie"; content:"Host"; http_header; classtype:trojan-activity; sid:100003875; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bestcarenepal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003876; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"betone.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003877; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"betycopaints.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003878; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"beveragesmiami.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003879; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bilbosaquet.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100003880; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bilhen.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003881; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"billing.rahitechnosoft.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003882; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"birdi.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003883; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"birminghamlink.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003884; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.callensaxen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003885; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.oyinblogs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003886; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.takbelit.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003887; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bmlifestyle.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003888; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bnrnews.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003889; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bodenstein.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003890; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bolnicaloznica.rs"; content:"Host"; http_header; classtype:trojan-activity; sid:100003891; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"booksearch.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003892; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bounces.mi-fs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003893; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bpo.correct.go.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100003894; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bradleyinstitute.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003895; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brandtrust.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003896; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brendanquine.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003897; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brideofmessiah.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003898; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bridesofmaldives.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003899; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brightmega.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003900; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brightonrooms.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003901; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brightstarshop.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003902; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"browardinsurancemiami.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003903; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bt2.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003904; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"btdapi.robotake.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003905; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bucrinsuranlceonlines.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003906; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"buenavista.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100003907; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"buigiaphat.com.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100003908; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bullseyemedia.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003909; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"busandvanrentalmalaysia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003910; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"buscascolegios.diit.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003911; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"business.softberg.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100003912; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"buyingmusiconline.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003913; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"buypropertyfast.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003914; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bwsr.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003915; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"c.oooooooooo.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100003916; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"c0140529.ferozo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003917; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cacapavaonline.sdserver144.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003918; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"callbury.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003919; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"camminachetipassa.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100003920; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"campusvirtual.cepsanjuanbosco.net.pe"; content:"Host"; http_header; classtype:trojan-activity; sid:100003921; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cancer.educandome.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100003922; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"capitalgroup-kw.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003923; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"capitalnewsagency.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003924; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"capoeiraventrelivre.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003925; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cashyinvestment.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003926; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"casoauditores.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003927; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"catchperch.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003928; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"catchpoolshetlands.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003929; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cazyacustomfurniture.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003930; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ccauthority.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003931; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cdaonline.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100003932; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cec.asso.ac-amiens.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003933; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cellas.sk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003934; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cendekiabinaaksara.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003935; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cespol-bote.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100003936; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cfs5.tistory.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003937; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ch.rmu.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100003938; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"changematterscounselling.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003939; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chardhamdodham.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003940; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cheacrilnsurances.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003941; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chealablilitycarinsurances.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003942; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chezalice.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003943; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"childselect.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003944; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chinhdropfile.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003945; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chinhdropfile80.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003946; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chipmania.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100003947; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cible-energy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003948; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cifeer.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003949; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"citycapproperty.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100003950; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cityglobalgospel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003951; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"civi.istmejia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003952; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cleanbydesignllc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003953; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"clim34000.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003954; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cloud.fc.co.mz"; content:"Host"; http_header; classtype:trojan-activity; sid:100003955; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"codsambal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003956; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"colinde.pricesne.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003957; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"colorpak.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003958; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"competancy.indigoconsult.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003959; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"conceptimagine.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100003960; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"config.cqhbkjzx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003961; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"constructoralyon.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003962; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"consulateins.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003963; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"contributeindustry.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003964; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"controladoradeplagasmm.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003965; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"copelandscapes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003966; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"corporativos.com.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100003967; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"coulsongraphics.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003968; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"coutler.newreadermedia.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003969; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"covid19.cyberschool.or.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003970; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cr-sq.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003971; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crearechile.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003972; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"creationskateboards.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003973; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crecerco.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003974; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crittersbythebay.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003975; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crm.notariavieitoyvelamazan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003976; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crmmanivela.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003977; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crscorretordeimoveis.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003978; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cse-engineer.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003979; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"csnserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003980; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cubescargoexpress.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003981; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cubrebocasenpuebla.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100003982; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"curasoles.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003983; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"currantmedia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003984; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cwa.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100003985; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cyber.searchkero.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003986; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cyclomove.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003987; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cynkon.kairoscs.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003988; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"czas.dbstrony.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003989; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"czsl.91756.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100003990; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"d.powerofwish.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003991; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"d9.99ddd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003992; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"da.alibuf.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003993; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"damagedessentialtelecommunications.testmail4.repl.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100003994; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dandyair.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003995; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dannexgh.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003996; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dartoonpictures.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003997; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"data.cdevelop.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003998; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"data.over-blog-kiwi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003999; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"datapolish.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004000; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dating.khokhas.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004001; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"datsom.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004002; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"daunhotq10.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004003; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"davethompson.me.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004004; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"davidmcguinness.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004005; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dayspringdaisies.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004006; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dd.qiyuea.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004007; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"de.gsearch.com.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004008; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"decifrar.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004009; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"deigratia2.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004010; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dekovizyon.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004011; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"demo-cliente.mindcreative.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004012; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"demo6.hiites.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004013; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dent-estet.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004014; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dental.xiaoxiao.media"; content:"Host"; http_header; classtype:trojan-activity; sid:100004015; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dentalalliance.se"; content:"Host"; http_header; classtype:trojan-activity; sid:100004016; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"designerliving.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004017; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"desiringhands.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004018; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"despertaresi.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004019; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"destinymc.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004020; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"detorre.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100004021; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dev-interestingtech.pantheonsite.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100004022; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dev.sebpo.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004023; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dezcom.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004024; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dfcf.91756.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004025; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dfsfcsfcdsfsdvcfsvcscv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004026; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"diamantenegro.mi-fs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004027; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dienmayminhhung.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004028; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"digilib.dianhusada.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004029; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"djking.f3322.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004030; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.1003b.56a.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004031; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.198424.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004032; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.installcdn-aws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004033; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.packetstormsecurity.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004034; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.rina-roleplay.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004035; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.zkytech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004036; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dns.cyberium.cc"; content:"Host"; http_header; classtype:trojan-activity; sid:100004037; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dockerupdate.anondns.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004038; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"docman.orientalservices.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004039; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dodsonimaging.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004040; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dokan.blueberrytec.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004041; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dom-chel74.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004042; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dom.daf.free.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004043; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"doncedyhall.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004044; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"donghobinhminh.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004045; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dongphuctop.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004046; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"donwnloasecury.ath.cx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004047; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dosame.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004048; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dosman.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004049; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dovberger.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004050; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.flash-plays.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004051; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.pcclear.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004052; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.posti-fi-fsa.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100004053; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.posti-fi-fwa.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100004054; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.udashi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004055; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.webbora.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004056; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down1.arpun.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004057; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.caihong.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004058; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.doumaibiji.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004059; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.exrnybuf.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004060; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.kaobeitu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004061; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.pdf00.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004062; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.rising.com.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004063; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.skycn.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004064; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.zjsyawqj.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004065; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"downloads.jxtsteel.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004066; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dragonsknot.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004067; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drbaby.com.sa"; content:"Host"; http_header; classtype:trojan-activity; sid:100004068; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drohnen.ensenanzainteligente.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004069; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drools-moved.46999.n3.nabble.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004070; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drrohanfonseca.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004071; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drsha.innovativesolutions.mobi"; content:"Host"; http_header; classtype:trojan-activity; sid:100004072; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dsenterprize.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004073; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dsspainting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004074; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"du-wizards.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004075; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"duque.guantanameratravel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004076; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dutapp.wisolve.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004077; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"duvalcharter.dekitout.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004078; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dx.qqyewu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004079; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dzinestudio87.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004080; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"e-commerce.saleensuporte.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004081; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"e.sldov.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004082; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ebruyatkin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004083; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"econews.treegle.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004084; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"edelweissdecoration.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004085; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"efficientegroup.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004086; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"elliot.newreadermedia.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004087; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"emaids.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004088; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"en.baoend.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004089; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"enc-tech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004090; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"endurotanzania.co.tz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004091; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"enkonooh.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004092; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ennovate.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004093; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"enriquecendocomconsorcio.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004094; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"envios.petpienso.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004095; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"equimination.ee"; content:"Host"; http_header; classtype:trojan-activity; sid:100004096; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"es.paymelist.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004097; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"escola.probommar.org.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004098; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"esnconsultants.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004099; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"essentia.org.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004100; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"eubanks7.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004101; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"evidencemarketing.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100004102; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"exilum.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004103; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"exitoalfaomega.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004104; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"extrovertoffers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004105; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"f1sol.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004106; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"familydentist.site"; content:"Host"; http_header; classtype:trojan-activity; sid:100004107; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"farmaciasdrogaminas.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004108; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"farmnatural.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004109; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"faveraprojects.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004110; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fc.co.mz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004111; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"felicienne.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004112; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fi.bonitastores.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004113; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"files.martellexpress.us"; content:"Host"; http_header; classtype:trojan-activity; sid:100004114; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"files6.uludagbilisim.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004115; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"filmotainment.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004116; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"final.makkahkmcc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004117; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fkd.derpcity.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004118; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"flintspin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004119; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"flyingbuddhadesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004120; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fmjplastering.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004121; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fms.buladde.or.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100004122; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"foothills.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004123; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"footweardirect.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004124; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"formestore.evencsoft.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004125; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"forum.mdb.nu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004126; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fotoobjetivo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004127; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"foundationrepairhoustontx.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004128; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"foxeps.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004129; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"freecnetdownload.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004130; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"freedombookshop.tickme.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004131; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"freisites.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004132; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ftp.n3twork30cm.ml"; content:"Host"; http_header; classtype:trojan-activity; sid:100004133; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fullelectronica.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004134; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"funletters.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004135; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fusionfiresolutions.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004136; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"futuregraphics.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004137; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gahanassociates.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004138; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gametwogame.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004139; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"garayvidalabogados.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004140; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"garciadogshow.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004141; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"garenanow.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004142; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"garenanow4.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004143; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gbbulls.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004144; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gcpc.co.id.chronoscurtain.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004145; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gcrcorporation.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004146; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"generaldeviales.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004147; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gfmodd1.webselffiles01.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004148; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gfold1.webselffiles01.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004149; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ghettohub.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004150; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ghislain.dartois.pagesperso-orange.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004151; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"giadungg7.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004152; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"giddos.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100004153; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"giteletropical.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004154; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"globaltask.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004155; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"glowinmedia.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100004156; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gmtransformationacademy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004157; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gmvadmission.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004158; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gnimelf.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004159; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gnscrew.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100004160; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gold.investforex.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004161; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcake.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004162; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcoastoffice365.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004163; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcoastoffice365.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004164; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcupmortgage.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004165; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"golden-memories-funerals.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004166; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldmen.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004167; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gracejukes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004168; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"grupoinmare.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004169; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gruposelt.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004170; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gs.monerorx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004171; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gulfac-house.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004172; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gvpcdpgc.edu.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004173; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"habbotips.free.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004174; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hagebakken.no"; content:"Host"; http_header; classtype:trojan-activity; sid:100004175; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"harrisauto.no"; content:"Host"; http_header; classtype:trojan-activity; sid:100004176; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"harshraval.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004177; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hd11315.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004178; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hdkamera2003.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004179; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hdrest.fastlinktz.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004180; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hds.sz4h.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004181; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"healthy20.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004182; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hechiceriadeamormaestrabelen.com.hechiceriadeamormaestrabelen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004183; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hellogorgeous.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004184; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"help.hizuko.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004185; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"herchinfitout.com.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100004186; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hhaward.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004187; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"highlandroadcoc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004188; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"highlandslasvegas.atakdev.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004189; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hindi.factsriver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004190; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hiptool.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004191; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hitpe.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004192; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hitstation.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004193; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hmpmall.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004194; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hoagietesting10.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004195; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hoayeuthuong-my.sharepoint.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004196; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"homefindersolutions.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004197; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hongluosi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004198; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hookedupboatclub.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004199; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hostelkielce.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004200; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hostzaa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004201; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"houstonshutters.site"; content:"Host"; http_header; classtype:trojan-activity; sid:100004202; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hr2019.vrcom7.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004203; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hseda.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004204; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hsmwebapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004205; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"htownbars.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004206; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hubtech.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004207; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"huequito.evencsoft.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004208; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hunggiang.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004209; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"husamiyahschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004210; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iam313.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004211; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"icon.shatangmu.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004212; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idea-secure-login.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004213; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idilsoft.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004214; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idj.no"; content:"Host"; http_header; classtype:trojan-activity; sid:100004215; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idvindia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004216; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iesanjosemonitos.edu.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004217; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ikexpert.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004218; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ilrafrica.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004219; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"imbueautoworx.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004220; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"imperiumtherapy.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004221; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"in-tune2016.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004222; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"incodimsa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004223; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"incrediblepixels.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004224; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"incredicole.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004225; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"industriasyuli.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004226; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"infair.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004227; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"infovator.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004228; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"innatosbrand.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004229; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"inodesthetotaldesigners.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004230; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"inovations.searchkero.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004231; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"inrajahmundry.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004232; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"insignificantfinecore.testmail4.repl.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004233; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"instvisionmexico.edu.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004234; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"intellectsmart.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004235; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"intersel-idf.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004236; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"intuitiveideas.com.my"; content:"Host"; http_header; classtype:trojan-activity; sid:100004237; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"inversiones.arrayanfinanciero.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004238; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"invest.xpcorporative.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004239; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ipmes.ma"; content:"Host"; http_header; classtype:trojan-activity; sid:100004240; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iremart.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100004241; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iris101.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004242; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iscamenabe.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004243; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iso-dubai.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004244; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"israrulhaq.me"; content:"Host"; http_header; classtype:trojan-activity; sid:100004245; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"isrorg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004246; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"issmbour.falllo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004247; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"isso.ps"; content:"Host"; http_header; classtype:trojan-activity; sid:100004248; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"it123.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004249; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"itc-demo.softgig.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100004250; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"itconsultus.com.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004251; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jamesjorgensen.newreadermedia.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004252; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jamiekaylive.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004253; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jamshed.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004254; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jansen-heesch.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004255; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jathra.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004256; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jay.diamondrelationscrm.us"; content:"Host"; http_header; classtype:trojan-activity; sid:100004257; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jebs.net.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004258; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jeffdahlke.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004259; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jhayesconsulting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004260; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jiaoyuzixun.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004261; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jing-da.com.tw"; content:"Host"; http_header; classtype:trojan-activity; sid:100004262; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jktnet.xyz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004263; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jmcomputacion.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004264; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jmtc.91756.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004265; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jnanbharati.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004266; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jobs.thebeessolution.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004267; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"joelbonissilver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004268; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"join.cl8movement.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004269; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"josegene.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004270; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"josuarochoa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004271; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jpwoodfordco.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004272; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"julietlaser.site"; content:"Host"; http_header; classtype:trojan-activity; sid:100004273; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jumpmanualjacobhiller.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004274; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jumpnjamchicago.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004275; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jupiter.toxsl.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004276; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jurgensen.newreadermedia.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004277; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"justinscott.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004278; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kaizenjanitorial.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004279; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kalawatihomes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004280; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kalpataru-elitus-mulund.thakkers.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004281; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"karer.by"; content:"Host"; http_header; classtype:trojan-activity; sid:100004282; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"katanvetov.co.il"; content:"Host"; http_header; classtype:trojan-activity; sid:100004283; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kbdom.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004284; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kensingtondriving.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004285; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kevinjewelry.com.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004286; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"keywatch.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004287; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kingssa.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004288; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kjcpromo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004289; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kleinendeli.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004290; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"korrectconceptservices.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004291; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ktb.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004292; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kubatoglubaklava.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004293; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kumaralok.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004294; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kwanfromhongkong.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004295; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kz.sldov.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004296; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lacasadelosalebrijes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004297; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ladylabonde.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004298; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lameguard.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004299; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"landing.yetiapp.ec"; content:"Host"; http_header; classtype:trojan-activity; sid:100004300; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"laodongnhat.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004301; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"laravel.pointersoftwares.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004302; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lasermobilesounds.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004303; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lauratomismith.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004304; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lautarosanmiguel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004305; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lawforall.edu.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004306; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lceventos.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004307; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ld.mediaget.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004308; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ldgcorp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004309; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"learning.real-academy.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004310; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"leasiacherise.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004311; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"leczkregoslup.acelero.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004312; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"legend.nu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004313; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"leluibuffet.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004314; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lestesteux.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100004315; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"libantravel.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004316; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"library.arihantmbainstitute.ac.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004317; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"library.uib.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004318; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lickmylash.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004319; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lidoraggiodisole.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100004320; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lifebeam.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004321; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lindnerelektroanlagen.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004322; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"linkintec.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004323; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"litroxlitro.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004324; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"livetrack.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004325; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydsindian.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004326; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lm.stagingarea.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004327; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lmaancha.co.il"; content:"Host"; http_header; classtype:trojan-activity; sid:100004328; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lms.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004329; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lms.login2.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004330; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lmvirtualbookkeeping.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004331; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lnt-rejuve-360.thakkers.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004332; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"location-voitures.ma"; content:"Host"; http_header; classtype:trojan-activity; sid:100004333; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"login.trezor.com.stockfootagesindia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004334; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"logotypfabriken.se"; content:"Host"; http_header; classtype:trojan-activity; sid:100004335; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lotix.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004336; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lotusanddragonfly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004337; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lp.definerisco.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004338; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lp.difusodesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004339; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lp.juancamilogarciareyes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004340; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lp.tecnimasdecolombia.com.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004341; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"luckybrownie.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004342; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"luminouspneuma.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004343; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"luxomodels.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004344; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"m-technics.kz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004345; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"m.estudiomoros.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004346; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"madicon.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004347; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"magianegramagiablancayamarres.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004348; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.bs-eiendomme.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004349; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.jeffsono.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004350; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"maksi.feb.unib.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004351; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"malaya.tv"; content:"Host"; http_header; classtype:trojan-activity; sid:100004352; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"malwarecoding.github.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100004353; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"managed.oss-cn-beijing.aliyuncs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004354; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"manantialesdelnorte.uy"; content:"Host"; http_header; classtype:trojan-activity; sid:100004355; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"manivelasst.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004356; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marcapinyo.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004357; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marcusthepoet.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004358; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mario-sunjic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004359; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mariobrown.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004360; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mariotessarollo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004361; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marketinfosales.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004362; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marketing.enexusgroup.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004363; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marksidfgs.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100004364; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"masjidhabeebiyarazviya.mysunni.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004365; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"materialescantu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004366; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"matinal-nominal.pt"; content:"Host"; http_header; classtype:trojan-activity; sid:100004367; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"matruchhaya.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004368; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mattysplayground.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004369; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"maxtox.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004370; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mbgrm.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004371; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mbsolutions.ge"; content:"Host"; http_header; classtype:trojan-activity; sid:100004372; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mdasa.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004373; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"medevlb.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004374; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"media-server.skyinternet.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004375; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mediamaster.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004376; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"medianews.ge"; content:"Host"; http_header; classtype:trojan-activity; sid:100004377; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"medistaffconsulting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004378; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"meeweb.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004379; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"megamart.afnan-amc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004380; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"merbay.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004381; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"merkathink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004382; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mertlog.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004383; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"metalin-cr.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004384; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mettaanand.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004385; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"meuoculosnanet.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004386; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mfevr.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004387; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mhkdhotbot.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004388; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mhkdhotbot80.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004389; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"micalle.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004390; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"michaelphilip.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004391; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"michimal2.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004392; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"microblading.mirliandias.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004393; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"microcomm-group.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004394; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"midlandtexasconstruction.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004395; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mindfulbuildingandliving.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004396; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mingguanwms.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004397; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"minuevavida.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004398; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mirror.mypage.sk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004399; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mis.nbcc.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100004400; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"misterson.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004401; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mixr.at"; content:"Host"; http_header; classtype:trojan-activity; sid:100004402; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mkontakt.az"; content:"Host"; http_header; classtype:trojan-activity; sid:100004403; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mktf.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004404; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mmogollon.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004405; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mncarteam.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004406; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"modelhouseturkey.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004407; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"modernmanna.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004408; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"monetization.business"; content:"Host"; http_header; classtype:trojan-activity; sid:100004409; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"moninediy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004410; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mopai.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100004411; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"motorcomunicacion.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004412; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mtspsmjeli.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004413; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"muzimbiti.xigubo.co.mz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004414; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mxpiqw.am.files.1drv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004415; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mydatebook.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004416; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mymlql.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004417; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"myritz.vettickal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004418; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"myscape.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004419; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mysura.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100004420; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"namnyak.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100004421; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nap.mgsservers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004422; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"navayurveda.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004423; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nec-i.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004424; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nelitrianggraeni.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004425; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nerve.untergrund.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004426; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nettube.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004427; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"networkwheels.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004428; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"neuroenergy.fahadjutt.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004429; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"neuromedic.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004430; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"neverseenshop.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004431; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newinfinitysynergy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004432; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"news.dbstrony.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004433; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newtreedesign.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004434; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newtrendeg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004435; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newvisionopticallab.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004436; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newxing.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004437; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nextdigitalday.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004438; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ngdaycare.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004439; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nguyenkekhuyen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004440; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nhorangtreem.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004441; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nicolas.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100004442; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nidhi.iexist.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004443; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nikanpolimer.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100004444; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nilinkeji.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004445; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nisacooks.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004446; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"njtiledesigncenter.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004447; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nobius.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004448; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocalnoodle.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004449; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nomadicbees.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004450; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nonnarina.ax"; content:"Host"; http_header; classtype:trojan-activity; sid:100004451; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"notamuzikaletleri.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004452; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"notif1.priruz.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004453; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ns1.the-widyantos.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004454; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nsb.org.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004455; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nsheldon.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004456; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nurmarkaz.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004457; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nuthuassociates.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004458; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nuwagi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004459; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nyeh2o.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004460; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oakleyandfriends.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004461; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"obseques-conseils.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004462; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ocean.tecnasulstore.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004463; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ohsewgorgeous.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004464; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oleholeh.memangbeda.website"; content:"Host"; http_header; classtype:trojan-activity; sid:100004465; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"olirecords.mixture.ltd"; content:"Host"; http_header; classtype:trojan-activity; sid:100004466; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"olooom.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004467; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omaromatic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004468; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omega.az"; content:"Host"; http_header; classtype:trojan-activity; sid:100004469; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oms.pappai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004470; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omscoc.pappai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004471; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"onedigitalcard.granvizionnecorp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004472; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"onedrive.listifyapp.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004473; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"online.creedglobal.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004474; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"onlinestatis.bar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004475; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"open.warehousesaas.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004476; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"opolis.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100004477; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"optimus.com.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100004478; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"optitechsa.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004479; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"order.bizpeed.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004480; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"orientgatewayltd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004481; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"orion445.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004482; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ottimade.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004483; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ourteam.searchkero.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004484; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ozemag.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004485; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"p1.lingpao8.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004486; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"p3.zbjimg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004487; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"p6.zbjimg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004488; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pablobrothel.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004489; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pacificgroup.ws"; content:"Host"; http_header; classtype:trojan-activity; sid:100004490; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pacwebdesigns.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004491; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pagos.krayem.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004492; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"palochusvet.szm.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004493; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"parallel.rockvideos.at"; content:"Host"; http_header; classtype:trojan-activity; sid:100004494; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"parejasfelices.mi-fs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004495; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"parkhussion.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004496; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pastorpaulocosta.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004497; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"patch2.51lg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004498; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"patch2.99ddd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004499; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"patch3.99ddd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004500; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"paths.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004501; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"paulmercier.biz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004502; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"payerrealty.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004503; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pcsoori.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004504; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pd.oceaniarp.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004505; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"perpus.onlineman7-jombang.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004506; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"perpustekim.untirta.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004507; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pestoclean.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004508; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"petercollie.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004509; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ph4s.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004510; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"phenhuong.sanpham.online"; content:"Host"; http_header; classtype:trojan-activity; sid:100004511; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"phittc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004512; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"photo360.kubooking.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004513; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"photographytipsclub.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004514; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pink99.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004515; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"plasfan.ind.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004516; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pmglance.startwriteup.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004517; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pokojewewladyslawowie.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004518; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pole.com.vc"; content:"Host"; http_header; classtype:trojan-activity; sid:100004519; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pool.phxdir.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004520; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pooltablemoversdenver.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004521; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"posmicrosystems.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004522; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"poulman.panagiotopoulos-tours.gr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004523; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ppdb.smk-ciptaskill.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004524; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pptvideotemplates.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004525; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prestasicash.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004526; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prestigehomeautomation.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004527; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prishaartcreations.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004528; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"production.sparshims.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004529; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"productprecise.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004530; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prof-dr-ahmedalmoatasem.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004531; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"programaoperadoronline.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004532; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"project.exquitec.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004533; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"promotoradescomplica.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004534; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"promoversdubai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004535; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"propertiq.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004536; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"propertiq2.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004537; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prosoc.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004538; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prostar.priruz.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004539; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prosyarmakassar.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004540; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"provence.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004541; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prueba.danielluza.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004542; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pujashoppe.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004543; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"punchdialogues.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004544; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"punjabdevelopersassociation.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004545; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"purefoe.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100004546; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"qadir.tickfa.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100004547; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"qatarglobalconsulting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004548; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"qmsled.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004549; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"quartier-midi.be"; content:"Host"; http_header; classtype:trojan-activity; sid:100004550; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"querocar.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004551; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rachmat-assuhaimi.my.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004552; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rainbowisp.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004553; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"raodigitalmedia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004554; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rarlabarchiver.ac"; content:"Host"; http_header; classtype:trojan-activity; sid:100004555; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rasadbar.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100004556; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rashika.ascarvalho.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004557; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ratemyfenancialadvisor.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004558; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ravenproductionsltd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004559; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rc.ixiaoyang.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004560; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"readymmade.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004561; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"realtheprocess.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004562; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"redchillicrackers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004563; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"reifenquick.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004564; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"relaxindulge.co.nz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004565; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"renehavis.com.ua"; content:"Host"; http_header; classtype:trojan-activity; sid:100004566; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"repatriacioncolombia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004567; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"res.uf1.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004568; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"reseller.digimitra.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004569; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"resuco.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004570; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rezkabum.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004571; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rhema.com.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100004572; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"richancyber.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004573; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"richmondminerals.co.zm"; content:"Host"; http_header; classtype:trojan-activity; sid:100004574; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rinaefoundation.org.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004575; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rinkaisystem-ht.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004576; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"riverfox.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004577; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rkcable.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004578; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rkverify.securestudies.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004579; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"roadfurylifts.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004580; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"robertmcardle.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004581; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"robertsinclair.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004582; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"robinhood-sports.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004583; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"romanianpoints.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004584; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ronnietucker.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004585; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"roomsvc.servegate.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004586; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"roshan.academy"; content:"Host"; http_header; classtype:trojan-activity; sid:100004587; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"roshnijewellery.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004588; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rs-toolkit.mikestclair.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004589; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rsgym.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004590; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rubazar.pro"; content:"Host"; http_header; classtype:trojan-activity; sid:100004591; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rubycityvietnam.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004592; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ruch.newreadermedia.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004593; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ruisgood.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004594; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ruwadalkuwait.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004595; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rzminc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004596; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"s.51shijuan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004597; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"s.thechinesemuslim.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004598; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sacredscentsonline.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004599; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"safcol-colors.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004600; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"safehubsecurity.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100004601; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"safety.nanotechproautocare.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004602; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sahathaikasetpan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004603; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"saisoftwareinc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004604; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"salecorner.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004605; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sandovalgraphics.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004606; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"santebarleyshop.jakewebtechs.ml"; content:"Host"; http_header; classtype:trojan-activity; sid:100004607; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"santyago.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004608; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sarakem.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004609; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sasystemsuk.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004610; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"savasaachi.systems"; content:"Host"; http_header; classtype:trojan-activity; sid:100004611; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"savingchintu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004612; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"scarfaceindustries.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004613; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"scglobal.co.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100004614; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"schalke04rss.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004615; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"scheff.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004616; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"schoolbustracker.softgig.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100004617; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sec-doc-w.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004618; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure-doc-reader.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004619; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sefp-boispro.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004620; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"segalsmetals.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004621; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sellmyphonela.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004622; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"selltechtoday.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004623; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"senbiaojita.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004624; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sentierodelviandante.ml"; content:"Host"; http_header; classtype:trojan-activity; sid:100004625; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"serendibsourcing.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004626; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"servicemhkd.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004627; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"servicemhkd80.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004628; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"serviciovirtual.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004629; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"seyranikenger.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004630; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sgessy.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004631; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shaheentbfoundation.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004632; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shahikhana.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004633; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sharkrigs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004634; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sharpelevators.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004635; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shembefoundation.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004636; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shivakunwar.com.np"; content:"Host"; http_header; classtype:trojan-activity; sid:100004637; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shoblasaathitrust.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004638; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shooka-co.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004639; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shop.clarostudio.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100004640; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shop.goldspot.agency"; content:"Host"; http_header; classtype:trojan-activity; sid:100004641; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shopsofe.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004642; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shrushtiinfotech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004643; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sibernetix.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004644; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"siddharthpanditpautra.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004645; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sige.brisainformatica.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004646; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"signatureads.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004647; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"siili.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004648; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"simoneporzi.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100004649; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"simplithy.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004650; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sindicato1ucm.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004651; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sinergidwireka.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004652; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sipahielektrik.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004653; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"siperb.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004654; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sistelligent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004655; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"site.sjc.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100004656; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"skkksolo.beweiretail.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004657; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"skyflyfares.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004658; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"skyscan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004659; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smarthouseforum.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004660; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smarts.tj"; content:"Host"; http_header; classtype:trojan-activity; sid:100004661; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smartzedu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004662; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smokeandgrowrichtour.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004663; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smokesolutionindia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004664; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sobethuacademy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004665; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"soft.110route.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004666; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"soft.officelabo.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004667; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sohs.conceptechs.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004668; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"solar.amazingtribe.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004669; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"solo2.dbstrony.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004670; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"somcorbera.cat"; content:"Host"; http_header; classtype:trojan-activity; sid:100004671; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"somir.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004672; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"soralapps.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004673; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sorteio.orgaostalita.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004674; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sota-france.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004675; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sowingminerals.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004676; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"space.proactint.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004677; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spaceframe.mobi.space-frame.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004678; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"specfloors.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004679; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"special-key.cf"; content:"Host"; http_header; classtype:trojan-activity; sid:100004680; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spent.com.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004681; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spetsesyachtcharter.gr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004682; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spititourism.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004683; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spittinfire.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004684; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sports-net.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004685; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"src1.minibai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004686; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sreenivasapaintingworks.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004687; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sriglobalit.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004688; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"srvmanos.no-ip.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004689; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ss.monita.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004690; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"staging.apparelpunch.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004691; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"starcountry.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004692; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"static.3001.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004693; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"statsres.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004694; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"statssound.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004695; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"statsspot.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004696; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"statsvilla.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004697; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stattilion.bar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004698; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stiepancasetia.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004699; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stott-thompson.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004700; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stratexec.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004701; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"streetdemo.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004702; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"suboldesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004703; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sumerians.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004704; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sunbrero.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004705; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sunmarkholidays.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004706; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"supermercadostia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004707; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"support-4-free.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004708; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"support.clz.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004709; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"supportit.online"; content:"Host"; http_header; classtype:trojan-activity; sid:100004710; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sw.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004711; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sweaty.dk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004712; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sweet-diet.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004713; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"swentsai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004714; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"swiftlogisticseg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004715; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"swwbia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004716; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"syedpro.dezinetimes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004717; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"syracusecoffee.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004718; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sys.pbmadu.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004719; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"systemsecuritylock.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004720; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sytraders.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004721; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"t.honker.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004722; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tacticohosting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004723; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tadoo.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100004724; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tafsantoursandtravels.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004725; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tallyinvoicecustomization.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004726; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"taltus.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004727; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tapalkoedacoffee.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004728; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tarravalleyfoods.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004729; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"taurus.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100004730; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"taxicabsrilanka.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004731; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"taxpos.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004732; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tc.snpsresidential.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004733; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tcy.198424.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004734; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tdsp.yngw518.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004735; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tech332.synology.me"; content:"Host"; http_header; classtype:trojan-activity; sid:100004736; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"techgms.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004737; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"technogreen.crmmanivela.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004738; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"technohub.searchkero.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004739; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tecnicaencolectores.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004740; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"teduae.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004741; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"teleargentina.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004742; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"telescopelms.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004743; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"telmed.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004744; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"temptmag.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004745; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tennisafrica.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004746; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tentandoserfitness.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004747; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tepresto.net.pe"; content:"Host"; http_header; classtype:trojan-activity; sid:100004748; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.adventser.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004749; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.letraele.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100004750; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.wanepghana.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004751; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test1.asistencia247.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004752; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test1.milenial.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004753; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test1.tenplusone.my"; content:"Host"; http_header; classtype:trojan-activity; sid:100004754; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test2.basis-web.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004755; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test2.marrenconstruction.ie"; content:"Host"; http_header; classtype:trojan-activity; sid:100004756; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"testing.clickitsolutionsmw.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004757; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"testing.thinkingcorp.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004758; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"testnew.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004759; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"teteaffiche.stephanebillon.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004760; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tewoerd.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004761; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"textile.softberg.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100004762; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"texts.bfftexts.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004763; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"texturesbyvinita.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004764; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tharringtonsponsorship.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004765; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thecleaningladiespdx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004766; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thecreativecafe.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004767; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thefuturelife.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004768; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thehighlightinterior.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004769; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thehouseofpragya.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004770; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thekassia.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004771; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thelaunchpadteam.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004772; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thelekhak.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004773; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thelogicalgroup.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004774; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thesummitpc.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004775; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"theurbantutors.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004776; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thosewebbs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004777; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thriveink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004778; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tianangdep.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004779; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tickfood.tickme.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004780; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tickjobs.tickme.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004781; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tickmart.tickme.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004782; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"timegonebuy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004783; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tksb.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004784; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tlcc.com.gt"; content:"Host"; http_header; classtype:trojan-activity; sid:100004785; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"todoapp.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004786; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tonydong.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004787; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tonyzone.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004788; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tooba.tenplusone.my"; content:"Host"; http_header; classtype:trojan-activity; sid:100004789; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"topcell9.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004790; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"topicsnepal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004791; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"toplevel.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004792; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"torresquinterocorp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004793; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"towme.services"; content:"Host"; http_header; classtype:trojan-activity; sid:100004794; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"toyotacollege.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100004795; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tpef.lsoftdemo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004796; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tpke.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004797; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tradezone.ejuicysolutions.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004798; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"translaterjemah.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004799; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"travel.travelwadi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004800; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"travelwithmanta.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004801; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"trezors.io.mahlongwa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004802; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"triplonet.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004803; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"troki.com.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004804; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tropics.codeleek.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004805; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"trudelfavreau.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004806; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tsd.jxwan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004807; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tulli.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004808; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tupperware.michaelroberge.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100004809; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"turanggaresources.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004810; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tushartyagiji.digitalswagger.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004811; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uat.indianfilmzone.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004812; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ublretailerdemo.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004813; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"udesk.searchkero.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004814; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ugprs-ubih.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004815; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ultimate-24.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004816; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"umwelt-kirchhof.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004817; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"unicorpbrunei.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004818; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uniengrisb.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004819; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"unisoftcc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004820; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"unitedpestsolutionstx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004821; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"unyazitelecom.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004822; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"upcbpta.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004823; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"urbane.dezinetimes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004824; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"useformoney.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004825; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"usmadetshirts.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004826; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uss.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100004827; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uzzepay.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004828; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vanzare.cabanabrazi2.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100004829; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vbcargo.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004830; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vcah.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004831; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vegadelcasero.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004832; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vendas.lidiacarmeli.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004833; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"verify.aicosoft.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004834; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vfocus.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004835; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vidmattic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004836; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vienen.gblix.srv.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004837; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"villamarand.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004838; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"villatera.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004839; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"violinstop.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004840; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"viraltalking.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004841; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"visions.alnisamart.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004842; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"visualhome.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004843; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vitoriamodaintima.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004844; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vivationdesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004845; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"viveirodoiscorregos.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004846; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vksales.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004847; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vokasi.ub.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004848; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vologroup.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004849; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"voteyouramerica.dekitout.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004850; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vstsample.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004851; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vtube.fadlymotivator.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004852; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vvsskmodinationalschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004853; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wahrewah.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004854; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wanepliberia.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004855; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wanepniger.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004856; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"weareactum.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004857; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.eng.ubu.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100004858; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.geomegasoft.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004859; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.newinnovationtechnology.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004860; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.smarts-works.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004861; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.thebeessolution.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004862; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"webgis.perumdasolo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004863; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"webmailwindstreamnetmessagesecureapp1rqr.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100004864; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"webpresario.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004865; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"website-work.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004866; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"weinsteincounseling.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004867; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wexfashion.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004868; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"whcms.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004869; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"whiteglovetailgate.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004870; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"whiteresponse.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004871; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wi522012.ferozo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004872; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wikalen.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004873; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wildnights.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004874; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wildtrust.mediadevstaging.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004875; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wimbamusica.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004876; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"windcomtechnologies.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004877; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"winnercircle.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100004878; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wishesconcierge.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004879; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"woezon.agency"; content:"Host"; http_header; classtype:trojan-activity; sid:100004880; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wolfgang-brodte.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004881; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"woodsytech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004882; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wordpress.saleensuporte.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004883; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wozata.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004884; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wp.readhere.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004885; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wpdemo.101clients.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004886; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"writtendeer.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004887; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ws5588.f3322.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004888; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wyklej.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004889; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"x2vn.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004890; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xia.beihaixue.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004891; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xixaoclothing.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004892; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xk.996is.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004893; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xmp.myracingaccounts.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004894; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--80akinnkiib6h.xn--90ais"; content:"Host"; http_header; classtype:trojan-activity; sid:100004895; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--polimerbizmimarlk-rvc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004896; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ybom.urbanolab.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004897; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yeichner.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004898; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ylfpremium.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004899; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yoast.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004900; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"youtubetrainingacademy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004901; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yskadvisors.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004902; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yummyyogaudaipur.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004903; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yzkzixun.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004904; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004905; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"zz.690tx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004906; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/64.exe"; http_uri; nocase; content:"2.indexsinas.me:811"; content:"Host"; http_header; classtype:trojan-activity; sid:100004907; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/86.exe"; http_uri; nocase; content:"2.indexsinas.me:811"; content:"Host"; http_header; classtype:trojan-activity; sid:100004908; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/c64.exe"; http_uri; nocase; content:"2.indexsinas.me:811"; content:"Host"; http_header; classtype:trojan-activity; sid:100004909; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/downfiles/file.exe"; http_uri; nocase; content:"akwer03.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100004910; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe"; http_uri; nocase; content:"amumufree.weebly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004911; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/files/proxyi.exe"; http_uri; nocase; content:"analogx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004912; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004913; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/densjons/bro/downloads/rew.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004914; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dvdfv/anjj/downloads/jami.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004915; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/jpavelski/chpock/downloads/4.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004916; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/jpavelski/chpock/downloads/6.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004917; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/clr.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004918; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/clr3.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004919; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/instaler.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004920; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/installer.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004921; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/updatej.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004922; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/updatev.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004923; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/work.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004924; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player2012/rumpa1/downloads/component.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004925; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player2012/rumpa1/downloads/nordvpnsetup.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004926; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player2012/rumpa1/downloads/regsvc.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004927; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/skygaming/updates/downloads/update.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004928; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/001.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004929; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1488.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004930; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1_cr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004931; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1cr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004932; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1fc2d.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004933; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/26a5.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004934; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/6e7_2021-01-19_18-04.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004935; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/abjects.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004936; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/attached.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004937; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/b7f2c.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004938; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/battletext.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004939; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/bkghj_nowin.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004940; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/bsdasdasd333.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004941; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004942; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build_makros.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004943; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build_silent.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004944; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build_sup.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004945; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildcmobiler.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004946; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildcmobiler.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004947; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildcr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004948; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildss.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004949; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/clientnik.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004950; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/clientrevers.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004951; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/dcrat.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004952; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/dllservices.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004953; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/dllservices2.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004954; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/exe_morris.mcdermott.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004955; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/hans.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004956; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/hulu.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004957; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelfive.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004958; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelfour.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004959; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelone.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004960; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelthree.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004961; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/inteltwo.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004962; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/jjuufksfn.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004963; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/kleiman.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004964; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/lucky_fixed.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004965; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/notepadplus.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004966; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/osiris_qqkz_nauto.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004967; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/out.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004968; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/out.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004969; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/pacbe_bin.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004970; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/putty.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004971; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/rockethcd.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004972; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/scvhost900.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004973; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/sessionwin.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004974; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/siliculose.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004975; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/statemobi.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004976; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/stealers.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004977; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/stealers2.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004978; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/stgedo.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004979; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/svcperf.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004980; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/symptomaticshon5.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004981; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/taurjok.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004982; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/taurusbabac.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004983; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/telekiller.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004984; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/updateanddr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004985; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/updateandr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004986; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/vhajeja.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004987; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/word.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004988; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/www.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004989; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/xlsd.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004990; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/teaserex/tease/downloads/b_kfmhkk172.bin"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004991; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/teaserex/tease/downloads/macro_xmprohiq27.bin"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004992; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/hmatrix/data/hack1226.exe"; http_uri; nocase; content:"cd.textfiles.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004993; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004994; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/816070119281131570/816070273254162442/all.txt"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004995; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/823355293043261515/823692323514482788/inquiry_-_rfq_hmg_u66_sw5558_pdf.iso"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004996; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/razor/rzr-winner_intro.zip"; http_uri; nocase; content:"chiptune.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004997; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz"; http_uri; nocase; content:"cloudme.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004998; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar"; http_uri; nocase; content:"cloudme.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004999; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/meteoradminz/hidden-tear/zip/master"; http_uri; nocase; content:"codeload.github.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005000; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/"; http_uri; nocase; content:"colfincas.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005001; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/kr.bin"; http_uri; nocase; content:"d.ttr3p.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005002; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/qz0h69.pdf"; http_uri; nocase; content:"deepfreedom.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005003; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/frm0reseen/prntscrnofamzorderid.jpg.exe"; http_uri; nocase; content:"drive.google.com.it-barcelona.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005004; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=0byfg0_4xbjgnwvuyev9ltuh4rmm"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005005; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=13vodfxml9fg8kcnexuafh64dzmnqv8ch"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005006; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=14l8sj2dqo04ozum88tvuy74yfcwk5fnf"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005007; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=15bd1dksg4pkrxehoczi7e0uok4vblz4e"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005008; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=167imxqgc8ehepa1gisxa6q6ifcjxceox"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005009; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=17xvn-rlhei5n9f6unuqqb_wh84u4w5cx"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005010; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1_vz7veeec-juwt23g9d9wjuid2kusew7"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005011; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1a-herfdxr6xamxeabcdao0mqw9bimrig"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005012; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1aphk_vq7gtn368zxpd5bg5rv8nk0bnhn"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005013; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1aqhdbelnscyjygigfopt7x_oafaqgwg1"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005014; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1cf8d3ljsfn3toddczqtkkbhrd5g00cjg"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005015; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005016; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1cynoc3t9rp-xvso3jcmx_prwppp8u-dv"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005017; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1d8fykmpewc_4yurihjh_cdehkdp_nuik"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005018; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1dgcin9vevl9f63cbhbkmc_gpa2b0zlrh"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005019; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1do7c-fjuscbueu0un2dbxe3-pnwdufb_"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005020; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1eqnvgn0qkunp7t6crk8oj7_e7rh5qxwi"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005021; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1f3kxfcvbpaaexgnchpvmyoxkcdmickjj"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005022; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1gsmk1t_yigh7jablxkuhbmmh93vwgikb"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005023; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1hmud67vsl-shqddzpxniqmyj92iynyis"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005024; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ik-x4_bsr5dbocs9j1ryg1ybw75fqu8t"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005025; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1in-rhdrss2qsjqj8xffb1hbwi9znp4je"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005026; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1iwc-lf99neesk6mvvo2al4futbmyoiev"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005027; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005028; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1jgykopezccdq3q5qprmkl1zdl1auymkq"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005029; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1lplk8rixxuboakkmut_qgzn92bkoulna"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005030; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1mug8m5o6kl_bx68x8cuxmzhn0gxnc7ki"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005031; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1n8o4hbvi7o9ks9jqhofny7okposfaz4y"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005032; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1nindqtjvyyzz-qk-hqa9gls5ccwhys-e"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005033; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1nio_cdsggt4zv1kdrpubrfpd0pzsyffd"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005034; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1nsyqwodoi1t9-i29arbxwe7fkafjydsz"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005035; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1nwctbvlr_1bewpvgdbmuhnny-zi6kp1l"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005036; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1o2dcrdwgu91moicmterbx9avcl9cavy1"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005037; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1o4lh97cmfnztr_hkocnwiucy5l6oskpy"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005038; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1oabvvnazifkxktvt-izbcdqpb7dm6nrw"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005039; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1oys1nkexzsuci6pfghowlbpwaw-_btxk"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005040; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1prxtn1juykhcr_9ilw-vtirv5anyeoej"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005041; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1pzywywxrwl2plk82nuodgvmcckpzrufb"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005042; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1q0uxhnzfs4j91rxz5x45iov8tjkomsgr"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005043; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1q9vzzhu-n9cu8ixdginpzaxxgvb1lrjv"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005044; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1qk8_jouqbnrfkky7x1aqunudfyl6fjii"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005045; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1qxv3i0dwy_cdx2bm1lqx6ef0qjwmhbpk"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005046; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1qzmi4jvter0_cwexcp4grjhxvr7lep5k"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005047; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1r-kstukxtxjqxlwypgd764dw-puj_7fz"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005048; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1r-zn6o95qzworq8e4fhz637bfuoxayby"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005049; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1rcykjynwhlc487sn1vwcsmjse_ctlrox"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005050; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1rdxnm_kxegbwlojlucu4qiff7kyax3oi"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005051; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1s9tu6akdxquy7cezquljtb2yarci99ab"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005052; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1serasql3bw7nc-sllzyrishnhodmefyf"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005053; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1shuxviwx167elbuz8mfcjc2bk99zzov_"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005054; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1sjzynfvpwdcwsr1p3w_q8-6ktsqiwadx"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005055; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1sogqqdapgyioillf7u62widsprhw3cjh"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005056; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1t1bd_itjnhsmozdl9was0gouehujm1fn"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005057; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1tfra7fzrjl2vdj73hcmcru5ynuqmz61g"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005058; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1tsmbsikhechaqedk6nktlfzasus_tghw"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005059; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ur9qebooqc-mjcdzn9wcbavocumdlosm"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005060; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1uvtmu3-hcryp3rskqnpkiodcjuchtz55"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005061; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1v4ima0sfnmboxmyoklp4g0_uehaj22x2"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005062; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1vevblftithattyguwyjot1p0wptg7l5t"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005063; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1vl9gje5llm7ja3dadct9okr6bzbmijc3"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005064; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1vvvujegfrgey39w6y3ybwpptl1guwf8a"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005065; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ws2ptumptku-imi9sv_k5g4fhsx30gnl"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005066; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1wtxdbb1fm9ozinx09a63-o-tn4ssgzpw"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005067; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1xbeqbw67xz4iqpu8dgmdrlkpa6kzotes"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005068; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1xdpxbb9gifdrugqxmg2_06xygbfq-x2k"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005069; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005070; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1xu9wvl5ktadwfxd94dicuej6y_j6kf8-"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005071; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1yawygcfjs9inzoiwagqfcn3utaywxmwi"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005072; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ycggxvacywdkt3jvqbpxpz9cyjcwvl_c"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005073; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1yhflwpk3yeyrdhlhanctlind-5j24iwv"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005074; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ys9rupdqvnhvrngizxfzstzcos0dlx-u"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005075; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1z6wmqtnaa-jtpm5bqkb3ebi_btjcvmat"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005076; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1zbclvhabervgfryoyqklo4_oe6icd8sr"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005077; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1zor7cinphnazfkldkthucb2h8jthlh9d"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005078; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1zsghzos5foggoqxq6w12xeqvanhccdyk"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005079; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=148pt6v0nlg8yoim7w6in7dpixkzaacbg&export=download&authuser=0"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005080; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/1zilg/"; http_uri; nocase; content:"drpamelageorge.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005081; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/qcgfmfvh/"; http_uri; nocase; content:"drpamelageorge.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005082; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/emclick.zip"; http_uri; nocase; content:"e-mudhra.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005083; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/informatica/informatica-actief/hoofdstuk1/extrasoftware/getallen.exe"; http_uri; nocase; content:"evertkok.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100005084; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/informatica/informatica-actief/hoofdstuk2/software/hksetup.exe"; http_uri; nocase; content:"evertkok.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100005085; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/register/phpcaptcha/images/19dnqhg1p/sbhvtqlysxhxn/"; http_uri; nocase; content:"expeditionquest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005086; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/register/phpcaptcha/images/35egphpl5uzpvdmz9bncmvon3p/"; http_uri; nocase; content:"expeditionquest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005087; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/x/"; http_uri; nocase; content:"expeditionquest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005088; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf/"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100005089; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf//"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100005090; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf///"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100005091; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf////"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100005092; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/web1/m00/8f/36/o4ybafy-2m2aarfzaahkaiik5pi122.exe"; http_uri; nocase; content:"file.elecfans.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005093; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/4cb7cebd101/e5fb4174-ab23-48e8-bf05-e80ec5fa2169.xls"; http_uri; nocase; content:"files.constantcontact.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005094; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ee304de9001/7e533e73-e272-4a44-9d9e-138cab64bf19.docx"; http_uri; nocase; content:"files.constantcontact.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005095; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe"; http_uri; nocase; content:"gist.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005096; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/"; http_uri; nocase; content:"hqdecig.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005097; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/suy/"; http_uri; nocase; content:"hsecaravans.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100005098; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/19/items/startup_20210219/startup.txt"; http_uri; nocase; content:"ia801802.us.archive.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005099; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/online-timer-kvhxz/ilxl/"; http_uri; nocase; content:"ie-best.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100005100; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/64.exe"; http_uri; nocase; content:"indonesias.me:9998"; content:"Host"; http_header; classtype:trojan-activity; sid:100005101; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/c64.exe"; http_uri; nocase; content:"indonesias.me:9998"; content:"Host"; http_header; classtype:trojan-activity; sid:100005102; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ebook/cs17.exe"; http_uri; nocase; content:"jcedu.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005103; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eng/wp-content/plugins/featurific-for-wordpress/1"; http_uri; nocase; content:"jointings.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005104; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eng/wp-content/plugins/featurific-for-wordpress/2"; http_uri; nocase; content:"jointings.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005105; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eng/wp-content/plugins/featurific-for-wordpress/3"; http_uri; nocase; content:"jointings.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005106; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/3/2/8/8/3288864/karma_koin_codes.exe"; http_uri; nocase; content:"karmakoincodes.weebly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005107; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dg/etrac/nf4emwz/"; http_uri; nocase; content:"kotakwarna.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100005108; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/down/affiliate/kuaizip_setup_10029.exe"; http_uri; nocase; content:"kuaizip.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005109; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/linuxforensicscode.zip"; http_uri; nocase; content:"linuxforensicsbook.com.s3.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005110; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/k/big5/1giof6/"; http_uri; nocase; content:"minpic.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100005111; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v1/ws2/:gianni1962/:ie6setup/ie6setup.exe"; http_uri; nocase; content:"my.cloudme.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005112; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/components/aacenc.exe"; http_uri; nocase; content:"nch.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100005113; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/components/doxillionsetup.exe"; http_uri; nocase; content:"nch.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100005114; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/4/1/6/6/4166984/keygen.exe"; http_uri; nocase; content:"newyarlfm.weebly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005115; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/efficiency-all-iuehb/bjug3jyhuyilwhcqs3ykssaqqw7tpyvmypb91wtzdbluio1ekope5vrbbcx8zhdar9yt/"; http_uri; nocase; content:"nhipcauytevietnhat.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005116; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/yws/api/personal/file/web3a243b322cf83ca7cae587a92916bac7?method=download&inline=true&sharekey=649ac0bb5d5b13d15cbf50b2609e193a"; http_uri; nocase; content:"note.youdao.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005117; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/spreadsheets/osv_stock_valuation-sample-dummy.exe"; http_uri; nocase; content:"oldschoolvalue.s3.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005118; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=81445407a9f44d37!197&authkey=apuz15kftzlrysa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005119; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=81445407a9f44d37!198&authkey=ags5rgb15_esaqq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005120; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=b4c15a27928f663b!229&authkey=aiarm61fwmd_npe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005121; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=b4c15a27928f663b!230&authkey=ancu1eabetiubzg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005122; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=b4c15a27928f663b!231&authkey=ai9h3sk_luxran0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005123; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=!aase4ma0-vo_cls&cid=4df11eda676a355f&resid=4df11eda676a355f!140"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005124; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=!akd6uxvljtlvpxu&cid=4df11eda676a355f&resid=4df11eda676a355f!130"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005125; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005126; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=adf5p_kn8rjf29y&cid=34224e3e49966a27&resid=34224e3e49966a27%211732"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005127; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=013413cfbbbcfae4&resid=13413cfbbbcfae4%211656&authkey=ai9wpcp_k9okgk4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005128; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c!111&authkey=aemrwamaaaiyyjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005129; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c%21111&authkey=aemrwamaaaiyyjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005130; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0175cdbe2d2944c5&resid=175cdbe2d2944c5%21107&authkey=al6uptubjmmugo0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005131; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!157&authkey=aagcsm7chqez6uu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005132; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!158&authkey=amsoii5nr6pomhc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005133; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21157&authkey=aagcsm7chqez6uu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005134; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21158&authkey=amsoii5nr6pomhc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005135; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=023f39d21b700310&resid=23f39d21b700310%211204&authkey=an2utsuaopn0fhc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005136; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211177&authkey=am0i98nwgvzgqvq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005137; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211183&authkey=anv33trmzmi5cko"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005138; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005139; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=03286724f74117f9&resid=3286724f74117f9!1179&authkey=acr-_rvrgp39kk4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005140; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=03286724f74117f9&resid=3286724f74117f9%211179&authkey=acr-_rvrgp39kk4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005141; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=032ce380af7ab389&resid=32ce380af7ab389!210&authkey=akcynbtc0h3ui7e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005142; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=032ce380af7ab389&resid=32ce380af7ab389%21210&authkey=akcynbtc0h3ui7e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005143; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005144; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005145; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005146; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005147; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005148; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!273&authkey=ae2m69e5nu3rrea"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005149; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21273&authkey=ae2m69e5nu3rrea"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005150; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21274&authkey=acqg0akutoxdpgo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005151; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0e26b39babdbf63c&resid=e26b39babdbf63c%21137&authkey=anshbgxg1_qa2h4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005152; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242!309&authkey=alfe36drai1zmwc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005153; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242%21309&authkey=alfe36drai1zmwc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005154; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21123&authkey=aco5hiwppfq8vrw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005155; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21124&authkey=ai6sfa2z-kqf6x0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005156; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=115bffdddaa40942&resid=115bffdddaa40942!540&authkey=aamhnqgfdtdsoxk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005157; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=115bffdddaa40942&resid=115bffdddaa40942%21540&authkey=aamhnqgfdtdsoxk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005158; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005159; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=13b301f1cb48f8cd&resid=13b301f1cb48f8cd%21106&authkey=aiae3olcs4lulz4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005160; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005161; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7%21118&authkey=antash3ig98aqte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005162; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e!348&authkey=ahnjoxa4ufoxa54"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005163; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e%21348&authkey=ahnjoxa4ufoxa54"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005164; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!126&authkey=ad4yflrisq6d82g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005165; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!129&authkey=apqoonsrce0ari4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005166; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21126&authkey=ad4yflrisq6d82g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005167; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21129&authkey=apqoonsrce0ari4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005168; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=196e83840ef8c152&resid=196e83840ef8c152%21107&authkey=ah2lhjyd0ukjcve"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005169; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1a162e8fcaaef5fa&resid=1a162e8fcaaef5fa%215495&authkey=aic7rmj1cm3rt2w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005170; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558!8182&authkey=aautw8tvzxr5v3a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005171; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558%218182&authkey=aautw8tvzxr5v3a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005172; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1cbd82dd55d70086&resid=1cbd82dd55d70086%212526&authkey=aogaboensav3jrg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005173; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1dbdf62bc3c2b05b&resid=1dbdf62bc3c2b05b!134&authkey=ape6bhxn7c89z60"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005174; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005175; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005176; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005177; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2184cd6093fdd997&resid=2184cd6093fdd997!136&authkey=agsnq9l7ncf4p-w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005178; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2184cd6093fdd997&resid=2184cd6093fdd997!137&authkey=aawcijw8fv4m-8g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005179; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2184cd6093fdd997&resid=2184cd6093fdd997%21136&authkey=agsnq9l7ncf4p-w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005180; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2184cd6093fdd997&resid=2184cd6093fdd997%21137&authkey=aawcijw8fv4m-8g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005181; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!123&authkey=am1rcmkppbht8v0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005182; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!124&authkey=am5sltharf-j_cc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005183; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!125&authkey=acgvgbbuowodg4c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005184; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21122&authkey=aa2f8su-5bfjlvs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005185; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005186; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0&c=3ii9gcd&r=7azia71ojgc8rxd0dmkukm&k=7s1&s=htgxfkpr86ttvokhkcn3enmimk12ewqfiglklz23spd"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005187; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21124&authkey=am5sltharf-j_cc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005188; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21125&authkey=acgvgbbuowodg4c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005189; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21154&authkey=alkjikpdfxvm8po"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005190; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21155&authkey=afu-yax_gxxddoe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005191; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21156&authkey=alqvv8nixrvsqrk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005192; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f!191&authkey=ajvumpkzpla_nca"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005193; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f%21191&authkey=ajvumpkzpla_nca"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005194; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=26bbd7d5ad88dd29&resid=26bbd7d5ad88dd29%21115&authkey=acipfa3gbiqqcvu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005195; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=26f87316a7e32bb5&resid=26f87316a7e32bb5%21106&authkey=aepqo5hlkxn1t1k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005196; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2831401bbac0235e&resid=2831401bbac0235e%211037&authkey=aagnkp6l76yhrlo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005197; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!182&authkey=apogh8yf-fj8xvk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005198; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!183&authkey=am4thhgmi0nlxei"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005199; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!185&authkey=akttgkvu39ugyte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005200; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21182&authkey=apogh8yf-fj8xvk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005201; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21183&authkey=am4thhgmi0nlxei"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005202; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21185&authkey=akttgkvu39ugyte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005203; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2894380eb084b79e&resid=2894380eb084b79e%21253&authkey=aimqerwvuylzjga"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005204; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2992e4d36c2a7dae&resid=2992e4d36c2a7dae%21132&authkey=af05vsjkocy8lly"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005205; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2b6e98d9e0cf1a17&resid=2b6e98d9e0cf1a17!2471&authkey=ai5r4hqy9i0g1qs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005206; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2b6e98d9e0cf1a17&resid=2b6e98d9e0cf1a17%212471&authkey=ai5r4hqy9i0g1qs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005207; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c1abc526306a6e1&resid=2c1abc526306a6e1%21106&authkey=adjthwhvjkbioc0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005208; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21109&authkey=aopcxq3owfiv620"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005209; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21114&authkey=ajzoj0ujggsnxlo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005210; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21115&authkey=aglznnsx71tbe9e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005211; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37!183&authkey=akon9i9zzhusiuk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005212; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37%21183&authkey=akon9i9zzhusiuk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005213; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f01a497b687285e&resid=2f01a497b687285e!734&authkey=aiumuxtp3phppy4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005214; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f01a497b687285e&resid=2f01a497b687285e%21734&authkey=aiumuxtp3phppy4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005215; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!116&authkey=!abwledjhfsqwap4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005216; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!121&authkey=!aa0qbuuss-wb13w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005217; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1!119&authkey=apmakx2cqb9rimu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005218; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21118&authkey=acrl2iiem-zjer8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005219; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21119&authkey=apmakx2cqb9rimu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005220; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2ffaa48ef4bec51a&resid=2ffaa48ef4bec51a%21107&authkey=aiohrvrc3uuo_cw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005221; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=30e33fc2c147c72f&resid=30e33fc2c147c72f!2742&authkey=ajviks-nvgb4gqs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005222; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=30e33fc2c147c72f&resid=30e33fc2c147c72f!2743&authkey=ao4um908kkhavqg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005223; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=30e33fc2c147c72f&resid=30e33fc2c147c72f%212742&authkey=ajviks-nvgb4gqs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005224; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=30e33fc2c147c72f&resid=30e33fc2c147c72f%212743&authkey=ao4um908kkhavqg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005225; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!320&authkey=aooujzuf408dclw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005226; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!321&authkey=almpxnbtsbzauna"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005227; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21320&authkey=aooujzuf408dclw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005228; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21321&authkey=almpxnbtsbzauna"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005229; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3164ddeba70d2263&resid=3164ddeba70d2263%21106&authkey=afkvqrm4zoor8qq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005230; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=31771958ea3373a1&resid=31771958ea3373a1%21108&authkey=aiofxduo9rdb_-o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005231; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=34207675f7506d94&resid=34207675f7506d94%21137&authkey=angxnhqpe2x5koc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005232; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005233; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005234; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005235; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c!139&authkey=ap4bbakgkikau-a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005236; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c%21139&authkey=ap4bbakgkikau-a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005237; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!198&authkey=acyz0gbpl6bp9mo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005238; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!199&authkey=admaszabh84m8ou"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005239; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e%21198&authkey=acyz0gbpl6bp9mo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005240; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e%21199&authkey=admaszabh84m8ou"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005241; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!152&authkey=am09sv26njxzyn0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005242; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!153&authkey=ajs0jkoeqkqjrze"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005243; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21152&authkey=am09sv26njxzyn0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005244; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21153&authkey=ajs0jkoeqkqjrze"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005245; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3a1715e2cb964f25&resid=3a1715e2cb964f25%213713&authkey=aortxmfnibnoqkk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005246; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237!963&authkey=aewqwrtr9szefem"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005247; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237!965&authkey=aaayllvoxl-rbdi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005248; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237!966&authkey=apsg26pur_hpk6k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005249; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237!971&authkey=amfm0a4mjjup0o8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005250; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237!973&authkey=acfwvefa0v7myb4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005251; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237!975&authkey=ajreyx8ik2l5uxm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005252; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237!976&authkey=alpmp7w4cfupsvu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005253; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237!977&authkey=adju1b_cnsxdxni"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005254; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21965&authkey=aaayllvoxl-rbdi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005255; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21966&authkey=apsg26pur_hpk6k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005256; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21971&authkey=amfm0a4mjjup0o8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005257; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21975&authkey=ajreyx8ik2l5uxm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005258; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21976&authkey=alpmp7w4cfupsvu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005259; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21977&authkey=adju1b_cnsxdxni"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005260; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21978&authkey=agg7tntwzgctq7s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005261; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21432&authkey=aa_npsupyqb2kge"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005262; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21435&authkey=admsjhgpkbtcqzs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005263; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005264; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f%21154&authkey=aasj15d0g_p2pog"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005265; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f!134&authkey=aaipzy8nllirlky"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005266; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f%21134&authkey=aaipzy8nllirlky"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005267; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=40cbf21d67b770f7&resid=40cbf21d67b770f7%21140&authkey=ah0uewz9k7-lzd0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005268; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2!106&authkey=aoigmqhuw6vqijm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005269; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2%21106&authkey=aoigmqhuw6vqijm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005270; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21108&authkey=akr9cesktucbqik"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005271; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21109&authkey=adzxmpjk-etbkjq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005272; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=45f0213456d899c0&resid=45f0213456d899c0%211133&authkey=alwgkm79xod8hpy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005273; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa!450&authkey=ahw0j-cme0jg6pw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005274; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa%21450&authkey=ahw0j-cme0jg6pw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005275; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=489dd700ea74963a&resid=489dd700ea74963a%21206&authkey=acgkmxuk000jse8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005276; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=489dd700ea74963a&resid=489dd700ea74963a%21210&authkey=aotjil_l-s-xh1c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005277; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ada4e22fff3e13&resid=48ada4e22fff3e13%21421&authkey=acd1sidm8c5fk0y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005278; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13805&authkey=ae-zbfo2uwln_gg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005279; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13806&authkey=aakiq-ymrjjodns"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005280; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113805&authkey=ae-zbfo2uwln_gg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005281; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113806&authkey=aakiq-ymrjjodns"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005282; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4ab7eafa48707b54&resid=4ab7eafa48707b54%21105&authkey=amb4gnkdn8igw8y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005283; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4b676ea3ff139b93&resid=4b676ea3ff139b93!133&authkey=amfix63glytflgo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005284; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21127&authkey=ablg20r-aat_ob4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005285; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21131&authkey=akbwlkrrtso_bqm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005286; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4df11eda676a355f&resid=4df11eda676a355f!130&authkey=!akd6uxvljtlvpxu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005287; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b!108&authkey=anbjpqxg-iwr4g8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005288; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b%21108&authkey=anbjpqxg-iwr4g8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005289; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005290; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005291; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21105&authkey=ajkwu0e9dzantl8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005292; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21107&authkey=apd9um4_12-kpe0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005293; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21116&authkey=anbj_rrcgyturjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005294; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21119&authkey=amrs3-3hsvcmtfs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005295; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21158&authkey=aodderdrnvhruts"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005296; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21161&authkey=agdsfxdnre82jjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005297; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21192&authkey=agn2xvrvup-xvtg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005298; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21206&authkey=ai1r52mhtbdnm2y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005299; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21247&authkey=ae6weny1fa4pday"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005300; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21252&authkey=aphl0oi4r6lrty0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005301; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21257&authkey=afnyvqwcghnyoas"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005302; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21265&authkey=abxqdhlwiurjvve"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005303; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21271&authkey=ae5qwlr5ceeptmy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005304; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21272&authkey=ahrqeoaynibwt14"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005305; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21275&authkey=af_sgsaxsmaxg7i"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005306; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21289&authkey=angyngbqixtrjaa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005307; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005308; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005309; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21306&authkey=ahpivoukyerzcjy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005310; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21314&authkey=aex2uv2-eiofr8q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005311; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21332&authkey=ad0jmjxgbaebvbm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005312; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21335&authkey=ah0vupcfbdfa6g4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005313; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21357&authkey=ap8sswuqjjjexho"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005314; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21366&authkey=aoblpmbmx7o_v18"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005315; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21379&authkey=air-bsjj46et47q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005316; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21389&authkey=aduenohuq_rbyhm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005317; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21391&authkey=aa15sw51njbn_na"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005318; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21392&authkey=abp0heeg6ybn0lk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005319; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21393&authkey=aa1pmur8sy8xtwe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005320; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212718&authkey=aie0v1d-cusuabi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005321; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212725&authkey=aanrz9et3bym3lc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005322; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212728&authkey=ahsmbkltfrwgqjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005323; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!395&authkey=alwvub_yhtogjxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005324; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!398&authkey=abaa_tjd7ohh4so"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005325; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!406&authkey=aarnp48wumgu6tq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005326; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!415&authkey=aglzsd6-g0nzj7s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005327; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!420&authkey=akk5droung_ecww"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005328; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!440&authkey=ai7-dpr11wnzyq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005329; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21395&authkey=alwvub_yhtogjxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005330; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21398&authkey=abaa_tjd7ohh4so"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005331; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21406&authkey=aarnp48wumgu6tq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005332; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21415&authkey=aglzsd6-g0nzj7s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005333; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21420&authkey=akk5droung_ecww"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005334; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21440&authkey=ai7-dpr11wnzyq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005335; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211121&authkey=al_fmezwfay4za4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005336; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211122&authkey=anz_q5njlanv2mu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005337; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21110&authkey=akars6koxqzdwgi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005338; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21112&authkey=aadare1gec7nzy8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005339; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005340; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8&em=2"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005341; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d%21109&authkey=adriswrtwdpbuc8&em=2"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005342; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53c5e6b8f6893887&resid=53c5e6b8f6893887!802&authkey=aapuufivkn2zwu8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005343; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!106&authkey=anzlf1ksptbqok8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005344; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!107&authkey=ag4dr58jrjuxfyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005345; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21106&authkey=anzlf1ksptbqok8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005346; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21107&authkey=ag4dr58jrjuxfyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005347; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005348; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005349; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5521b68dc17baf21&resid=5521b68dc17baf21%21129&authkey=ajdr2dbh-9h63wa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005350; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005351; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613!157&authkey=an55tjzt-9vbjfy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005352; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613%21156&authkey=agiuawekkbxb_4o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005353; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=55c9feaf3907aae5&resid=55c9feaf3907aae5%21208&authkey=adwuyrapfdzkyoa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005354; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950!280&authkey=advq4p3xhfhinq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005355; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950%21280&authkey=advq4p3xhfhinq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005356; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5629da828892367d&resid=5629da828892367d!803&authkey=aphjbq-bsg7ohpc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005357; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21383&authkey=adldpuaya7kj1dk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005358; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21384&authkey=alsuxvtsof32vea"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005359; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3599&authkey=am4yicme6lrjpki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005360; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3604&authkey=al6pb71mtq4jr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005361; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213599&authkey=am4yicme6lrjpki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005362; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213604&authkey=al6pb71mtq4jr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005363; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b!68197&authkey=aowpm7ocl_21-oc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005364; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b%2168197&authkey=aowpm7ocl_21-oc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005365; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=59389d626d829e8c&resid=59389d626d829e8c%212940&authkey=anx1ngd27vqeiwo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005366; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211568&authkey=aemrnwoi75oflva"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005367; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211572&authkey=aelz-gxlrxcwtnc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005368; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211573&authkey=ahksfdvda0doles"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005369; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005370; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005371; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!407&authkey=adnh8af-rvoxlcc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005372; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21406&authkey=aeyeq5j9zfepgai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005373; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21407&authkey=adnh8af-rvoxlcc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005374; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21892&authkey=apwphufzjdtsedw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005375; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005376; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21121&authkey=adjzlorvgx_ezhq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005377; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21123&authkey=ancfnepawtbmnug"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005378; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21124&authkey=ao7bknnuodxtfua"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005379; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21126&authkey=an6sswp8an1kfoe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005380; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6196314c52185efc&resid=6196314c52185efc%21106&authkey=ape4rx1hrtmrxxe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005381; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!490&authkey=aljraz5ktivqax4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005382; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!491&authkey=aopwdha2wyjx0aa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005383; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!492&authkey=akwg8p5adkpjm5w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005384; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!493&authkey=aeg__7wcf7esydo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005385; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21490&authkey=aljraz5ktivqax4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005386; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21491&authkey=aopwdha2wyjx0aa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005387; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21492&authkey=akwg8p5adkpjm5w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005388; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21493&authkey=aeg__7wcf7esydo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005389; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005390; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005391; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1094&authkey=anqjzd7pr18fu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005392; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211094&authkey=anqjzd7pr18fu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005393; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21129&authkey=ak5szbnikeklmzk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005394; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21132&authkey=ad3ia_1wkq0lyd4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005395; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6608a4dea9ff5918&resid=6608a4dea9ff5918%21399&authkey=aoya7flv_s9toxo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005396; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2%21505&authkey=ag7xi3lcnvi_hji"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005397; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad!1421&authkey=adixg2-asekemjw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005398; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad%211421&authkey=adixg2-asekemjw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005399; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213096&authkey=aob-cm9vv6erxqg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005400; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213097&authkey=abcuevfyu6pdw70"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005401; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=69b503a3f081a183&resid=69b503a3f081a183%21111&authkey=aazm9wlg1rvgzoc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005402; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!112&authkey=aasndgbcwol3mys"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005403; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!113&authkey=ak3tzu1lg4uuh5m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005404; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21112&authkey=aasndgbcwol3mys"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005405; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21113&authkey=ak3tzu1lg4uuh5m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005406; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21108&authkey=ameouv2jdxo5obw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005407; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21119&authkey=aazzzrl7mv2xbwq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005408; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a7b40a2bc530c6c&resid=6a7b40a2bc530c6c%21112&authkey=afuov36rbymlvxm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005409; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3!118&authkey=aepf8f3mfmlsng0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005410; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3%21118&authkey=aepf8f3mfmlsng0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005411; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b61e983f930f79f&resid=6b61e983f930f79f!540&authkey=ap2n5w41ifew0i8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005412; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7!1154&authkey=acnbdscb8-rbmcu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005413; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7%211154&authkey=acnbdscb8-rbmcu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005414; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21106&authkey=apvhok6edhtogfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005415; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21115&authkey=amc_k1nnlywdc4i"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005416; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=724b5c509337556e&resid=724b5c509337556e%21908&authkey=agcbb3nakpteyam"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005417; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7285f51e65036769&resid=7285f51e65036769%21264&authkey=akyjvrz006qlble"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005418; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21243&authkey=apivjmxivosek60"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005419; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21256&authkey=adljht0ogfq775k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005420; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21260&authkey=aig6cydr4_e-qj8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005421; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21262&authkey=ak4fiz1-a1ks8rg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005422; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21264&authkey=aizkjymvlgqwpte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005423; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=77518d098ad4dfb0&resid=77518d098ad4dfb0%21939&authkey=akzqobxxxn89z34"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005424; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005425; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005426; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21117&authkey=aivf1ddcvvu22em"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005427; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21210&authkey=agpl0pgvft8faaa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005428; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21211&authkey=anxavz-oaf9pv_c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005429; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005430; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005431; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005432; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21120&authkey=ajj7ueqjvobgfum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005433; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c1fc7da38ab958e&resid=7c1fc7da38ab958e!146&authkey=aktmjqz8n4s_sbm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005434; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125575&authkey=ahnmpmvzshrwoyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005435; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125579&authkey=amhnrbwecb4hp_k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005436; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5295&authkey=aasceqj1mdodeuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005437; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5296&authkey=ank3vz5syaf6bny"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005438; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5298&authkey=albzyizuqczfv9s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005439; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215295&authkey=aasceqj1mdodeuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005440; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215296&authkey=ank3vz5syaf6bny"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005441; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215298&authkey=albzyizuqczfv9s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005442; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7d109f249b512466&resid=7d109f249b512466!543&authkey=acqc4xjghclmwbs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005443; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b!183&authkey=aggjy50pjuecoli"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005444; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21181&authkey=ama3betib0dac18"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005445; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21183&authkey=aggjy50pjuecoli"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005446; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!443&authkey=abue79u9di9axjm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005447; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!444&authkey=abzxvycu0ggtmg8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005448; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0%21443&authkey=abue79u9di9axjm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005449; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0%21444&authkey=abzxvycu0ggtmg8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005450; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7e81645429ac5a22&resid=7e81645429ac5a22%21105&authkey=aa691jwf5wqi80c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005451; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7fed4fbea32e3c1e&resid=7fed4fbea32e3c1e%21107&authkey=aeoxfycpolifch0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005452; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=806bac90dc071edf&resid=806bac90dc071edf!105&authkey=!ao7jyz6-licb8hq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005453; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=81c2d8b116274e17&resid=81c2d8b116274e17%21107&authkey=aaqw-t4dx2sbvda"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005454; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=82977114b1af209d&resid=82977114b1af209d!220&authkey=abuin5vdedjughm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005455; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=860a0980486c93fa&resid=860a0980486c93fa!303&authkey=!agcmlab4r6syfvk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005456; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21164&authkey=agbeiinncf8ok_4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005457; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21165&authkey=aiof8rdvxglnm-c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005458; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4!2402&authkey=amigiam45mt6jia"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005459; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4%212402&authkey=amigiam45mt6jia"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005460; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=890837b4e4ca07c6&resid=890837b4e4ca07c6%21289&authkey=abujc0akmtbsxf4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005461; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8983011c6ecfb1d8&resid=8983011c6ecfb1d8%21132&authkey=ah0vja7wpyfjj84"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005462; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8a1574ed0cecd68a&resid=8a1574ed0cecd68a%21395&authkey=ane01evt0sz-1wk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005463; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8c77cee60e33a6b1&resid=8c77cee60e33a6b1%21106&authkey=af8h8jn801bjnbk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005464; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8ca507baa15fdb5c&resid=8ca507baa15fdb5c!213&authkey=acyrjlhflcrypae"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005465; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8ffd8cbd6540c065&resid=8ffd8cbd6540c065!822&authkey=acfj7bbrmktj1i0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005466; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!243&authkey=aeiqd4ihuqopwm8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005467; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21276&authkey=afig5wsljtdc33s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005468; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005469; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25!130&authkey=ais_g9dqoddonsc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005470; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005471; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21109&authkey=akr1n3qxtmnttuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005472; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21113&authkey=ajpvf1h89sqstti"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005473; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!289&authkey=aoiy68zx8ddnjhe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005474; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!290&authkey=afn1bhvmpaicari"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005475; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!291&authkey=aknqfhnxttsrvz4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005476; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!297&authkey=agy0f-5almc6_ia"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005477; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!298&authkey=ajiut2kebcaycok"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005478; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21288&authkey=ag9wi9pub-q4jly"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005479; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21289&authkey=aoiy68zx8ddnjhe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005480; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21290&authkey=afn1bhvmpaicari"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005481; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21291&authkey=aknqfhnxttsrvz4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005482; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21295&authkey=afvy6r0mspzeb6m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005483; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21297&authkey=agy0f-5almc6_ia"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005484; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21298&authkey=ajiut2kebcaycok"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005485; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21299&authkey=agmfs3scdvngolm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005486; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21105&authkey=ah9x7rn0p03kd_m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005487; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21110&authkey=ammswulpdsjeu4w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005488; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3!107&authkey=ac-m9dlvo5l7wfk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005489; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3%21107&authkey=ac-m9dlvo5l7wfk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005490; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=96a54b19ff5f6bab&resid=96a54b19ff5f6bab%21107&authkey=anxv07ez7s5sh_k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005491; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21410&authkey=acwug6bewxk0pli"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005492; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21411&authkey=aj8o1fcvfhibmlm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005493; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=96fd249b957988a2&resid=96fd249b957988a2%211303&authkey=ah_etf1fqofknue"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005494; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935!778&authkey=aaezyk4ypt-elma"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005495; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21772&authkey=akeozmv0aafqlbg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005496; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21774&authkey=aly_m3fnrvh6dfq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005497; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21775&authkey=abblpjxi4mwomgs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005498; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21777&authkey=ahmuwqi4jg8rvho"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005499; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=98103c88c2d68867&resid=98103c88c2d68867!773&authkey=akptbml43mi4ufc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005500; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211925&authkey=amhhfhcsigeue9w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005501; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211927&authkey=an_3paqpemptbvm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005502; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211953&authkey=abdfqiyruwplpo0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005503; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211954&authkey=aok-srkhxjazccy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005504; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21172&authkey=ahharhcv0fmn5fm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005505; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21173&authkey=aecb3qcquacvzhi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005506; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21174&authkey=afv7cprqwxezgsi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005507; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005508; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005509; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005510; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9fb622acb27482ef&resid=9fb622acb27482ef%211197&authkey=aeacibxy2zlyxro"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005511; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005512; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005513; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005514; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340!997&authkey=akw6btyej2zht08"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005515; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340%21997&authkey=akw6btyej2zht08"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005516; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a1c8c8055848b889&resid=a1c8c8055848b889!111&authkey=agzlftsgr4lspvo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005517; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a2cd2cdb93584d7e&resid=a2cd2cdb93584d7e%21106&authkey=aeifpqbwo1s3dyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005518; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211064&authkey=apebndb6tstxywi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005519; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211065&authkey=aca4_dggi5gbbfs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005520; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211067&authkey=ae-3ej9zzj4ibhw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005521; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211069&authkey=agx6b8qjt_clm-o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005522; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4acaf66051e469e&resid=a4acaf66051e469e!189&authkey=alnhzcg0wzhusdc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005523; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a502994ea313f5c7&resid=a502994ea313f5c7%21215&authkey=aiydvejv0l8stbs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005524; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21!6053&authkey=agfh0ahstj7rrki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005525; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21%216053&authkey=agfh0ahstj7rrki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005526; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005527; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a76c2c9b2bbef5ec&resid=a76c2c9b2bbef5ec%21141&authkey=akcfuxzfafd_c9c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005528; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21414&authkey=akf9uwwkitvhrvc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005529; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21415&authkey=ag_5kthuezprnoy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005530; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21416&authkey=airlma-pycgfkyc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005531; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21419&authkey=ab1-sgyv2gibyey"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005532; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21422&authkey=acphsmdy415izjg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005533; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21424&authkey=afvfwz5uvde1pui"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005534; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a819c72315838312&resid=a819c72315838312%21112&authkey=abl1vflnfw3nrgi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005535; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=aa4e252db942faec&resid=aa4e252db942faec%21168&authkey=anlnjo7xnwtswuk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005536; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ae28961c75435487&resid=ae28961c75435487%21106&authkey=alph5awcis8r9iw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005537; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992!113&authkey=agh9q_zzyjjcspc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005538; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992%21113&authkey=agh9q_zzyjjcspc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005539; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=af84ebf13dd5499c&resid=af84ebf13dd5499c!167&authkey=anqr_yvn_hdh2_e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005540; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308!2152&authkey=abutaac83l5utks"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005541; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308%212152&authkey=abutaac83l5utks"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005542; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b0fddd36b3843d3b&resid=b0fddd36b3843d3b!561&authkey=abhena0pdghcveu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005543; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b0fddd36b3843d3b&resid=b0fddd36b3843d3b%21561&authkey=abhena0pdghcveu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005544; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21650&authkey=aht-wbxsofyx33u"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005545; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21651&authkey=aebbyk6sevdmzgm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005546; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21652&authkey=afsw5wahxo5kwjy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005547; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1c3a5ef115e135c&resid=b1c3a5ef115e135c%216219&authkey=ahr7bklirbub0pc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005548; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b2289382b9cf7ba8&resid=b2289382b9cf7ba8%21106&authkey=ajwobaztcbbpxmy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005549; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21120&authkey=aozmspl2dqkgkgy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005550; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21123&authkey=aj18p0rtfbtwa84"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005551; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21139&authkey=ahwfjvw4zmjukeo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005552; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21140&authkey=aksvfpmrfqrrggw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005553; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21141&authkey=acznh6clby0qyww"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005554; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21142&authkey=ajf7j1rr3d7jcxy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005555; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21143&authkey=ahs21wnsqb_vu9w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005556; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b50c4248502103d0&resid=b50c4248502103d0%21107&authkey=alf1nley7ja4dbq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005557; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6!164&authkey=adfsfcdaw3biboy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005558; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6%21164&authkey=adfsfcdaw3biboy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005559; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b7cb31db66675eb4&resid=b7cb31db66675eb4%21922&authkey=aghayyucvwey7lg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005560; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b86046e8cbd4254b&resid=b86046e8cbd4254b%21115&authkey=agwstptwpaquleg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005561; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b!7521&authkey=ablt9zdyq2d4rb0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005562; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b%217521&authkey=ablt9zdyq2d4rb0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005563; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b90c1aa3b6cd0326&resid=b90c1aa3b6cd0326%21471&authkey=aoil8ra4oc4s_2m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005564; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b9690a1860a591d0&resid=b9690a1860a591d0%21161&authkey=aehawjpwf6tqtm8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005565; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b!246&authkey=afyrchdutalpu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005566; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b%21246&authkey=afyrchdutalpu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005567; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=bf83d9247c2329e0&resid=bf83d9247c2329e0%211108&authkey=absaw-bpqrc6mpq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005568; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c121261804708478&resid=c121261804708478%214199&authkey=adgqe8qiyu92bqm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005569; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c121261804708478&resid=c121261804708478%214200&authkey=adqtju8i3nmlgai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005570; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c121261804708478&resid=c121261804708478%214201&authkey=ahqber27s7gg8kk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005571; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019!1251&authkey=act34eizpzjugfa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005572; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019%211251&authkey=act34eizpzjugfa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005573; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1337&authkey=afnvu1fsuczht5e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005574; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1338&authkey=ajngambosws75_c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005575; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1340&authkey=al1ay3fbtude6d8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005576; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1342&authkey=acpr_htn2jtaxfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005577; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1343&authkey=abodysrxu9l2xxu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005578; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1344&authkey=aozerppd6mnokwy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005579; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1345&authkey=aevvyhonxhtcdh0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005580; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1346&authkey=achrnf5vlov1gf4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005581; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1347&authkey=al-zge-ttvr921s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005582; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211337&authkey=afnvu1fsuczht5e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005583; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211338&authkey=ajngambosws75_c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005584; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211340&authkey=al1ay3fbtude6d8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005585; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211342&authkey=acpr_htn2jtaxfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005586; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211343&authkey=abodysrxu9l2xxu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005587; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211344&authkey=aozerppd6mnokwy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005588; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211345&authkey=aevvyhonxhtcdh0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005589; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211346&authkey=achrnf5vlov1gf4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005590; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211347&authkey=al-zge-ttvr921s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005591; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c701663053a57d59&resid=c701663053a57d59%211009&authkey=ahowgkak7j0p2q8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005592; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21486&authkey=amy4euf_rrlcykc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005593; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21489&authkey=ako3anwfnqfohnc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005594; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c7c32628aba70e70&resid=c7c32628aba70e70%21114&authkey=agdy8xpuh32sluw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005595; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c80630c4d385fb9d&resid=c80630c4d385fb9d%21286&authkey=amgaucv8bld_5qs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005596; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c8b0c7dc2b2570c5&resid=c8b0c7dc2b2570c5!122&authkey=aa4yfqt4cckzxhe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005597; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c8b0c7dc2b2570c5&resid=c8b0c7dc2b2570c5%21122&authkey=aa4yfqt4cckzxhe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005598; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21546&authkey=aa6q-ryiifnet5m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005599; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21547&authkey=aipm8qnwbgo4yga"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005600; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!355&authkey=aajjwf_sm4xdqdk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005601; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!357&authkey=alw3vqqxz6myrle"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005602; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21354&authkey=aa_ukeour7rex1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005603; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21355&authkey=aajjwf_sm4xdqdk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005604; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21357&authkey=alw3vqqxz6myrle"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005605; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca897bdd16fc7940&resid=ca897bdd16fc7940%21106&authkey=aniklpt8vtlahbg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005606; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2!109&authkey=ac4gxwjoopafr9a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005607; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2%21109&authkey=ac4gxwjoopafr9a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005608; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cbb66cac420484bc&resid=cbb66cac420484bc!10968&authkey=aj9bjkobu-rlnaw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005609; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!742&authkey=akbxju17f8g0r2s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005610; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!744&authkey=adak4zftd0yhhhs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005611; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21742&authkey=akbxju17f8g0r2s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005612; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21744&authkey=adak4zftd0yhhhs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005613; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!872&authkey=ap9hchztywo8zuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005614; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!874&authkey=alkzcbxz-dscgum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005615; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!875&authkey=aka55ybdhqnoc6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005616; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21872&authkey=ap9hchztywo8zuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005617; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21874&authkey=alkzcbxz-dscgum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005618; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21875&authkey=aka55ybdhqnoc6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005619; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d2f3748954f6f8a8&resid=d2f3748954f6f8a8%21119&authkey=aex5s9uoun2zps0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005620; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1029&authkey=ann3uz8huqi7ogw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005621; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1030&authkey=aeqnasuksxccax4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005622; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1031&authkey=acxtarrhbwrqt20"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005623; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1032&authkey=aemitbkn-vma9yk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005624; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1033&authkey=abiydifgst6musa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005625; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1035&authkey=ahd_ichsrf8ok_u"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005626; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1038&authkey=anxf-kuw1jn9-8y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005627; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211029&authkey=ann3uz8huqi7ogw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005628; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211030&authkey=aeqnasuksxccax4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005629; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211031&authkey=acxtarrhbwrqt20"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005630; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211032&authkey=aemitbkn-vma9yk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005631; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211035&authkey=ahd_ichsrf8ok_u"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005632; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!191&authkey=ajl2uegqunsgc3q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005633; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!192&authkey=acd_hx4bka3z0nw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005634; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21191&authkey=ajl2uegqunsgc3q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005635; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21192&authkey=acd_hx4bka3z0nw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005636; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005637; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21109&authkey=adnbm6mekgzvvh8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005638; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!141&authkey=alya4infudqs53o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005639; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!142&authkey=aiemnxi-s-5vrz0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005640; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21141&authkey=alya4infudqs53o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005641; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21142&authkey=aiemnxi-s-5vrz0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005642; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21142&authkey=aiemnxi-s-5vrz0&c=3ii9gcd&r=5onulz3wldybwlmup37su3&k=7s1&s=kzymn52eroemh1tamvmlsfsn9jtvwguukky5hlxcfgw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005643; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=db0fc77df51690e1&resid=db0fc77df51690e1%21802&authkey=apefr8w_rdk--pe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005644; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=db5548cd728f142b&resid=db5548cd728f142b%21187&authkey=aansxudby0o7uwq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005645; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=db62f747c6d887d0&resid=db62f747c6d887d0%21111&authkey=ai2guftczvfehs4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005646; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dcd65237fcd1a1a9&resid=dcd65237fcd1a1a9%21162&authkey=aprqs0hugnfo6uq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005647; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7527&authkey=aipybipwht56um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005648; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7530&authkey=am9p2ic6zdkgfmy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005649; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7532&authkey=aonjnubquvon_uk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005650; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217527&authkey=aipybipwht56um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005651; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217530&authkey=am9p2ic6zdkgfmy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005652; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217532&authkey=aonjnubquvon_uk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005653; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21107&authkey=akrabrcroiddkxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005654; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21115&authkey=ad1ncwtj_zcjsh0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005655; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21132&authkey=akpbxohbtjebyn4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005656; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21150&authkey=aevazjbqnu7cmjs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005657; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21160&authkey=aiendf-9lyln0x0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005658; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e1065ab3e86a5fc2&resid=e1065ab3e86a5fc2%211443&authkey=apybkcvf4iwxp_q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005659; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e3ddc3980f743711&resid=e3ddc3980f743711%21795&authkey=aptivsvyk2we5xc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005660; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21745&authkey=ah1i_jo73zgdxpc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005661; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21746&authkey=ag1mhwlznwdxpw0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005662; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e43694f4bd6f68d1&resid=e43694f4bd6f68d1!563&authkey=aj8ovsob9ll6r-c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005663; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!509&authkey=akmdyqkzcsuf_gg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005664; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!511&authkey=agfs0q7dz7os1lu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005665; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c%21511&authkey=agfs0q7dz7os1lu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005666; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e54ea4e0368d023b&resid=e54ea4e0368d023b%21106&authkey=aozas6g9pm0fzvq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005667; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21349&authkey=ae9ea8jdsa7vmom"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005668; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21350&authkey=ao-vuexoihzj7da"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005669; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2!142&authkey=ais88uad5aom6qu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005670; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2%21142&authkey=ais88uad5aom6qu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005671; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e86539a3497e46a2&resid=e86539a3497e46a2!120&authkey=amd6o5flalahjsy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005672; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e86539a3497e46a2&resid=e86539a3497e46a2%21120&authkey=amd6o5flalahjsy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005673; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e97110434470423e&resid=e97110434470423e%21113&authkey=afowclex54if0g0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005674; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005675; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005676; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211215&authkey=ac1jr_bieufz0ai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005677; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211219&authkey=akgo75rmvr4khlc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005678; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ebacca5dec27fd20&resid=ebacca5dec27fd20%2118735&authkey=ajfyl1mzidnylc8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005679; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21113&authkey=aovavpmokd2jrns"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005680; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21116&authkey=aadnj5xyfasugu8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005681; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ef04dd7f0a6a5f7c&resid=ef04dd7f0a6a5f7c%21142&authkey=aad-nuysvlhc-i4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005682; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!202&authkey=ah1gjq8j29darw4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005683; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!203&authkey=af8xr99mrqp8um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005684; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!204&authkey=ad0nbzlscbg-0sa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005685; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21202&authkey=ah1gjq8j29darw4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005686; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21203&authkey=af8xr99mrqp8um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005687; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21204&authkey=ad0nbzlscbg-0sa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005688; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21489&authkey=ads_gff3tjkd0w0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005689; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21490&authkey=aj_rld7xooge6aw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005690; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21492&authkey=ahdb75ptd1_uc8e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005691; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f06038a5f7dbd6d6&resid=f06038a5f7dbd6d6%215498&authkey=aiozi3z5qzdysmu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005692; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f293cebb54e5ea71&resid=f293cebb54e5ea71%21293&authkey=aha74rsqiuewnpq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005693; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21566&authkey=aevafh7rydhi19k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005694; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21581&authkey=agx0b8ho87w4uie"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005695; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21582&authkey=af-9_xwysl1o7-c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005696; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21598&authkey=ah-gkc-b7fa8h-g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005697; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21599&authkey=aajunhe1ex_-zta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005698; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!216&authkey=alslscyemd7hr_o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005699; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!223&authkey=ajbtso2laio00ao"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005700; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21216&authkey=alslscyemd7hr_o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005701; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f50a3aff00683adc&resid=f50a3aff00683adc%21108&authkey=ac44gtgp13l9xpw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005702; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f50a3aff00683adc&resid=f50a3aff00683adc%21139&authkey=aovmqh4ookdlkty"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005703; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f79e41c0e32d3314&resid=f79e41c0e32d3314%211182&authkey=aiqtptberyvlgqk&em=2%22"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005704; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806!1368&authkey=anphh1fijhvzv6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005705; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806%211368&authkey=anphh1fijhvzv6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005706; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382!159&authkey=ai4_8srrzf48hw0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005707; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382%21159&authkey=ai4_8srrzf48hw0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005708; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fb2177c192eed796&resid=fb2177c192eed796%21124&authkey=abotnmdhu_tg7bc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005709; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fd50774e5ce0e314&resid=fd50774e5ce0e314%21778&authkey=aoxb2vhhz3qodiu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005710; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fe85161c3947f2c1&resid=fe85161c3947f2c1%211441&authkey=agb6c1ecr91svrw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005711; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e!192&authkey=ab_lrrmyxmcfrjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005712; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e%21192&authkey=ab_lrrmyxmcfrjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005713; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!693&authkey=agcpkhnewfte_yc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005714; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!694&authkey=aa5jqzjsp0esr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005715; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21693&authkey=agcpkhnewfte_yc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005716; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21694&authkey=aa5jqzjsp0esr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005717; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!330&authkey=adxnzkb0a09pizw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005718; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!334&authkey=agsvox_t7qim4ta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005719; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!335&authkey=ach14e6omcghwgg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005720; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21330&authkey=adxnzkb0a09pizw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005721; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21333&authkey=aielwtaiuvcttlm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005722; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005723; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/raw/yqvsvlvq"; http_uri; nocase; content:"pastebin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005724; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/llc/mwcacs65xienqdp/"; http_uri; nocase; content:"pierreconsulting.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100005725; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/bayesian-forecasting-amj5e/s5hqmf6/"; http_uri; nocase; content:"pioneiraagronegocio.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100005726; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/2020/10/skoda22.jpg"; http_uri; nocase; content:"procrossover.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100005727; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/2020/10/skodaqq.jpg"; http_uri; nocase; content:"procrossover.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100005728; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/zzcoiatsr5wujrwagsgbnm2wkjxldvgu/"; http_uri; nocase; content:"qjbutterflyevents.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100005729; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/order+acknowledgement+bc202374++stock++20021+dem+p4.ace"; http_uri; nocase; content:"quen.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005730; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/purchasing+ordersigned+contractinv-30067121.ace"; http_uri; nocase; content:"quen.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005731; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/arntsonl/calc_security_poc/master/dll/calc.dll"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005732; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/bero1985/berotinypascal/e34bd4164f4b7c27e7cf667dffd9274d33d6dfbe/bin/btpc.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005733; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/evil-coder66/defendercontrol/main/defendercontrol.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005734; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/fuzzbunch/fuzzbunch/master/payloads/doublepulsar-1.3.1.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005735; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005736; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/malwares/webshell/master/ajax_php%20command%20shell.rar"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005737; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/myqseeaccount/one/main/one.htm"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005738; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/realtek25556/rhti2/gh-pages/90hfnvo69vk2ot.bmp"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005739; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/secwiki/windows-kernel-exploits/master/ms15-076/binary/trebuchet.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005740; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/secwiki/windows-kernel-exploits/master/ms16-098/bfill.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005741; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tennc/webshell/master/other/small_shell.txt"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005742; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player/launch/2017/09/12/da5f9a1c23034353852750488feeaf36.exe"; http_uri; nocase; content:"res.yeshen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005743; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pro/dl/q05z91"; http_uri; nocase; content:"sendspace.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005744; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ey4lpx8rx.zip"; http_uri; nocase; content:"shribharatvatika.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005745; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/site/stormqk/dn/stormagent.apk?attredirects=0"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005746; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6ca94027662tilxa4p/base.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005747; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005748; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6cd19c87f44r9fomit/base64jef.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005749; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6e2cbda22efxk3t7x2/base64.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005750; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6e2f6c8c5adup2yiwx/basejefin.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005751; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6eab37b8dadmy1gx7c/base3.5.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005752; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6eb2aa215a8cvwcf6s/fudjs.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005753; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aamus8/go.jpeg"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005754; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c7921a2cf26cunjcgvm/nanocoregomes.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005755; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005756; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/a-nurse-ss8d9/z/"; http_uri; nocase; content:"technologydistilled.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005757; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/databases/merit.php"; http_uri; nocase; content:"truemerit.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100005758; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/23.exe"; http_uri; nocase; content:"tsrv4.ws"; content:"Host"; http_header; classtype:trojan-activity; sid:100005759; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/crisanar/defis/jek_crackme1.7.zip"; http_uri; nocase; content:"users.skynet.be"; content:"Host"; http_header; classtype:trojan-activity; sid:100005760; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/gnuboard/data/scan/amowvegfrt9ja/"; http_uri; nocase; content:"vniel.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100005761; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/gnuboard/data/scan/fu6jvxzzs46uqlp7l/"; http_uri; nocase; content:"vniel.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100005762; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/kolya/.f/root/net.mit.edu/net/user/chris/winnt/mit_agenda2a.doc"; http_uri; nocase; content:"web.mit.edu"; content:"Host"; http_header; classtype:trojan-activity; sid:100005763; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/kolya/.f/root/net.mit.edu/sipb/user/kolya/afs/root.afs/net/user/chris/winnt/mit_agenda2a.doc"; http_uri; nocase; content:"web.mit.edu"; content:"Host"; http_header; classtype:trojan-activity; sid:100005764; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/136_140/flt_shovemydiscoupyourarse.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100005765; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/136_140/kb%5efr_ouverture.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100005766; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/136_140/kb^fr_ouverture.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100005767; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/146_150/bc_memories_from_the_mcp.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100005768; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/151_155/tidex_-_short_stuff.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100005769; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/syria-files/attach/222/222051_instruction.zip"; http_uri; nocase; content:"wikileaks.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005770; rev:1;)
-alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/common/yz.vbs"; http_uri; nocase; content:"yp.hnggzyjy.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100005771; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.225.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100000185; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.233.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000186; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.235.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000187; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.249.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000188; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110.35.4.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000189; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"110fss.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100000190; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.118.111.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000191; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.118.41.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000192; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.118.88.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100000193; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.119.245.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000194; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.125.67.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100000195; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.160.112.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000196; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.162.224.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000197; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.163.50.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000198; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.165.21.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000199; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.165.28.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100000200; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.17.186.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000201; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.170.84.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000202; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.170.86.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000203; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.172.164.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100000204; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.176.182.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000205; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.179.153.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000206; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.179.243.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100000207; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.182.232.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000208; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.177.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000209; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.23.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000210; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.230.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000211; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.27.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000212; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.185.48.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100000213; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.103.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000214; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.103.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000215; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.103.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100000216; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.103.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100000217; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.104.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000218; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.104.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000219; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.106.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000220; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.106.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000221; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.106.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100000222; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.121.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000223; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.121.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100000224; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.121.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000225; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.123.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000226; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.123.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000227; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.123.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100000228; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.123.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000229; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.123.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000230; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.26.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000231; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.26.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000232; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.38.8.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100000233; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.61.52.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000234; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.73.99.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000235; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.91.185.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100000236; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.92.63.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100000237; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"111.93.169.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000238; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.105.117.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000239; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.111.100.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100000240; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.111.108.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000241; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.111.31.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000242; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.122.36.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000243; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.123.200.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100000244; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.132.134.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100000245; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.159.108.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000246; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.170.124.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000247; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.170.233.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000248; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.186.210.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100000249; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.186.96.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100000250; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.187.91.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100000251; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.214.127.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000252; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.187.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000253; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.236.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000254; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.43.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000255; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.52.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100000256; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.225.82.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100000257; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.118.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000258; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.176.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100000259; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.195.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100000260; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.202.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100000261; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.205.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000262; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.47.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000263; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.67.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000264; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.226.92.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100000265; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.228.100.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100000266; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.228.180.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000267; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.228.79.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100000268; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.228.79.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100000269; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.229.178.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000270; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.229.188.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000271; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.229.199.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000272; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.234.134.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000273; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.234.16.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100000274; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.234.194.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000275; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.234.216.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000276; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.234.218.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000277; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.235.149.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000278; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.235.188.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100000279; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.236.126.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000280; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.236.171.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000281; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.236.228.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000282; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.141.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100000283; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.144.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100000284; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.197.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000285; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.230.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100000286; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.75.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100000287; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.237.89.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100000288; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.143.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000289; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.17.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000290; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.190.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000291; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.194.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000292; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.227.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000293; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.238.73.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100000294; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.240.184.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000295; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.240.216.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000296; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.242.106.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000297; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.242.18.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000298; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.242.2.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000299; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.243.115.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100000300; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.245.12.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000301; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.245.5.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000302; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.245.8.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100000303; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.246.162.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000304; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.246.180.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100000305; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.100.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000306; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.121.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100000307; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.14.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000308; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.161.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000309; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.191.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000310; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.214.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000311; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.240.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100000312; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.248.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100000313; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.81.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000314; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.82.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000315; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.247.89.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100000316; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.248.148.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000317; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.248.197.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000318; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.248.44.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100000319; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.109.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000320; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.118.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100000321; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.206.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000322; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.26.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100000323; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.41.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000324; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.249.79.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000325; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.250.102.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000326; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.250.57.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000327; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.251.17.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000328; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.251.218.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100000329; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.251.23.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000330; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.136.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000331; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.199.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000332; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.221.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000333; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.236.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100000334; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.237.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000335; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.239.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000336; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.245.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000337; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.252.46.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000338; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.254.208.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000339; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.255.38.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000340; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.255.52.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100000341; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.255.8.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000342; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.121.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000343; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.123.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100000344; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000345; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000346; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100000347; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000348; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100000349; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100000350; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000351; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000352; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100000353; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000354; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100000355; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000356; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100000357; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000358; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000359; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000360; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000361; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100000362; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000363; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000364; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000365; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000366; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000367; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000368; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000369; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100000370; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100000371; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000372; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000373; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000374; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000375; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100000376; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100000377; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000378; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100000379; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000380; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100000381; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.124.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000382; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.126.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000383; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.127.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000384; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.80.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000385; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.80.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000386; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.80.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000387; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.82.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100000388; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.83.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000389; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.83.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000390; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.87.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100000391; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.88.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100000392; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.91.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000393; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.27.91.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000394; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000395; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100000396; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100000397; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100000398; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000399; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000400; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100000401; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100000402; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000403; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100000404; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000405; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100000406; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100000407; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000408; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000409; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100000410; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000411; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000412; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000413; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000414; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000415; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000416; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.1.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000417; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.100.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000418; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000419; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100000420; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100000421; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100000422; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000423; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000424; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100000425; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000426; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000427; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000428; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000429; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000430; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000431; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000432; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000433; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100000434; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.110.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100000435; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.35.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000436; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.38.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100000437; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.38.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100000438; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100000439; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100000440; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000441; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000442; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000443; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000444; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000445; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000446; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000447; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.30.4.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000448; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.31.211.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000449; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.53.224.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000450; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.53.227.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000451; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.53.227.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100000452; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.65.53.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000453; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.153.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000454; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.162.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100000455; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.162.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100000456; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.175.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000457; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.176.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000458; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.176.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000459; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.72.226.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000460; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.78.45.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100000461; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.80.118.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100000462; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.80.127.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000463; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.80.215.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100000464; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.81.161.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000465; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.81.199.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100000466; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.81.49.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000467; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.131.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100000468; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.141.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000469; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.146.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000470; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.148.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000471; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.18.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100000472; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.224.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100000473; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.227.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000474; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.82.228.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000475; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.86.133.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100000476; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.86.253.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000477; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.9.140.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000478; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.93.29.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100000479; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.95.22.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000480; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"112.95.23.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000481; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.103.10.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100000482; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.104.237.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000483; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.105.71.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100000484; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.116.121.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100000485; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.116.149.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100000486; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.116.150.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000487; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.116.246.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000488; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.116.48.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000489; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.118.195.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000490; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.122.238.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100000491; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.122.59.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000492; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.161.58.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100000493; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.172.250.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000494; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.179.129.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000495; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.194.133.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000496; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.194.135.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100000497; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.195.163.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000498; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.195.166.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000499; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.201.24.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000500; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.224.225.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100000501; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.226.42.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000502; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.227.128.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000503; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.227.169.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100000504; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.227.35.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000505; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.231.211.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100000506; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.231.93.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000507; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.232.141.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000508; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.232.211.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000509; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.234.224.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000510; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.235.116.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100000511; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.237.129.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100000512; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.253.144.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000513; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.254.169.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000514; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.3.153.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000515; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.3.155.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100000516; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.133.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100000517; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.59.154.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000518; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.61.204.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100000519; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.81.112.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000520; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.86.204.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100000521; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.87.175.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000522; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.87.248.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000523; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.88.100.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000524; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.88.208.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100000525; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.88.232.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000526; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.88.242.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100000527; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.88.38.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000528; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.89.245.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100000529; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.89.41.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000530; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.199.204.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000531; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.226.100.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000532; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.227.156.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100000533; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.228.205.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100000534; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.228.242.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100000535; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.229.165.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000536; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.229.52.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000537; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.235.115.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100000538; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.235.42.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100000539; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.79.161.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000540; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"114.79.172.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000541; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.165.216.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000542; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.171.239.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000543; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.193.130.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100000544; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.201.38.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000545; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.208.101.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000546; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.213.187.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000547; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.223.159.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000548; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.23.88.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000549; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.42.47.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000550; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.45.178.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100000551; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.48.130.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100000552; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.48.130.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100000553; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.48.135.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000554; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.48.141.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100000555; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.48.198.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000556; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.48.200.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000557; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.48.22.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100000558; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.48.228.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100000559; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.48.9.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100000560; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.49.100.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100000561; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.49.152.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100000562; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.49.242.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100000563; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.49.60.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100000564; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.49.80.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100000565; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.49.96.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100000566; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.1.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000567; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.158.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100000568; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.2.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000569; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.202.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100000570; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.220.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100000571; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.239.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000572; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.240.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100000573; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.61.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000574; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.64.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000575; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.50.81.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000576; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.51.104.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000577; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.51.107.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000578; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.51.123.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100000579; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.51.93.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100000580; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.52.112.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000581; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.52.17.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100000582; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.52.19.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000583; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.52.200.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100000584; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.52.201.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100000585; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.52.21.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000586; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.52.22.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000587; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.54.160.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000588; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.54.212.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000589; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.54.236.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000590; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.54.240.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000591; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.54.241.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000592; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.54.70.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000593; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.54.73.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000594; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.54.73.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000595; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.144.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000596; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.144.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000597; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.144.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000598; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.145.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000599; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.149.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100000600; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.178.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100000601; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.198.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100000602; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.211.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100000603; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.211.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100000604; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.3.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000605; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.42.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000606; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.55.53.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000607; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.134.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100000608; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.134.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100000609; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.136.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000610; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.139.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000611; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.142.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000612; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.143.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100000613; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.148.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000614; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.154.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000615; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.155.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100000616; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.156.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000617; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.156.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000618; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.162.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000619; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.177.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000620; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.188.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100000621; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.31.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000622; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.86.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000623; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.87.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100000624; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.56.98.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100000625; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.111.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000626; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.119.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100000627; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.132.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100000628; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.134.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000629; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.141.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000630; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.167.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100000631; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.20.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100000632; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.83.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100000633; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.88.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000634; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.58.93.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000635; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.197.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000636; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.198.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000637; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.198.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000638; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.210.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100000639; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.215.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100000640; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.235.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100000641; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.253.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000642; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.63.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100000643; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.59.95.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100000644; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.60.201.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100000645; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.107.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000646; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.118.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100000647; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.119.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100000648; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.119.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000649; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.119.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000650; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.125.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000651; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.180.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000652; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.182.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100000653; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.185.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100000654; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.97.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000655; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.61.97.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000656; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.62.152.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000657; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.62.26.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100000658; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.63.135.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000659; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.63.140.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100000660; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.63.4.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000661; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.63.56.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100000662; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.73.3.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100000663; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.74.217.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000664; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.75.217.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000665; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.78.133.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000666; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"115.92.174.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100000667; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.124.219.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000668; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.127.207.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100000669; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.149.119.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000670; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.2.100.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100000671; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.2.66.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100000672; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.206.164.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000673; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.211.100.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100000674; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.212.142.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000675; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.24.153.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100000676; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.72.202.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100000677; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.72.202.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100000678; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.72.203.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000679; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.74.84.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100000680; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.75.194.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000681; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.76.114.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000682; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"116.88.65.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100000683; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.11.234.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000684; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.15.201.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100000685; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.156.69.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000686; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.194.160.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100000687; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.194.161.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100000688; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.194.162.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000689; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.196.48.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100000690; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.204.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100000691; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.204.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000692; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.210.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100000693; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.220.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100000694; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.236.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100000695; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.20.243.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100000696; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.200.76.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000697; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.200.76.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000698; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.201.128.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100000699; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.202.66.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000700; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.202.68.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100000701; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.208.133.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100000702; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.222.161.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100000703; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.222.162.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000704; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.222.163.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000705; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.222.165.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100000706; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.222.170.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100000707; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.222.171.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100000708; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.222.172.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100000709; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.241.66.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000710; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.241.67.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100000711; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.242.210.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000712; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.242.211.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100000713; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.242.211.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000714; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.251.56.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100000715; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.251.59.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100000716; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.251.60.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000717; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.251.60.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000718; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.26.110.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100000719; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.26.235.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000720; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.27.10.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000721; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.63.113.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000722; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.63.195.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100000723; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.63.252.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100000724; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.63.53.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100000725; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.63.56.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100000726; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.86.105.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000727; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.87.170.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100000728; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.90.78.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100000729; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.91.240.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100000730; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.93.115.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100000731; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"117.93.79.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100000732; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.176.104.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000733; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.176.157.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100000734; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.176.7.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100000735; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.211.38.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000736; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.223.32.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000737; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.223.5.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000738; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.223.72.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000739; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.128.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100000740; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.208.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000741; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.209.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100000742; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.214.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100000743; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.88.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100000744; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.96.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100000745; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.232.96.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000746; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.233.221.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100000747; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.233.63.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100000748; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.233.65.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000749; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.249.136.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000750; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.250.51.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100000751; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.42.125.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100000752; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.43.180.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000753; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.68.245.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000754; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.75.120.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000755; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.75.240.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100000756; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.75.50.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100000757; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.75.70.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100000758; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.125.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100000759; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.164.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100000760; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.218.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100000761; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.50.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000762; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.58.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100000763; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.79.73.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000764; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.83.79.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000765; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.99.179.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000766; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.99.183.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000767; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"118.99.239.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000768; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.100.40.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100000769; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.108.188.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000770; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.108.252.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000771; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.109.34.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100000772; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.112.22.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000773; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.118.251.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000774; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.119.52.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000775; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.123.175.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100000776; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.14.143.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100000777; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.147.213.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000778; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.162.109.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100000779; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.163.144.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100000780; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.163.93.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100000781; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.164.18.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100000782; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.164.31.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100000783; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.164.74.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100000784; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.107.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000785; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.163.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100000786; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.174.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100000787; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.208.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100000788; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.241.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000789; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.27.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100000790; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.165.68.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100000791; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.166.170.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100000792; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.166.19.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100000793; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.166.97.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000794; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.167.1.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100000795; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.167.2.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100000796; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.167.26.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100000797; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.167.63.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000798; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.176.231.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000799; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.178.201.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100000800; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.178.248.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100000801; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.178.249.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100000802; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.157.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100000803; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.16.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100000804; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.170.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000805; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.27.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100000806; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.43.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100000807; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.44.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000808; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.179.75.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000809; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.18.38.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000810; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.101.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000811; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.106.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100000812; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.108.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000813; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.108.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000814; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.11.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100000815; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.231.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000816; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.33.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000817; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.80.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100000818; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.9.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100000819; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.180.94.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000820; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.181.124.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000821; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.181.43.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000822; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.183.109.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100000823; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.183.115.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100000824; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.183.9.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100000825; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.184.14.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100000826; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.184.172.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100000827; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.184.172.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000828; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.185.102.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100000829; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.185.237.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100000830; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.185.39.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100000831; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.185.43.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000832; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.186.22.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100000833; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.187.195.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100000834; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.187.220.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000835; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.187.62.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100000836; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.189.137.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000837; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.189.227.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000838; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.190.211.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100000839; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.190.240.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000840; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.150.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000841; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.187.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000842; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.215.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100000843; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.191.253.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000844; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.204.30.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000845; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.250.129.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100000846; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.250.218.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000847; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.251.105.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100000848; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.251.12.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000849; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.251.14.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100000850; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.131.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100000851; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.143.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000852; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.143.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100000853; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.144.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100000854; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.148.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000855; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.155.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000856; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.166.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100000857; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.172.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100000858; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.56.206.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100000859; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.96.37.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100000860; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.96.70.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100000861; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.99.188.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100000862; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.99.190.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100000863; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"119.99.232.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100000864; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.132.113.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000865; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.15.69.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100000866; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100000867; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100000868; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000869; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.178.187.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100000870; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"12.207.39.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000871; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.12.144.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100000872; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.12.153.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100000873; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.12.212.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100000874; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.142.222.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000875; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.150.213.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100000876; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.151.248.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100000877; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100000878; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100000879; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100000880; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100000881; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100000882; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100000883; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000884; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100000885; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100000886; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100000887; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100000888; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100000889; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100000890; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000891; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100000892; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000893; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100000894; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000895; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000896; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100000897; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000898; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100000899; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100000900; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100000901; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100000902; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000903; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.91.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100000904; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.193.93.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100000905; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.121.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000906; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000907; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100000908; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100000909; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000910; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000911; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.126.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000912; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.127.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100000913; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.209.99.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100000914; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.210.89.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100000915; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.43.54.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100000916; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.50.66.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100000917; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.50.93.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100000918; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.6.141.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000919; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.6.8.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100000920; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.69.113.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100000921; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.69.131.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000922; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.7.90.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100000923; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.165.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100000924; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.173.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100000925; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.174.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100000926; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.174.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100000927; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.174.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100000928; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.199.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000929; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.212.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100000930; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.85.237.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100000931; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"120.9.32.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100000932; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.100.114.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100000933; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.100.96.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000934; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.121.44.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100000935; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.123.53.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100000936; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.127.155.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100000937; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.141.11.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100000938; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.15.142.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100000939; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.151.78.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100000940; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.159.22.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100000941; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.16.155.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100000942; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.17.103.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100000943; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.170.234.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100000944; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.185.31.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100000945; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.190.36.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100000946; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.205.229.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100000947; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.225.11.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100000948; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.226.82.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100000949; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.23.18.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100000950; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.230.171.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100000951; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.231.103.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000952; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.237.225.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100000953; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.238.175.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100000954; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.239.15.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100000955; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.24.116.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100000956; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.25.101.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100000957; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.254.43.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100000958; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.34.150.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100000959; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.61.101.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100000960; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.61.102.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100000961; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.61.107.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100000962; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.61.97.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100000963; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.61.98.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100000964; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"121.88.99.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100000965; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.100.150.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100000966; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.137.52.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100000967; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.160.147.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100000968; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.188.86.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100000969; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.190.19.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100000970; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.192.190.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100000971; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.194.191.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100000972; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.199.72.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000973; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.199.79.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100000974; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.199.83.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100000975; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.202.37.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100000976; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.202.41.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100000977; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.252.250.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100000978; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.254.183.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100000979; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.254.29.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100000980; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"122.254.33.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100000981; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.0.240.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000982; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.10.128.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100000983; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.10.131.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100000984; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.10.140.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100000985; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.10.209.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100000986; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.10.36.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100000987; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.10.41.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100000988; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.10.83.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100000989; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.124.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100000990; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.124.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100000991; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.170.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100000992; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.182.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100000993; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.19.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100000994; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.200.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100000995; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.110.238.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100000996; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.12.229.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100000997; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.12.3.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100000998; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.12.36.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100000999; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.128.128.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100001000; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.128.133.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100001001; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.129.84.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001002; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.129.88.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100001003; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.13.101.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001004; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.13.30.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001005; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.208.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100001006; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.23.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001007; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.37.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001008; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.130.61.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100001009; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.131.186.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001010; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.132.219.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001011; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.133.125.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001012; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.133.144.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001013; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.133.98.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001014; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.134.14.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001015; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.134.50.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001016; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.135.157.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100001017; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.135.39.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001018; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.135.71.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001019; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.101.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100001020; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.150.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001021; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.205.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001022; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.217.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001023; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.235.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001024; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.76.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100001025; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.14.88.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100001026; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.152.42.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001027; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.152.43.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100001028; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.154.94.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001029; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.155.118.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001030; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.156.136.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100001031; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.159.137.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100001032; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.159.31.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001033; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.159.8.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100001034; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.183.123.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001035; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.191.173.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100001036; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.192.101.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001037; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.192.194.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001038; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.193.149.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100001039; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.193.53.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001040; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.235.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001041; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.35.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100001042; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.52.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001043; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.194.60.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001044; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.195.112.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100001045; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.195.184.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001046; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.195.98.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001047; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.212.29.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100001048; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.213.225.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001049; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.233.130.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001050; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.233.152.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100001051; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.234.100.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001052; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.234.116.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001053; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.234.184.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001054; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.234.246.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100001055; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.240.103.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001056; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.240.181.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001057; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.240.79.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100001058; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.241.148.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100001059; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.241.184.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100001060; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.27.44.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001061; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.28.217.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001062; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.180.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100001063; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.185.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100001064; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.193.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001065; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.44.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100001066; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.85.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100001067; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.4.92.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001068; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.5.123.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001069; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.5.178.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100001070; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.5.188.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100001071; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.5.22.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001072; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.5.27.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001073; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.8.183.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001074; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.8.254.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001075; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.8.40.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001076; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.8.41.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001077; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.8.62.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001078; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.9.243.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001079; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.105.105.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100001080; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.129.162.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001081; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.129.221.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001082; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.129.76.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001083; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.130.167.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001084; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.130.40.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001085; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.104.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001086; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.130.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001087; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.136.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001088; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.151.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001089; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.21.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100001090; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.26.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001091; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.26.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100001092; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.54.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001093; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.70.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001094; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.131.72.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001095; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.132.110.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001096; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.135.34.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001097; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.153.136.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100001098; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.153.236.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001099; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.160.126.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001100; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.138.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100001101; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.167.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001102; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.65.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001103; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.72.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100001104; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.77.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001105; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.163.90.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001106; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.165.123.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001107; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.167.186.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001108; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.187.111.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100001109; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.199.56.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001110; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.226.24.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100001111; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.230.174.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001112; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.234.6.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001113; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.5.92.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001114; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.6.0.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001115; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.7.254.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001116; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.80.46.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100001117; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.92.148.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001118; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"124.95.17.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001119; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.106.125.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100001120; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.106.252.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001121; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.126.69.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001122; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.128.28.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001123; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.142.93.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001124; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.168.10.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001125; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.191.113.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100001126; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.1.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100001127; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.107.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001128; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.113.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001129; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.136.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100001130; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.150.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001131; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.16.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001132; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.163.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001133; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.237.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001134; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.65.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100001135; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.73.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001136; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.74.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001137; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.40.75.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001138; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.106.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001139; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.138.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001140; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.189.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100001141; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.191.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100001142; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.196.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001143; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.200.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100001144; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.204.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100001145; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.205.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001146; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.6.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001147; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.7.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001148; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.80.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001149; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.86.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100001150; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.41.96.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100001151; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.42.124.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100001152; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.42.125.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100001153; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.42.234.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001154; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.42.96.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100001155; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.42.98.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100001156; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.105.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001157; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.106.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001158; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.112.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100001159; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.126.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001160; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.130.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100001161; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.136.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001162; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.177.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100001163; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.21.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001164; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.26.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001165; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.34.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001166; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.53.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100001167; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.43.73.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100001168; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.168.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001169; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.212.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001170; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.213.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100001171; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.230.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001172; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.30.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001173; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.31.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001174; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.44.8.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001175; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.45.57.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100001176; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.45.65.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001177; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.45.90.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100001178; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.46.138.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100001179; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.46.184.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001180; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.46.206.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100001181; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.193.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001182; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.200.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100001183; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.209.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001184; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.244.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100001185; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.252.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001186; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.254.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100001187; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.28.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100001188; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.36.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001189; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.45.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001190; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.71.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100001191; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.90.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001192; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.47.91.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001193; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"125.99.220.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100001194; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"128.116.133.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100001195; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"130.255.159.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001196; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"134.195.139.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001197; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"138.99.204.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100001198; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.159.226.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001199; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.170.173.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001200; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.170.174.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001201; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.170.228.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001202; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.216.102.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001203; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"139.227.46.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100001204; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.102.17.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100001205; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.136.80.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001206; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.138.109.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100001207; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.138.109.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001208; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.138.8.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001209; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.138.8.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001210; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.155.220.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100001211; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.155.223.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001212; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.169.164.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001213; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.189.247.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001214; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.205.201.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001215; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.37.222.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001216; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.45.127.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001217; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.46.25.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100001218; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.46.98.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100001219; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.55.29.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001220; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"140.237.30.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100001221; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"140.237.5.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100001222; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"142.11.216.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001223; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"142.177.56.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100001224; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"146.71.79.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001225; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"148.69.108.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100001226; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.20.176.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001227; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001228; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001229; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001230; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100001231; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.255.15.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001232; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.3.85.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100001233; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"150.116.207.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100001234; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"150.129.105.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100001235; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"151.177.163.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001236; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"151.33.230.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001237; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"151.51.158.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100001238; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"151.73.124.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001239; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.101.225.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001240; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.101.234.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001241; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.3.123.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001242; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.3.43.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100001243; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.3.44.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100001244; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.34.135.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100001245; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.34.23.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100001246; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.34.29.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001247; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.35.111.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001248; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.35.27.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001249; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"153.36.126.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001250; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"154.126.178.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001251; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"154.91.1.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001252; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"157.122.105.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100001253; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"158.101.165.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001254; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"158.174.213.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001255; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"158.51.125.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001256; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"159.224.74.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001257; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.191.165.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001258; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.191.205.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100001259; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.191.249.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100001260; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.194.28.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001261; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"162.209.98.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001262; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.183.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100001263; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.195.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100001264; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.200.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100001265; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.200.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100001266; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.202.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001267; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.202.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001268; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.203.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001269; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.207.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100001270; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.250.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100001271; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.125.68.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100001272; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"163.53.206.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001273; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"165.90.16.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001274; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"170.78.39.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001275; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"170.81.238.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001276; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.118.18.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001277; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.118.210.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100001278; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.119.217.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001279; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.119.218.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001280; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.119.219.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001281; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.119.255.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001282; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.120.125.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001283; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.121.6.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001284; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.123.189.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100001285; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.125.30.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001286; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.125.30.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001287; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.125.64.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001288; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.125.65.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001289; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.126.109.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100001290; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.34.112.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001291; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.34.114.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100001292; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.34.179.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001293; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.35.161.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001294; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.35.162.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100001295; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.35.173.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001296; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.35.174.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001297; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.36.42.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100001298; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.38.219.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100001299; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"171.44.254.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001300; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.105.36.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100001301; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.114.244.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100001302; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.245.5.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100001303; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.245.5.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001304; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.167.85.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001305; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.169.46.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001306; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.19.58.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100001307; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.220.222.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001308; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.233.85.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001309; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.235.209.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001310; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.25.113.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100001311; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.52.95.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001312; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.52.97.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100001313; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.56.119.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100001314; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.56.92.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001315; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.106.33.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001316; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.48.181.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100001317; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.73.246.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100001318; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.81.78.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100001319; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.84.148.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100001320; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.96.30.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100001321; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.10.147.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001322; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.11.193.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001323; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.115.241.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001324; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.117.66.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100001325; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.145.200.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100001326; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.146.17.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001327; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.153.144.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001328; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.162.69.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100001329; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.169.172.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100001330; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.173.196.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001331; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.174.93.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001332; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.199.33.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001333; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.201.104.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001334; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.208.230.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100001335; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.212.6.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001336; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.42.46.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001337; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"175.9.24.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001338; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001339; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001340; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001341; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001342; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.111.174.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100001343; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100001344; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100001345; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100001346; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100001347; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001348; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001349; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100001350; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001351; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001352; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001353; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100001354; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100001355; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100001356; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.161.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001357; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.113.174.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001358; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.12.117.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001359; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.123.4.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001360; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.123.7.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001361; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.123.7.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100001362; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.123.9.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001363; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.124.7.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001364; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.221.251.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001365; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.240.40.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100001366; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.240.84.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001367; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"176.32.151.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001368; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.229.64.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001369; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.44.61.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001370; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.54.82.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100001371; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"177.86.235.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001372; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.124.182.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100001373; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.134.185.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001374; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.141.161.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100001375; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.141.25.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001376; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.141.57.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001377; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.150.174.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100001378; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.165.122.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001379; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.0.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100001380; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.0.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100001381; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100001382; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001383; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001384; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.1.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100001385; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.10.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100001386; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.10.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100001387; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.10.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001388; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.10.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001389; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.10.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001390; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100001391; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100001392; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001393; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001394; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001395; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.100.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001396; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.101.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001397; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.101.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001398; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001399; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100001400; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100001401; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100001402; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001403; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.102.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001404; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.103.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001405; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.103.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100001406; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.103.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100001407; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001408; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001409; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100001410; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001411; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001412; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001413; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001414; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001415; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100001416; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100001417; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001418; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001419; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.104.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100001420; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100001421; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100001422; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100001423; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100001424; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100001425; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001426; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100001427; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001428; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001429; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100001430; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.105.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001431; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001432; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001433; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100001434; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001435; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100001436; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001437; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001438; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.106.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001439; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001440; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001441; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001442; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001443; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.107.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100001444; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100001445; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100001446; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100001447; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001448; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100001449; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100001450; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001451; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.108.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001452; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.109.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001453; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.109.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100001454; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.109.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100001455; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.109.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100001456; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.109.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001457; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.109.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100001458; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100001459; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001460; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100001461; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.11.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100001462; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001463; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001464; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100001465; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100001466; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100001467; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.110.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100001468; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001469; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100001470; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001471; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100001472; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100001473; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.111.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100001474; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001475; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001476; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001477; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.112.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001478; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.113.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001479; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.113.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001480; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.113.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001481; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.113.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001482; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.113.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001483; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.113.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001484; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001485; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001486; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001487; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001488; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100001489; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100001490; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100001491; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001492; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100001493; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001494; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001495; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100001496; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.114.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100001497; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001498; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100001499; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100001500; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100001501; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001502; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100001503; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100001504; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001505; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100001506; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001507; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001508; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.115.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100001509; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.116.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100001510; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.116.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001511; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.116.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100001512; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.116.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001513; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.116.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100001514; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.117.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001515; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.117.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100001516; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.117.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100001517; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.117.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001518; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.117.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100001519; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001520; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100001521; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001522; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001523; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.118.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001524; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100001525; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001526; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001527; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100001528; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.119.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100001529; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100001530; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001531; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100001532; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.12.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100001533; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.120.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100001534; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.120.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001535; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.120.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001536; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.120.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001537; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.120.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100001538; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100001539; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001540; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100001541; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100001542; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001543; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100001544; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.121.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100001545; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001546; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001547; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001548; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.122.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001549; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100001550; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001551; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001552; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100001553; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001554; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.123.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001555; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001556; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001557; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001558; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001559; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001560; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001561; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001562; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.124.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001563; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100001564; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001565; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001566; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100001567; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001568; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001569; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.125.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100001570; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100001571; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001572; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001573; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001574; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100001575; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100001576; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001577; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.126.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001578; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100001579; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001580; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100001581; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100001582; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100001583; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100001584; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100001585; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001586; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100001587; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001588; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001589; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001590; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.127.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001591; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.13.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001592; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.14.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100001593; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.14.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100001594; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.14.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001595; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.14.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100001596; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100001597; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100001598; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100001599; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001600; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100001601; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001602; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100001603; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100001604; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.15.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001605; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001606; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100001607; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100001608; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100001609; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001610; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100001611; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001612; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100001613; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.16.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100001614; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.17.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100001615; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.17.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001616; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.18.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001617; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.18.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001618; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.18.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001619; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100001620; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100001621; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001622; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001623; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100001624; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100001625; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100001626; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.19.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100001627; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001628; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001629; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001630; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.2.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001631; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100001632; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100001633; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001634; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100001635; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001636; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001637; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001638; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100001639; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100001640; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.20.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001641; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001642; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001643; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100001644; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.21.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100001645; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.22.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001646; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.22.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100001647; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.23.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100001648; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.23.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100001649; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.23.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100001650; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.23.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001651; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100001652; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001653; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100001654; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001655; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001656; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.24.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001657; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100001658; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100001659; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100001660; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100001661; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001662; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001663; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.25.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001664; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001665; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100001666; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001667; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001668; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001669; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100001670; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001671; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.26.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001672; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100001673; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001674; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100001675; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001676; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100001677; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001678; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100001679; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001680; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100001681; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100001682; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100001683; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100001684; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100001685; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100001686; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100001687; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.27.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100001688; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.28.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100001689; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.28.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100001690; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.28.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001691; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.28.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100001692; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100001693; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001694; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100001695; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001696; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.29.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100001697; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100001698; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100001699; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100001700; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001701; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100001702; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001703; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001704; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100001705; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001706; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.3.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100001707; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001708; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.30.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001709; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.31.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001710; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.31.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100001711; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.31.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100001712; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.31.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100001713; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001714; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100001715; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100001716; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100001717; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001718; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100001719; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001720; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100001721; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001722; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.32.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001723; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001724; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001725; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001726; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001727; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001728; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100001729; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100001730; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100001731; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100001732; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100001733; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100001734; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001735; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001736; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.33.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100001737; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.34.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001738; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.34.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001739; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.34.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100001740; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.34.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001741; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.35.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100001742; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.35.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100001743; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.35.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100001744; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.35.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001745; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.35.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001746; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001747; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001748; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100001749; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001750; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100001751; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100001752; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100001753; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100001754; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001755; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001756; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001757; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001758; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001759; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.36.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100001760; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001761; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100001762; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100001763; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.37.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100001764; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001765; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001766; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001767; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001768; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100001769; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100001770; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100001771; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.38.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100001772; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.39.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100001773; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.39.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100001774; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.39.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100001775; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.39.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100001776; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001777; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100001778; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001779; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.4.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001780; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001781; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100001782; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001783; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001784; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001785; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100001786; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001787; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001788; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100001789; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001790; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100001791; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.40.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001792; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100001793; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001794; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100001795; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100001796; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100001797; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100001798; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100001799; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.41.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001800; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001801; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100001802; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100001803; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001804; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100001805; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100001806; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.42.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100001807; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001808; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001809; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100001810; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001811; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100001812; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001813; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.43.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100001814; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001815; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001816; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100001817; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100001818; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001819; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001820; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001821; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001822; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001823; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100001824; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001825; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100001826; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100001827; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.44.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001828; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.45.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100001829; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.45.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100001830; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.45.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100001831; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.45.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100001832; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100001833; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100001834; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001835; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.46.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100001836; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001837; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.47.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001838; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.48.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100001839; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.48.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100001840; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.48.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100001841; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.48.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100001842; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100001843; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100001844; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100001845; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001846; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100001847; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100001848; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.49.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100001849; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.5.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100001850; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.5.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100001851; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.5.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001852; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100001853; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100001854; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001855; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100001856; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001857; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100001858; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.50.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100001859; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.51.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100001860; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.51.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100001861; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.51.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001862; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.51.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001863; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001864; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.52.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001865; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100001866; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001867; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100001868; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001869; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100001870; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100001871; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.53.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100001872; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001873; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100001874; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100001875; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100001876; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.54.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100001877; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100001878; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001879; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001880; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100001881; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100001882; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100001883; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100001884; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001885; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.55.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100001886; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100001887; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001888; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001889; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100001890; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.56.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100001891; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.57.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001892; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.57.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100001893; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.57.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100001894; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.58.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100001895; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.58.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001896; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100001897; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100001898; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100001899; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100001900; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100001901; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001902; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.59.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100001903; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100001904; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100001905; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100001906; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.6.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100001907; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.60.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100001908; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.60.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100001909; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100001910; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100001911; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001912; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100001913; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100001914; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100001915; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100001916; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100001917; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.61.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100001918; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100001919; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001920; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100001921; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100001922; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100001923; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100001924; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.62.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001925; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.63.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100001926; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.63.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100001927; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.63.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100001928; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100001929; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100001930; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100001931; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100001932; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100001933; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100001934; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.64.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001935; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.65.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100001936; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.65.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100001937; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.65.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100001938; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.65.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100001939; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.65.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100001940; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.65.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100001941; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.65.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100001942; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100001943; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001944; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100001945; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100001946; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100001947; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001948; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100001949; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.66.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100001950; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100001951; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100001952; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100001953; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100001954; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.67.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001955; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100001956; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100001957; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100001958; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100001959; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100001960; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100001961; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100001962; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100001963; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100001964; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.68.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100001965; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100001966; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100001967; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100001968; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100001969; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100001970; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100001971; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100001972; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100001973; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100001974; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.69.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100001975; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.7.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100001976; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100001977; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100001978; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100001979; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100001980; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100001981; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100001982; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100001983; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.70.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100001984; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100001985; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100001986; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100001987; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100001988; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100001989; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100001990; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100001991; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100001992; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.71.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100001993; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100001994; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100001995; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100001996; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.72.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100001997; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.73.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100001998; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.73.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100001999; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.74.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100002000; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.74.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100002001; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.74.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002002; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.75.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100002003; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.75.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100002004; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.75.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100002005; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.75.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002006; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.75.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100002007; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002008; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100002009; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100002010; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100002011; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100002012; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100002013; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002014; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.76.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100002015; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.77.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100002016; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.77.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100002017; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.77.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100002018; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100002019; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100002020; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100002021; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100002022; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100002023; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.78.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100002024; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.79.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100002025; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.79.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100002026; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.79.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100002027; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.79.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100002028; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.79.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002029; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.8.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100002030; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.8.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100002031; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.8.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002032; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.8.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100002033; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.8.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100002034; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100002035; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100002036; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100002037; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002038; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100002039; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.80.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100002040; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100002041; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100002042; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100002043; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100002044; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002045; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002046; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100002047; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002048; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100002049; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100002050; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.81.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100002051; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.82.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100002052; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.82.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100002053; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.83.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100002054; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.83.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100002055; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.83.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100002056; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100002057; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002058; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100002059; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100002060; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100002061; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100002062; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.84.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002063; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100002064; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100002065; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100002066; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100002067; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100002068; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.85.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100002069; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.86.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100002070; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.86.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100002071; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.86.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002072; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100002073; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100002074; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002075; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.87.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100002076; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002077; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.88.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100002078; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.89.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002079; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.89.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100002080; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.89.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100002081; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.89.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100002082; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.89.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100002083; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100002084; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100002085; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100002086; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100002087; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100002088; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002089; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100002090; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100002091; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100002092; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002093; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.9.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100002094; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100002095; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100002096; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100002097; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100002098; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100002099; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100002100; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100002101; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.90.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100002102; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100002103; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100002104; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100002105; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100002106; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100002107; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100002108; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100002109; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002110; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.91.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002111; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100002112; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100002113; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100002114; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100002115; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100002116; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100002117; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100002118; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.92.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100002119; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100002120; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100002121; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100002122; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100002123; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100002124; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100002125; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100002126; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100002127; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100002128; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100002129; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100002130; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100002131; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100002132; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.93.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100002133; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100002134; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100002135; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100002136; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100002137; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.94.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100002138; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100002139; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100002140; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100002141; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100002142; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100002143; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002144; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100002145; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002146; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.95.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100002147; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.96.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100002148; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.96.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100002149; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.96.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100002150; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.97.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100002151; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.97.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100002152; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.97.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100002153; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.97.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002154; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.97.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002155; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.97.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100002156; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.98.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100002157; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.98.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100002158; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.98.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100002159; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.98.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100002160; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100002161; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002162; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002163; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100002164; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100002165; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.175.99.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100002166; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.19.183.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100002167; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.21.164.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100002168; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.217.8.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002169; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.22.117.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100002170; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.222.252.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002171; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.34.183.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100002172; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.92.246.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100002173; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"178.95.115.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002174; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.159.58.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100002175; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.4.187.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100002176; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.48.156.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002177; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.60.84.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002178; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"179.99.210.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100002179; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.109.36.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002180; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.111.101.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100002181; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.114.111.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100002182; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.116.203.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002183; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.120.149.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100002184; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.122.13.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100002185; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.125.44.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002186; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.157.66.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100002187; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.175.93.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100002188; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.105.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002189; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.110.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100002190; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.165.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100002191; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.214.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100002192; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.34.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100002193; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.176.96.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100002194; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.177.104.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100002195; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.177.242.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100002196; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.218.5.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100002197; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.248.80.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100002198; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.66.111.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002199; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.66.53.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100002200; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"180.94.170.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002201; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.112.138.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100002202; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.112.218.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100002203; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.112.218.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100002204; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.143.60.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002205; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.193.107.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100002206; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.199.170.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100002207; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.199.170.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100002208; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.199.170.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100002209; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.199.170.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100002210; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.210.45.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002211; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.215.47.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002212; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.224.242.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100002213; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.49.236.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100002214; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"181.49.59.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002215; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.112.0.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002216; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.112.15.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100002217; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.112.39.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100002218; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.112.52.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100002219; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.113.0.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100002220; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.113.222.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100002221; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.113.233.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100002222; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.113.24.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100002223; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.106.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100002224; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.202.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100002225; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.114.64.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100002226; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.101.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002227; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.103.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100002228; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.108.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002229; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.108.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002230; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.110.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100002231; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.119.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100002232; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.60.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100002233; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.61.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002234; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.65.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100002235; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.65.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100002236; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.68.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100002237; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.69.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100002238; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.94.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100002239; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.99.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100002240; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.116.99.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002241; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.155.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100002242; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.25.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100002243; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.26.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100002244; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.29.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002245; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.29.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002246; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.117.43.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100002247; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.118.140.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100002248; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.100.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100002249; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.13.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100002250; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.14.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002251; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.166.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100002252; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.196.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100002253; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.211.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100002254; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.220.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100002255; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.236.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100002256; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.49.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002257; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.50.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100002258; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.7.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100002259; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.119.81.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002260; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.10.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100002261; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.16.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002262; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.16.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100002263; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.37.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100002264; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.43.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100002265; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.120.86.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100002266; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.101.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100002267; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.109.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100002268; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.12.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100002269; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.125.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100002270; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.129.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100002271; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.133.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100002272; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.133.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100002273; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.134.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100002274; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.148.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100002275; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.157.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100002276; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.165.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002277; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.205.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100002278; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.206.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100002279; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.219.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100002280; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.233.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100002281; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.249.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100002282; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.50.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100002283; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.78.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100002284; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.81.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100002285; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.92.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100002286; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.93.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100002287; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.121.98.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100002288; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.122.170.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100002289; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.122.202.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100002290; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.122.220.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002291; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.122.229.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100002292; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.122.245.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100002293; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.122.246.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100002294; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.122.249.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100002295; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.122.251.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100002296; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.124.134.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100002297; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.124.15.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100002298; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.124.166.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100002299; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.124.188.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100002300; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.124.95.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100002301; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.113.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100002302; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.117.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002303; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.124.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100002304; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.126.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002305; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.127.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100002306; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.139.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100002307; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.139.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002308; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.140.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100002309; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.178.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100002310; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.181.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100002311; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.241.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002312; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.52.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100002313; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.82.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100002314; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.83.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100002315; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.87.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100002316; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.126.95.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100002317; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.155.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100002318; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.166.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100002319; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.210.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002320; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.6.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100002321; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.70.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100002322; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.78.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100002323; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.91.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100002324; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.127.96.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100002325; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.172.36.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002326; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.233.0.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002327; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.235.252.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100002328; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.53.197.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100002329; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.58.160.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100002330; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.59.227.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100002331; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.88.235.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100002332; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.105.104.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100002333; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.105.225.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100002334; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.109.169.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100002335; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.11.238.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100002336; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.136.252.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100002337; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.150.138.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100002338; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.16.208.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100002339; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.187.163.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100002340; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.188.151.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100002341; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.188.180.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100002342; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.188.180.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100002343; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.188.188.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100002344; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.191.162.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100002345; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.83.105.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100002346; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.83.14.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100002347; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.83.15.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100002348; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.83.23.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100002349; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.83.99.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002350; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.92.195.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100002351; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.95.147.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100002352; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"183.97.22.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100002353; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"184.164.185.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002354; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"184.175.115.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100002355; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"184.74.149.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100002356; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.106.209.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100002357; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.107.3.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100002358; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.172.110.235"; content:"Host"; http_header; classtype:trojan-activity; sid:100002359; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.181.10.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100002360; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.200.241.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100002361; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100002362; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100002363; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002364; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.215.113.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100002365; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.219.133.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100002366; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.221.3.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002367; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.228.141.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002368; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.239.243.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002369; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.26.113.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100002370; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.43.19.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100002371; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.55.1.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100002372; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.68.230.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100002373; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.81.157.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100002374; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.217.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100002375; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100002376; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100002377; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.82.219.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100002378; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.90.166.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100002379; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.151.144.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100002380; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.219.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002381; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.243.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100002382; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.243.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002383; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.243.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100002384; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.179.253.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100002385; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.225.120.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100002386; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.227.148.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002387; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.232.44.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100002388; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.28.60.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100002389; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.33.112.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100002390; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"186.73.188.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100002391; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.12.10.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100002392; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.188.124.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100002393; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"187.212.200.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002394; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.10.21.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100002395; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.10.231.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100002396; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.113.102.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002397; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.113.81.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002398; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.127.224.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100002399; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.127.227.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100002400; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.127.227.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100002401; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.127.231.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100002402; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.127.231.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100002403; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.127.235.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100002404; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.127.235.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002405; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.127.235.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100002406; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.127.237.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100002407; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.127.254.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100002408; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.13.179.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100002409; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.138.200.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100002410; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.152.41.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100002411; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.169.178.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100002412; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.169.30.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100002413; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.169.36.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002414; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.242.167.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100002415; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.242.242.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100002416; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.83.202.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100002417; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"188.93.233.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100002418; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"189.222.157.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100002419; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"19.dbstrony.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002420; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.0.42.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100002421; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.110.161.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002422; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.111.151.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002423; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.119.207.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002424; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.12.99.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002425; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.121.194.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002426; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100002427; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100002428; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100002429; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002430; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.122.112.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002431; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.130.15.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100002432; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.130.20.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100002433; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.141.117.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002434; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.159.240.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100002435; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.187.55.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100002436; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.210.214.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002437; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.213.177.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100002438; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.213.226.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100002439; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.213.49.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100002440; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.216.140.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100002441; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.35.225.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002442; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.65.206.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002443; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.92.4.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100002444; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.98.37.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100002445; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.98.37.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100002446; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"190.98.41.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002447; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"191.255.248.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002448; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.210.175.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002449; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.210.241.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100002450; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.185.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100002451; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.209.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100002452; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.227.228.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100002453; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.3.152.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002454; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.3.73.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100002455; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"192.99.240.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002456; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"193.142.146.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100002457; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"193.228.135.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100002458; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"193.91.131.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100002459; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.15.36.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100002460; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.15.36.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100002461; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.152.35.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100002462; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.38.20.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100002463; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.87.139.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100002464; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.123.213.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100002465; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.139.126.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100002466; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.228.231.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100002467; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.24.94.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100002468; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"195.64.163.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100002469; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.202.26.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100002470; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.218.48.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002471; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.221.148.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100002472; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"196.221.166.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002473; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"197.159.2.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100002474; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"197.50.27.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002475; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.133.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100002476; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.207.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100002477; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.213.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100002478; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.23.251.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100002479; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.46.201.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100002480; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"198.46.202.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002481; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"1am.co.nz"; content:"Host"; http_header; classtype:trojan-activity; sid:100002482; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.229.89.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100002483; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.249.161.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100002484; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.45.111.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100002485; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.45.4.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100002486; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.55.125.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100002487; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.55.92.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100002488; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.83.152.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100002489; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"20.dbstrony.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002490; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.105.167.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100002491; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.111.189.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100002492; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.194.4.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100002493; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.2.161.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100002494; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"200.30.132.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100002495; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.142.147.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100002496; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.184.163.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100002497; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.184.248.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100002498; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.187.102.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100002499; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.200.254.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100002500; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.203.221.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100002501; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.208.139.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002502; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.215.84.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100002503; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.218.97.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100002504; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.107.233.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002505; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.111.131.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100002506; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.164.150.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002507; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.166.217.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100002508; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.169.234.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002509; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.169.234.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100002510; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.169.234.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100002511; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.169.234.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100002512; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.169.234.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100002513; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.29.95.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100002514; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.4.124.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002515; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.51.176.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100002516; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.51.191.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100002517; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"202.74.236.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100002518; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.109.201.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100002519; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.170.115.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002520; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.189.156.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002521; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.202.248.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100002522; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.204.232.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002523; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.229.21.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100002524; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.236.190.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100002525; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.238.86.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100002526; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.70.166.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002527; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.77.80.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100002528; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.80.119.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002529; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.80.171.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100002530; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.82.36.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100002531; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.93.6.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100002532; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"204.195.116.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100002533; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"205.185.123.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002534; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"206.248.137.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100002535; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"206.47.41.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002536; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"207.200.247.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100002537; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"207.44.28.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100002538; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"207.5.32.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100002539; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"208.163.58.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002540; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.141.39.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100002541; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.141.40.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100002542; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.145.60.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100002543; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.102.196.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100002544; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.124.149.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100002545; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.216.152.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100002546; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.216.153.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100002547; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.57.237.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100002548; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.57.245.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002549; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.68.242.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100002550; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"210.96.116.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100002551; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.172.11.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100002552; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.187.132.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100002553; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.187.75.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002554; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.204.215.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100002555; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.210.66.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100002556; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.210.93.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100002557; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.216.66.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100002558; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.237.114.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002559; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.237.120.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100002560; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.238.83.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100002561; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.247.113.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100002562; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.247.5.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002563; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.36.174.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100002564; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.41.197.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100002565; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.47.102.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100002566; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"211.51.174.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100002567; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.122.86.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100002568; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.143.227.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002569; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.156.215.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100002570; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.46.197.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100002571; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"212.56.197.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100002572; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.119.74.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100002573; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.123.206.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100002574; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.135.178.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100002575; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.14.173.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100002576; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.149.182.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100002577; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.149.190.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100002578; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.104.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100002579; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.104.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100002580; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.104.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100002581; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.104.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100002582; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100002583; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100002584; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100002585; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100002586; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.113.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100002587; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.114.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100002588; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100002589; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100002590; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100002591; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002592; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.115.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100002593; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.116.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100002594; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.116.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002595; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.116.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002596; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.116.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100002597; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.116.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002598; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.116.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100002599; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.117.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100002600; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.118.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100002601; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.118.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100002602; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.118.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100002603; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.119.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100002604; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100002605; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100002606; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100002607; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002608; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.126.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100002609; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.127.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002610; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.163.127.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100002611; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.189.178.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002612; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.240.218.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100002613; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.249.156.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100002614; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.27.8.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100002615; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.80.44.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002616; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.92.254.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100002617; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.92.255.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002618; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"213.92.255.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002619; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.12.93.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100002620; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.127.185.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100002621; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.170.240.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100002622; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.183.54.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100002623; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.24.72.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100002624; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.36.12.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100002625; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"217.11.75.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002626; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"217.127.133.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100002627; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.103.180.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100002628; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.215.243.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100002629; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.238.246.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100002630; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.28.160.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100002631; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.207.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100002632; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.227.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100002633; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.68.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100002634; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.35.81.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100002635; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.48.135.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100002636; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.56.93.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100002637; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.57.53.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100002638; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.59.116.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100002639; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.72.198.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100002640; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"218.79.103.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100002641; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.104.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100002642; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.119.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100002643; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.141.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100002644; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.154.182.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100002645; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.102.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100002646; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.12.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100002647; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.14.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002648; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.170.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002649; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.208.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100002650; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.24.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100002651; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.241.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100002652; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.26.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100002653; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.31.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100002654; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.31.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100002655; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.37.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100002656; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.155.9.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100002657; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.156.103.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100002658; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.156.21.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100002659; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.156.23.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100002660; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.156.60.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100002661; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.156.9.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100002662; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.146.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100002663; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.150.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100002664; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.162.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100002665; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.17.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100002666; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.178.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100002667; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.183.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100002668; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.202.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002669; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.220.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100002670; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.221.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100002671; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.223.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100002672; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.244.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002673; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.32.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002674; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.50.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100002675; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.54.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100002676; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.157.56.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100002677; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.241.6.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002678; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.1.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100002679; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.1.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002680; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.163.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002681; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.171.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100002682; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.245.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100002683; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.251.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100002684; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.68.5.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100002685; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.69.71.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100002686; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.80.217.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100002687; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"219.85.145.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002688; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"21robo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100002689; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.118.168.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100002690; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.126.237.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002691; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.173.160.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100002692; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.200.22.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100002693; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.71.239.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002694; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"220.90.159.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100002695; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.0.16.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100002696; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.1.162.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002697; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.124.78.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100002698; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.14.122.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100002699; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.14.182.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100002700; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.14.46.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100002701; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.14.58.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100002702; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.14.58.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002703; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.147.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002704; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.153.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002705; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.218.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100002706; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.234.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100002707; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.234.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100002708; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.237.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002709; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.54.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100002710; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.15.7.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100002711; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.157.191.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100002712; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.160.136.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100002713; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.160.177.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100002714; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.160.177.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002715; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.160.177.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100002716; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.196.12.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002717; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.214.130.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100002718; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.214.162.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002719; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.214.224.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100002720; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.116.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100002721; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.172.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100002722; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.184.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100002723; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.237.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100002724; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.239.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002725; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.252.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100002726; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.215.8.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100002727; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.232.1.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002728; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.232.179.70"; content:"Host"; http_header; classtype:trojan-activity; sid:100002729; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.235.137.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002730; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.235.142.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100002731; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.112.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100002732; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.32.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100002733; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.34.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100002734; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.43.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100002735; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.3.68.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100002736; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"221.5.30.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100002737; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.108.17.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100002738; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.119.65.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100002739; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.132.125.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100002740; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.133.102.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100002741; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.133.103.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100002742; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.133.105.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100002743; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.135.113.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002744; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.135.219.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100002745; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.135.26.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100002746; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.136.231.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100002747; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.136.49.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002748; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.101.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100002749; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.113.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100002750; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.121.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100002751; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.136.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100002752; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.137.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100002753; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.137.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100002754; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.138.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100002755; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.139.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100002756; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.148.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100002757; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.152.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100002758; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.172.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100002759; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.175.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100002760; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.186.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100002761; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.22.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100002762; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.220.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100002763; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.221.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100002764; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.49.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100002765; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.5.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100002766; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.72.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100002767; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.81.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100002768; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.137.83.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100002769; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.137.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100002770; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.143.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002771; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.189.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100002772; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.203.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002773; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.215.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100002774; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.232.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100002775; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.232.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002776; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.49.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100002777; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.138.96.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100002778; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.139.16.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100002779; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.139.59.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100002780; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.112.150"; content:"Host"; http_header; classtype:trojan-activity; sid:100002781; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.117.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100002782; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.161.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100002783; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.163.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100002784; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.17.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100002785; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.209.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100002786; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.219.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100002787; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.140.39.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002788; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.150.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100002789; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.165.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002790; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.244.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100002791; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.40.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100002792; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.41.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100002793; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.44.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100002794; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.45.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100002795; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.60.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100002796; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.73.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100002797; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.141.85.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100002798; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.142.162.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002799; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.142.192.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002800; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.142.209.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002801; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.142.65.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100002802; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.179.215.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100002803; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.185.116.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100002804; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.187.9.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100002805; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.211.72.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002806; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.214.54.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100002807; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.218.220.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100002808; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.238.230.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002809; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.239.83.232"; content:"Host"; http_header; classtype:trojan-activity; sid:100002810; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.248.64.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100002811; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.64.16.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100002812; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.83.150.240"; content:"Host"; http_header; classtype:trojan-activity; sid:100002813; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.92.9.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100002814; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.99.171.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100002815; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.166.117.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100002816; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.167.118.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002817; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.212.225.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100002818; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.212.234.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100002819; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.212.252.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002820; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.212.5.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100002821; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"223.212.73.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100002822; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.125.186.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100002823; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.126.120.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100002824; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.228.143.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002825; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.24.213.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100002826; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.243.149.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100002827; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.243.21.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100002828; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"23.95.89.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100002829; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.103.74.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002830; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.11.141.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100002831; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.119.158.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002832; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.137.147.95"; content:"Host"; http_header; classtype:trojan-activity; sid:100002833; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.152.235.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100002834; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.158.25.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100002835; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.176.206.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100002836; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.184.1.41"; content:"Host"; http_header; classtype:trojan-activity; sid:100002837; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.192.191.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100002838; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.225.114.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100002839; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.227.190.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100002840; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.35.245.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100002841; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.39.181.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002842; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.39.34.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100002843; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.42.229.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100002844; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.45.4.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100002845; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.51.91.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100002846; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.53.163.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100002847; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.53.163.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100002848; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"24.dbstrony.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100002849; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.1.245.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100002850; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.1.245.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100002851; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.105.106.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100002852; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.105.152.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100002853; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.116.84.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100002854; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.12.234.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100002855; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.12.245.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100002856; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.13.83.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100002857; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.14.211.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100002858; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.141.218.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100002859; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.147.29.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100002860; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.147.40.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100002861; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.153.132.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100002862; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.153.207.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100002863; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.184.244.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100002864; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.184.54.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100002865; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.187.248.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100002866; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.193.196.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100002867; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.193.217.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100002868; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.194.149.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100002869; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.194.158.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100002870; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.194.192.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002871; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.194.210.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100002872; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.194.224.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002873; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.197.17.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100002874; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.197.22.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002875; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.197.23.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100002876; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.197.24.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100002877; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.199.232.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100002878; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.199.3.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002879; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.199.34.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100002880; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.200.140.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100002881; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.200.23.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100002882; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.200.32.146"; content:"Host"; http_header; classtype:trojan-activity; sid:100002883; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.202.182.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100002884; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.202.21.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100002885; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.202.66.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100002886; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.102.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100002887; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.126.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100002888; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.154.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100002889; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.165.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100002890; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.185.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002891; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.185.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100002892; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.213.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100002893; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.234.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100002894; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.246.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100002895; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.255.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100002896; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.28.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100002897; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.4.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100002898; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.54.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002899; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.87.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100002900; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.203.94.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100002901; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.204.253.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002902; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.205.178.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100002903; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.136.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100002904; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.14.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100002905; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.148.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100002906; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.154.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100002907; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.185.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100002908; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.26.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100002909; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.81.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002910; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.83.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100002911; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.206.97.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100002912; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.207.155.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100002913; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.207.194.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100002914; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.207.199.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002915; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.152.10"; content:"Host"; http_header; classtype:trojan-activity; sid:100002916; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.160.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100002917; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.164.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100002918; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.166.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100002919; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.201.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100002920; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.247.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100002921; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.25.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100002922; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.34.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100002923; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.208.92.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100002924; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.209.160.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100002925; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.209.231.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100002926; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.209.60.21"; content:"Host"; http_header; classtype:trojan-activity; sid:100002927; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.107.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100002928; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.127.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100002929; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.146.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100002930; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.172.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100002931; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.234.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100002932; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.236.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100002933; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.210.63.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100002934; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.211.251.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100002935; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.104.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100002936; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.109.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100002937; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.109.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002938; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.145.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100002939; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.167.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100002940; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.175.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100002941; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.220.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100002942; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.255.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100002943; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.255.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100002944; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.213.84.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100002945; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.214.37.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100002946; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.139.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100002947; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.190.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100002948; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.212.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100002949; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.253.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100002950; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.34.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100002951; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.38.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100002952; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.71.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100002953; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.215.98.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100002954; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.131.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002955; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.144.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002956; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.193.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100002957; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.197.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100002958; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.225.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100002959; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.234.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100002960; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.46.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100002961; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.58.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100002962; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.216.95.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100002963; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.217.120.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100002964; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.217.133.53"; content:"Host"; http_header; classtype:trojan-activity; sid:100002965; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.217.155.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100002966; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.217.191.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100002967; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.217.31.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100002968; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.217.76.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100002969; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.218.180.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100002970; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.218.219.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100002971; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.218.248.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100002972; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.132.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100002973; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.151.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100002974; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.160.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100002975; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.172.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100002976; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.173.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100002977; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.176.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100002978; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.184.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100002979; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.192.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100002980; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.219.83.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100002981; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.220.40.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100002982; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.220.85.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100002983; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.221.239.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100002984; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.222.241.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100002985; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.222.249.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100002986; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.222.249.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100002987; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.222.42.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100002988; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.222.50.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100002989; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.223.242.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100002990; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.223.44.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100002991; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.24.28.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100002992; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.129.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100002993; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.154.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100002994; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.16.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100002995; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.2.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100002996; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.212.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100002997; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.35.58.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100002998; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.41.153.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100002999; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.41.154.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100003000; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.43.82.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100003001; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.46.45.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100003002; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.46.47.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100003003; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.5.16.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100003004; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.5.26.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100003005; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.5.26.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100003006; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.5.27.1"; content:"Host"; http_header; classtype:trojan-activity; sid:100003007; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"27.5.35.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100003008; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.0.98.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100003009; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.11.51.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100003010; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.13.23.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100003011; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.154.234.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100003012; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.163.191.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100003013; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.124.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100003014; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.179.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100003015; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.184.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100003016; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.191.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100003017; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.194.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100003018; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.216.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100003019; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.219.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100003020; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.24.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100003021; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.30.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100003022; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.60.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100003023; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.63.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100003024; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.65.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100003025; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.168.94.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100003026; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.179.201.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100003027; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.195.84.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100003028; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.204.174.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100003029; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.210.20.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100003030; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.210.20.177"; content:"Host"; http_header; classtype:trojan-activity; sid:100003031; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.210.20.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100003032; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.28.7.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100003033; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.30.119.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100003034; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.62.255.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100003035; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"32.208.157.193"; content:"Host"; http_header; classtype:trojan-activity; sid:100003036; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"32792.prolocksmithwinterpark.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003037; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"35.184.169.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100003038; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.108.231.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100003039; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.109.132.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100003040; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.250.203.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100003041; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.157.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100003042; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.18.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100003043; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.19.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100003044; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.251.51.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100003045; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.255.90.219"; content:"Host"; http_header; classtype:trojan-activity; sid:100003046; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.33.128.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100003047; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.33.160.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100003048; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.36.243.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100003049; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.66.105.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100003050; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.66.111.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100003051; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.66.133.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100003052; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.66.139.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100003053; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.67.152.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100003054; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.89.18.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100003055; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"36.96.187.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100003056; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"360.lcy2zzx.pw"; content:"Host"; http_header; classtype:trojan-activity; sid:100003057; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"360down7.miiyun.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100003058; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.222.98.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100003059; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.233.60.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100003060; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.34.179.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100003061; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.34.180.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100003062; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.44.238.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100003063; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.49.229.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100003064; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.49.230.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100003065; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.52.117.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100003066; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.54.14.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100003067; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"38.77.14.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100003068; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"38.81.149.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100003069; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.113.245.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003070; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.113.98.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100003071; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.114.137.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100003072; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.117.31.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100003073; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.162.104.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100003074; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.64.28.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100003075; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.65.171.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100003076; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.65.196.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100003077; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.65.59.160"; content:"Host"; http_header; classtype:trojan-activity; sid:100003078; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.66.129.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100003079; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.66.85.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100003080; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.104.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100003081; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.125.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100003082; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.146.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100003083; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.148.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100003084; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.67.92.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100003085; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.68.124.76"; content:"Host"; http_header; classtype:trojan-activity; sid:100003086; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.68.249.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100003087; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.72.130.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100003088; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.72.167.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100003089; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.72.67.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100003090; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.10.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100003091; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.163.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003092; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.203.225"; content:"Host"; http_header; classtype:trojan-activity; sid:100003093; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.73.44.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100003094; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.74.104.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100003095; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.74.21.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100003096; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.74.28.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100003097; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.74.31.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100003098; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.74.68.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100003099; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.76.194.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100003100; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.76.79.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100003101; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.76.97.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100003102; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.113.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100003103; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.114.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100003104; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.136.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100003105; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.14.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100003106; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.150.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100003107; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.197.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100003108; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.209.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100003109; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.94.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100003110; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.77.95.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100003111; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.107.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100003112; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.166.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100003113; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.218.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100003114; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.62.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100003115; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.90.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100003116; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.91.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100003117; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.79.93.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100003118; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.127.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100003119; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.191.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100003120; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.205.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100003121; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.24.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100003122; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.34.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100003123; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.80.36.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100003124; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.124.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100003125; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.130.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100003126; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.251.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100003127; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.27.15"; content:"Host"; http_header; classtype:trojan-activity; sid:100003128; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.81.29.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003129; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.82.86.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100003130; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.83.94.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100003131; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.84.157.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100003132; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.84.34.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100003133; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.84.95.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100003134; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.85.54.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100003135; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.85.54.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100003136; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.129.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100003137; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.13.0"; content:"Host"; http_header; classtype:trojan-activity; sid:100003138; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.151.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100003139; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.170.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100003140; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.184.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100003141; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.211.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100003142; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.234.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100003143; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.248.91"; content:"Host"; http_header; classtype:trojan-activity; sid:100003144; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.60.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100003145; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.66.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100003146; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.76.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100003147; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.86.78.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100003148; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.87.63.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003149; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.87.90.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100003150; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.87.93.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100003151; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.141.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100003152; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.155.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100003153; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.233.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100003154; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.39.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100003155; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.41.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100003156; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.67.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100003157; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.88.72.9"; content:"Host"; http_header; classtype:trojan-activity; sid:100003158; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.146.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100003159; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.146.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100003160; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.157.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100003161; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.89.63.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100003162; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.90.86.212"; content:"Host"; http_header; classtype:trojan-activity; sid:100003163; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.139.209.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100003164; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.165.130.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100003165; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.190.63.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100003166; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.193.192.100"; content:"Host"; http_header; classtype:trojan-activity; sid:100003167; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.219.185.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100003168; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.230.31.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003169; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.72.203.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100003170; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.18.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100003171; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.18.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100003172; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.18.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100003173; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.18.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100003174; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.18.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100003175; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.18.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100003176; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.21.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100003177; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.21.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100003178; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.21.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100003179; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"41.86.5.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100003180; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.176.112.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100003181; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.202.101.147"; content:"Host"; http_header; classtype:trojan-activity; sid:100003182; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.122.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100003183; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.128.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100003184; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.168.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100003185; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.168.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100003186; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.176.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100003187; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.179.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100003188; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.209.156"; content:"Host"; http_header; classtype:trojan-activity; sid:100003189; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.212.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100003190; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.218.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100003191; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.233.247"; content:"Host"; http_header; classtype:trojan-activity; sid:100003192; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.235.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100003193; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.249.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100003194; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.37.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100003195; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.37.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100003196; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.43.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100003197; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.64.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100003198; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.70.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100003199; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.76.168"; content:"Host"; http_header; classtype:trojan-activity; sid:100003200; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.76.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100003201; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.8.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100003202; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.90.17"; content:"Host"; http_header; classtype:trojan-activity; sid:100003203; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.224.91.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100003204; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.225.240.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100003205; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.225.250.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100003206; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.225.33.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100003207; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.226.89.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100003208; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.227.179.209"; content:"Host"; http_header; classtype:trojan-activity; sid:100003209; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.227.66.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100003210; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.198.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100003211; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.60.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100003212; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.65.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100003213; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.70.126"; content:"Host"; http_header; classtype:trojan-activity; sid:100003214; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.70.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003215; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.75.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100003216; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.228.76.135"; content:"Host"; http_header; classtype:trojan-activity; sid:100003217; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.230.100.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100003218; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.230.174.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100003219; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.230.219.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100003220; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.230.228.78"; content:"Host"; http_header; classtype:trojan-activity; sid:100003221; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.230.66.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100003222; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.230.82.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100003223; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.230.88.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100003224; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.230.93.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100003225; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.231.223.215"; content:"Host"; http_header; classtype:trojan-activity; sid:100003226; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.231.244.80"; content:"Host"; http_header; classtype:trojan-activity; sid:100003227; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.231.66.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100003228; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.231.95.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100003229; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.232.102.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100003230; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.232.170.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100003231; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.232.226.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100003232; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.233.90.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100003233; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.234.105.6"; content:"Host"; http_header; classtype:trojan-activity; sid:100003234; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.234.162.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100003235; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.234.166.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100003236; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.234.255.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100003237; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.235.124.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100003238; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.235.169.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100003239; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.235.23.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100003240; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.235.66.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100003241; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.235.90.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100003242; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.235.92.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100003243; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.236.148.201"; content:"Host"; http_header; classtype:trojan-activity; sid:100003244; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.236.212.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100003245; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.236.212.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100003246; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.236.215.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100003247; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.236.236.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100003248; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.237.45.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100003249; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.237.54.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100003250; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.238.175.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100003251; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.238.191.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100003252; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.238.241.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100003253; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.238.59.222"; content:"Host"; http_header; classtype:trojan-activity; sid:100003254; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.239.192.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100003255; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.242.200.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100003256; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.52.180.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100003257; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.56.15.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100003258; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.61.99.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100003259; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.82.217.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100003260; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"42.84.14.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100003261; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"43.230.156.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100003262; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"43.241.106.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100003263; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"43.241.106.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100003264; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"43.252.8.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100003265; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.112.203.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100003266; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.130.138.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100003267; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.133.1.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100003268; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.133.1.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100003269; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.133.203.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100003270; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.135.134.228"; content:"Host"; http_header; classtype:trojan-activity; sid:100003271; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.14.149.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100003272; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.14.149.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100003273; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.14.149.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100003274; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.14.149.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100003275; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.141.84.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100003276; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100003277; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100003278; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.144.225.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100003279; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.148.10.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100003280; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.15.143.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100003281; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.164.140.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100003282; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.108.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100003283; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.108.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100003284; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.110.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100003285; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.111.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100003286; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.111.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100003287; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.111.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100003288; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.176.111.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100003289; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.178.101.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100003290; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.201.165.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100003291; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.22.209.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003292; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.23.22.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100003293; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.27.253.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100003294; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.33.112.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100003295; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.51.104.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100003296; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.81.235.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100003297; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.9.148.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100003298; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.151.155.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100003299; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.172.75.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003300; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.175.184.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100003301; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.182.173.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100003302; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.20.63.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100003303; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.201.214.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100003304; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.21.153.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003305; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.214.27.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100003306; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.24.130.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003307; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.243.179.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100003308; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.249.33.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100003309; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.25.242.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100003310; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.42.118.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100003311; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.42.86.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100003312; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.97.76.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100003313; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.145.152.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100003314; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.151.23.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100003315; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.157.97.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100003316; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.16.131.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100003317; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.197.0.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100003318; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.21.202.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100003319; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.223.167.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100003320; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.46.231.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100003321; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.142.162.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100003322; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.142.87.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100003323; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.143.43.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100003324; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.156.35.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100003325; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.158.201.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100003326; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.159.20.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100003327; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.159.21.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100003328; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.174.182.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100003329; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.213.170.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100003330; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.213.178.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100003331; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.213.179.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100003332; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.68.221.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100003333; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.68.249.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100003334; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"49.70.15.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100003335; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.181.135.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100003336; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.2.70.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100003337; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.53.146.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100003338; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"5.8.10.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100003339; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.115.174.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100003340; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.121.91.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100003341; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"50.252.47.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100003342; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"51.171.146.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100003343; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"51.222.56.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100003344; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"54.180.158.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100003345; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"54.253.194.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100003346; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"54.36.114.136"; content:"Host"; http_header; classtype:trojan-activity; sid:100003347; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"54.36.180.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100003348; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"54.37.93.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100003349; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.114.246.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100003350; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.115.162.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100003351; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.115.174.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100003352; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.125.191.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100003353; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.126.247.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100003354; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.142.166.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100003355; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.142.200.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100003356; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.143.142.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100003357; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.143.189.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100003358; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.18.103.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100003359; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.19.249.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100003360; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.217.171.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100003361; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.22.212.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100003362; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.226.129.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100003363; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.229.194.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100003364; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.23.245.24"; content:"Host"; http_header; classtype:trojan-activity; sid:100003365; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.230.89.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100003366; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.232.155.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100003367; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.238.42.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100003368; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.240.147.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100003369; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.241.57.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100003370; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.241.78.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100003371; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.117.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100003372; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.143.173"; content:"Host"; http_header; classtype:trojan-activity; sid:100003373; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.144.97"; content:"Host"; http_header; classtype:trojan-activity; sid:100003374; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.149.117"; content:"Host"; http_header; classtype:trojan-activity; sid:100003375; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.149.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100003376; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.154.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100003377; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.154.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100003378; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.76.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100003379; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.248.79.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100003380; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.18.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100003381; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.74.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100003382; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.74.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100003383; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.74.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100003384; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.77.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100003385; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.78.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100003386; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.80.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100003387; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.80.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100003388; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.86.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100003389; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.87.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100003390; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.89.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100003391; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.90.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100003392; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.249.90.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100003393; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.252.176.107"; content:"Host"; http_header; classtype:trojan-activity; sid:100003394; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.252.177.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100003395; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.255.43.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100003396; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.48.154.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100003397; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.50.178.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100003398; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.50.221.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100003399; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.72.165.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100003400; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.72.165.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100003401; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.97.201.45"; content:"Host"; http_header; classtype:trojan-activity; sid:100003402; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"58.97.206.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100003403; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.0.211.161"; content:"Host"; http_header; classtype:trojan-activity; sid:100003404; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.102.168.189"; content:"Host"; http_header; classtype:trojan-activity; sid:100003405; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.151.202.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100003406; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.151.214.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100003407; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.151.237.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100003408; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.29.133.229"; content:"Host"; http_header; classtype:trojan-activity; sid:100003409; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.30.12.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003410; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.32.97.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100003411; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.58.104.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100003412; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.58.117.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100003413; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.7.124.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100003414; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.8.35.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100003415; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.92.182.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100003416; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.92.218.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100003417; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.92.219.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100003418; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.97.174.85"; content:"Host"; http_header; classtype:trojan-activity; sid:100003419; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"59.99.47.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100003420; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.13.61.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100003421; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.14.48.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100003422; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.162.122.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100003423; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.162.160.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100003424; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.164.130.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100003425; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.17.12.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100003426; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.176.249.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100003427; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.20.217.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100003428; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.208.135.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100003429; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.122.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100003430; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.186.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100003431; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.216.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100003432; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.209.33.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100003433; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.211.19.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100003434; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.211.6.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100003435; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.211.7.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100003436; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.100.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100003437; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.162.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100003438; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.206.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100003439; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.218.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100003440; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.220.167"; content:"Host"; http_header; classtype:trojan-activity; sid:100003441; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.23.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100003442; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.212.254.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100003443; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.213.162.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100003444; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.213.58.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100003445; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.213.83.55"; content:"Host"; http_header; classtype:trojan-activity; sid:100003446; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.214.93.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100003447; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.215.165.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100003448; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.215.195.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100003449; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.215.207.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100003450; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.215.219.108"; content:"Host"; http_header; classtype:trojan-activity; sid:100003451; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.215.4.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100003452; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.216.95.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100003453; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.217.177.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100003454; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.217.86.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100003455; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.220.22.89"; content:"Host"; http_header; classtype:trojan-activity; sid:100003456; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.25.115.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100003457; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.25.76.224"; content:"Host"; http_header; classtype:trojan-activity; sid:100003458; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.4.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100003459; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.42.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100003460; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.51.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100003461; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.60.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100003462; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.8.36"; content:"Host"; http_header; classtype:trojan-activity; sid:100003463; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.253.8.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100003464; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.254.49.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100003465; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.7.10.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100003466; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.7.136.8"; content:"Host"; http_header; classtype:trojan-activity; sid:100003467; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.7.202.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100003468; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.7.8.43"; content:"Host"; http_header; classtype:trojan-activity; sid:100003469; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"60.7.99.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003470; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.102.243.124"; content:"Host"; http_header; classtype:trojan-activity; sid:100003471; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.109.164.140"; content:"Host"; http_header; classtype:trojan-activity; sid:100003472; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.141.124.123"; content:"Host"; http_header; classtype:trojan-activity; sid:100003473; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.162.169.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100003474; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.162.55.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100003475; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.164.96.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100003476; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.179.171.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100003477; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.179.91.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100003478; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.179.91.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100003479; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.179.93.79"; content:"Host"; http_header; classtype:trojan-activity; sid:100003480; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.18.112.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100003481; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.192.73.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100003482; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.213.118.28"; content:"Host"; http_header; classtype:trojan-activity; sid:100003483; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.247.224.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100003484; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.253.94.230"; content:"Host"; http_header; classtype:trojan-activity; sid:100003485; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.3.124.3"; content:"Host"; http_header; classtype:trojan-activity; sid:100003486; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.3.124.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100003487; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.47.220.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100003488; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.102.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100003489; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.103.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100003490; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.11.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100003491; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.135.192"; content:"Host"; http_header; classtype:trojan-activity; sid:100003492; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.157.4"; content:"Host"; http_header; classtype:trojan-activity; sid:100003493; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.159.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003494; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.195.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100003495; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.212.191"; content:"Host"; http_header; classtype:trojan-activity; sid:100003496; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.212.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100003497; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.243.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100003498; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.247.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100003499; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.35.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100003500; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.39.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100003501; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.43.174"; content:"Host"; http_header; classtype:trojan-activity; sid:100003502; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.48.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100003503; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.5.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100003504; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.63.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100003505; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.76.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100003506; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.9.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100003507; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.52.99.183"; content:"Host"; http_header; classtype:trojan-activity; sid:100003508; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.100.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100003509; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.123.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100003510; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.125.182"; content:"Host"; http_header; classtype:trojan-activity; sid:100003511; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.251.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100003512; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.62.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100003513; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.73.171"; content:"Host"; http_header; classtype:trojan-activity; sid:100003514; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.81.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100003515; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.53.83.14"; content:"Host"; http_header; classtype:trojan-activity; sid:100003516; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.172.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100003517; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.240.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100003518; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.58.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100003519; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.58.20"; content:"Host"; http_header; classtype:trojan-activity; sid:100003520; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.61.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100003521; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.64.104"; content:"Host"; http_header; classtype:trojan-activity; sid:100003522; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.54.77.175"; content:"Host"; http_header; classtype:trojan-activity; sid:100003523; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.56.180.67"; content:"Host"; http_header; classtype:trojan-activity; sid:100003524; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.56.181.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100003525; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.57.96.116"; content:"Host"; http_header; classtype:trojan-activity; sid:100003526; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.58.170.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100003527; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.58.73.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100003528; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.61.218.23"; content:"Host"; http_header; classtype:trojan-activity; sid:100003529; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.65.172.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100003530; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.0.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100003531; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.104.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100003532; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.110.59"; content:"Host"; http_header; classtype:trojan-activity; sid:100003533; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.132.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100003534; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.132.86"; content:"Host"; http_header; classtype:trojan-activity; sid:100003535; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.255.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100003536; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.70.45.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100003537; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"61.98.144.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100003538; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.1.98.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100003539; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.117.124.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100003540; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.141.73.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003541; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.219.131.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100003542; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.219.143.46"; content:"Host"; http_header; classtype:trojan-activity; sid:100003543; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.219.155.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100003544; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.219.227.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100003545; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.31.126.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100003546; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.38.149.66"; content:"Host"; http_header; classtype:trojan-activity; sid:100003547; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.38.222.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100003548; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.43.207.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100003549; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"62.90.165.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100003550; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"63.245.122.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100003551; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"64.233.154.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100003552; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.125.128.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100003553; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.21.58.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100003554; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"65.26.155.131"; content:"Host"; http_header; classtype:trojan-activity; sid:100003555; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.153.233.87"; content:"Host"; http_header; classtype:trojan-activity; sid:100003556; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.229.214.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100003557; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.57.55.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100003558; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.74.7.197"; content:"Host"; http_header; classtype:trojan-activity; sid:100003559; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.91.21.31"; content:"Host"; http_header; classtype:trojan-activity; sid:100003560; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.97.181.196"; content:"Host"; http_header; classtype:trojan-activity; sid:100003561; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"66.97.181.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100003562; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.245.151.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100003563; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.3.169.223"; content:"Host"; http_header; classtype:trojan-activity; sid:100003564; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.8.138.101"; content:"Host"; http_header; classtype:trojan-activity; sid:100003565; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.81.98.111"; content:"Host"; http_header; classtype:trojan-activity; sid:100003566; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.82.242.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100003567; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.83.49.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100003568; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.84.138.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100003569; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.148.103.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100003570; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.151.244.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100003571; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.174.182.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100003572; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.175.107.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100003573; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.188.144.143"; content:"Host"; http_header; classtype:trojan-activity; sid:100003574; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.204.88.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100003575; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.205.106.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100003576; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.205.119.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100003577; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.78.33.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100003578; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.115.37.205"; content:"Host"; http_header; classtype:trojan-activity; sid:100003579; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.120.237.255"; content:"Host"; http_header; classtype:trojan-activity; sid:100003580; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.123.245.151"; content:"Host"; http_header; classtype:trojan-activity; sid:100003581; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.124.231.110"; content:"Host"; http_header; classtype:trojan-activity; sid:100003582; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.127.214.47"; content:"Host"; http_header; classtype:trojan-activity; sid:100003583; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.146.232.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100003584; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.165.173.49"; content:"Host"; http_header; classtype:trojan-activity; sid:100003585; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.196.158.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100003586; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.222.157.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100003587; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.229.0.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100003588; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.63.73.234"; content:"Host"; http_header; classtype:trojan-activity; sid:100003589; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.75.115.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100003590; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.75.227.186"; content:"Host"; http_header; classtype:trojan-activity; sid:100003591; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"69.76.240.206"; content:"Host"; http_header; classtype:trojan-activity; sid:100003592; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.115.31.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100003593; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.118.240.88"; content:"Host"; http_header; classtype:trojan-activity; sid:100003594; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.167.10.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100003595; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.236.190.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100003596; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.25.5.105"; content:"Host"; http_header; classtype:trojan-activity; sid:100003597; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.33.144.248"; content:"Host"; http_header; classtype:trojan-activity; sid:100003598; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"70.93.129.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100003599; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.127.148.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100003600; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.19.150.93"; content:"Host"; http_header; classtype:trojan-activity; sid:100003601; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.204.63.239"; content:"Host"; http_header; classtype:trojan-activity; sid:100003602; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.29.48.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100003603; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.34.191.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100003604; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.40.234.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100003605; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.43.2.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100003606; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.43.235.106"; content:"Host"; http_header; classtype:trojan-activity; sid:100003607; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.47.133.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003608; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.71.60.69"; content:"Host"; http_header; classtype:trojan-activity; sid:100003609; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"71.85.106.211"; content:"Host"; http_header; classtype:trojan-activity; sid:100003610; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.17.22.30"; content:"Host"; http_header; classtype:trojan-activity; sid:100003611; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.186.139.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100003612; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.189.180.98"; content:"Host"; http_header; classtype:trojan-activity; sid:100003613; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.214.69.226"; content:"Host"; http_header; classtype:trojan-activity; sid:100003614; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.229.230.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100003615; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.229.35.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100003616; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"72.31.40.122"; content:"Host"; http_header; classtype:trojan-activity; sid:100003617; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"73.204.216.103"; content:"Host"; http_header; classtype:trojan-activity; sid:100003618; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.101.1.159"; content:"Host"; http_header; classtype:trojan-activity; sid:100003619; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.108.224.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100003620; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.194.117.165"; content:"Host"; http_header; classtype:trojan-activity; sid:100003621; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.195.115.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100003622; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.199.84.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100003623; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.75.165.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100003624; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"75.127.141.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100003625; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"75.82.36.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100003626; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"75.83.102.27"; content:"Host"; http_header; classtype:trojan-activity; sid:100003627; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"75.99.213.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100003628; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.108.199.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100003629; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.170.11.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100003630; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.178.22.145"; content:"Host"; http_header; classtype:trojan-activity; sid:100003631; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.250.199.133"; content:"Host"; http_header; classtype:trojan-activity; sid:100003632; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.254.129.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100003633; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.84.134.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100003634; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"76.95.12.137"; content:"Host"; http_header; classtype:trojan-activity; sid:100003635; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.237.25.210"; content:"Host"; http_header; classtype:trojan-activity; sid:100003636; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.45.183.39"; content:"Host"; http_header; classtype:trojan-activity; sid:100003637; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.71.50.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100003638; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.71.52.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100003639; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.79.191.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100003640; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"77.89.203.238"; content:"Host"; http_header; classtype:trojan-activity; sid:100003641; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.179.225.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003642; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.186.155.18"; content:"Host"; http_header; classtype:trojan-activity; sid:100003643; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.187.141.144"; content:"Host"; http_header; classtype:trojan-activity; sid:100003644; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.187.240.125"; content:"Host"; http_header; classtype:trojan-activity; sid:100003645; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.187.41.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100003646; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.188.168.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100003647; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.188.188.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100003648; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.189.104.157"; content:"Host"; http_header; classtype:trojan-activity; sid:100003649; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.189.176.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100003650; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.23.172.81"; content:"Host"; http_header; classtype:trojan-activity; sid:100003651; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.72.231.120"; content:"Host"; http_header; classtype:trojan-activity; sid:100003652; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.8.225.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100003653; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.11.195.121"; content:"Host"; http_header; classtype:trojan-activity; sid:100003654; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.13.49.221"; content:"Host"; http_header; classtype:trojan-activity; sid:100003655; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.130.253.13"; content:"Host"; http_header; classtype:trojan-activity; sid:100003656; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.147.123.48"; content:"Host"; http_header; classtype:trojan-activity; sid:100003657; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.170.31.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100003658; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.175.42.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100003659; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.21.84.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100003660; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.7.170.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003661; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.79.58.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100003662; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.8.70.162"; content:"Host"; http_header; classtype:trojan-activity; sid:100003663; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"79.9.88.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100003664; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.107.89.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100003665; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.19.101.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100003666; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.211.181.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100003667; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.217.12.7"; content:"Host"; http_header; classtype:trojan-activity; sid:100003668; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"80.99.128.61"; content:"Host"; http_header; classtype:trojan-activity; sid:100003669; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.136.146.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100003670; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.165.44.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100003671; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.191.40.58"; content:"Host"; http_header; classtype:trojan-activity; sid:100003672; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.198.7.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100003673; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.213.111.60"; content:"Host"; http_header; classtype:trojan-activity; sid:100003674; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.213.141.184"; content:"Host"; http_header; classtype:trojan-activity; sid:100003675; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.215.199.29"; content:"Host"; http_header; classtype:trojan-activity; sid:100003676; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.218.187.113"; content:"Host"; http_header; classtype:trojan-activity; sid:100003677; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.218.195.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100003678; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.237.128.200"; content:"Host"; http_header; classtype:trojan-activity; sid:100003679; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.246.225.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100003680; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"81.92.36.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100003681; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.103.108.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100003682; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.135.196.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100003683; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.166.212.178"; content:"Host"; http_header; classtype:trojan-activity; sid:100003684; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.166.85.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100003685; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.207.61.194"; content:"Host"; http_header; classtype:trojan-activity; sid:100003686; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.209.250.155"; content:"Host"; http_header; classtype:trojan-activity; sid:100003687; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.211.156.38"; content:"Host"; http_header; classtype:trojan-activity; sid:100003688; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.62.110.252"; content:"Host"; http_header; classtype:trojan-activity; sid:100003689; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.62.53.77"; content:"Host"; http_header; classtype:trojan-activity; sid:100003690; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.138.72"; content:"Host"; http_header; classtype:trojan-activity; sid:100003691; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.139.92"; content:"Host"; http_header; classtype:trojan-activity; sid:100003692; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.154.214"; content:"Host"; http_header; classtype:trojan-activity; sid:100003693; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.80.187.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100003694; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.100.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100003695; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.106.65"; content:"Host"; http_header; classtype:trojan-activity; sid:100003696; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.108.172"; content:"Host"; http_header; classtype:trojan-activity; sid:100003697; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.131.158"; content:"Host"; http_header; classtype:trojan-activity; sid:100003698; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.19.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100003699; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.197.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003700; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.215.149"; content:"Host"; http_header; classtype:trojan-activity; sid:100003701; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.232.68"; content:"Host"; http_header; classtype:trojan-activity; sid:100003702; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.234.195"; content:"Host"; http_header; classtype:trojan-activity; sid:100003703; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.246.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100003704; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.28.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100003705; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.4.57"; content:"Host"; http_header; classtype:trojan-activity; sid:100003706; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.55.84"; content:"Host"; http_header; classtype:trojan-activity; sid:100003707; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.73.245"; content:"Host"; http_header; classtype:trojan-activity; sid:100003708; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.9.62"; content:"Host"; http_header; classtype:trojan-activity; sid:100003709; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.81.98.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100003710; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.165.237.163"; content:"Host"; http_header; classtype:trojan-activity; sid:100003711; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.234.147.99"; content:"Host"; http_header; classtype:trojan-activity; sid:100003712; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.234.218.42"; content:"Host"; http_header; classtype:trojan-activity; sid:100003713; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.242.253.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100003714; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"83.252.9.37"; content:"Host"; http_header; classtype:trojan-activity; sid:100003715; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.210.219.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100003716; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.210.219.213"; content:"Host"; http_header; classtype:trojan-activity; sid:100003717; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.212.219.127"; content:"Host"; http_header; classtype:trojan-activity; sid:100003718; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.224.162.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100003719; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.228.50.118"; content:"Host"; http_header; classtype:trojan-activity; sid:100003720; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.228.95.204"; content:"Host"; http_header; classtype:trojan-activity; sid:100003721; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.238.24.35"; content:"Host"; http_header; classtype:trojan-activity; sid:100003722; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.247.83.74"; content:"Host"; http_header; classtype:trojan-activity; sid:100003723; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.254.39.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100003724; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.33.111.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100003725; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.38.152.148"; content:"Host"; http_header; classtype:trojan-activity; sid:100003726; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.40.127.242"; content:"Host"; http_header; classtype:trojan-activity; sid:100003727; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"84.42.20.217"; content:"Host"; http_header; classtype:trojan-activity; sid:100003728; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003729; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.11.216"; content:"Host"; http_header; classtype:trojan-activity; sid:100003730; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.123.251"; content:"Host"; http_header; classtype:trojan-activity; sid:100003731; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.135.187"; content:"Host"; http_header; classtype:trojan-activity; sid:100003732; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.208.25"; content:"Host"; http_header; classtype:trojan-activity; sid:100003733; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.224.141"; content:"Host"; http_header; classtype:trojan-activity; sid:100003734; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.241.2"; content:"Host"; http_header; classtype:trojan-activity; sid:100003735; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.105.9.152"; content:"Host"; http_header; classtype:trojan-activity; sid:100003736; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.214.149.236"; content:"Host"; http_header; classtype:trojan-activity; sid:100003737; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.64.181.50"; content:"Host"; http_header; classtype:trojan-activity; sid:100003738; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.74.215.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100003739; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.97.130.227"; content:"Host"; http_header; classtype:trojan-activity; sid:100003740; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"85.97.195.129"; content:"Host"; http_header; classtype:trojan-activity; sid:100003741; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"86.35.43.220"; content:"Host"; http_header; classtype:trojan-activity; sid:100003742; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"87.121.98.51"; content:"Host"; http_header; classtype:trojan-activity; sid:100003743; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"87.61.89.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100003744; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.119.171.253"; content:"Host"; http_header; classtype:trojan-activity; sid:100003745; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.2.208.71"; content:"Host"; http_header; classtype:trojan-activity; sid:100003746; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.2.219.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100003747; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.225.222.128"; content:"Host"; http_header; classtype:trojan-activity; sid:100003748; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.247.96.19"; content:"Host"; http_header; classtype:trojan-activity; sid:100003749; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.248.136.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003750; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.248.51.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100003751; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.249.244.180"; content:"Host"; http_header; classtype:trojan-activity; sid:100003752; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.250.204.12"; content:"Host"; http_header; classtype:trojan-activity; sid:100003753; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.250.226.26"; content:"Host"; http_header; classtype:trojan-activity; sid:100003754; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"88.250.254.90"; content:"Host"; http_header; classtype:trojan-activity; sid:100003755; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.122.183.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100003756; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.136.197.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100003757; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.29.213.33"; content:"Host"; http_header; classtype:trojan-activity; sid:100003758; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.35.62.96"; content:"Host"; http_header; classtype:trojan-activity; sid:100003759; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.40.85.166"; content:"Host"; http_header; classtype:trojan-activity; sid:100003760; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"89.40.87.5"; content:"Host"; http_header; classtype:trojan-activity; sid:100003761; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"8poieq.bn.files.1drv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003762; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"90.152.144.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100003763; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.177.139.132"; content:"Host"; http_header; classtype:trojan-activity; sid:100003764; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.187.103.32"; content:"Host"; http_header; classtype:trojan-activity; sid:100003765; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.212.150.241"; content:"Host"; http_header; classtype:trojan-activity; sid:100003766; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.212.150.243"; content:"Host"; http_header; classtype:trojan-activity; sid:100003767; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.217.104.185"; content:"Host"; http_header; classtype:trojan-activity; sid:100003768; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.233.112.188"; content:"Host"; http_header; classtype:trojan-activity; sid:100003769; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.234.60.94"; content:"Host"; http_header; classtype:trojan-activity; sid:100003770; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.239.168.83"; content:"Host"; http_header; classtype:trojan-activity; sid:100003771; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.244.114.198"; content:"Host"; http_header; classtype:trojan-activity; sid:100003772; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.244.169.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100003773; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.92.16.244"; content:"Host"; http_header; classtype:trojan-activity; sid:100003774; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"91.98.4.181"; content:"Host"; http_header; classtype:trojan-activity; sid:100003775; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.114.191.82"; content:"Host"; http_header; classtype:trojan-activity; sid:100003776; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.241.78.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100003777; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.27.246.202"; content:"Host"; http_header; classtype:trojan-activity; sid:100003778; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.54.237.237"; content:"Host"; http_header; classtype:trojan-activity; sid:100003779; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"92.85.18.138"; content:"Host"; http_header; classtype:trojan-activity; sid:100003780; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.171.157.73"; content:"Host"; http_header; classtype:trojan-activity; sid:100003781; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.21.224.154"; content:"Host"; http_header; classtype:trojan-activity; sid:100003782; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.39.115.176"; content:"Host"; http_header; classtype:trojan-activity; sid:100003783; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.41.137.16"; content:"Host"; http_header; classtype:trojan-activity; sid:100003784; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.41.182.249"; content:"Host"; http_header; classtype:trojan-activity; sid:100003785; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.41.206.56"; content:"Host"; http_header; classtype:trojan-activity; sid:100003786; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.57.43.233"; content:"Host"; http_header; classtype:trojan-activity; sid:100003787; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"93.73.99.102"; content:"Host"; http_header; classtype:trojan-activity; sid:100003788; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.136.69.199"; content:"Host"; http_header; classtype:trojan-activity; sid:100003789; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.143.53.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100003790; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.154.17.170"; content:"Host"; http_header; classtype:trojan-activity; sid:100003791; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.154.82.190"; content:"Host"; http_header; classtype:trojan-activity; sid:100003792; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.200.16.22"; content:"Host"; http_header; classtype:trojan-activity; sid:100003793; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.224.83.208"; content:"Host"; http_header; classtype:trojan-activity; sid:100003794; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.43.139.153"; content:"Host"; http_header; classtype:trojan-activity; sid:100003795; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"94.53.120.109"; content:"Host"; http_header; classtype:trojan-activity; sid:100003796; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.132.129.250"; content:"Host"; http_header; classtype:trojan-activity; sid:100003797; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.154.20.231"; content:"Host"; http_header; classtype:trojan-activity; sid:100003798; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.158.19.130"; content:"Host"; http_header; classtype:trojan-activity; sid:100003799; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.170.113.52"; content:"Host"; http_header; classtype:trojan-activity; sid:100003800; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.170.201.34"; content:"Host"; http_header; classtype:trojan-activity; sid:100003801; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.181.155.112"; content:"Host"; http_header; classtype:trojan-activity; sid:100003802; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.214.52.64"; content:"Host"; http_header; classtype:trojan-activity; sid:100003803; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.54.11.179"; content:"Host"; http_header; classtype:trojan-activity; sid:100003804; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.60.146.134"; content:"Host"; http_header; classtype:trojan-activity; sid:100003805; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.60.6.114"; content:"Host"; http_header; classtype:trojan-activity; sid:100003806; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.66.196.63"; content:"Host"; http_header; classtype:trojan-activity; sid:100003807; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"95.9.120.40"; content:"Host"; http_header; classtype:trojan-activity; sid:100003808; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"96.239.73.246"; content:"Host"; http_header; classtype:trojan-activity; sid:100003809; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"96.47.147.169"; content:"Host"; http_header; classtype:trojan-activity; sid:100003810; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"97.68.140.254"; content:"Host"; http_header; classtype:trojan-activity; sid:100003811; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"97.96.199.75"; content:"Host"; http_header; classtype:trojan-activity; sid:100003812; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.0.210.218"; content:"Host"; http_header; classtype:trojan-activity; sid:100003813; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.0.239.142"; content:"Host"; http_header; classtype:trojan-activity; sid:100003814; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.113.239.207"; content:"Host"; http_header; classtype:trojan-activity; sid:100003815; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.116.72.119"; content:"Host"; http_header; classtype:trojan-activity; sid:100003816; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.128.147.115"; content:"Host"; http_header; classtype:trojan-activity; sid:100003817; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.178.242.44"; content:"Host"; http_header; classtype:trojan-activity; sid:100003818; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.249.236.11"; content:"Host"; http_header; classtype:trojan-activity; sid:100003819; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.28.200.139"; content:"Host"; http_header; classtype:trojan-activity; sid:100003820; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"98.30.24.54"; content:"Host"; http_header; classtype:trojan-activity; sid:100003821; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"99.150.245.203"; content:"Host"; http_header; classtype:trojan-activity; sid:100003822; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"99.33.195.164"; content:"Host"; http_header; classtype:trojan-activity; sid:100003823; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abcd.bg"; content:"Host"; http_header; classtype:trojan-activity; sid:100003824; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abclicks.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003825; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abissnet.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003826; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aboveandbelow.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003827; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"absoftechworld.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003828; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"absupplies.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003829; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"abyssos.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003830; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"academyshademani.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003831; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"acbick.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003832; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"accounts.thesmarttechhub.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003833; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aceeprc.com.aceeprc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003834; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"acellr.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003835; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aciabogados.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003836; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"acteon.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100003837; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"activateyourdiscount.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003838; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"activecost.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003839; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"adamorinmusic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003840; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"addahealingmusic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003841; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"adithimedia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003842; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"adithimedia.memengers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003843; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"admin.erapor.smk-alasror.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003844; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"admin.gentbcn.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003845; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"admin.grandoceanvilla.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003846; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"adventureexplorer.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003847; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aeropilates.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003848; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"afrimedspecialist.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003849; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agemn.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003850; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agenciadigitalwdys.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003851; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agenciatabletshouse.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003852; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agenda.gmelloinformatica.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003853; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agenmovie.xyz"; content:"Host"; http_header; classtype:trojan-activity; sid:100003854; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agentt.ac.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100003855; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agile8studio.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003856; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"agmcarpetcare.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003857; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aiqtest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003858; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ajpharmaholding.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003859; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ajstudiollc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003860; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aktyd05.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100003861; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"al-wahd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003862; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alasdemariposas.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003863; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alemelektronik.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003864; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alena1971.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100003865; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alexdubai.com.aldiabsteel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003866; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alka.institute"; content:"Host"; http_header; classtype:trojan-activity; sid:100003867; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"allforcreative.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003868; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alltheway.travel"; content:"Host"; http_header; classtype:trojan-activity; sid:100003869; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"alpaylar.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003870; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"am-concepts.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100003871; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amamontajes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003872; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amarresdeamorymaestroshechiceros.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003873; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amarteargentina.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100003874; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amenyan.zouri.jp"; content:"Host"; http_header; classtype:trojan-activity; sid:100003875; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"amos524.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003876; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ams.alvinasschools.org.ng"; content:"Host"; http_header; classtype:trojan-activity; sid:100003877; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anantam.net.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003878; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andreelapeyre.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003879; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andremaraisbeleggings.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003880; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andres.ac.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100003881; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andres.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100003882; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"andreshconcejal.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003883; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"angelazgheibld.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003884; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"angelsdetour.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003885; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"angloteste.bigprime.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003886; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anhung1102.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100003887; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"anysbergbiltong.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003888; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"apartamentoscitta.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003889; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"api-ms.cobainaja.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003890; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"api.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003891; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"api.quocbao.biz"; content:"Host"; http_header; classtype:trojan-activity; sid:100003892; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"api.sampy.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100003893; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aplicativoparasindicato.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003894; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"apoolcondo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003895; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"app.adsensearticle.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003896; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"app.prerana.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100003897; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"apps.saintsoporte.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003898; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aqv.news"; content:"Host"; http_header; classtype:trojan-activity; sid:100003899; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"areyoulivingwell.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003900; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"arsapetrolab.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003901; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"artedibujoyarquitectura.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003902; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ask-regard.call-save.biz"; content:"Host"; http_header; classtype:trojan-activity; sid:100003903; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"atfile.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003904; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"athenacapsg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003905; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"atlasconcreteworks.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003906; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"attach.66rpg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003907; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"atteuqpotentialunlimited.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003908; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"augustair.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003909; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"aulist.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003910; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"australiafashions.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003911; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"automaticrefreshments.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003912; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"avadhanagames.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003913; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"avissrilanka.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003914; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ayamallah.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003915; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"azmeasurement.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003916; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"azraktours.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003917; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"backgrounds.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003918; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"backup.agewsage.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003919; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"badeggdesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003920; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"balealgodon.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100003921; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bangkok-orchids.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003922; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"barcionstw.eastus.cloudapp.azure.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003923; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bary.sz4h.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003924; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"basma.com.kw"; content:"Host"; http_header; classtype:trojan-activity; sid:100003925; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bausch.kr-atlas.monaxikoslykos@zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003926; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bavhome.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003927; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bbia.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003928; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bcmt.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003929; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bcrg.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003930; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bearcatpumps.com.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100003931; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"beautincollagen.rs"; content:"Host"; http_header; classtype:trojan-activity; sid:100003932; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bekape.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003933; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bespokeweddings.ie"; content:"Host"; http_header; classtype:trojan-activity; sid:100003934; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bestcarenepal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003935; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"betone.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003936; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"betycopaints.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003937; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"beveragesmiami.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003938; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bhavaniengineering.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003939; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bigbag.wootraining.certificacion.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003940; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bilbosaquet.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100003941; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bilhen.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003942; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"billing.rahitechnosoft.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003943; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"birdi.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003944; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"birminghamlink.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003945; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.callensaxen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003946; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.oyinblogs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003947; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bmlifestyle.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003948; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bnrbook.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003949; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bnrnews.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100003950; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bodenstein.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003951; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"booksearch.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003952; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bounces.mi-fs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003953; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bpo.correct.go.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100003954; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bradleyinstitute.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003955; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brandtrust.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003956; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brendanquine.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003957; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brideofmessiah.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003958; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bridesofmaldives.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003959; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brightmega.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003960; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brightonrooms.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003961; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"brightstarshop.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003962; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"browardinsurancemiami.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003963; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bt2.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003964; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bucrinsuranlceonlines.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003965; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"buenavista.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100003966; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bullseyemedia.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003967; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"busandvanrentalmalaysia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003968; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"buscascolegios.diit.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100003969; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"business.softberg.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100003970; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"buyingmusiconline.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003971; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"bwsr.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100003972; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"c.oooooooooo.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100003973; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"c0140529.ferozo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003974; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"caballo.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100003975; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cacapavaonline.sdserver144.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100003976; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"calgaryautorepairservice.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003977; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"callbury.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100003978; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"camminachetipassa.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100003979; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cancer.educandome.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100003980; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"capitalgroup-kw.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003981; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"capitalnewsagency.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003982; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"capoeiraventrelivre.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003983; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cashyinvestment.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100003984; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"casoauditores.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003985; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"catchperch.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003986; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"catchpoolshetlands.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100003987; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cazyacustomfurniture.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003988; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ccauthority.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100003989; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cdaonline.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100003990; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cec.asso.ac-amiens.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100003991; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cendekiabinaaksara.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003992; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cespol-bote.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100003993; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cfs5.tistory.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003994; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ch.rmu.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100003995; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chardhamdodham.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003996; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cheacrilnsurances.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003997; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chealablilitycarinsurances.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100003998; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chezalice.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100003999; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"childselect.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004000; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chinhdropfile.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004001; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"chinhdropfile80.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004002; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cible-energy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004003; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cifeer.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004004; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"citycapproperty.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004005; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cityglobalgospel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004006; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"civi.istmejia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004007; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cleanbydesignllc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004008; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cloud.fc.co.mz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004009; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"clurbgolf.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004010; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"codsambal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004011; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"colinde.pricesne.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004012; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"colorpak.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004013; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"competancy.indigoconsult.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004014; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"conceptimagine.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100004015; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"config.cqhbkjzx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004016; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"constructoralyon.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004017; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"consulateins.solucioneslink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004018; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"contributeindustry.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004019; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"controladoradeplagasmm.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004020; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"copelandscapes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004021; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"corporativos.com.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004022; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"coulsongraphics.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004023; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"coutler.newreadermedia.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004024; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"covid19.cyberschool.or.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004025; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cr-sq.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004026; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crearechile.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004027; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"creationskateboards.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004028; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crecerco.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004029; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crittersbythebay.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004030; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crm.notariavieitoyvelamazan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004031; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"crscorretordeimoveis.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004032; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cse-engineer.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004033; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"csnserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004034; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cubescargoexpress.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004035; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cubrebocasenpuebla.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004036; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"curasoles.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004037; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"currantmedia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004038; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cwa.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004039; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cyber.searchkero.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004040; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cyclomove.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004041; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"cynkon.kairoscs.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004042; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"czas.dbstrony.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004043; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"czsl.91756.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004044; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"d.powerofwish.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004045; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"d9.99ddd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004046; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"da.alibuf.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004047; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"damagedessentialtelecommunications.testmail4.repl.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004048; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dandyair.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004049; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dannexgh.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004050; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dartoonpictures.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004051; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"data.cdevelop.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004052; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"data.over-blog-kiwi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004053; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"datapolish.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004054; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dating.khokhas.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004055; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"datsom.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004056; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"daunhotq10.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004057; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"davethompson.me.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004058; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"davidmcguinness.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004059; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dayspringdaisies.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004060; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dd.qiyuea.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004061; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"de.gsearch.com.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004062; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"decifrar.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004063; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"deigratia2.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004064; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dekovizyon.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004065; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"demo-cliente.mindcreative.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004066; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"demo6.hiites.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004067; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dent-estet.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004068; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dental.xiaoxiao.media"; content:"Host"; http_header; classtype:trojan-activity; sid:100004069; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dentalalliance.se"; content:"Host"; http_header; classtype:trojan-activity; sid:100004070; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"designerliving.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004071; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"desiringhands.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004072; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"despertaresi.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004073; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"destinymc.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004074; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"detorre.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100004075; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dev-interestingtech.pantheonsite.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100004076; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dev.sebpo.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004077; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dfcf.91756.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004078; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dfsfcsfcdsfsdvcfsvcscv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004079; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"diamantenegro.mi-fs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004080; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dienmayminhhung.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004081; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"digilib.dianhusada.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004082; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"djking.f3322.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004083; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.1003b.56a.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004084; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.198424.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004085; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.installcdn-aws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004086; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.packetstormsecurity.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004087; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.rina-roleplay.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004088; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dl.zkytech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004089; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dns.cyberium.cc"; content:"Host"; http_header; classtype:trojan-activity; sid:100004090; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dockerupdate.anondns.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004091; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"docman.orientalservices.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004092; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dodsonimaging.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004093; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dokan.blueberrytec.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004094; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dom-chel74.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004095; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dom.daf.free.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004096; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"doncedyhall.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004097; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"donghobinhminh.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004098; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dongphuctop.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004099; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dosame.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004100; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dosman.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004101; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dovberger.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004102; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.flash-plays.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004103; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.pcclear.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004104; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.posti-fi-fsa.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100004105; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.posti-fi-fwa.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100004106; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.posti-fi-ij.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100004107; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.posti-fi-in.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100004108; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.posti-fi-iz.top"; content:"Host"; http_header; classtype:trojan-activity; sid:100004109; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.udashi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004110; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down.webbora.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004111; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"down1.arpun.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004112; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.caihong.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004113; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.doumaibiji.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004114; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.exrnybuf.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004115; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.kaobeitu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004116; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.pdf00.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004117; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.rising.com.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004118; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.skycn.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004119; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"download.zjsyawqj.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004120; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"downloads.jxtsteel.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004121; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dragonsknot.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004122; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drbaby.com.sa"; content:"Host"; http_header; classtype:trojan-activity; sid:100004123; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drohnen.ensenanzainteligente.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004124; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drools-moved.46999.n3.nabble.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004125; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"drsha.innovativesolutions.mobi"; content:"Host"; http_header; classtype:trojan-activity; sid:100004126; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dsenterprize.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004127; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dsspainting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004128; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"du-wizards.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004129; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"duque.guantanameratravel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004130; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dutapp.wisolve.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004131; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"duvalcharter.dekitout.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004132; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dx.qqyewu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004133; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"dzinestudio87.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004134; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"e-commerce.saleensuporte.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004135; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"e.sldov.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004136; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ebruyatkin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004137; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"econews.treegle.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004138; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"efficientegroup.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004139; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"elliot.newreadermedia.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004140; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"en.baoend.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004141; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"enc-tech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004142; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"endurotanzania.co.tz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004143; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ennovate.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004144; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"enriquecendocomconsorcio.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004145; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"envios.petpienso.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004146; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"equimination.ee"; content:"Host"; http_header; classtype:trojan-activity; sid:100004147; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"escola.probommar.org.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004148; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"esnconsultants.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004149; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"essentia.org.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004150; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"eubanks7.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004151; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"evidencemarketing.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100004152; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"exilum.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004153; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"exitoalfaomega.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004154; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"extrovertoffers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004155; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"f1sol.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004156; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"familydentist.site"; content:"Host"; http_header; classtype:trojan-activity; sid:100004157; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"farmaciasdrogaminas.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004158; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"faveraprojects.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004159; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fc.co.mz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004160; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"felicienne.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004161; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fi.bonitastores.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004162; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"files.martellexpress.us"; content:"Host"; http_header; classtype:trojan-activity; sid:100004163; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"files6.uludagbilisim.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004164; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"final.makkahkmcc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004165; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fineartgallerym.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004166; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fkd.derpcity.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004167; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"flintspin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004168; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"flyingbuddhadesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004169; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fmjplastering.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004170; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fms.buladde.or.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100004171; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"foothills.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004172; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"footweardirect.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004173; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"forum.mdb.nu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004174; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fotoobjetivo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004175; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"foundationrepairhoustontx.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004176; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"foxeps.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004177; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"freecnetdownload.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004178; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"freisites.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004179; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ftp.n3twork30cm.ml"; content:"Host"; http_header; classtype:trojan-activity; sid:100004180; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fullelectronica.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004181; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"funletters.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004182; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"fusionfiresolutions.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004183; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"futuregraphics.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004184; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gametwogame.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004185; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"garayvidalabogados.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004186; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"garciadogshow.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004187; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"garenanow.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004188; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"garenanow4.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004189; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gbbulls.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004190; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gcpc.co.id.chronoscurtain.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004191; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"generaldeviales.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004192; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gfmodd1.webselffiles01.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004193; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gfold1.webselffiles01.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004194; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ghettohub.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004195; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ghislain.dartois.pagesperso-orange.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004196; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"giadungg7.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004197; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"giddos.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100004198; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gilliem.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004199; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"girotexuniformes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004200; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"giteletropical.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004201; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"globaltask.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004202; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"glowinmedia.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100004203; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gmtransformationacademy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004204; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gmvadmission.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004205; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gnimelf.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004206; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gnscrew.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100004207; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gold.investforex.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004208; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcake.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004209; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcoastoffice365.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004210; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcoastoffice365.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004211; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcupmortgage.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004212; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"golden-memories-funerals.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004213; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldmen.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004214; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gorecycle.fahadjutt.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004215; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gracejukes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004216; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"grupoinmare.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004217; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gruposelt.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004218; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gs.monerorx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004219; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"guide-to-cell-phones.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004220; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gulfac-house.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004221; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"gvpcdpgc.edu.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004222; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"habbotips.free.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004223; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hagebakken.no"; content:"Host"; http_header; classtype:trojan-activity; sid:100004224; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"harrisauto.no"; content:"Host"; http_header; classtype:trojan-activity; sid:100004225; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"harshraval.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004226; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hd11315.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004227; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hdkamera2003.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004228; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hdrest.fastlinktz.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004229; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hds.sz4h.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004230; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"healthy20.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004231; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hechiceriadeamormaestrabelen.com.hechiceriadeamormaestrabelen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004232; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hellogorgeous.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004233; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"help.hizuko.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004234; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"herchinfitout.com.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100004235; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hhaward.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004236; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"highlandroadcoc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004237; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"highlandslasvegas.atakdev.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004238; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hindi.factsriver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004239; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hiptool.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004240; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hitpe.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004241; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hitstation.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004242; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hmpmall.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004243; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hoagietesting10.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004244; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hoayeuthuong-my.sharepoint.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004245; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"holmesprpmgmt.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004246; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"homefindersolutions.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004247; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hongluosi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004248; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hookedupboatclub.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004249; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hostelkielce.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004250; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hostzaa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004251; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"houstonshutters.site"; content:"Host"; http_header; classtype:trojan-activity; sid:100004252; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hr2019.vrcom7.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004253; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hseda.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004254; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hsmwebapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004255; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"htownbars.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004256; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hubtech.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004257; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"hunggiang.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004258; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"husamiyahschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004259; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iam313.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004260; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"icon.shatangmu.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004261; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idea-secure-login.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004262; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idilsoft.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004263; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idj.no"; content:"Host"; http_header; classtype:trojan-activity; sid:100004264; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"idvindia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004265; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iesanjosemonitos.edu.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004266; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ikexpert.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004267; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ilrafrica.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004268; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"images.jermiau.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004269; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"imbueautoworx.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004270; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"imperiumtherapy.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004271; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"in-tune2016.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004272; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"incodimsa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004273; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"incrediblepixels.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004274; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"incredicole.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004275; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"industriasyuli.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004276; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"infair.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004277; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"infovator.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004278; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"innatosbrand.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004279; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"inodesthetotaldesigners.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004280; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"inovations.searchkero.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004281; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"inrajahmundry.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004282; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"insignificantfinecore.testmail4.repl.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004283; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"instantindialoan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004284; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"instvisionmexico.edu.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004285; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"intellectsmart.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004286; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"intersel-idf.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004287; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"intuitiveideas.com.my"; content:"Host"; http_header; classtype:trojan-activity; sid:100004288; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"inversiones.arrayanfinanciero.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004289; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"invest.xpcorporative.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004290; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ipmes.ma"; content:"Host"; http_header; classtype:trojan-activity; sid:100004291; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iremart.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100004292; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iris101.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004293; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iscamenabe.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004294; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ismf.com.ng"; content:"Host"; http_header; classtype:trojan-activity; sid:100004295; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"iso-dubai.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004296; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"israrulhaq.me"; content:"Host"; http_header; classtype:trojan-activity; sid:100004297; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"isrorg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004298; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"issmbour.falllo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004299; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"isso.ps"; content:"Host"; http_header; classtype:trojan-activity; sid:100004300; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"it123.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004301; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"itc-demo.softgig.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100004302; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"itconsultus.com.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004303; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jamesjorgensen.newreadermedia.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004304; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jamiekaylive.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004305; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jamshed.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004306; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jansen-heesch.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004307; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jathra.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004308; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jay.diamondrelationscrm.us"; content:"Host"; http_header; classtype:trojan-activity; sid:100004309; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jebs.net.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004310; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jeffdahlke.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004311; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jhayesconsulting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004312; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jiaoyuzixun.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004313; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jing-da.com.tw"; content:"Host"; http_header; classtype:trojan-activity; sid:100004314; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jktnet.xyz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004315; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jmtc.91756.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004316; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jnanbharati.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004317; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jobs.thebeessolution.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004318; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"joelbonissilver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004319; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"join.cl8movement.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004320; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"josegene.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004321; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"josuarochoa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004322; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jpwoodfordco.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004323; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jumpmanualjacobhiller.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004324; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jupiter.toxsl.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004325; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"jurgensen.newreadermedia.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004326; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"justinscott.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004327; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kaizenjanitorial.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004328; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kalawatihomes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004329; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kalpataru-elitus-mulund.thakkers.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004330; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"karer.by"; content:"Host"; http_header; classtype:trojan-activity; sid:100004331; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"katanvetov.co.il"; content:"Host"; http_header; classtype:trojan-activity; sid:100004332; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kbdom.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004333; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kensingtondriving.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004334; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kevinjewelry.com.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004335; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"keywatch.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004336; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kingssa.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004337; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kjcpromo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004338; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kleinendeli.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004339; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"korrectconceptservices.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004340; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ktb.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004341; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kubatoglubaklava.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004342; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kumaralok.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004343; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kwanfromhongkong.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004344; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"kz.sldov.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004345; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lab18.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100004346; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lacasadelosalebrijes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004347; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ladylabonde.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004348; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lameguard.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004349; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"landing.yetiapp.ec"; content:"Host"; http_header; classtype:trojan-activity; sid:100004350; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"laodongnhat.vn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004351; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"laravel.pointersoftwares.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004352; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lasermobilesounds.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004353; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lauratomismith.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004354; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lautarosanmiguel.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004355; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lawforall.edu.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004356; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lceventos.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004357; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ld.mediaget.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004358; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ldgcorp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004359; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"learning.real-academy.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004360; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"leasiacherise.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004361; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"leczkregoslup.acelero.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004362; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"legend.nu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004363; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"leluibuffet.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004364; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lestesteux.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100004365; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"libantravel.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004366; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"library.arihantmbainstitute.ac.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004367; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"library.uib.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004368; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lickmylash.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004369; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lidoraggiodisole.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100004370; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lifebeam.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004371; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lindnerelektroanlagen.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004372; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"linkintec.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004373; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"litroxlitro.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004374; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"livetrack.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004375; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydsindian.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004376; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lm.stagingarea.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004377; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lmaancha.co.il"; content:"Host"; http_header; classtype:trojan-activity; sid:100004378; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lms.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004379; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lms.login2.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004380; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lmvirtualbookkeeping.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004381; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lnt-rejuve-360.thakkers.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004382; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"location-voitures.ma"; content:"Host"; http_header; classtype:trojan-activity; sid:100004383; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"login.trezor.com.stockfootagesindia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004384; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"logotypfabriken.se"; content:"Host"; http_header; classtype:trojan-activity; sid:100004385; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lotix.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004386; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lotusanddragonfly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004387; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lp.definerisco.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004388; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lp.difusodesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004389; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lp.juancamilogarciareyes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004390; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"lp.tecnimasdecolombia.com.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004391; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ltc.typoten.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004392; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"luckybrownie.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004393; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"luminouspneuma.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004394; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"luxomodels.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004395; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"m-technics.kz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004396; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"m.estudiomoros.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004397; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"madicon.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004398; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"magianegramagiablancayamarres.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004399; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.bs-eiendomme.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004400; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.golimoapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004401; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.jeffsono.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004402; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"maksi.feb.unib.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004403; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"malaya.tv"; content:"Host"; http_header; classtype:trojan-activity; sid:100004404; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"malwarecoding.github.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100004405; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"managed.oss-cn-beijing.aliyuncs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004406; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"managemysalon.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004407; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"manantialesdelnorte.uy"; content:"Host"; http_header; classtype:trojan-activity; sid:100004408; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marcapinyo.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004409; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mario-sunjic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004410; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mariobrown.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004411; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mariotessarollo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004412; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marketinfosales.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004413; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marketing.enexusgroup.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004414; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"marksidfgs.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100004415; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"masjidhabeebiyarazviya.mysunni.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004416; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"materialescantu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004417; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"matruchhaya.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004418; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mattysplayground.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004419; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"maxtox.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004420; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mbgrm.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004421; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mbsolutions.ge"; content:"Host"; http_header; classtype:trojan-activity; sid:100004422; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mdasa.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004423; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"medevlb.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004424; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"media-server.skyinternet.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004425; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mediamaster.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004426; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"medianews.ge"; content:"Host"; http_header; classtype:trojan-activity; sid:100004427; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"medistaffconsulting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004428; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"meditreat.itwebservice.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004429; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"meeweb.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004430; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"megamart.afnan-amc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004431; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"merbay.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004432; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"merkathink.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004433; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mertlog.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004434; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"metalin-cr.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004435; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mettaanand.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004436; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"meuoculosnanet.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004437; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mfevr.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004438; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mhkdhotbot.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004439; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mhkdhotbot80.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004440; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"micalle.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004441; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"michaelphilip.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004442; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"michimal2.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004443; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"microblading.mirliandias.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004444; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"microcomm-group.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004445; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"midlandtexasconstruction.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004446; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mindfulbuildingandliving.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004447; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mingguanwms.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004448; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"minuevavida.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004449; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mis.nbcc.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100004450; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"misterson.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004451; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mixr.at"; content:"Host"; http_header; classtype:trojan-activity; sid:100004452; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mkontakt.az"; content:"Host"; http_header; classtype:trojan-activity; sid:100004453; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mktf.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004454; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mmogollon.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004455; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mncarteam.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004456; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mobile.illumetechnology.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004457; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"modelhouseturkey.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004458; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"modernmanna.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004459; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"monetization.business"; content:"Host"; http_header; classtype:trojan-activity; sid:100004460; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"moninediy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004461; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mopai.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100004462; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"motorcomunicacion.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004463; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"msacontabil.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004464; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mtspsmjeli.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004465; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"muzimbiti.xigubo.co.mz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004466; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mxpiqw.am.files.1drv.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004467; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mydatebook.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004468; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mymlql.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004469; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"myritz.vettickal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004470; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"myscape.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004471; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"mysura.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100004472; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"namnyak.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100004473; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nap.mgsservers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004474; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"navayurveda.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004475; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nec-i.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004476; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nelitrianggraeni.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004477; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nerve.untergrund.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004478; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nettube.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004479; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"networkwheels.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004480; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"neuroenergy.fahadjutt.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004481; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"neuromedic.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004482; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"neverseenshop.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004483; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newinfinitysynergy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004484; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"news.dbstrony.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004485; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newtreedesign.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004486; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newtrendeg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004487; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newvisionopticallab.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004488; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"newxing.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004489; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nextdigitalday.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004490; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ngdaycare.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004491; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nguyenkekhuyen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004492; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nhorangtreem.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004493; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nicolas.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100004494; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nidhi.iexist.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004495; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nikanpolimer.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100004496; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nilehouse.co.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100004497; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nilinkeji.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004498; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"njtiledesigncenter.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004499; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nobius.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004500; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocalnoodle.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004501; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nomadicbees.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004502; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nonnarina.ax"; content:"Host"; http_header; classtype:trojan-activity; sid:100004503; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"notamuzikaletleri.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004504; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"notif1.priruz.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004505; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ns1.the-widyantos.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004506; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nsb.org.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004507; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nsheldon.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004508; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nurmarkaz.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004509; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nuthuassociates.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004510; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nuwagi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004511; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"nyeh2o.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004512; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oakleyandfriends.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004513; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"obseques-conseils.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004514; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ocean.tecnasulstore.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004515; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ohe.ie"; content:"Host"; http_header; classtype:trojan-activity; sid:100004516; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ohsewgorgeous.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004517; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oknoplastik.sk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004518; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oleholeh.memangbeda.website"; content:"Host"; http_header; classtype:trojan-activity; sid:100004519; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"olirecords.mixture.ltd"; content:"Host"; http_header; classtype:trojan-activity; sid:100004520; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"olooom.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004521; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omaia.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004522; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omaromatic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004523; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omega.az"; content:"Host"; http_header; classtype:trojan-activity; sid:100004524; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oms.pappai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004525; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"omscoc.pappai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004526; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"onedigitalcard.granvizionnecorp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004527; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"onedrive.listifyapp.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004528; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"online.creedglobal.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004529; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"onlinestatis.bar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004530; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ont.proman.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004531; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"open.warehousesaas.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004532; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"opolis.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100004533; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"optimus.com.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100004534; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"optitechsa.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004535; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"order.bizpeed.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004536; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"orientgatewayltd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004537; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"orion445.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004538; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"oserve.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004539; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"otolithenrichment.fahadjutt.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004540; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ottimade.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004541; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ourteam.searchkero.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004542; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ozemag.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004543; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"p1.lingpao8.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004544; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"p3.zbjimg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004545; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"p6.zbjimg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004546; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pablobrothel.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004547; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pacificgroup.ws"; content:"Host"; http_header; classtype:trojan-activity; sid:100004548; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pacwebdesigns.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004549; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pagos.krayem.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004550; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"palochusvet.szm.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004551; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"parallel.rockvideos.at"; content:"Host"; http_header; classtype:trojan-activity; sid:100004552; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"parejasfelices.mi-fs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004553; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"parkhussion.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004554; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pastorpaulocosta.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004555; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"patch2.51lg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004556; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"patch2.99ddd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004557; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"patch3.99ddd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004558; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"paths.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004559; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"paulmercier.biz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004560; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"payerrealty.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004561; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"payments.atifsiddiqui.me"; content:"Host"; http_header; classtype:trojan-activity; sid:100004562; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pcsoori.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004563; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pd.oceaniarp.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004564; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"perpus.onlineman7-jombang.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004565; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"perpustekim.untirta.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004566; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pestoclean.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004567; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"petercollie.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004568; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ph4s.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004569; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"phenhuong.sanpham.online"; content:"Host"; http_header; classtype:trojan-activity; sid:100004570; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"phittc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004571; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"photo360.kubooking.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004572; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"photographytipsclub.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004573; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pink99.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004574; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pizzabarletta.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004575; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"plasfan.ind.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004576; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pmglance.startwriteup.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004577; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pokojewewladyslawowie.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004578; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pole.com.vc"; content:"Host"; http_header; classtype:trojan-activity; sid:100004579; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pool.phxdir.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004580; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pooltablemoversdenver.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004581; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"posmicrosystems.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004582; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"poulman.panagiotopoulos-tours.gr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004583; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ppdb.smk-ciptaskill.sch.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004584; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prestasicash.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004585; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prestigehomeautomation.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004586; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prishaartcreations.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004587; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"production.sparshims.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004588; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"programaoperadoronline.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004589; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"project.exquitec.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004590; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"promolyko.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004591; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"promotoradescomplica.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004592; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"promoversdubai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004593; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"propertiq.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004594; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"propertiq2.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004595; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prosoc.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004596; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prostar.priruz.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004597; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prosyarmakassar.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004598; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"provence.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004599; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"prueba.danielluza.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004600; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pujashoppe.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004601; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"punchdialogues.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004602; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"punjabdevelopersassociation.com.pk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004603; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"pvcprinting.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004604; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"qadir.tickfa.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100004605; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"qatarglobalconsulting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004606; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"qmsled.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004607; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"quartier-midi.be"; content:"Host"; http_header; classtype:trojan-activity; sid:100004608; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"querocar.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004609; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rachmat-assuhaimi.my.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004610; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rainbowisp.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004611; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"raodigitalmedia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004612; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rarlabarchiver.ac"; content:"Host"; http_header; classtype:trojan-activity; sid:100004613; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rasadbar.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100004614; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rashika.ascarvalho.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004615; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ratemyfenancialadvisor.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004616; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ravenproductionsltd.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004617; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rc.ixiaoyang.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004618; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"readymmade.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004619; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"redchillicrackers.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004620; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"reifenquick.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004621; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"relaxindulge.co.nz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004622; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"renehavis.com.ua"; content:"Host"; http_header; classtype:trojan-activity; sid:100004623; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"repatriacioncolombia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004624; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"res.uf1.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100004625; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"reseller.digimitra.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004626; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"resuco.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004627; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rezkabum.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004628; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rhema.com.sg"; content:"Host"; http_header; classtype:trojan-activity; sid:100004629; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"richancyber.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004630; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"richmondminerals.co.zm"; content:"Host"; http_header; classtype:trojan-activity; sid:100004631; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rinaefoundation.org.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004632; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rinkaisystem-ht.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004633; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"riverfox.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004634; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rkcable.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004635; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rkverify.securestudies.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004636; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"roadfurylifts.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004637; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"robertmcardle.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004638; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"robertsinclair.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004639; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"robinhood-sports.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004640; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"romanianpoints.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004641; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ronnietucker.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004642; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"roomsvc.servegate.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004643; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"roshan.academy"; content:"Host"; http_header; classtype:trojan-activity; sid:100004644; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"roshnijewellery.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004645; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rs-toolkit.mikestclair.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004646; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rsgym.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004647; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rubazar.pro"; content:"Host"; http_header; classtype:trojan-activity; sid:100004648; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rubycityvietnam.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004649; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ruch.newreadermedia.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004650; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ruisgood.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004651; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ruwadalkuwait.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004652; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"rzminc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004653; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"s.51shijuan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004654; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"s.thechinesemuslim.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004655; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sacredscentsonline.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004656; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"safcol-colors.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004657; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"safehubsecurity.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100004658; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"safety.nanotechproautocare.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004659; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sahathaikasetpan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004660; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"saisoftwareinc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004661; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"salecorner.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004662; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sandovalgraphics.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004663; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"santebarleyshop.jakewebtechs.ml"; content:"Host"; http_header; classtype:trojan-activity; sid:100004664; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"santyago.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004665; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sarakem.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004666; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sasystemsuk.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004667; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"savasaachi.systems"; content:"Host"; http_header; classtype:trojan-activity; sid:100004668; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"scarfaceindustries.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004669; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"scglobal.co.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100004670; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"schalke04rss.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004671; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"scheff.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004672; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"schoolbustracker.softgig.co.ke"; content:"Host"; http_header; classtype:trojan-activity; sid:100004673; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sec-doc-w.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004674; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure-doc-reader.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004675; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"segalsmetals.elin.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004676; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sellmyphonela.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004677; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"senbiaojita.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004678; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sentierodelviandante.ml"; content:"Host"; http_header; classtype:trojan-activity; sid:100004679; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"serendibsourcing.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004680; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"servicemhkd.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004681; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"servicemhkd80.myvnc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004682; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"serviciovirtual.com.ar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004683; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"seyranikenger.com.tr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004684; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sgessy.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004685; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shaheentbfoundation.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004686; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shahikhana.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004687; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sharkrigs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004688; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sharpelevators.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004689; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shembefoundation.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004690; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shivakunwar.com.np"; content:"Host"; http_header; classtype:trojan-activity; sid:100004691; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shoblasaathitrust.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004692; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shooka-co.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004693; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shop.goldspot.agency"; content:"Host"; http_header; classtype:trojan-activity; sid:100004694; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shopsofe.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004695; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"shrushtiinfotech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004696; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sibernetix.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004697; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"siddharthpanditpautra.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004698; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sige.brisainformatica.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004699; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"signatureads.co.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004700; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"siili.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004701; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"simoneporzi.it"; content:"Host"; http_header; classtype:trojan-activity; sid:100004702; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"simplithy.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004703; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sindicato1ucm.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004704; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sindpol.tiejuris.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004705; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sinergidwireka.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004706; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sipahielektrik.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004707; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"siperb.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004708; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sistelligent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004709; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"skkksolo.beweiretail.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004710; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"skyflyfares.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004711; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"skyscan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004712; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smarthouseforum.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100004713; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smarts.tj"; content:"Host"; http_header; classtype:trojan-activity; sid:100004714; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smartzedu.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004715; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smokeandgrowrichtour.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004716; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"smokesolutionindia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004717; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sobethuacademy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004718; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"soft.officelabo.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004719; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sohs.conceptechs.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004720; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"solar.amazingtribe.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004721; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"solo2.dbstrony.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004722; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"somcorbera.cat"; content:"Host"; http_header; classtype:trojan-activity; sid:100004723; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"somir.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004724; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"soralapps.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004725; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sorteio.orgaostalita.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004726; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sosgsm.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004727; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sota-france.fr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004728; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sowingminerals.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004729; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"space.proactint.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004730; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spaceframe.mobi.space-frame.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004731; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"special-key.cf"; content:"Host"; http_header; classtype:trojan-activity; sid:100004732; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spent.com.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004733; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spetsesyachtcharter.gr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004734; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spititourism.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004735; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"spittinfire.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004736; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sports-net.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004737; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"src1.minibai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004738; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sreenivasapaintingworks.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004739; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sriglobalit.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004740; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"srvmanos.no-ip.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004741; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ss.monita.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004742; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"staging.apparelpunch.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004743; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"starcountry.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004744; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"static.3001.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004745; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"statsres.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004746; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"statssound.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004747; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"statsspot.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004748; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"statsvilla.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004749; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stattilion.bar"; content:"Host"; http_header; classtype:trojan-activity; sid:100004750; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stiepancasetia.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004751; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stott-thompson.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004752; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"stratexec.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004753; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"streetdemo.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004754; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"suboldesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004755; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sumerians.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004756; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sunbrero.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004757; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sunmarkholidays.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004758; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"supermercadostia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004759; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"support-4-free.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004760; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"support.clz.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100004761; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"supportit.online"; content:"Host"; http_header; classtype:trojan-activity; sid:100004762; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"surestdysbonescagexc.dns.army"; content:"Host"; http_header; classtype:trojan-activity; sid:100004763; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sw.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004764; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sweaty.dk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004765; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sweet-diet.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004766; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"swentsai.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004767; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"swiftlogisticseg.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004768; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"swwbia.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004769; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"syedpro.dezinetimes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004770; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"syracusecoffee.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004771; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sys.pbmadu.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004772; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"systemsecuritylock.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004773; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"sytraders.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004774; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"t.honker.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004775; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tacticohosting.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004776; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tadoo.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100004777; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tafsantoursandtravels.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004778; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tallyinvoicecustomization.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004779; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"taltus.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004780; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tapalkoedacoffee.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004781; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tarravalleyfoods.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004782; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"taurus.ug"; content:"Host"; http_header; classtype:trojan-activity; sid:100004783; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"taxicabsrilanka.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004784; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"taxpos.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004785; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tc.snpsresidential.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004786; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tcy.198424.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004787; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tdsp.yngw518.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004788; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"techgms.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004789; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"technogreen.crmmanivela.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004790; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"technohub.searchkero.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004791; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tecnicaencolectores.com.mx"; content:"Host"; http_header; classtype:trojan-activity; sid:100004792; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tecnologyschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004793; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"teduae.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004794; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"teleargentina.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004795; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"telescopelms.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004796; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"telmed.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004797; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"temptmag.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004798; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tennisafrica.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004799; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tentandoserfitness.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004800; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.adventser.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004801; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.letraele.es"; content:"Host"; http_header; classtype:trojan-activity; sid:100004802; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.typoten.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004803; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.wanepghana.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004804; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test1.asistencia247.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004805; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test1.milenial.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004806; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test1.tenplusone.my"; content:"Host"; http_header; classtype:trojan-activity; sid:100004807; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test2.basis-web.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004808; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"test2.marrenconstruction.ie"; content:"Host"; http_header; classtype:trojan-activity; sid:100004809; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"testing.clickitsolutionsmw.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004810; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"testing.thinkingcorp.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004811; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"testnew.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004812; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"teteaffiche.stephanebillon.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004813; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tewoerd.eu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004814; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"textile.softberg.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100004815; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"texturesbyvinita.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004816; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thecleaningladiespdx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004817; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thecreativecafe.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004818; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thefuturelife.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004819; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thehighlightinterior.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004820; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thehouseofpragya.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004821; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thekassia.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004822; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thelaunchpadteam.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004823; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thelogicalgroup.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004824; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thesummitpc.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004825; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"theurbantutors.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004826; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thewwpc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004827; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"thosewebbs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004828; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tianangdep.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004829; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tickfood.tickme.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004830; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tickjobs.tickme.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004831; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tickmart.tickme.lk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004832; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"timegonebuy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004833; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tksb.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004834; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tlcc.com.gt"; content:"Host"; http_header; classtype:trojan-activity; sid:100004835; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"todoapp.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004836; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tonydong.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004837; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tonyzone.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004838; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tooba.tenplusone.my"; content:"Host"; http_header; classtype:trojan-activity; sid:100004839; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"topcell9.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004840; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"topicsnepal.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004841; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"toplevel.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004842; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"torresquinterocorp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004843; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"towme.services"; content:"Host"; http_header; classtype:trojan-activity; sid:100004844; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"toyotacollege.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100004845; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tpef.lsoftdemo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004846; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tpke.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004847; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tradezone.ejuicysolutions.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004848; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"translaterjemah.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004849; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"travel.travelwadi.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004850; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"travelwithmanta.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004851; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"trezors.io.mahlongwa.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004852; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"triplonet.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004853; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"troki.com.co"; content:"Host"; http_header; classtype:trojan-activity; sid:100004854; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tropics.codeleek.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004855; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"trudelfavreau.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004856; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tsd.jxwan.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004857; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tulli.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100004858; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"tupperware.michaelroberge.ca"; content:"Host"; http_header; classtype:trojan-activity; sid:100004859; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"turanggaresources.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004860; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uat.indianfilmzone.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004861; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ublretailerdemo.cstdevs.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004862; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"udesk.searchkero.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004863; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ugprs-ubih.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004864; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ultimate-24.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004865; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"umwelt-kirchhof.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004866; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"unicorpbrunei.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004867; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uniengrisb.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004868; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"unisoftcc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004869; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"unyazitelecom.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004870; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"upcbpta.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004871; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"urbane.dezinetimes.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004872; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"useformoney.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004873; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"usmadetshirts.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004874; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uss.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100004875; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"uzzepay.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004876; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vanzare.cabanabrazi2.ro"; content:"Host"; http_header; classtype:trojan-activity; sid:100004877; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vbcargo.hu"; content:"Host"; http_header; classtype:trojan-activity; sid:100004878; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vcah.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004879; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vegadelcasero.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004880; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vendas.lidiacarmeli.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004881; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"verify.aicosoft.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004882; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vfocus.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004883; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vidmattic.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004884; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vienen.gblix.srv.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004885; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"villamarand.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004886; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"villatera.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004887; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"violinstop.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004888; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"viraltalking.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004889; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"visions.alnisamart.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004890; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"visualhome.cl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004891; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vitoriamodaintima.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004892; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vivationdesign.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004893; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"viveirodoiscorregos.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004894; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vksales.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004895; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vladimirinternational.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004896; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vokasi.ub.ac.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100004897; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vologroup.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004898; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"voteyouramerica.dekitout.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004899; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vstsample.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004900; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vtube.fadlymotivator.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004901; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"vvsskmodinationalschool.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004902; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wanepliberia.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004903; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wanepniger.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004904; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"weareactum.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004905; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.eng.ubu.ac.th"; content:"Host"; http_header; classtype:trojan-activity; sid:100004906; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.geetle.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100004907; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.geomegasoft.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004908; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.newinnovationtechnology.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004909; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.smarts-works.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004910; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.thebeessolution.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004911; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"webgis.perumdasolo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004912; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"webmailwindstreamnetmessagesecureapp1rqr.ga"; content:"Host"; http_header; classtype:trojan-activity; sid:100004913; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"webpresario.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004914; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"website-work.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004915; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"weinsteincounseling.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004916; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wexfashion.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004917; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"whcms.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004918; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"whiteglovetailgate.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004919; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"whiteresponse.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004920; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"whynt.xyz"; content:"Host"; http_header; classtype:trojan-activity; sid:100004921; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wi522012.ferozo.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004922; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wikalen.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100004923; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wildnights.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004924; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wildtrust.mediadevstaging.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004925; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wimbamusica.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004926; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wishesconcierge.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004927; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"woezon.agency"; content:"Host"; http_header; classtype:trojan-activity; sid:100004928; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wolfgang-brodte.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100004929; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"woodsytech.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004930; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wordpress.saleensuporte.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004931; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wozata.000webhostapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004932; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wp.readhere.in"; content:"Host"; http_header; classtype:trojan-activity; sid:100004933; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wpdemo.101clients.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100004934; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"writtendeer.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004935; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ws5588.f3322.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100004936; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"wyklej.pl"; content:"Host"; http_header; classtype:trojan-activity; sid:100004937; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"x2vn.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004938; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xia.beihaixue.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004939; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xixaoclothing.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004940; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xk.996is.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004941; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--80akinnkiib6h.xn--90ais"; content:"Host"; http_header; classtype:trojan-activity; sid:100004942; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--polimerbizmimarlk-rvc.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004943; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ybom.urbanolab.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004944; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yeichner.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004945; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"ylfpremium.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004946; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yoast.yourpageserver.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004947; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"youtubetrainingacademy.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004948; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yskadvisors.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004949; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yummyyogaudaipur.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004950; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"yzkzixun.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004951; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"zakra.tecnasulstore.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100004952; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"zytrox.tk"; content:"Host"; http_header; classtype:trojan-activity; sid:100004953; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"zz.690tx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004954; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/64.exe"; http_uri; nocase; content:"2.indexsinas.me:811"; content:"Host"; http_header; classtype:trojan-activity; sid:100004955; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/86.exe"; http_uri; nocase; content:"2.indexsinas.me:811"; content:"Host"; http_header; classtype:trojan-activity; sid:100004956; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/c64.exe"; http_uri; nocase; content:"2.indexsinas.me:811"; content:"Host"; http_header; classtype:trojan-activity; sid:100004957; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe"; http_uri; nocase; content:"amumufree.weebly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004958; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/files/proxyi.exe"; http_uri; nocase; content:"analogx.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100004959; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004960; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/densjons/bro/downloads/rew.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004961; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dvdfv/anjj/downloads/jami.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004962; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/jpavelski/chpock/downloads/4.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004963; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/jpavelski/chpock/downloads/6.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004964; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/clr.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004965; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/clr3.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004966; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/instaler.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004967; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/installer.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004968; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/updatej.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004969; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/updatev.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004970; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mminminminmin05/testtest/downloads/work.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004971; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player2012/rumpa1/downloads/component.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004972; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player2012/rumpa1/downloads/nordvpnsetup.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004973; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player2012/rumpa1/downloads/regsvc.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004974; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/skygaming/updates/downloads/update.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004975; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/001.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004976; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1488.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004977; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1_cr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004978; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1cr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004979; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/1fc2d.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004980; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/26a5.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004981; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/6e7_2021-01-19_18-04.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004982; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/abjects.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004983; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/attached.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004984; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/b7f2c.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004985; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/battletext.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004986; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/bkghj_nowin.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004987; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/bsdasdasd333.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004988; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004989; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build_makros.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004990; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build_silent.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004991; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/build_sup.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004992; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildcmobiler.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004993; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildcmobiler.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004994; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildcr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004995; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/buildss.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004996; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/clientnik.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004997; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/clientrevers.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004998; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/dcrat.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100004999; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/dllservices.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005000; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/dllservices2.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005001; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/exe_morris.mcdermott.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005002; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/hans.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005003; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/hulu.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005004; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelfive.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005005; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelfour.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005006; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelone.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005007; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/intelthree.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005008; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/inteltwo.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005009; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/jjuufksfn.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005010; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/kleiman.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005011; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/lucky_fixed.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005012; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/notepadplus.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005013; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/osiris_qqkz_nauto.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005014; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/out.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005015; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/out.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005016; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/pacbe_bin.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005017; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/putty.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005018; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/rockethcd.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005019; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/scvhost900.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005020; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/sessionwin.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005021; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/siliculose.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005022; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/statemobi.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005023; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/stealers.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005024; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/stealers2.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005025; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/stgedo.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005026; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/svcperf.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005027; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/symptomaticshon5.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005028; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/taurjok.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005029; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/taurusbabac.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005030; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/telekiller.exe"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005031; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/updateanddr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005032; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/updateandr.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005033; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/vhajeja.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005034; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/word.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005035; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/www.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005036; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tanake5518/fi/downloads/xlsd.txt"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005037; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/teaserex/tease/downloads/b_kfmhkk172.bin"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005038; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/teaserex/tease/downloads/macro_xmprohiq27.bin"; http_uri; nocase; content:"bitbucket.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005039; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/hmatrix/data/hack1226.exe"; http_uri; nocase; content:"cd.textfiles.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005040; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005041; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/816070119281131570/816070273254162442/all.txt"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005042; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachments/823355293043261515/823692323514482788/inquiry_-_rfq_hmg_u66_sw5558_pdf.iso"; http_uri; nocase; content:"cdn.discordapp.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005043; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/razor/rzr-winner_intro.zip"; http_uri; nocase; content:"chiptune.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005044; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz"; http_uri; nocase; content:"cloudme.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005045; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar"; http_uri; nocase; content:"cloudme.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005046; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/meteoradminz/hidden-tear/zip/master"; http_uri; nocase; content:"codeload.github.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005047; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/"; http_uri; nocase; content:"colfincas.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005048; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/qz0h69.pdf"; http_uri; nocase; content:"deepfreedom.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005049; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/frm0reseen/prntscrnofamzorderid.jpg.exe"; http_uri; nocase; content:"drive.google.com.it-barcelona.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005050; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=0byfg0_4xbjgnwvuyev9ltuh4rmm"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005051; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=13vodfxml9fg8kcnexuafh64dzmnqv8ch"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005052; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=167imxqgc8ehepa1gisxa6q6ifcjxceox"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005053; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1a-herfdxr6xamxeabcdao0mqw9bimrig"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005054; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1aphk_vq7gtn368zxpd5bg5rv8nk0bnhn"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005055; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005056; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1eqnvgn0qkunp7t6crk8oj7_e7rh5qxwi"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005057; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1in-rhdrss2qsjqj8xffb1hbwi9znp4je"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005058; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1iwc-lf99neesk6mvvo2al4futbmyoiev"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005059; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005060; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1n8o4hbvi7o9ks9jqhofny7okposfaz4y"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005061; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1nio_cdsggt4zv1kdrpubrfpd0pzsyffd"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005062; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1oabvvnazifkxktvt-izbcdqpb7dm6nrw"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005063; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1prxtn1juykhcr_9ilw-vtirv5anyeoej"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005064; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1t1bd_itjnhsmozdl9was0gouehujm1fn"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005065; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1tsmbsikhechaqedk6nktlfzasus_tghw"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005066; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1uvtmu3-hcryp3rskqnpkiodcjuchtz55"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005067; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1vevblftithattyguwyjot1p0wptg7l5t"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005068; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005069; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1yawygcfjs9inzoiwagqfcn3utaywxmwi"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005070; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1yhflwpk3yeyrdhlhanctlind-5j24iwv"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005071; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?export=download&id=1zbclvhabervgfryoyqklo4_oe6icd8sr"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005072; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uc?id=148pt6v0nlg8yoim7w6in7dpixkzaacbg&export=download&authuser=0"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005073; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/1zilg/"; http_uri; nocase; content:"drpamelageorge.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005074; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/qcgfmfvh/"; http_uri; nocase; content:"drpamelageorge.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005075; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/downloads/emclick.zip"; http_uri; nocase; content:"e-mudhra.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005076; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/informatica/informatica-actief/hoofdstuk1/extrasoftware/getallen.exe"; http_uri; nocase; content:"evertkok.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100005077; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/informatica/informatica-actief/hoofdstuk2/software/hksetup.exe"; http_uri; nocase; content:"evertkok.nl"; content:"Host"; http_header; classtype:trojan-activity; sid:100005078; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/register/phpcaptcha/images/19dnqhg1p/sbhvtqlysxhxn/"; http_uri; nocase; content:"expeditionquest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005079; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/register/phpcaptcha/images/35egphpl5uzpvdmz9bncmvon3p/"; http_uri; nocase; content:"expeditionquest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005080; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/x/"; http_uri; nocase; content:"expeditionquest.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005081; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf/"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100005082; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf//"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100005083; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf///"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100005084; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf////"; http_uri; nocase; content:"exxonabnie.ir"; content:"Host"; http_header; classtype:trojan-activity; sid:100005085; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/web1/m00/8f/36/o4ybafy-2m2aarfzaahkaiik5pi122.exe"; http_uri; nocase; content:"file.elecfans.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005086; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/4cb7cebd101/e5fb4174-ab23-48e8-bf05-e80ec5fa2169.xls"; http_uri; nocase; content:"files.constantcontact.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005087; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ee304de9001/7e533e73-e272-4a44-9d9e-138cab64bf19.docx"; http_uri; nocase; content:"files.constantcontact.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005088; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe"; http_uri; nocase; content:"gist.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005089; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/"; http_uri; nocase; content:"hqdecig.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005090; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/suy/"; http_uri; nocase; content:"hsecaravans.co.uk"; content:"Host"; http_header; classtype:trojan-activity; sid:100005091; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/19/items/startup_20210219/startup.txt"; http_uri; nocase; content:"ia801802.us.archive.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005092; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/online-timer-kvhxz/ilxl/"; http_uri; nocase; content:"ie-best.net"; content:"Host"; http_header; classtype:trojan-activity; sid:100005093; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/64.exe"; http_uri; nocase; content:"indonesias.me:9998"; content:"Host"; http_header; classtype:trojan-activity; sid:100005094; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/c64.exe"; http_uri; nocase; content:"indonesias.me:9998"; content:"Host"; http_header; classtype:trojan-activity; sid:100005095; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ebook/cs17.exe"; http_uri; nocase; content:"jcedu.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005096; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eng/wp-content/plugins/featurific-for-wordpress/1"; http_uri; nocase; content:"jointings.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005097; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eng/wp-content/plugins/featurific-for-wordpress/2"; http_uri; nocase; content:"jointings.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005098; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eng/wp-content/plugins/featurific-for-wordpress/3"; http_uri; nocase; content:"jointings.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005099; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/file/jl01o54yy09qrzg/fac215.tgz/file"; http_uri; nocase; content:"justlficante.mediafire.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005100; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/3/2/8/8/3288864/karma_koin_codes.exe"; http_uri; nocase; content:"karmakoincodes.weebly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005101; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dg/etrac/nf4emwz/"; http_uri; nocase; content:"kotakwarna.co.id"; content:"Host"; http_header; classtype:trojan-activity; sid:100005102; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/down/affiliate/kuaizip_setup_10029.exe"; http_uri; nocase; content:"kuaizip.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005103; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/linuxforensicscode.zip"; http_uri; nocase; content:"linuxforensicsbook.com.s3.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005104; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/k/big5/1giof6/"; http_uri; nocase; content:"minpic.de"; content:"Host"; http_header; classtype:trojan-activity; sid:100005105; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-contentbak/t9m/"; http_uri; nocase; content:"morrobaydrugandgift.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005106; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v1/ws2/:gianni1962/:ie6setup/ie6setup.exe"; http_uri; nocase; content:"my.cloudme.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005107; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/components/aacenc.exe"; http_uri; nocase; content:"nch.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100005108; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/components/doxillionsetup.exe"; http_uri; nocase; content:"nch.com.au"; content:"Host"; http_header; classtype:trojan-activity; sid:100005109; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/uploads/4/1/6/6/4166984/keygen.exe"; http_uri; nocase; content:"newyarlfm.weebly.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005110; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/efficiency-all-iuehb/bjug3jyhuyilwhcqs3ykssaqqw7tpyvmypb91wtzdbluio1ekope5vrbbcx8zhdar9yt/"; http_uri; nocase; content:"nhipcauytevietnhat.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005111; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/yws/api/personal/file/web3a243b322cf83ca7cae587a92916bac7?method=download&inline=true&sharekey=649ac0bb5d5b13d15cbf50b2609e193a"; http_uri; nocase; content:"note.youdao.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005112; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/spreadsheets/osv_stock_valuation-sample-dummy.exe"; http_uri; nocase; content:"oldschoolvalue.s3.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005113; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=81445407a9f44d37!197&authkey=apuz15kftzlrysa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005114; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=81445407a9f44d37!198&authkey=ags5rgb15_esaqq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005115; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=b4c15a27928f663b!229&authkey=aiarm61fwmd_npe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005116; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=b4c15a27928f663b!230&authkey=ancu1eabetiubzg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005117; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=b4c15a27928f663b!231&authkey=ai9h3sk_luxran0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005118; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?&resid=c127f9e0fb7cbbea!214&authkey=aat73nvghhjdr9g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005119; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=!aase4ma0-vo_cls&cid=4df11eda676a355f&resid=4df11eda676a355f!140"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005120; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=!akd6uxvljtlvpxu&cid=4df11eda676a355f&resid=4df11eda676a355f!130"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005121; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005122; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?authkey=adf5p_kn8rjf29y&cid=34224e3e49966a27&resid=34224e3e49966a27%211732"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005123; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=013413cfbbbcfae4&resid=13413cfbbbcfae4%211656&authkey=ai9wpcp_k9okgk4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005124; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c!111&authkey=aemrwamaaaiyyjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005125; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c%21111&authkey=aemrwamaaaiyyjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005126; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0175cdbe2d2944c5&resid=175cdbe2d2944c5%21107&authkey=al6uptubjmmugo0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005127; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!157&authkey=aagcsm7chqez6uu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005128; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!158&authkey=amsoii5nr6pomhc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005129; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21157&authkey=aagcsm7chqez6uu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005130; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21158&authkey=amsoii5nr6pomhc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005131; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=023f39d21b700310&resid=23f39d21b700310%211204&authkey=an2utsuaopn0fhc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005132; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211177&authkey=am0i98nwgvzgqvq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005133; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211183&authkey=anv33trmzmi5cko"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005134; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005135; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=03286724f74117f9&resid=3286724f74117f9!1179&authkey=acr-_rvrgp39kk4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005136; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=03286724f74117f9&resid=3286724f74117f9%211179&authkey=acr-_rvrgp39kk4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005137; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005138; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005139; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005140; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005141; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005142; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!273&authkey=ae2m69e5nu3rrea"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005143; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!274&authkey=acqg0akutoxdpgo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005144; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21273&authkey=ae2m69e5nu3rrea"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005145; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21274&authkey=acqg0akutoxdpgo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005146; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0e26b39babdbf63c&resid=e26b39babdbf63c%21137&authkey=anshbgxg1_qa2h4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005147; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242!309&authkey=alfe36drai1zmwc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005148; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242%21309&authkey=alfe36drai1zmwc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005149; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21123&authkey=aco5hiwppfq8vrw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005150; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21124&authkey=ai6sfa2z-kqf6x0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005151; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=115bffdddaa40942&resid=115bffdddaa40942!540&authkey=aamhnqgfdtdsoxk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005152; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=115bffdddaa40942&resid=115bffdddaa40942%21540&authkey=aamhnqgfdtdsoxk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005153; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005154; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=13b301f1cb48f8cd&resid=13b301f1cb48f8cd%21106&authkey=aiae3olcs4lulz4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005155; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=14f52af71b98dbc5&resid=14f52af71b98dbc5%212449&authkey=anfs_n5cs1noojo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005156; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005157; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7%21118&authkey=antash3ig98aqte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005158; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f%21286&authkey=almwisomhv3c0zc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005159; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e!348&authkey=ahnjoxa4ufoxa54"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005160; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e%21348&authkey=ahnjoxa4ufoxa54"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005161; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!126&authkey=ad4yflrisq6d82g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005162; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!129&authkey=apqoonsrce0ari4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005163; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21126&authkey=ad4yflrisq6d82g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005164; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21129&authkey=apqoonsrce0ari4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005165; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=196e83840ef8c152&resid=196e83840ef8c152%21107&authkey=ah2lhjyd0ukjcve"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005166; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1a162e8fcaaef5fa&resid=1a162e8fcaaef5fa%215495&authkey=aic7rmj1cm3rt2w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005167; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558!8182&authkey=aautw8tvzxr5v3a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005168; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558%218182&authkey=aautw8tvzxr5v3a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005169; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1cbd82dd55d70086&resid=1cbd82dd55d70086%212526&authkey=aogaboensav3jrg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005170; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1dbdf62bc3c2b05b&resid=1dbdf62bc3c2b05b!134&authkey=ape6bhxn7c89z60"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005171; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005172; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005173; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005174; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!123&authkey=am1rcmkppbht8v0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005175; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!124&authkey=am5sltharf-j_cc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005176; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!125&authkey=acgvgbbuowodg4c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005177; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21122&authkey=aa2f8su-5bfjlvs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005178; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005179; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0&c=3ii9gcd&r=7azia71ojgc8rxd0dmkukm&k=7s1&s=htgxfkpr86ttvokhkcn3enmimk12ewqfiglklz23spd"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005180; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21124&authkey=am5sltharf-j_cc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005181; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21125&authkey=acgvgbbuowodg4c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005182; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21154&authkey=alkjikpdfxvm8po"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005183; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21155&authkey=afu-yax_gxxddoe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005184; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21156&authkey=alqvv8nixrvsqrk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005185; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f!191&authkey=ajvumpkzpla_nca"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005186; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f%21191&authkey=ajvumpkzpla_nca"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005187; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=26bbd7d5ad88dd29&resid=26bbd7d5ad88dd29%21115&authkey=acipfa3gbiqqcvu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005188; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=26f87316a7e32bb5&resid=26f87316a7e32bb5%21106&authkey=aepqo5hlkxn1t1k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005189; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2831401bbac0235e&resid=2831401bbac0235e%211037&authkey=aagnkp6l76yhrlo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005190; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!182&authkey=apogh8yf-fj8xvk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005191; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!183&authkey=am4thhgmi0nlxei"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005192; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!185&authkey=akttgkvu39ugyte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005193; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21182&authkey=apogh8yf-fj8xvk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005194; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21183&authkey=am4thhgmi0nlxei"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005195; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21185&authkey=akttgkvu39ugyte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005196; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2894380eb084b79e&resid=2894380eb084b79e%21253&authkey=aimqerwvuylzjga"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005197; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2992e4d36c2a7dae&resid=2992e4d36c2a7dae%21132&authkey=af05vsjkocy8lly"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005198; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2b6e98d9e0cf1a17&resid=2b6e98d9e0cf1a17!2471&authkey=ai5r4hqy9i0g1qs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005199; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2b6e98d9e0cf1a17&resid=2b6e98d9e0cf1a17%212471&authkey=ai5r4hqy9i0g1qs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005200; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c1abc526306a6e1&resid=2c1abc526306a6e1%21106&authkey=adjthwhvjkbioc0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005201; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21109&authkey=aopcxq3owfiv620"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005202; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21114&authkey=ajzoj0ujggsnxlo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005203; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21115&authkey=aglznnsx71tbe9e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005204; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37!183&authkey=akon9i9zzhusiuk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005205; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37%21183&authkey=akon9i9zzhusiuk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005206; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6!161&authkey=aovldmsenzzpjrw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005207; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6%21161&authkey=aovldmsenzzpjrw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005208; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f01a497b687285e&resid=2f01a497b687285e!734&authkey=aiumuxtp3phppy4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005209; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f01a497b687285e&resid=2f01a497b687285e%21734&authkey=aiumuxtp3phppy4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005210; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!116&authkey=!abwledjhfsqwap4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005211; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!121&authkey=!aa0qbuuss-wb13w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005212; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1!119&authkey=apmakx2cqb9rimu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005213; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21118&authkey=acrl2iiem-zjer8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005214; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21119&authkey=apmakx2cqb9rimu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005215; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=2ffaa48ef4bec51a&resid=2ffaa48ef4bec51a%21107&authkey=aiohrvrc3uuo_cw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005216; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=30e33fc2c147c72f&resid=30e33fc2c147c72f!2742&authkey=ajviks-nvgb4gqs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005217; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=30e33fc2c147c72f&resid=30e33fc2c147c72f!2743&authkey=ao4um908kkhavqg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005218; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=30e33fc2c147c72f&resid=30e33fc2c147c72f%212742&authkey=ajviks-nvgb4gqs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005219; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=30e33fc2c147c72f&resid=30e33fc2c147c72f%212743&authkey=ao4um908kkhavqg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005220; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!320&authkey=aooujzuf408dclw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005221; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!321&authkey=almpxnbtsbzauna"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005222; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21320&authkey=aooujzuf408dclw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005223; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21321&authkey=almpxnbtsbzauna"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005224; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3164ddeba70d2263&resid=3164ddeba70d2263%21106&authkey=afkvqrm4zoor8qq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005225; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=31771958ea3373a1&resid=31771958ea3373a1%21108&authkey=aiofxduo9rdb_-o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005226; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=34207675f7506d94&resid=34207675f7506d94%21137&authkey=angxnhqpe2x5koc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005227; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005228; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005229; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005230; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!198&authkey=acyz0gbpl6bp9mo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005231; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!199&authkey=admaszabh84m8ou"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005232; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e%21198&authkey=acyz0gbpl6bp9mo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005233; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e%21199&authkey=admaszabh84m8ou"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005234; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!152&authkey=am09sv26njxzyn0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005235; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!153&authkey=ajs0jkoeqkqjrze"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005236; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21152&authkey=am09sv26njxzyn0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005237; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21153&authkey=ajs0jkoeqkqjrze"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005238; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3a1715e2cb964f25&resid=3a1715e2cb964f25%213713&authkey=aortxmfnibnoqkk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005239; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21432&authkey=aa_npsupyqb2kge"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005240; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21435&authkey=admsjhgpkbtcqzs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005241; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005242; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f%21154&authkey=aasj15d0g_p2pog"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005243; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f!134&authkey=aaipzy8nllirlky"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005244; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f%21134&authkey=aaipzy8nllirlky"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005245; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=40cbf21d67b770f7&resid=40cbf21d67b770f7%21140&authkey=ah0uewz9k7-lzd0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005246; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2!106&authkey=aoigmqhuw6vqijm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005247; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2%21106&authkey=aoigmqhuw6vqijm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005248; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21108&authkey=akr9cesktucbqik"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005249; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21109&authkey=adzxmpjk-etbkjq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005250; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=45f0213456d899c0&resid=45f0213456d899c0%211133&authkey=alwgkm79xod8hpy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005251; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa!450&authkey=ahw0j-cme0jg6pw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005252; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa%21450&authkey=ahw0j-cme0jg6pw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005253; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=489dd700ea74963a&resid=489dd700ea74963a%21206&authkey=acgkmxuk000jse8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005254; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=489dd700ea74963a&resid=489dd700ea74963a%21210&authkey=aotjil_l-s-xh1c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005255; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ada4e22fff3e13&resid=48ada4e22fff3e13%21421&authkey=acd1sidm8c5fk0y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005256; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13805&authkey=ae-zbfo2uwln_gg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005257; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13806&authkey=aakiq-ymrjjodns"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005258; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113805&authkey=ae-zbfo2uwln_gg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005259; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113806&authkey=aakiq-ymrjjodns"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005260; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4ab7eafa48707b54&resid=4ab7eafa48707b54%21105&authkey=amb4gnkdn8igw8y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005261; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4b676ea3ff139b93&resid=4b676ea3ff139b93!133&authkey=amfix63glytflgo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005262; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21127&authkey=ablg20r-aat_ob4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005263; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21131&authkey=akbwlkrrtso_bqm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005264; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4df11eda676a355f&resid=4df11eda676a355f!130&authkey=!akd6uxvljtlvpxu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005265; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b!108&authkey=anbjpqxg-iwr4g8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005266; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b%21108&authkey=anbjpqxg-iwr4g8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005267; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005268; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005269; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21105&authkey=ajkwu0e9dzantl8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005270; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21107&authkey=apd9um4_12-kpe0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005271; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21116&authkey=anbj_rrcgyturjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005272; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21119&authkey=amrs3-3hsvcmtfs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005273; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21158&authkey=aodderdrnvhruts"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005274; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21161&authkey=agdsfxdnre82jjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005275; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21192&authkey=agn2xvrvup-xvtg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005276; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21206&authkey=ai1r52mhtbdnm2y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005277; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21247&authkey=ae6weny1fa4pday"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005278; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21252&authkey=aphl0oi4r6lrty0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005279; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21257&authkey=afnyvqwcghnyoas"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005280; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21265&authkey=abxqdhlwiurjvve"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005281; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21271&authkey=ae5qwlr5ceeptmy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005282; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21272&authkey=ahrqeoaynibwt14"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005283; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21275&authkey=af_sgsaxsmaxg7i"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005284; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21289&authkey=angyngbqixtrjaa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005285; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005286; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005287; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21306&authkey=ahpivoukyerzcjy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005288; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21314&authkey=aex2uv2-eiofr8q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005289; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21332&authkey=ad0jmjxgbaebvbm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005290; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21335&authkey=ah0vupcfbdfa6g4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005291; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21357&authkey=ap8sswuqjjjexho"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005292; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21366&authkey=aoblpmbmx7o_v18"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005293; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21379&authkey=air-bsjj46et47q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005294; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21389&authkey=aduenohuq_rbyhm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005295; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21391&authkey=aa15sw51njbn_na"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005296; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21392&authkey=abp0heeg6ybn0lk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005297; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21393&authkey=aa1pmur8sy8xtwe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005298; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212718&authkey=aie0v1d-cusuabi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005299; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212725&authkey=aanrz9et3bym3lc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005300; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212728&authkey=ahsmbkltfrwgqjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005301; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!395&authkey=alwvub_yhtogjxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005302; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!398&authkey=abaa_tjd7ohh4so"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005303; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!406&authkey=aarnp48wumgu6tq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005304; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!415&authkey=aglzsd6-g0nzj7s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005305; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!420&authkey=akk5droung_ecww"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005306; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!440&authkey=ai7-dpr11wnzyq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005307; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21395&authkey=alwvub_yhtogjxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005308; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21398&authkey=abaa_tjd7ohh4so"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005309; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21406&authkey=aarnp48wumgu6tq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005310; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21415&authkey=aglzsd6-g0nzj7s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005311; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21420&authkey=akk5droung_ecww"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005312; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21440&authkey=ai7-dpr11wnzyq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005313; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211121&authkey=al_fmezwfay4za4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005314; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211122&authkey=anz_q5njlanv2mu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005315; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21110&authkey=akars6koxqzdwgi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005316; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21112&authkey=aadare1gec7nzy8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005317; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005318; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8&em=2"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005319; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d%21109&authkey=adriswrtwdpbuc8&em=2"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005320; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=53c5e6b8f6893887&resid=53c5e6b8f6893887!802&authkey=aapuufivkn2zwu8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005321; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!106&authkey=anzlf1ksptbqok8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005322; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!107&authkey=ag4dr58jrjuxfyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005323; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21106&authkey=anzlf1ksptbqok8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005324; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21107&authkey=ag4dr58jrjuxfyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005325; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005326; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005327; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5521b68dc17baf21&resid=5521b68dc17baf21%21129&authkey=ajdr2dbh-9h63wa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005328; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005329; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613!157&authkey=an55tjzt-9vbjfy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005330; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613%21156&authkey=agiuawekkbxb_4o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005331; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=55c9feaf3907aae5&resid=55c9feaf3907aae5%21208&authkey=adwuyrapfdzkyoa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005332; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950!280&authkey=advq4p3xhfhinq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005333; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950%21280&authkey=advq4p3xhfhinq8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005334; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5629da828892367d&resid=5629da828892367d!803&authkey=aphjbq-bsg7ohpc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005335; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21383&authkey=adldpuaya7kj1dk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005336; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21384&authkey=alsuxvtsof32vea"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005337; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3599&authkey=am4yicme6lrjpki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005338; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3604&authkey=al6pb71mtq4jr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005339; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213599&authkey=am4yicme6lrjpki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005340; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213604&authkey=al6pb71mtq4jr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005341; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b!68197&authkey=aowpm7ocl_21-oc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005342; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b%2168197&authkey=aowpm7ocl_21-oc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005343; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=59389d626d829e8c&resid=59389d626d829e8c%212940&authkey=anx1ngd27vqeiwo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005344; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211568&authkey=aemrnwoi75oflva"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005345; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211572&authkey=aelz-gxlrxcwtnc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005346; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211573&authkey=ahksfdvda0doles"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005347; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005348; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005349; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!407&authkey=adnh8af-rvoxlcc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005350; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21406&authkey=aeyeq5j9zfepgai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005351; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21407&authkey=adnh8af-rvoxlcc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005352; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21892&authkey=apwphufzjdtsedw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005353; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005354; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21121&authkey=adjzlorvgx_ezhq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005355; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21123&authkey=ancfnepawtbmnug"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005356; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21124&authkey=ao7bknnuodxtfua"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005357; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21126&authkey=an6sswp8an1kfoe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005358; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6196314c52185efc&resid=6196314c52185efc%21106&authkey=ape4rx1hrtmrxxe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005359; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!490&authkey=aljraz5ktivqax4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005360; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!491&authkey=aopwdha2wyjx0aa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005361; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!492&authkey=akwg8p5adkpjm5w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005362; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!493&authkey=aeg__7wcf7esydo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005363; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21490&authkey=aljraz5ktivqax4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005364; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21491&authkey=aopwdha2wyjx0aa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005365; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21492&authkey=akwg8p5adkpjm5w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005366; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21493&authkey=aeg__7wcf7esydo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005367; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005368; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005369; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1094&authkey=anqjzd7pr18fu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005370; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211094&authkey=anqjzd7pr18fu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005371; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21129&authkey=ak5szbnikeklmzk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005372; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21132&authkey=ad3ia_1wkq0lyd4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005373; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6608a4dea9ff5918&resid=6608a4dea9ff5918%21399&authkey=aoya7flv_s9toxo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005374; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2%21505&authkey=ag7xi3lcnvi_hji"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005375; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad!1421&authkey=adixg2-asekemjw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005376; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad%211421&authkey=adixg2-asekemjw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005377; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213096&authkey=aob-cm9vv6erxqg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005378; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213097&authkey=abcuevfyu6pdw70"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005379; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=69b503a3f081a183&resid=69b503a3f081a183%21111&authkey=aazm9wlg1rvgzoc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005380; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!112&authkey=aasndgbcwol3mys"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005381; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!113&authkey=ak3tzu1lg4uuh5m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005382; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21112&authkey=aasndgbcwol3mys"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005383; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21113&authkey=ak3tzu1lg4uuh5m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005384; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21108&authkey=ameouv2jdxo5obw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005385; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21119&authkey=aazzzrl7mv2xbwq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005386; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6a7b40a2bc530c6c&resid=6a7b40a2bc530c6c%21112&authkey=afuov36rbymlvxm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005387; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3!118&authkey=aepf8f3mfmlsng0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005388; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3%21118&authkey=aepf8f3mfmlsng0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005389; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b61e983f930f79f&resid=6b61e983f930f79f!540&authkey=ap2n5w41ifew0i8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005390; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7!1154&authkey=acnbdscb8-rbmcu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005391; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7%211154&authkey=acnbdscb8-rbmcu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005392; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21106&authkey=apvhok6edhtogfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005393; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21115&authkey=amc_k1nnlywdc4i"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005394; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=724b5c509337556e&resid=724b5c509337556e%21908&authkey=agcbb3nakpteyam"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005395; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7285f51e65036769&resid=7285f51e65036769%21264&authkey=akyjvrz006qlble"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005396; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21243&authkey=apivjmxivosek60"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005397; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21256&authkey=adljht0ogfq775k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005398; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21260&authkey=aig6cydr4_e-qj8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005399; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21262&authkey=ak4fiz1-a1ks8rg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005400; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21264&authkey=aizkjymvlgqwpte"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005401; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=77518d098ad4dfb0&resid=77518d098ad4dfb0%21939&authkey=akzqobxxxn89z34"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005402; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005403; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005404; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21117&authkey=aivf1ddcvvu22em"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005405; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb!211&authkey=anxavz-oaf9pv_c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005406; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21210&authkey=agpl0pgvft8faaa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005407; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21211&authkey=anxavz-oaf9pv_c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005408; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005409; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005410; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005411; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21120&authkey=ajj7ueqjvobgfum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005412; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c1fc7da38ab958e&resid=7c1fc7da38ab958e!146&authkey=aktmjqz8n4s_sbm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005413; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125575&authkey=ahnmpmvzshrwoyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005414; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125579&authkey=amhnrbwecb4hp_k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005415; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5295&authkey=aasceqj1mdodeuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005416; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5296&authkey=ank3vz5syaf6bny"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005417; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5298&authkey=albzyizuqczfv9s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005418; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215295&authkey=aasceqj1mdodeuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005419; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215296&authkey=ank3vz5syaf6bny"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005420; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215298&authkey=albzyizuqczfv9s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005421; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7d109f249b512466&resid=7d109f249b512466!543&authkey=acqc4xjghclmwbs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005422; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b!183&authkey=aggjy50pjuecoli"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005423; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21181&authkey=ama3betib0dac18"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005424; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21183&authkey=aggjy50pjuecoli"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005425; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!443&authkey=abue79u9di9axjm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005426; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!444&authkey=abzxvycu0ggtmg8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005427; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0%21443&authkey=abue79u9di9axjm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005428; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0%21444&authkey=abzxvycu0ggtmg8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005429; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7e81645429ac5a22&resid=7e81645429ac5a22%21105&authkey=aa691jwf5wqi80c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005430; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=7fed4fbea32e3c1e&resid=7fed4fbea32e3c1e%21107&authkey=aeoxfycpolifch0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005431; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=806bac90dc071edf&resid=806bac90dc071edf!105&authkey=!ao7jyz6-licb8hq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005432; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=81c2d8b116274e17&resid=81c2d8b116274e17%21107&authkey=aaqw-t4dx2sbvda"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005433; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=82977114b1af209d&resid=82977114b1af209d!220&authkey=abuin5vdedjughm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005434; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=860a0980486c93fa&resid=860a0980486c93fa!303&authkey=!agcmlab4r6syfvk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005435; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21164&authkey=agbeiinncf8ok_4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005436; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21165&authkey=aiof8rdvxglnm-c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005437; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4!2402&authkey=amigiam45mt6jia"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005438; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4%212402&authkey=amigiam45mt6jia"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005439; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=890837b4e4ca07c6&resid=890837b4e4ca07c6%21289&authkey=abujc0akmtbsxf4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005440; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8983011c6ecfb1d8&resid=8983011c6ecfb1d8%21132&authkey=ah0vja7wpyfjj84"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005441; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8a1574ed0cecd68a&resid=8a1574ed0cecd68a%21395&authkey=ane01evt0sz-1wk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005442; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8c77cee60e33a6b1&resid=8c77cee60e33a6b1%21106&authkey=af8h8jn801bjnbk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005443; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8ca507baa15fdb5c&resid=8ca507baa15fdb5c!213&authkey=acyrjlhflcrypae"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005444; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=8ffd8cbd6540c065&resid=8ffd8cbd6540c065!822&authkey=acfj7bbrmktj1i0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005445; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!243&authkey=aeiqd4ihuqopwm8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005446; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005447; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25!130&authkey=ais_g9dqoddonsc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005448; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005449; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21109&authkey=akr1n3qxtmnttuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005450; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21113&authkey=ajpvf1h89sqstti"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005451; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!289&authkey=aoiy68zx8ddnjhe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005452; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!290&authkey=afn1bhvmpaicari"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005453; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!291&authkey=aknqfhnxttsrvz4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005454; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!297&authkey=agy0f-5almc6_ia"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005455; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!298&authkey=ajiut2kebcaycok"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005456; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21288&authkey=ag9wi9pub-q4jly"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005457; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21289&authkey=aoiy68zx8ddnjhe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005458; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21290&authkey=afn1bhvmpaicari"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005459; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21291&authkey=aknqfhnxttsrvz4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005460; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21295&authkey=afvy6r0mspzeb6m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005461; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21297&authkey=agy0f-5almc6_ia"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005462; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21298&authkey=ajiut2kebcaycok"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005463; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21299&authkey=agmfs3scdvngolm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005464; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21105&authkey=ah9x7rn0p03kd_m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005465; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21110&authkey=ammswulpdsjeu4w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005466; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3!107&authkey=ac-m9dlvo5l7wfk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005467; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3%21107&authkey=ac-m9dlvo5l7wfk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005468; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=96a54b19ff5f6bab&resid=96a54b19ff5f6bab%21107&authkey=anxv07ez7s5sh_k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005469; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21410&authkey=acwug6bewxk0pli"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005470; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21411&authkey=aj8o1fcvfhibmlm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005471; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=96fd249b957988a2&resid=96fd249b957988a2%211303&authkey=ah_etf1fqofknue"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005472; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935!778&authkey=aaezyk4ypt-elma"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005473; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21772&authkey=akeozmv0aafqlbg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005474; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21774&authkey=aly_m3fnrvh6dfq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005475; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21775&authkey=abblpjxi4mwomgs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005476; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21777&authkey=ahmuwqi4jg8rvho"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005477; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=98103c88c2d68867&resid=98103c88c2d68867!773&authkey=akptbml43mi4ufc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005478; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211925&authkey=amhhfhcsigeue9w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005479; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211927&authkey=an_3paqpemptbvm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005480; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211953&authkey=abdfqiyruwplpo0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005481; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211954&authkey=aok-srkhxjazccy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005482; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21172&authkey=ahharhcv0fmn5fm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005483; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21173&authkey=aecb3qcquacvzhi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005484; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21174&authkey=afv7cprqwxezgsi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005485; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005486; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005487; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005488; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005489; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005490; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005491; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340!997&authkey=akw6btyej2zht08"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005492; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340%21997&authkey=akw6btyej2zht08"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005493; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a1c8c8055848b889&resid=a1c8c8055848b889!111&authkey=agzlftsgr4lspvo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005494; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a2cd2cdb93584d7e&resid=a2cd2cdb93584d7e%21106&authkey=aeifpqbwo1s3dyq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005495; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211064&authkey=apebndb6tstxywi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005496; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211065&authkey=aca4_dggi5gbbfs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005497; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211067&authkey=ae-3ej9zzj4ibhw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005498; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211069&authkey=agx6b8qjt_clm-o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005499; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a4acaf66051e469e&resid=a4acaf66051e469e!189&authkey=alnhzcg0wzhusdc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005500; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a502994ea313f5c7&resid=a502994ea313f5c7%21215&authkey=aiydvejv0l8stbs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005501; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21!6053&authkey=agfh0ahstj7rrki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005502; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21%216053&authkey=agfh0ahstj7rrki"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005503; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005504; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21414&authkey=akf9uwwkitvhrvc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005505; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21415&authkey=ag_5kthuezprnoy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005506; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21416&authkey=airlma-pycgfkyc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005507; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21419&authkey=ab1-sgyv2gibyey"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005508; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21422&authkey=acphsmdy415izjg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005509; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21424&authkey=afvfwz5uvde1pui"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005510; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=a819c72315838312&resid=a819c72315838312%21112&authkey=abl1vflnfw3nrgi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005511; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=aa4e252db942faec&resid=aa4e252db942faec%21168&authkey=anlnjo7xnwtswuk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005512; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ae28961c75435487&resid=ae28961c75435487%21106&authkey=alph5awcis8r9iw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005513; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992!113&authkey=agh9q_zzyjjcspc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005514; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992%21113&authkey=agh9q_zzyjjcspc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005515; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=af84ebf13dd5499c&resid=af84ebf13dd5499c!167&authkey=anqr_yvn_hdh2_e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005516; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308!2152&authkey=abutaac83l5utks"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005517; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308%212152&authkey=abutaac83l5utks"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005518; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b0fddd36b3843d3b&resid=b0fddd36b3843d3b!561&authkey=abhena0pdghcveu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005519; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b0fddd36b3843d3b&resid=b0fddd36b3843d3b%21561&authkey=abhena0pdghcveu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005520; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21650&authkey=aht-wbxsofyx33u"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005521; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21651&authkey=aebbyk6sevdmzgm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005522; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21652&authkey=afsw5wahxo5kwjy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005523; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b1c3a5ef115e135c&resid=b1c3a5ef115e135c%216219&authkey=ahr7bklirbub0pc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005524; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b2289382b9cf7ba8&resid=b2289382b9cf7ba8%21106&authkey=ajwobaztcbbpxmy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005525; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21120&authkey=aozmspl2dqkgkgy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005526; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21123&authkey=aj18p0rtfbtwa84"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005527; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21139&authkey=ahwfjvw4zmjukeo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005528; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21140&authkey=aksvfpmrfqrrggw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005529; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21141&authkey=acznh6clby0qyww"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005530; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21142&authkey=ajf7j1rr3d7jcxy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005531; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21143&authkey=ahs21wnsqb_vu9w"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005532; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b50c4248502103d0&resid=b50c4248502103d0%21107&authkey=alf1nley7ja4dbq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005533; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6!164&authkey=adfsfcdaw3biboy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005534; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6%21164&authkey=adfsfcdaw3biboy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005535; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b7cb31db66675eb4&resid=b7cb31db66675eb4%21922&authkey=aghayyucvwey7lg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005536; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b86046e8cbd4254b&resid=b86046e8cbd4254b%21115&authkey=agwstptwpaquleg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005537; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b!7521&authkey=ablt9zdyq2d4rb0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005538; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b%217521&authkey=ablt9zdyq2d4rb0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005539; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b90c1aa3b6cd0326&resid=b90c1aa3b6cd0326%21471&authkey=aoil8ra4oc4s_2m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005540; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=b9690a1860a591d0&resid=b9690a1860a591d0%21161&authkey=aehawjpwf6tqtm8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005541; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b!246&authkey=afyrchdutalpu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005542; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b%21246&authkey=afyrchdutalpu90"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005543; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=bf83d9247c2329e0&resid=bf83d9247c2329e0%211108&authkey=absaw-bpqrc6mpq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005544; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c121261804708478&resid=c121261804708478%214199&authkey=adgqe8qiyu92bqm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005545; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c121261804708478&resid=c121261804708478%214200&authkey=adqtju8i3nmlgai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005546; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c121261804708478&resid=c121261804708478%214201&authkey=ahqber27s7gg8kk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005547; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019!1251&authkey=act34eizpzjugfa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005548; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019%211251&authkey=act34eizpzjugfa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005549; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1337&authkey=afnvu1fsuczht5e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005550; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1338&authkey=ajngambosws75_c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005551; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1340&authkey=al1ay3fbtude6d8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005552; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1342&authkey=acpr_htn2jtaxfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005553; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1343&authkey=abodysrxu9l2xxu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005554; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1344&authkey=aozerppd6mnokwy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005555; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1345&authkey=aevvyhonxhtcdh0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005556; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1346&authkey=achrnf5vlov1gf4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005557; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1347&authkey=al-zge-ttvr921s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005558; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211337&authkey=afnvu1fsuczht5e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005559; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211338&authkey=ajngambosws75_c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005560; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211340&authkey=al1ay3fbtude6d8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005561; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211342&authkey=acpr_htn2jtaxfu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005562; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211343&authkey=abodysrxu9l2xxu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005563; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211344&authkey=aozerppd6mnokwy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005564; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211345&authkey=aevvyhonxhtcdh0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005565; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211346&authkey=achrnf5vlov1gf4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005566; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211347&authkey=al-zge-ttvr921s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005567; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c701663053a57d59&resid=c701663053a57d59%211009&authkey=ahowgkak7j0p2q8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005568; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21486&authkey=amy4euf_rrlcykc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005569; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21489&authkey=ako3anwfnqfohnc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005570; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c7c32628aba70e70&resid=c7c32628aba70e70%21114&authkey=agdy8xpuh32sluw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005571; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c80630c4d385fb9d&resid=c80630c4d385fb9d%21286&authkey=amgaucv8bld_5qs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005572; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c8b0c7dc2b2570c5&resid=c8b0c7dc2b2570c5!122&authkey=aa4yfqt4cckzxhe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005573; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=c8b0c7dc2b2570c5&resid=c8b0c7dc2b2570c5%21122&authkey=aa4yfqt4cckzxhe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005574; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21546&authkey=aa6q-ryiifnet5m"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005575; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21547&authkey=aipm8qnwbgo4yga"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005576; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!355&authkey=aajjwf_sm4xdqdk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005577; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!357&authkey=alw3vqqxz6myrle"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005578; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21354&authkey=aa_ukeour7rex1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005579; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21355&authkey=aajjwf_sm4xdqdk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005580; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21357&authkey=alw3vqqxz6myrle"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005581; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ca897bdd16fc7940&resid=ca897bdd16fc7940%21106&authkey=aniklpt8vtlahbg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005582; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2!109&authkey=ac4gxwjoopafr9a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005583; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2%21109&authkey=ac4gxwjoopafr9a"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005584; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cbb66cac420484bc&resid=cbb66cac420484bc!10968&authkey=aj9bjkobu-rlnaw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005585; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!742&authkey=akbxju17f8g0r2s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005586; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!744&authkey=adak4zftd0yhhhs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005587; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21742&authkey=akbxju17f8g0r2s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005588; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21744&authkey=adak4zftd0yhhhs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005589; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!872&authkey=ap9hchztywo8zuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005590; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!874&authkey=alkzcbxz-dscgum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005591; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!875&authkey=aka55ybdhqnoc6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005592; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21872&authkey=ap9hchztywo8zuo"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005593; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21874&authkey=alkzcbxz-dscgum"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005594; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21875&authkey=aka55ybdhqnoc6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005595; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d2f3748954f6f8a8&resid=d2f3748954f6f8a8%21119&authkey=aex5s9uoun2zps0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005596; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1029&authkey=ann3uz8huqi7ogw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005597; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1030&authkey=aeqnasuksxccax4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005598; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1031&authkey=acxtarrhbwrqt20"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005599; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1032&authkey=aemitbkn-vma9yk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005600; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1033&authkey=abiydifgst6musa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005601; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1035&authkey=ahd_ichsrf8ok_u"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005602; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1038&authkey=anxf-kuw1jn9-8y"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005603; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211029&authkey=ann3uz8huqi7ogw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005604; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211030&authkey=aeqnasuksxccax4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005605; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211031&authkey=acxtarrhbwrqt20"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005606; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211032&authkey=aemitbkn-vma9yk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005607; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211033&authkey=abiydifgst6musa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005608; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211035&authkey=ahd_ichsrf8ok_u"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005609; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!191&authkey=ajl2uegqunsgc3q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005610; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!192&authkey=acd_hx4bka3z0nw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005611; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21191&authkey=ajl2uegqunsgc3q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005612; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21192&authkey=acd_hx4bka3z0nw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005613; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005614; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21107&authkey=alo4lep7wht05na"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005615; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21109&authkey=adnbm6mekgzvvh8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005616; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!141&authkey=alya4infudqs53o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005617; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!142&authkey=aiemnxi-s-5vrz0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005618; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21141&authkey=alya4infudqs53o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005619; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21142&authkey=aiemnxi-s-5vrz0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005620; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21142&authkey=aiemnxi-s-5vrz0&c=3ii9gcd&r=5onulz3wldybwlmup37su3&k=7s1&s=kzymn52eroemh1tamvmlsfsn9jtvwguukky5hlxcfgw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005621; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=db0fc77df51690e1&resid=db0fc77df51690e1%21802&authkey=apefr8w_rdk--pe"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005622; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=db5548cd728f142b&resid=db5548cd728f142b%21187&authkey=aansxudby0o7uwq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005623; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=db62f747c6d887d0&resid=db62f747c6d887d0%21111&authkey=ai2guftczvfehs4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005624; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dcd65237fcd1a1a9&resid=dcd65237fcd1a1a9%21162&authkey=aprqs0hugnfo6uq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005625; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7527&authkey=aipybipwht56um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005626; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7530&authkey=am9p2ic6zdkgfmy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005627; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7532&authkey=aonjnubquvon_uk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005628; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217527&authkey=aipybipwht56um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005629; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217530&authkey=am9p2ic6zdkgfmy"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005630; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217532&authkey=aonjnubquvon_uk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005631; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21107&authkey=akrabrcroiddkxw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005632; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21115&authkey=ad1ncwtj_zcjsh0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005633; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21132&authkey=akpbxohbtjebyn4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005634; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21150&authkey=aevazjbqnu7cmjs"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005635; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21160&authkey=aiendf-9lyln0x0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005636; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e1065ab3e86a5fc2&resid=e1065ab3e86a5fc2%211443&authkey=apybkcvf4iwxp_q"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005637; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e3ddc3980f743711&resid=e3ddc3980f743711%21795&authkey=aptivsvyk2we5xc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005638; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21745&authkey=ah1i_jo73zgdxpc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005639; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21746&authkey=ag1mhwlznwdxpw0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005640; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e43694f4bd6f68d1&resid=e43694f4bd6f68d1!563&authkey=aj8ovsob9ll6r-c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005641; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!509&authkey=akmdyqkzcsuf_gg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005642; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!511&authkey=agfs0q7dz7os1lu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005643; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c%21511&authkey=agfs0q7dz7os1lu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005644; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e54ea4e0368d023b&resid=e54ea4e0368d023b%21106&authkey=aozas6g9pm0fzvq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005645; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21349&authkey=ae9ea8jdsa7vmom"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005646; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21350&authkey=ao-vuexoihzj7da"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005647; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2!142&authkey=ais88uad5aom6qu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005648; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2%21142&authkey=ais88uad5aom6qu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005649; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e97110434470423e&resid=e97110434470423e%21113&authkey=afowclex54if0g0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005650; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005651; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005652; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211215&authkey=ac1jr_bieufz0ai"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005653; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211219&authkey=akgo75rmvr4khlc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005654; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ebacca5dec27fd20&resid=ebacca5dec27fd20%2118735&authkey=ajfyl1mzidnylc8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005655; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21113&authkey=aovavpmokd2jrns"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005656; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21116&authkey=aadnj5xyfasugu8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005657; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ef04dd7f0a6a5f7c&resid=ef04dd7f0a6a5f7c%21142&authkey=aad-nuysvlhc-i4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005658; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!202&authkey=ah1gjq8j29darw4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005659; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!203&authkey=af8xr99mrqp8um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005660; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!204&authkey=ad0nbzlscbg-0sa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005661; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21202&authkey=ah1gjq8j29darw4"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005662; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21203&authkey=af8xr99mrqp8um8"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005663; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21204&authkey=ad0nbzlscbg-0sa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005664; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21489&authkey=ads_gff3tjkd0w0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005665; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21490&authkey=aj_rld7xooge6aw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005666; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21492&authkey=ahdb75ptd1_uc8e"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005667; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f06038a5f7dbd6d6&resid=f06038a5f7dbd6d6%215498&authkey=aiozi3z5qzdysmu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005668; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f293cebb54e5ea71&resid=f293cebb54e5ea71%21293&authkey=aha74rsqiuewnpq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005669; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21566&authkey=aevafh7rydhi19k"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005670; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21581&authkey=agx0b8ho87w4uie"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005671; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21582&authkey=af-9_xwysl1o7-c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005672; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21598&authkey=ah-gkc-b7fa8h-g"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005673; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21599&authkey=aajunhe1ex_-zta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005674; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!216&authkey=alslscyemd7hr_o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005675; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!223&authkey=ajbtso2laio00ao"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005676; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21216&authkey=alslscyemd7hr_o"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005677; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f50a3aff00683adc&resid=f50a3aff00683adc%21108&authkey=ac44gtgp13l9xpw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005678; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f50a3aff00683adc&resid=f50a3aff00683adc%21139&authkey=aovmqh4ookdlkty"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005679; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f79e41c0e32d3314&resid=f79e41c0e32d3314%211182&authkey=aiqtptberyvlgqk&em=2%22"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005680; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806!1368&authkey=anphh1fijhvzv6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005681; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806%211368&authkey=anphh1fijhvzv6c"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005682; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382!159&authkey=ai4_8srrzf48hw0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005683; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382%21159&authkey=ai4_8srrzf48hw0"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005684; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fb2177c192eed796&resid=fb2177c192eed796%21124&authkey=abotnmdhu_tg7bc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005685; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fd50774e5ce0e314&resid=fd50774e5ce0e314%21778&authkey=aoxb2vhhz3qodiu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005686; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fe85161c3947f2c1&resid=fe85161c3947f2c1%211441&authkey=agb6c1ecr91svrw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005687; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e!192&authkey=ab_lrrmyxmcfrjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005688; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e%21192&authkey=ab_lrrmyxmcfrjc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005689; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!693&authkey=agcpkhnewfte_yc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005690; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!694&authkey=aa5jqzjsp0esr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005691; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21693&authkey=agcpkhnewfte_yc"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005692; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21694&authkey=aa5jqzjsp0esr1s"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005693; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!330&authkey=adxnzkb0a09pizw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005694; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!334&authkey=agsvox_t7qim4ta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005695; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!335&authkey=ach14e6omcghwgg"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005696; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21330&authkey=adxnzkb0a09pizw"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005697; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21333&authkey=aielwtaiuvcttlm"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005698; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005699; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/raw/yqvsvlvq"; http_uri; nocase; content:"pastebin.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005700; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/llc/mwcacs65xienqdp/"; http_uri; nocase; content:"pierreconsulting.info"; content:"Host"; http_header; classtype:trojan-activity; sid:100005701; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/bayesian-forecasting-amj5e/s5hqmf6/"; http_uri; nocase; content:"pioneiraagronegocio.com.br"; content:"Host"; http_header; classtype:trojan-activity; sid:100005702; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/2020/10/skoda22.jpg"; http_uri; nocase; content:"procrossover.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100005703; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/2020/10/skodaqq.jpg"; http_uri; nocase; content:"procrossover.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100005704; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/zzcoiatsr5wujrwagsgbnm2wkjxldvgu/"; http_uri; nocase; content:"qjbutterflyevents.co.za"; content:"Host"; http_header; classtype:trojan-activity; sid:100005705; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/order+acknowledgement+bc202374++stock++20021+dem+p4.ace"; http_uri; nocase; content:"quen.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005706; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/purchasing+ordersigned+contractinv-30067121.ace"; http_uri; nocase; content:"quen.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005707; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/arntsonl/calc_security_poc/master/dll/calc.dll"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005708; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/bero1985/berotinypascal/e34bd4164f4b7c27e7cf667dffd9274d33d6dfbe/bin/btpc.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005709; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/evil-coder66/defendercontrol/main/defendercontrol.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005710; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/fuzzbunch/fuzzbunch/master/payloads/doublepulsar-1.3.1.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005711; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005712; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/malwares/webshell/master/ajax_php%20command%20shell.rar"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005713; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/myqseeaccount/one/main/one.htm"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005714; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/realtek25556/rhti2/gh-pages/90hfnvo69vk2ot.bmp"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005715; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/secwiki/windows-kernel-exploits/master/ms15-076/binary/trebuchet.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005716; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/secwiki/windows-kernel-exploits/master/ms16-098/bfill.exe"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005717; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tennc/webshell/master/other/small_shell.txt"; http_uri; nocase; content:"raw.githubusercontent.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005718; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/player/launch/2017/09/12/da5f9a1c23034353852750488feeaf36.exe"; http_uri; nocase; content:"res.yeshen.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005719; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pro/dl/q05z91"; http_uri; nocase; content:"sendspace.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005720; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ey4lpx8rx.zip"; http_uri; nocase; content:"shribharatvatika.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005721; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/site/stormqk/dn/stormagent.apk?attredirects=0"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005722; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6ca94027662tilxa4p/base.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005723; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005724; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6cd19c87f44r9fomit/base64jef.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005725; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6e2cbda22efxk3t7x2/base64.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005726; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6e2f6c8c5adup2yiwx/basejefin.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005727; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6eab37b8dadmy1gx7c/base3.5.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005728; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6eb2aa215a8cvwcf6s/fudjs.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005729; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aamus8/go.jpeg"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005730; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c7921a2cf26cunjcgvm/nanocoregomes.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005731; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005732; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/a-nurse-ss8d9/z/"; http_uri; nocase; content:"technologydistilled.com"; content:"Host"; http_header; classtype:trojan-activity; sid:100005733; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/databases/merit.php"; http_uri; nocase; content:"truemerit.io"; content:"Host"; http_header; classtype:trojan-activity; sid:100005734; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/23.exe"; http_uri; nocase; content:"tsrv4.ws"; content:"Host"; http_header; classtype:trojan-activity; sid:100005735; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/crisanar/defis/jek_crackme1.7.zip"; http_uri; nocase; content:"users.skynet.be"; content:"Host"; http_header; classtype:trojan-activity; sid:100005736; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/gnuboard/data/scan/amowvegfrt9ja/"; http_uri; nocase; content:"vniel.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100005737; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/gnuboard/data/scan/fu6jvxzzs46uqlp7l/"; http_uri; nocase; content:"vniel.co.kr"; content:"Host"; http_header; classtype:trojan-activity; sid:100005738; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/kolya/.f/root/net.mit.edu/net/user/chris/winnt/mit_agenda2a.doc"; http_uri; nocase; content:"web.mit.edu"; content:"Host"; http_header; classtype:trojan-activity; sid:100005739; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/kolya/.f/root/net.mit.edu/sipb/user/kolya/afs/root.afs/net/user/chris/winnt/mit_agenda2a.doc"; http_uri; nocase; content:"web.mit.edu"; content:"Host"; http_header; classtype:trojan-activity; sid:100005740; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/136_140/flt_shovemydiscoupyourarse.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100005741; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/136_140/kb%5efr_ouverture.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100005742; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/136_140/kb^fr_ouverture.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100005743; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/146_150/bc_memories_from_the_mcp.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100005744; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/issues/151_155/tidex_-_short_stuff.exe"; http_uri; nocase; content:"websound.ru"; content:"Host"; http_header; classtype:trojan-activity; sid:100005745; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/syria-files/attach/222/222051_instruction.zip"; http_uri; nocase; content:"wikileaks.org"; content:"Host"; http_header; classtype:trojan-activity; sid:100005746; rev:1;)
+alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; content:"GET"; http_method; content:"/common/yz.vbs"; http_uri; nocase; content:"yp.hnggzyjy.cn"; content:"Host"; http_header; classtype:trojan-activity; sid:100005747; rev:1;)
diff --git a/urlhaus-filter-snort3-online.rules b/urlhaus-filter-snort3-online.rules
index 4237aadd..bee0685a 100644
--- a/urlhaus-filter-snort3-online.rules
+++ b/urlhaus-filter-snort3-online.rules
@@ -1,5 +1,5 @@
 # Title: Online Malicious URL Snort3 Ruleset
-# Updated: Thu, 25 Mar 2021 12:12:40 UTC
+# Updated: Fri, 26 Mar 2021 00:12:29 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -12,29 +12,29 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.192.180.19",nocase; classtype:trojan-activity; sid:100000006; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.222.140.251",nocase; classtype:trojan-activity; sid:100000007; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.222.196.60",nocase; classtype:trojan-activity; sid:100000008; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.24.132.118",nocase; classtype:trojan-activity; sid:100000009; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.245.4.163",nocase; classtype:trojan-activity; sid:100000010; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.107",nocase; classtype:trojan-activity; sid:100000011; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.109",nocase; classtype:trojan-activity; sid:100000012; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.127",nocase; classtype:trojan-activity; sid:100000013; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.134",nocase; classtype:trojan-activity; sid:100000014; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.14",nocase; classtype:trojan-activity; sid:100000015; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.153",nocase; classtype:trojan-activity; sid:100000016; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.16",nocase; classtype:trojan-activity; sid:100000017; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.165",nocase; classtype:trojan-activity; sid:100000018; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.245.4.163",nocase; classtype:trojan-activity; sid:100000009; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.107",nocase; classtype:trojan-activity; sid:100000010; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.109",nocase; classtype:trojan-activity; sid:100000011; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.127",nocase; classtype:trojan-activity; sid:100000012; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.134",nocase; classtype:trojan-activity; sid:100000013; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.14",nocase; classtype:trojan-activity; sid:100000014; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.153",nocase; classtype:trojan-activity; sid:100000015; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.16",nocase; classtype:trojan-activity; sid:100000016; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.165",nocase; classtype:trojan-activity; sid:100000017; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.228",nocase; classtype:trojan-activity; sid:100000018; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.232",nocase; classtype:trojan-activity; sid:100000019; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.234",nocase; classtype:trojan-activity; sid:100000020; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.245",nocase; classtype:trojan-activity; sid:100000021; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.249",nocase; classtype:trojan-activity; sid:100000022; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.38",nocase; classtype:trojan-activity; sid:100000023; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.41",nocase; classtype:trojan-activity; sid:100000024; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.43",nocase; classtype:trojan-activity; sid:100000025; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.45",nocase; classtype:trojan-activity; sid:100000026; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.56",nocase; classtype:trojan-activity; sid:100000027; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.69",nocase; classtype:trojan-activity; sid:100000028; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.8",nocase; classtype:trojan-activity; sid:100000029; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.80",nocase; classtype:trojan-activity; sid:100000030; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.9",nocase; classtype:trojan-activity; sid:100000031; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.237",nocase; classtype:trojan-activity; sid:100000021; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.245",nocase; classtype:trojan-activity; sid:100000022; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.249",nocase; classtype:trojan-activity; sid:100000023; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.38",nocase; classtype:trojan-activity; sid:100000024; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.41",nocase; classtype:trojan-activity; sid:100000025; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.43",nocase; classtype:trojan-activity; sid:100000026; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.45",nocase; classtype:trojan-activity; sid:100000027; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.56",nocase; classtype:trojan-activity; sid:100000028; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.69",nocase; classtype:trojan-activity; sid:100000029; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.8",nocase; classtype:trojan-activity; sid:100000030; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.80",nocase; classtype:trojan-activity; sid:100000031; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.222.98",nocase; classtype:trojan-activity; sid:100000032; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.10",nocase; classtype:trojan-activity; sid:100000033; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.246.223.103",nocase; classtype:trojan-activity; sid:100000034; rev:1;)
@@ -66,72 +66,72 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.250.159.41",nocase; classtype:trojan-activity; sid:100000060; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.252.102.28",nocase; classtype:trojan-activity; sid:100000061; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.254.250.52",nocase; classtype:trojan-activity; sid:100000062; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.60.77.53",nocase; classtype:trojan-activity; sid:100000063; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.62.195.101",nocase; classtype:trojan-activity; sid:100000064; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.58.223.96",nocase; classtype:trojan-activity; sid:100000063; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.60.77.53",nocase; classtype:trojan-activity; sid:100000064; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.65.166.225",nocase; classtype:trojan-activity; sid:100000065; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.82.104.89",nocase; classtype:trojan-activity; sid:100000066; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1.85.84.38",nocase; classtype:trojan-activity; sid:100000067; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"100.12.184.63",nocase; classtype:trojan-activity; sid:100000068; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"100.2.131.143",nocase; classtype:trojan-activity; sid:100000069; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"100.8.77.4",nocase; classtype:trojan-activity; sid:100000070; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1008691.com",nocase; classtype:trojan-activity; sid:100000071; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.108.130.108",nocase; classtype:trojan-activity; sid:100000072; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.108.131.202",nocase; classtype:trojan-activity; sid:100000073; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.108.133.231",nocase; classtype:trojan-activity; sid:100000074; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.16.183.179",nocase; classtype:trojan-activity; sid:100000075; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.16.98.170",nocase; classtype:trojan-activity; sid:100000076; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.229.85.127",nocase; classtype:trojan-activity; sid:100000077; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.255.36.154",nocase; classtype:trojan-activity; sid:100000078; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.28.102.38",nocase; classtype:trojan-activity; sid:100000079; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.28.105.132",nocase; classtype:trojan-activity; sid:100000080; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.28.106.134",nocase; classtype:trojan-activity; sid:100000081; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.28.145.2",nocase; classtype:trojan-activity; sid:100000082; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.28.76.34",nocase; classtype:trojan-activity; sid:100000083; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.30.128.184",nocase; classtype:trojan-activity; sid:100000084; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.64.119.250",nocase; classtype:trojan-activity; sid:100000085; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.64.161.70",nocase; classtype:trojan-activity; sid:100000086; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.75.157.99",nocase; classtype:trojan-activity; sid:100000087; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"102.130.115.14",nocase; classtype:trojan-activity; sid:100000088; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"102.141.240.139",nocase; classtype:trojan-activity; sid:100000089; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.106.29.148",nocase; classtype:trojan-activity; sid:100000090; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.107.113.22",nocase; classtype:trojan-activity; sid:100000091; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.113.99.79",nocase; classtype:trojan-activity; sid:100000092; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.124.104.118",nocase; classtype:trojan-activity; sid:100000093; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.125.218.107",nocase; classtype:trojan-activity; sid:100000094; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.136.82.50",nocase; classtype:trojan-activity; sid:100000095; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.139.89.205",nocase; classtype:trojan-activity; sid:100000096; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.141.138.12",nocase; classtype:trojan-activity; sid:100000097; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.144.36.20",nocase; classtype:trojan-activity; sid:100000098; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.145.13.24",nocase; classtype:trojan-activity; sid:100000099; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.146.174.208",nocase; classtype:trojan-activity; sid:100000100; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.156.221.66",nocase; classtype:trojan-activity; sid:100000101; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.16.145.25",nocase; classtype:trojan-activity; sid:100000102; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.217.215.21",nocase; classtype:trojan-activity; sid:100000103; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.224.200.40",nocase; classtype:trojan-activity; sid:100000104; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.233.64.182",nocase; classtype:trojan-activity; sid:100000105; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.235.165.183",nocase; classtype:trojan-activity; sid:100000106; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.238.228.3",nocase; classtype:trojan-activity; sid:100000107; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.238.228.4",nocase; classtype:trojan-activity; sid:100000108; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.240.249.121",nocase; classtype:trojan-activity; sid:100000109; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.70.160.51",nocase; classtype:trojan-activity; sid:100000110; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.79.112.254",nocase; classtype:trojan-activity; sid:100000111; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.82.145.111",nocase; classtype:trojan-activity; sid:100000112; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.82.98.170",nocase; classtype:trojan-activity; sid:100000113; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.84.240.130",nocase; classtype:trojan-activity; sid:100000114; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.84.240.228",nocase; classtype:trojan-activity; sid:100000115; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.11",nocase; classtype:trojan-activity; sid:100000116; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.12",nocase; classtype:trojan-activity; sid:100000117; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.17",nocase; classtype:trojan-activity; sid:100000118; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.19",nocase; classtype:trojan-activity; sid:100000119; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.20",nocase; classtype:trojan-activity; sid:100000120; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.3",nocase; classtype:trojan-activity; sid:100000121; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.36",nocase; classtype:trojan-activity; sid:100000122; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"100.12.184.63",nocase; classtype:trojan-activity; sid:100000067; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"100.2.131.143",nocase; classtype:trojan-activity; sid:100000068; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"100.8.77.4",nocase; classtype:trojan-activity; sid:100000069; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1008691.com",nocase; classtype:trojan-activity; sid:100000070; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.108.130.108",nocase; classtype:trojan-activity; sid:100000071; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.16.183.179",nocase; classtype:trojan-activity; sid:100000072; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.16.98.170",nocase; classtype:trojan-activity; sid:100000073; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.229.85.127",nocase; classtype:trojan-activity; sid:100000074; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.255.36.154",nocase; classtype:trojan-activity; sid:100000075; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.28.105.132",nocase; classtype:trojan-activity; sid:100000076; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.28.106.134",nocase; classtype:trojan-activity; sid:100000077; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.28.145.2",nocase; classtype:trojan-activity; sid:100000078; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.28.76.34",nocase; classtype:trojan-activity; sid:100000079; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.30.128.184",nocase; classtype:trojan-activity; sid:100000080; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.64.119.250",nocase; classtype:trojan-activity; sid:100000081; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.64.161.70",nocase; classtype:trojan-activity; sid:100000082; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"101.75.157.99",nocase; classtype:trojan-activity; sid:100000083; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"102.130.115.14",nocase; classtype:trojan-activity; sid:100000084; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"102.141.240.139",nocase; classtype:trojan-activity; sid:100000085; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.107.113.22",nocase; classtype:trojan-activity; sid:100000086; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.113.99.79",nocase; classtype:trojan-activity; sid:100000087; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.124.104.118",nocase; classtype:trojan-activity; sid:100000088; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.125.218.107",nocase; classtype:trojan-activity; sid:100000089; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.136.82.50",nocase; classtype:trojan-activity; sid:100000090; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.141.138.12",nocase; classtype:trojan-activity; sid:100000091; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.144.36.20",nocase; classtype:trojan-activity; sid:100000092; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.145.13.24",nocase; classtype:trojan-activity; sid:100000093; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.146.174.208",nocase; classtype:trojan-activity; sid:100000094; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.156.221.66",nocase; classtype:trojan-activity; sid:100000095; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.16.145.25",nocase; classtype:trojan-activity; sid:100000096; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.161.232.16",nocase; classtype:trojan-activity; sid:100000097; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.207.0.134",nocase; classtype:trojan-activity; sid:100000098; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.217.215.21",nocase; classtype:trojan-activity; sid:100000099; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.224.200.40",nocase; classtype:trojan-activity; sid:100000100; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.233.64.182",nocase; classtype:trojan-activity; sid:100000101; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.238.228.3",nocase; classtype:trojan-activity; sid:100000102; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.238.228.4",nocase; classtype:trojan-activity; sid:100000103; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.240.249.121",nocase; classtype:trojan-activity; sid:100000104; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.4.117.26",nocase; classtype:trojan-activity; sid:100000105; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.70.160.51",nocase; classtype:trojan-activity; sid:100000106; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.79.112.254",nocase; classtype:trojan-activity; sid:100000107; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.82.144.197",nocase; classtype:trojan-activity; sid:100000108; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.82.145.111",nocase; classtype:trojan-activity; sid:100000109; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.82.98.151",nocase; classtype:trojan-activity; sid:100000110; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.82.98.170",nocase; classtype:trojan-activity; sid:100000111; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.84.240.228",nocase; classtype:trojan-activity; sid:100000112; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.12",nocase; classtype:trojan-activity; sid:100000113; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.16",nocase; classtype:trojan-activity; sid:100000114; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.17",nocase; classtype:trojan-activity; sid:100000115; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.19",nocase; classtype:trojan-activity; sid:100000116; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.20",nocase; classtype:trojan-activity; sid:100000117; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.27",nocase; classtype:trojan-activity; sid:100000118; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.3",nocase; classtype:trojan-activity; sid:100000119; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.30",nocase; classtype:trojan-activity; sid:100000120; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.36",nocase; classtype:trojan-activity; sid:100000121; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.41",nocase; classtype:trojan-activity; sid:100000122; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.46",nocase; classtype:trojan-activity; sid:100000123; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.47",nocase; classtype:trojan-activity; sid:100000124; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.91.245.54",nocase; classtype:trojan-activity; sid:100000125; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.92.25.90",nocase; classtype:trojan-activity; sid:100000126; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"103.92.25.95",nocase; classtype:trojan-activity; sid:100000127; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.168.44.57",nocase; classtype:trojan-activity; sid:100000128; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.168.98.105",nocase; classtype:trojan-activity; sid:100000128; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.184.75.123",nocase; classtype:trojan-activity; sid:100000129; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.33.52.85",nocase; classtype:trojan-activity; sid:100000130; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"104.61.86.37",nocase; classtype:trojan-activity; sid:100000131; rev:1;)
@@ -140,5638 +140,5614 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.104.193.155",nocase; classtype:trojan-activity; sid:100000134; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.113.145.32",nocase; classtype:trojan-activity; sid:100000135; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.113.177.60",nocase; classtype:trojan-activity; sid:100000136; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.172.134.48",nocase; classtype:trojan-activity; sid:100000137; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.172.193.132",nocase; classtype:trojan-activity; sid:100000138; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.172.249.148",nocase; classtype:trojan-activity; sid:100000139; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.173.155.54",nocase; classtype:trojan-activity; sid:100000140; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.174.144.195",nocase; classtype:trojan-activity; sid:100000141; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.175.197.135",nocase; classtype:trojan-activity; sid:100000142; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.181.136.96",nocase; classtype:trojan-activity; sid:100000143; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.194.242.170",nocase; classtype:trojan-activity; sid:100000144; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.219.185.75",nocase; classtype:trojan-activity; sid:100000145; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.220.119.25",nocase; classtype:trojan-activity; sid:100000146; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.221.96.202",nocase; classtype:trojan-activity; sid:100000147; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"108.190.201.37",nocase; classtype:trojan-activity; sid:100000148; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"108.190.250.48",nocase; classtype:trojan-activity; sid:100000149; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"108.55.199.65",nocase; classtype:trojan-activity; sid:100000150; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.104.151.108",nocase; classtype:trojan-activity; sid:100000151; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.124.90.229",nocase; classtype:trojan-activity; sid:100000152; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.233.196.232",nocase; classtype:trojan-activity; sid:100000153; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.235.7.228",nocase; classtype:trojan-activity; sid:100000154; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.248.58.238",nocase; classtype:trojan-activity; sid:100000155; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"106.4.138.95",nocase; classtype:trojan-activity; sid:100000137; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.172.134.48",nocase; classtype:trojan-activity; sid:100000138; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.172.193.132",nocase; classtype:trojan-activity; sid:100000139; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.172.249.148",nocase; classtype:trojan-activity; sid:100000140; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.173.155.54",nocase; classtype:trojan-activity; sid:100000141; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.174.144.195",nocase; classtype:trojan-activity; sid:100000142; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.175.197.135",nocase; classtype:trojan-activity; sid:100000143; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.181.136.96",nocase; classtype:trojan-activity; sid:100000144; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.194.242.170",nocase; classtype:trojan-activity; sid:100000145; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.219.185.75",nocase; classtype:trojan-activity; sid:100000146; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.220.119.25",nocase; classtype:trojan-activity; sid:100000147; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"107.221.96.202",nocase; classtype:trojan-activity; sid:100000148; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"108.190.201.37",nocase; classtype:trojan-activity; sid:100000149; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"108.190.250.48",nocase; classtype:trojan-activity; sid:100000150; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"108.55.199.65",nocase; classtype:trojan-activity; sid:100000151; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.104.151.108",nocase; classtype:trojan-activity; sid:100000152; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.124.90.229",nocase; classtype:trojan-activity; sid:100000153; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.233.196.232",nocase; classtype:trojan-activity; sid:100000154; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.235.7.228",nocase; classtype:trojan-activity; sid:100000155; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.86.85.253",nocase; classtype:trojan-activity; sid:100000156; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.95.200.102",nocase; classtype:trojan-activity; sid:100000157; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.95.200.230",nocase; classtype:trojan-activity; sid:100000158; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.96.127.90",nocase; classtype:trojan-activity; sid:100000159; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.96.57.246",nocase; classtype:trojan-activity; sid:100000160; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.99.37.97",nocase; classtype:trojan-activity; sid:100000161; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"10abcabc0.cf",nocase; classtype:trojan-activity; sid:100000162; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.10.58.38",nocase; classtype:trojan-activity; sid:100000163; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.12.123.11",nocase; classtype:trojan-activity; sid:100000164; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.14.58.190",nocase; classtype:trojan-activity; sid:100000165; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.187.229.182",nocase; classtype:trojan-activity; sid:100000166; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.228.190.50",nocase; classtype:trojan-activity; sid:100000167; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.228.195.46",nocase; classtype:trojan-activity; sid:100000168; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.241.119.168",nocase; classtype:trojan-activity; sid:100000169; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.241.23.107",nocase; classtype:trojan-activity; sid:100000170; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.248.124.254",nocase; classtype:trojan-activity; sid:100000171; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.248.224.19",nocase; classtype:trojan-activity; sid:100000172; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.248.251.194",nocase; classtype:trojan-activity; sid:100000173; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.251.10.18",nocase; classtype:trojan-activity; sid:100000174; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.253.103.53",nocase; classtype:trojan-activity; sid:100000175; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.253.213.198",nocase; classtype:trojan-activity; sid:100000176; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.253.51.112",nocase; classtype:trojan-activity; sid:100000177; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.255.101.184",nocase; classtype:trojan-activity; sid:100000178; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.255.167.147",nocase; classtype:trojan-activity; sid:100000179; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.145.127",nocase; classtype:trojan-activity; sid:100000180; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.208.21",nocase; classtype:trojan-activity; sid:100000181; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.209.175",nocase; classtype:trojan-activity; sid:100000182; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.221.77",nocase; classtype:trojan-activity; sid:100000183; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.88.185.119",nocase; classtype:trojan-activity; sid:100000157; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.95.200.102",nocase; classtype:trojan-activity; sid:100000158; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.95.200.230",nocase; classtype:trojan-activity; sid:100000159; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.96.127.90",nocase; classtype:trojan-activity; sid:100000160; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.96.57.246",nocase; classtype:trojan-activity; sid:100000161; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"109.99.37.97",nocase; classtype:trojan-activity; sid:100000162; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"10abcabc0.cf",nocase; classtype:trojan-activity; sid:100000163; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.10.58.38",nocase; classtype:trojan-activity; sid:100000164; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.12.123.11",nocase; classtype:trojan-activity; sid:100000165; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.14.58.190",nocase; classtype:trojan-activity; sid:100000166; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.187.229.182",nocase; classtype:trojan-activity; sid:100000167; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.228.190.50",nocase; classtype:trojan-activity; sid:100000168; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.228.195.46",nocase; classtype:trojan-activity; sid:100000169; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.241.119.168",nocase; classtype:trojan-activity; sid:100000170; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.241.23.107",nocase; classtype:trojan-activity; sid:100000171; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.247.151.4",nocase; classtype:trojan-activity; sid:100000172; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.248.124.254",nocase; classtype:trojan-activity; sid:100000173; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.248.224.19",nocase; classtype:trojan-activity; sid:100000174; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.248.251.194",nocase; classtype:trojan-activity; sid:100000175; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.251.10.18",nocase; classtype:trojan-activity; sid:100000176; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.253.103.53",nocase; classtype:trojan-activity; sid:100000177; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.253.213.198",nocase; classtype:trojan-activity; sid:100000178; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.253.51.112",nocase; classtype:trojan-activity; sid:100000179; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.255.101.184",nocase; classtype:trojan-activity; sid:100000180; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.255.167.147",nocase; classtype:trojan-activity; sid:100000181; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.208.21",nocase; classtype:trojan-activity; sid:100000182; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.209.175",nocase; classtype:trojan-activity; sid:100000183; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.223.92",nocase; classtype:trojan-activity; sid:100000184; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.235.57",nocase; classtype:trojan-activity; sid:100000185; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.4.2",nocase; classtype:trojan-activity; sid:100000186; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.82.195.88",nocase; classtype:trojan-activity; sid:100000187; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110fss.net",nocase; classtype:trojan-activity; sid:100000188; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.118.124.223",nocase; classtype:trojan-activity; sid:100000189; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.118.41.173",nocase; classtype:trojan-activity; sid:100000190; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.118.88.61",nocase; classtype:trojan-activity; sid:100000191; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.125.67.125",nocase; classtype:trojan-activity; sid:100000192; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.160.112.142",nocase; classtype:trojan-activity; sid:100000193; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.162.224.14",nocase; classtype:trojan-activity; sid:100000194; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.163.50.120",nocase; classtype:trojan-activity; sid:100000195; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.17.186.194",nocase; classtype:trojan-activity; sid:100000196; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.170.84.182",nocase; classtype:trojan-activity; sid:100000197; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.170.86.133",nocase; classtype:trojan-activity; sid:100000198; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.172.164.104",nocase; classtype:trojan-activity; sid:100000199; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.176.182.149",nocase; classtype:trojan-activity; sid:100000200; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.179.153.69",nocase; classtype:trojan-activity; sid:100000201; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.179.243.126",nocase; classtype:trojan-activity; sid:100000202; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.182.232.18",nocase; classtype:trojan-activity; sid:100000203; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.177.85",nocase; classtype:trojan-activity; sid:100000204; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.23.84",nocase; classtype:trojan-activity; sid:100000205; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.230.136",nocase; classtype:trojan-activity; sid:100000206; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.27.9",nocase; classtype:trojan-activity; sid:100000207; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.48.248",nocase; classtype:trojan-activity; sid:100000208; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.103.122",nocase; classtype:trojan-activity; sid:100000209; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.103.13",nocase; classtype:trojan-activity; sid:100000210; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.103.66",nocase; classtype:trojan-activity; sid:100000211; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.104.141",nocase; classtype:trojan-activity; sid:100000212; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.104.165",nocase; classtype:trojan-activity; sid:100000213; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.106.128",nocase; classtype:trojan-activity; sid:100000214; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.106.19",nocase; classtype:trojan-activity; sid:100000215; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.106.48",nocase; classtype:trojan-activity; sid:100000216; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.121.222",nocase; classtype:trojan-activity; sid:100000217; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.121.223",nocase; classtype:trojan-activity; sid:100000218; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.121.228",nocase; classtype:trojan-activity; sid:100000219; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.123.18",nocase; classtype:trojan-activity; sid:100000220; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.123.184",nocase; classtype:trojan-activity; sid:100000221; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.123.197",nocase; classtype:trojan-activity; sid:100000222; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.123.200",nocase; classtype:trojan-activity; sid:100000223; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.123.23",nocase; classtype:trojan-activity; sid:100000224; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.26.173",nocase; classtype:trojan-activity; sid:100000225; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.26.243",nocase; classtype:trojan-activity; sid:100000226; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.8.81",nocase; classtype:trojan-activity; sid:100000227; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.61.52.53",nocase; classtype:trojan-activity; sid:100000228; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.73.99.162",nocase; classtype:trojan-activity; sid:100000229; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.91.185.131",nocase; classtype:trojan-activity; sid:100000230; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.93.169.90",nocase; classtype:trojan-activity; sid:100000231; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.105.117.227",nocase; classtype:trojan-activity; sid:100000232; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.111.100.236",nocase; classtype:trojan-activity; sid:100000233; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.111.108.184",nocase; classtype:trojan-activity; sid:100000234; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.111.31.175",nocase; classtype:trojan-activity; sid:100000235; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.122.36.108",nocase; classtype:trojan-activity; sid:100000236; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.123.109.156",nocase; classtype:trojan-activity; sid:100000237; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.123.200.47",nocase; classtype:trojan-activity; sid:100000238; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.123.61.115",nocase; classtype:trojan-activity; sid:100000239; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.132.134.106",nocase; classtype:trojan-activity; sid:100000240; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.170.124.75",nocase; classtype:trojan-activity; sid:100000241; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.170.233.9",nocase; classtype:trojan-activity; sid:100000242; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.186.210.211",nocase; classtype:trojan-activity; sid:100000243; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.186.96.252",nocase; classtype:trojan-activity; sid:100000244; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.187.91.117",nocase; classtype:trojan-activity; sid:100000245; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.214.127.42",nocase; classtype:trojan-activity; sid:100000246; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.187.19",nocase; classtype:trojan-activity; sid:100000247; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.236.77",nocase; classtype:trojan-activity; sid:100000248; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.43.27",nocase; classtype:trojan-activity; sid:100000249; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.52.145",nocase; classtype:trojan-activity; sid:100000250; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.82.4",nocase; classtype:trojan-activity; sid:100000251; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.118.229",nocase; classtype:trojan-activity; sid:100000252; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.176.167",nocase; classtype:trojan-activity; sid:100000253; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.195.104",nocase; classtype:trojan-activity; sid:100000254; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.202.111",nocase; classtype:trojan-activity; sid:100000255; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.205.96",nocase; classtype:trojan-activity; sid:100000256; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.47.235",nocase; classtype:trojan-activity; sid:100000257; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.67.193",nocase; classtype:trojan-activity; sid:100000258; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.92.34",nocase; classtype:trojan-activity; sid:100000259; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.228.100.15",nocase; classtype:trojan-activity; sid:100000260; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.228.180.95",nocase; classtype:trojan-activity; sid:100000261; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.228.79.114",nocase; classtype:trojan-activity; sid:100000262; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.228.79.137",nocase; classtype:trojan-activity; sid:100000263; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.229.178.109",nocase; classtype:trojan-activity; sid:100000264; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.229.188.28",nocase; classtype:trojan-activity; sid:100000265; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.229.199.19",nocase; classtype:trojan-activity; sid:100000266; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.234.134.244",nocase; classtype:trojan-activity; sid:100000267; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.234.16.252",nocase; classtype:trojan-activity; sid:100000268; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.234.194.178",nocase; classtype:trojan-activity; sid:100000269; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.234.216.151",nocase; classtype:trojan-activity; sid:100000270; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.234.218.202",nocase; classtype:trojan-activity; sid:100000271; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.235.149.73",nocase; classtype:trojan-activity; sid:100000272; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.235.188.86",nocase; classtype:trojan-activity; sid:100000273; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.236.126.177",nocase; classtype:trojan-activity; sid:100000274; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.236.171.69",nocase; classtype:trojan-activity; sid:100000275; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.236.228.21",nocase; classtype:trojan-activity; sid:100000276; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.141.241",nocase; classtype:trojan-activity; sid:100000277; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.144.226",nocase; classtype:trojan-activity; sid:100000278; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.197.144",nocase; classtype:trojan-activity; sid:100000279; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.230.192",nocase; classtype:trojan-activity; sid:100000280; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.75.157",nocase; classtype:trojan-activity; sid:100000281; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.89.82",nocase; classtype:trojan-activity; sid:100000282; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.143.135",nocase; classtype:trojan-activity; sid:100000283; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.17.120",nocase; classtype:trojan-activity; sid:100000284; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.190.207",nocase; classtype:trojan-activity; sid:100000285; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.194.18",nocase; classtype:trojan-activity; sid:100000286; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.227.228",nocase; classtype:trojan-activity; sid:100000287; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.73.181",nocase; classtype:trojan-activity; sid:100000288; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.240.184.162",nocase; classtype:trojan-activity; sid:100000289; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.240.216.17",nocase; classtype:trojan-activity; sid:100000290; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.242.106.228",nocase; classtype:trojan-activity; sid:100000291; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.242.18.128",nocase; classtype:trojan-activity; sid:100000292; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.242.2.247",nocase; classtype:trojan-activity; sid:100000293; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.243.115.183",nocase; classtype:trojan-activity; sid:100000294; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.245.12.89",nocase; classtype:trojan-activity; sid:100000295; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.245.246.253",nocase; classtype:trojan-activity; sid:100000296; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.245.5.141",nocase; classtype:trojan-activity; sid:100000297; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.245.8.24",nocase; classtype:trojan-activity; sid:100000298; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.246.162.50",nocase; classtype:trojan-activity; sid:100000299; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.100.14",nocase; classtype:trojan-activity; sid:100000300; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.121.39",nocase; classtype:trojan-activity; sid:100000301; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.14.135",nocase; classtype:trojan-activity; sid:100000302; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.161.45",nocase; classtype:trojan-activity; sid:100000303; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.191.118",nocase; classtype:trojan-activity; sid:100000304; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.214.146",nocase; classtype:trojan-activity; sid:100000305; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.240.226",nocase; classtype:trojan-activity; sid:100000306; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.81.173",nocase; classtype:trojan-activity; sid:100000307; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.82.122",nocase; classtype:trojan-activity; sid:100000308; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.89.81",nocase; classtype:trojan-activity; sid:100000309; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.248.148.90",nocase; classtype:trojan-activity; sid:100000310; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.248.197.164",nocase; classtype:trojan-activity; sid:100000311; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.248.44.153",nocase; classtype:trojan-activity; sid:100000312; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.109.217",nocase; classtype:trojan-activity; sid:100000313; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.118.157",nocase; classtype:trojan-activity; sid:100000314; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.26.129",nocase; classtype:trojan-activity; sid:100000315; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.41.142",nocase; classtype:trojan-activity; sid:100000316; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.250.102.173",nocase; classtype:trojan-activity; sid:100000317; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.250.57.99",nocase; classtype:trojan-activity; sid:100000318; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.251.17.5",nocase; classtype:trojan-activity; sid:100000319; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.251.218.210",nocase; classtype:trojan-activity; sid:100000320; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.251.23.55",nocase; classtype:trojan-activity; sid:100000321; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.136.84",nocase; classtype:trojan-activity; sid:100000322; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.199.150",nocase; classtype:trojan-activity; sid:100000323; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.221.244",nocase; classtype:trojan-activity; sid:100000324; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.236.40",nocase; classtype:trojan-activity; sid:100000325; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.237.109",nocase; classtype:trojan-activity; sid:100000326; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.239.103",nocase; classtype:trojan-activity; sid:100000327; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.245.249",nocase; classtype:trojan-activity; sid:100000328; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.254.208.123",nocase; classtype:trojan-activity; sid:100000329; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.255.38.10",nocase; classtype:trojan-activity; sid:100000330; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.255.52.179",nocase; classtype:trojan-activity; sid:100000331; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.255.8.235",nocase; classtype:trojan-activity; sid:100000332; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.121.163",nocase; classtype:trojan-activity; sid:100000333; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.123.174",nocase; classtype:trojan-activity; sid:100000334; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.109",nocase; classtype:trojan-activity; sid:100000335; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.110",nocase; classtype:trojan-activity; sid:100000336; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.111",nocase; classtype:trojan-activity; sid:100000337; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.112",nocase; classtype:trojan-activity; sid:100000338; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.117",nocase; classtype:trojan-activity; sid:100000339; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.119",nocase; classtype:trojan-activity; sid:100000340; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.120",nocase; classtype:trojan-activity; sid:100000341; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.122",nocase; classtype:trojan-activity; sid:100000342; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.127",nocase; classtype:trojan-activity; sid:100000343; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.128",nocase; classtype:trojan-activity; sid:100000344; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.130",nocase; classtype:trojan-activity; sid:100000345; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.131",nocase; classtype:trojan-activity; sid:100000346; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.132",nocase; classtype:trojan-activity; sid:100000347; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.133",nocase; classtype:trojan-activity; sid:100000348; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.136",nocase; classtype:trojan-activity; sid:100000349; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.139",nocase; classtype:trojan-activity; sid:100000350; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.140",nocase; classtype:trojan-activity; sid:100000351; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.142",nocase; classtype:trojan-activity; sid:100000352; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.143",nocase; classtype:trojan-activity; sid:100000353; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.144",nocase; classtype:trojan-activity; sid:100000354; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.146",nocase; classtype:trojan-activity; sid:100000355; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.149",nocase; classtype:trojan-activity; sid:100000356; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.150",nocase; classtype:trojan-activity; sid:100000357; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.151",nocase; classtype:trojan-activity; sid:100000358; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.155",nocase; classtype:trojan-activity; sid:100000359; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.158",nocase; classtype:trojan-activity; sid:100000360; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.160",nocase; classtype:trojan-activity; sid:100000361; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.162",nocase; classtype:trojan-activity; sid:100000362; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.163",nocase; classtype:trojan-activity; sid:100000363; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.165",nocase; classtype:trojan-activity; sid:100000364; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.168",nocase; classtype:trojan-activity; sid:100000365; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.171",nocase; classtype:trojan-activity; sid:100000366; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.172",nocase; classtype:trojan-activity; sid:100000367; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.175",nocase; classtype:trojan-activity; sid:100000368; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.176",nocase; classtype:trojan-activity; sid:100000369; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.178",nocase; classtype:trojan-activity; sid:100000370; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.179",nocase; classtype:trojan-activity; sid:100000371; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.71",nocase; classtype:trojan-activity; sid:100000372; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.126.243",nocase; classtype:trojan-activity; sid:100000373; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.127.155",nocase; classtype:trojan-activity; sid:100000374; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.80.120",nocase; classtype:trojan-activity; sid:100000375; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.80.121",nocase; classtype:trojan-activity; sid:100000376; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.80.98",nocase; classtype:trojan-activity; sid:100000377; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.82.29",nocase; classtype:trojan-activity; sid:100000378; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.83.182",nocase; classtype:trojan-activity; sid:100000379; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.83.23",nocase; classtype:trojan-activity; sid:100000380; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.87.213",nocase; classtype:trojan-activity; sid:100000381; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.88.116",nocase; classtype:trojan-activity; sid:100000382; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.91.212",nocase; classtype:trojan-activity; sid:100000383; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.91.247",nocase; classtype:trojan-activity; sid:100000384; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.150",nocase; classtype:trojan-activity; sid:100000385; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.158",nocase; classtype:trojan-activity; sid:100000386; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.159",nocase; classtype:trojan-activity; sid:100000387; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.168",nocase; classtype:trojan-activity; sid:100000388; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.177",nocase; classtype:trojan-activity; sid:100000389; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.178",nocase; classtype:trojan-activity; sid:100000390; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.181",nocase; classtype:trojan-activity; sid:100000391; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.188",nocase; classtype:trojan-activity; sid:100000392; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.194",nocase; classtype:trojan-activity; sid:100000393; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.197",nocase; classtype:trojan-activity; sid:100000394; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.200",nocase; classtype:trojan-activity; sid:100000395; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.211",nocase; classtype:trojan-activity; sid:100000396; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.219",nocase; classtype:trojan-activity; sid:100000397; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.229",nocase; classtype:trojan-activity; sid:100000398; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.230",nocase; classtype:trojan-activity; sid:100000399; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.245",nocase; classtype:trojan-activity; sid:100000400; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.247",nocase; classtype:trojan-activity; sid:100000401; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.54",nocase; classtype:trojan-activity; sid:100000402; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.55",nocase; classtype:trojan-activity; sid:100000403; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.57",nocase; classtype:trojan-activity; sid:100000404; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.60",nocase; classtype:trojan-activity; sid:100000405; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.90",nocase; classtype:trojan-activity; sid:100000406; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.91",nocase; classtype:trojan-activity; sid:100000407; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.100.228",nocase; classtype:trojan-activity; sid:100000408; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.27",nocase; classtype:trojan-activity; sid:100000409; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.30",nocase; classtype:trojan-activity; sid:100000410; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.31",nocase; classtype:trojan-activity; sid:100000411; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.32",nocase; classtype:trojan-activity; sid:100000412; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.33",nocase; classtype:trojan-activity; sid:100000413; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.37",nocase; classtype:trojan-activity; sid:100000414; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.38",nocase; classtype:trojan-activity; sid:100000415; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.41",nocase; classtype:trojan-activity; sid:100000416; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.42",nocase; classtype:trojan-activity; sid:100000417; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.43",nocase; classtype:trojan-activity; sid:100000418; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.52",nocase; classtype:trojan-activity; sid:100000419; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.55",nocase; classtype:trojan-activity; sid:100000420; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.57",nocase; classtype:trojan-activity; sid:100000421; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.58",nocase; classtype:trojan-activity; sid:100000422; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.60",nocase; classtype:trojan-activity; sid:100000423; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.62",nocase; classtype:trojan-activity; sid:100000424; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.64",nocase; classtype:trojan-activity; sid:100000425; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.35.237",nocase; classtype:trojan-activity; sid:100000426; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.38.100",nocase; classtype:trojan-activity; sid:100000427; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.38.19",nocase; classtype:trojan-activity; sid:100000428; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.118",nocase; classtype:trojan-activity; sid:100000429; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.119",nocase; classtype:trojan-activity; sid:100000430; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.121",nocase; classtype:trojan-activity; sid:100000431; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.136",nocase; classtype:trojan-activity; sid:100000432; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.37",nocase; classtype:trojan-activity; sid:100000433; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.52",nocase; classtype:trojan-activity; sid:100000434; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.53",nocase; classtype:trojan-activity; sid:100000435; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.73",nocase; classtype:trojan-activity; sid:100000436; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.77",nocase; classtype:trojan-activity; sid:100000437; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.90",nocase; classtype:trojan-activity; sid:100000438; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.31.211.135",nocase; classtype:trojan-activity; sid:100000439; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.53.224.79",nocase; classtype:trojan-activity; sid:100000440; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.53.227.57",nocase; classtype:trojan-activity; sid:100000441; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.53.227.66",nocase; classtype:trojan-activity; sid:100000442; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.65.53.175",nocase; classtype:trojan-activity; sid:100000443; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.153.37",nocase; classtype:trojan-activity; sid:100000444; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.162.159",nocase; classtype:trojan-activity; sid:100000445; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.162.49",nocase; classtype:trojan-activity; sid:100000446; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.162.53",nocase; classtype:trojan-activity; sid:100000447; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.175.147",nocase; classtype:trojan-activity; sid:100000448; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.176.112",nocase; classtype:trojan-activity; sid:100000449; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.176.84",nocase; classtype:trojan-activity; sid:100000450; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.226.202",nocase; classtype:trojan-activity; sid:100000451; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.231.35",nocase; classtype:trojan-activity; sid:100000452; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.78.45.158",nocase; classtype:trojan-activity; sid:100000453; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.80.118.16",nocase; classtype:trojan-activity; sid:100000454; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.80.127.91",nocase; classtype:trojan-activity; sid:100000455; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.80.215.101",nocase; classtype:trojan-activity; sid:100000456; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.81.161.10",nocase; classtype:trojan-activity; sid:100000457; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.81.199.218",nocase; classtype:trojan-activity; sid:100000458; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.81.49.200",nocase; classtype:trojan-activity; sid:100000459; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.131.124",nocase; classtype:trojan-activity; sid:100000460; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.141.200",nocase; classtype:trojan-activity; sid:100000461; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.146.253",nocase; classtype:trojan-activity; sid:100000462; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.148.146",nocase; classtype:trojan-activity; sid:100000463; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.18.255",nocase; classtype:trojan-activity; sid:100000464; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.224.139",nocase; classtype:trojan-activity; sid:100000465; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.227.41",nocase; classtype:trojan-activity; sid:100000466; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.228.175",nocase; classtype:trojan-activity; sid:100000467; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.86.133.125",nocase; classtype:trojan-activity; sid:100000468; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.86.23.41",nocase; classtype:trojan-activity; sid:100000469; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.86.253.238",nocase; classtype:trojan-activity; sid:100000470; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.9.140.247",nocase; classtype:trojan-activity; sid:100000471; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.93.29.211",nocase; classtype:trojan-activity; sid:100000472; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.95.22.17",nocase; classtype:trojan-activity; sid:100000473; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.95.23.121",nocase; classtype:trojan-activity; sid:100000474; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.103.10.209",nocase; classtype:trojan-activity; sid:100000475; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.105.71.239",nocase; classtype:trojan-activity; sid:100000476; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.11.95.254",nocase; classtype:trojan-activity; sid:100000477; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.110.247.207",nocase; classtype:trojan-activity; sid:100000478; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.116.121.167",nocase; classtype:trojan-activity; sid:100000479; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.116.149.83",nocase; classtype:trojan-activity; sid:100000480; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.116.246.109",nocase; classtype:trojan-activity; sid:100000481; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.116.48.217",nocase; classtype:trojan-activity; sid:100000482; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.118.195.247",nocase; classtype:trojan-activity; sid:100000483; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.122.238.68",nocase; classtype:trojan-activity; sid:100000484; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.122.59.84",nocase; classtype:trojan-activity; sid:100000485; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.161.58.249",nocase; classtype:trojan-activity; sid:100000486; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.172.250.35",nocase; classtype:trojan-activity; sid:100000487; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.179.129.99",nocase; classtype:trojan-activity; sid:100000488; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.188.76.31",nocase; classtype:trojan-activity; sid:100000489; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.194.133.9",nocase; classtype:trojan-activity; sid:100000490; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.194.135.154",nocase; classtype:trojan-activity; sid:100000491; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.195.163.26",nocase; classtype:trojan-activity; sid:100000492; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.195.166.46",nocase; classtype:trojan-activity; sid:100000493; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.224.225.172",nocase; classtype:trojan-activity; sid:100000494; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.226.42.250",nocase; classtype:trojan-activity; sid:100000495; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.227.128.9",nocase; classtype:trojan-activity; sid:100000496; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.227.169.170",nocase; classtype:trojan-activity; sid:100000497; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.227.35.229",nocase; classtype:trojan-activity; sid:100000498; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.231.211.131",nocase; classtype:trojan-activity; sid:100000499; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.231.93.142",nocase; classtype:trojan-activity; sid:100000500; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.232.141.23",nocase; classtype:trojan-activity; sid:100000501; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.232.211.182",nocase; classtype:trojan-activity; sid:100000502; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.235.116.209",nocase; classtype:trojan-activity; sid:100000503; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.237.129.7",nocase; classtype:trojan-activity; sid:100000504; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.245.218.18",nocase; classtype:trojan-activity; sid:100000505; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.254.169.251",nocase; classtype:trojan-activity; sid:100000506; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.3.153.57",nocase; classtype:trojan-activity; sid:100000507; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.3.155.199",nocase; classtype:trojan-activity; sid:100000508; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.133.16",nocase; classtype:trojan-activity; sid:100000509; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.136.39",nocase; classtype:trojan-activity; sid:100000510; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.144.42",nocase; classtype:trojan-activity; sid:100000511; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.154.21",nocase; classtype:trojan-activity; sid:100000512; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.191.47",nocase; classtype:trojan-activity; sid:100000513; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.61.204.205",nocase; classtype:trojan-activity; sid:100000514; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.86.204.13",nocase; classtype:trojan-activity; sid:100000515; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.87.175.112",nocase; classtype:trojan-activity; sid:100000516; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.87.32.93",nocase; classtype:trojan-activity; sid:100000517; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.88.208.189",nocase; classtype:trojan-activity; sid:100000518; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.88.232.36",nocase; classtype:trojan-activity; sid:100000519; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.88.38.232",nocase; classtype:trojan-activity; sid:100000520; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.89.41.33",nocase; classtype:trojan-activity; sid:100000521; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.89.41.51",nocase; classtype:trojan-activity; sid:100000522; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.92.156.196",nocase; classtype:trojan-activity; sid:100000523; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.93.225.12",nocase; classtype:trojan-activity; sid:100000524; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.199.204.37",nocase; classtype:trojan-activity; sid:100000525; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.199.253.235",nocase; classtype:trojan-activity; sid:100000526; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.223.122.19",nocase; classtype:trojan-activity; sid:100000527; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.226.100.56",nocase; classtype:trojan-activity; sid:100000528; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.227.156.119",nocase; classtype:trojan-activity; sid:100000529; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.228.205.101",nocase; classtype:trojan-activity; sid:100000530; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.228.242.109",nocase; classtype:trojan-activity; sid:100000531; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.229.165.194",nocase; classtype:trojan-activity; sid:100000532; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.229.52.14",nocase; classtype:trojan-activity; sid:100000533; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.235.115.236",nocase; classtype:trojan-activity; sid:100000534; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.235.42.152",nocase; classtype:trojan-activity; sid:100000535; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.30.54.64",nocase; classtype:trojan-activity; sid:100000536; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.79.161.94",nocase; classtype:trojan-activity; sid:100000537; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.79.172.42",nocase; classtype:trojan-activity; sid:100000538; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.165.216.112",nocase; classtype:trojan-activity; sid:100000539; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.193.130.126",nocase; classtype:trojan-activity; sid:100000540; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.208.101.195",nocase; classtype:trojan-activity; sid:100000541; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.223.159.80",nocase; classtype:trojan-activity; sid:100000542; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.23.88.135",nocase; classtype:trojan-activity; sid:100000543; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.42.47.36",nocase; classtype:trojan-activity; sid:100000544; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.48.130.181",nocase; classtype:trojan-activity; sid:100000545; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.48.141.239",nocase; classtype:trojan-activity; sid:100000546; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.48.198.142",nocase; classtype:trojan-activity; sid:100000547; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.48.215.189",nocase; classtype:trojan-activity; sid:100000548; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.48.22.130",nocase; classtype:trojan-activity; sid:100000549; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.48.228.176",nocase; classtype:trojan-activity; sid:100000550; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.48.9.246",nocase; classtype:trojan-activity; sid:100000551; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.49.100.124",nocase; classtype:trojan-activity; sid:100000552; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.49.18.53",nocase; classtype:trojan-activity; sid:100000553; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.49.216.150",nocase; classtype:trojan-activity; sid:100000554; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.49.60.231",nocase; classtype:trojan-activity; sid:100000555; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.1.143",nocase; classtype:trojan-activity; sid:100000556; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.158.223",nocase; classtype:trojan-activity; sid:100000557; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.2.251",nocase; classtype:trojan-activity; sid:100000558; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.219.100",nocase; classtype:trojan-activity; sid:100000559; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.22.86",nocase; classtype:trojan-activity; sid:100000560; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.220.156",nocase; classtype:trojan-activity; sid:100000561; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.224.175",nocase; classtype:trojan-activity; sid:100000562; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.230.43",nocase; classtype:trojan-activity; sid:100000563; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.232.149",nocase; classtype:trojan-activity; sid:100000564; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.239.222",nocase; classtype:trojan-activity; sid:100000565; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.3.25",nocase; classtype:trojan-activity; sid:100000566; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.56.198",nocase; classtype:trojan-activity; sid:100000567; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.8.131",nocase; classtype:trojan-activity; sid:100000568; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.81.194",nocase; classtype:trojan-activity; sid:100000569; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.51.104.85",nocase; classtype:trojan-activity; sid:100000570; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.51.123.216",nocase; classtype:trojan-activity; sid:100000571; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.51.93.76",nocase; classtype:trojan-activity; sid:100000572; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.52.112.200",nocase; classtype:trojan-activity; sid:100000573; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.52.19.250",nocase; classtype:trojan-activity; sid:100000574; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.52.200.245",nocase; classtype:trojan-activity; sid:100000575; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.52.21.5",nocase; classtype:trojan-activity; sid:100000576; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.54.192.172",nocase; classtype:trojan-activity; sid:100000577; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.54.222.126",nocase; classtype:trojan-activity; sid:100000578; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.54.236.22",nocase; classtype:trojan-activity; sid:100000579; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.54.241.122",nocase; classtype:trojan-activity; sid:100000580; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.54.73.162",nocase; classtype:trojan-activity; sid:100000581; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.105.163",nocase; classtype:trojan-activity; sid:100000582; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.144.146",nocase; classtype:trojan-activity; sid:100000583; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.144.222",nocase; classtype:trojan-activity; sid:100000584; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.144.42",nocase; classtype:trojan-activity; sid:100000585; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.145.147",nocase; classtype:trojan-activity; sid:100000586; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.149.30",nocase; classtype:trojan-activity; sid:100000587; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.178.67",nocase; classtype:trojan-activity; sid:100000588; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.198.209",nocase; classtype:trojan-activity; sid:100000589; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.211.86",nocase; classtype:trojan-activity; sid:100000590; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.42.200",nocase; classtype:trojan-activity; sid:100000591; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.53.51",nocase; classtype:trojan-activity; sid:100000592; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.134.116",nocase; classtype:trojan-activity; sid:100000593; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.134.220",nocase; classtype:trojan-activity; sid:100000594; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.139.122",nocase; classtype:trojan-activity; sid:100000595; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.142.251",nocase; classtype:trojan-activity; sid:100000596; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.143.241",nocase; classtype:trojan-activity; sid:100000597; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.148.22",nocase; classtype:trojan-activity; sid:100000598; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.155.72",nocase; classtype:trojan-activity; sid:100000599; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.156.185",nocase; classtype:trojan-activity; sid:100000600; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.162.173",nocase; classtype:trojan-activity; sid:100000601; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.178.107",nocase; classtype:trojan-activity; sid:100000602; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.188.24",nocase; classtype:trojan-activity; sid:100000603; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.31.54",nocase; classtype:trojan-activity; sid:100000604; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.67.22",nocase; classtype:trojan-activity; sid:100000605; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.86.251",nocase; classtype:trojan-activity; sid:100000606; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.87.42",nocase; classtype:trojan-activity; sid:100000607; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.98.205",nocase; classtype:trojan-activity; sid:100000608; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.111.222",nocase; classtype:trojan-activity; sid:100000609; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.119.171",nocase; classtype:trojan-activity; sid:100000610; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.134.143",nocase; classtype:trojan-activity; sid:100000611; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.141.177",nocase; classtype:trojan-activity; sid:100000612; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.83.233",nocase; classtype:trojan-activity; sid:100000613; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.88.163",nocase; classtype:trojan-activity; sid:100000614; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.93.151",nocase; classtype:trojan-activity; sid:100000615; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.197.123",nocase; classtype:trojan-activity; sid:100000616; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.198.165",nocase; classtype:trojan-activity; sid:100000617; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.210.228",nocase; classtype:trojan-activity; sid:100000618; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.235.229",nocase; classtype:trojan-activity; sid:100000619; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.253.202",nocase; classtype:trojan-activity; sid:100000620; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.26.134",nocase; classtype:trojan-activity; sid:100000621; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.63.220",nocase; classtype:trojan-activity; sid:100000622; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.107.203",nocase; classtype:trojan-activity; sid:100000623; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.111.142",nocase; classtype:trojan-activity; sid:100000624; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.119.187",nocase; classtype:trojan-activity; sid:100000625; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.119.198",nocase; classtype:trojan-activity; sid:100000626; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.119.77",nocase; classtype:trojan-activity; sid:100000627; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.125.184",nocase; classtype:trojan-activity; sid:100000628; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.137.47",nocase; classtype:trojan-activity; sid:100000629; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.180.193",nocase; classtype:trojan-activity; sid:100000630; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.182.138",nocase; classtype:trojan-activity; sid:100000631; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.185.246",nocase; classtype:trojan-activity; sid:100000632; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.97.190",nocase; classtype:trojan-activity; sid:100000633; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.62.26.39",nocase; classtype:trojan-activity; sid:100000634; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.62.60.206",nocase; classtype:trojan-activity; sid:100000635; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.63.135.206",nocase; classtype:trojan-activity; sid:100000636; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.63.4.244",nocase; classtype:trojan-activity; sid:100000637; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.63.56.176",nocase; classtype:trojan-activity; sid:100000638; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.73.3.11",nocase; classtype:trojan-activity; sid:100000639; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.74.217.2",nocase; classtype:trojan-activity; sid:100000640; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.75.217.79",nocase; classtype:trojan-activity; sid:100000641; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.92.174.231",nocase; classtype:trojan-activity; sid:100000642; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.124.219.2",nocase; classtype:trojan-activity; sid:100000643; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.127.207.224",nocase; classtype:trojan-activity; sid:100000644; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.149.119.185",nocase; classtype:trojan-activity; sid:100000645; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.2.100.221",nocase; classtype:trojan-activity; sid:100000646; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.2.66.3",nocase; classtype:trojan-activity; sid:100000647; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.206.164.46",nocase; classtype:trojan-activity; sid:100000648; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.211.100.26",nocase; classtype:trojan-activity; sid:100000649; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.212.142.215",nocase; classtype:trojan-activity; sid:100000650; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.24.153.40",nocase; classtype:trojan-activity; sid:100000651; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.72.201.93",nocase; classtype:trojan-activity; sid:100000652; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.75.192.140",nocase; classtype:trojan-activity; sid:100000653; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.76.114.71",nocase; classtype:trojan-activity; sid:100000654; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.88.65.131",nocase; classtype:trojan-activity; sid:100000655; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.11.234.35",nocase; classtype:trojan-activity; sid:100000656; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.11.95.179",nocase; classtype:trojan-activity; sid:100000657; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.15.201.1",nocase; classtype:trojan-activity; sid:100000658; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.192.224.243",nocase; classtype:trojan-activity; sid:100000659; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.192.225.29",nocase; classtype:trojan-activity; sid:100000660; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.192.226.96",nocase; classtype:trojan-activity; sid:100000661; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.194.162.116",nocase; classtype:trojan-activity; sid:100000662; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.194.163.237",nocase; classtype:trojan-activity; sid:100000663; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.204.138",nocase; classtype:trojan-activity; sid:100000664; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.204.5",nocase; classtype:trojan-activity; sid:100000665; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.210.52",nocase; classtype:trojan-activity; sid:100000666; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.220.126",nocase; classtype:trojan-activity; sid:100000667; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.236.14",nocase; classtype:trojan-activity; sid:100000668; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.243.40",nocase; classtype:trojan-activity; sid:100000669; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.200.76.54",nocase; classtype:trojan-activity; sid:100000670; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.200.76.60",nocase; classtype:trojan-activity; sid:100000671; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.201.128.152",nocase; classtype:trojan-activity; sid:100000672; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.202.66.23",nocase; classtype:trojan-activity; sid:100000673; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.202.67.181",nocase; classtype:trojan-activity; sid:100000674; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.202.67.218",nocase; classtype:trojan-activity; sid:100000675; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.202.68.75",nocase; classtype:trojan-activity; sid:100000676; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.213.41.18",nocase; classtype:trojan-activity; sid:100000677; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.213.42.147",nocase; classtype:trojan-activity; sid:100000678; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.213.42.226",nocase; classtype:trojan-activity; sid:100000679; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.213.44.184",nocase; classtype:trojan-activity; sid:100000680; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.213.45.119",nocase; classtype:trojan-activity; sid:100000681; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.213.45.150",nocase; classtype:trojan-activity; sid:100000682; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.213.45.204",nocase; classtype:trojan-activity; sid:100000683; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.213.46.124",nocase; classtype:trojan-activity; sid:100000684; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.213.46.243",nocase; classtype:trojan-activity; sid:100000685; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.215.213.155",nocase; classtype:trojan-activity; sid:100000686; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.215.215.188",nocase; classtype:trojan-activity; sid:100000687; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.222.160.86",nocase; classtype:trojan-activity; sid:100000688; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.222.165.221",nocase; classtype:trojan-activity; sid:100000689; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.222.166.6",nocase; classtype:trojan-activity; sid:100000690; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.222.169.193",nocase; classtype:trojan-activity; sid:100000691; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.222.170.122",nocase; classtype:trojan-activity; sid:100000692; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.222.175.220",nocase; classtype:trojan-activity; sid:100000693; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.241.66.200",nocase; classtype:trojan-activity; sid:100000694; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.241.67.68",nocase; classtype:trojan-activity; sid:100000695; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.242.211.217",nocase; classtype:trojan-activity; sid:100000696; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.247.204.33",nocase; classtype:trojan-activity; sid:100000697; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.247.206.195",nocase; classtype:trojan-activity; sid:100000698; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.248.60.21",nocase; classtype:trojan-activity; sid:100000699; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.251.56.191",nocase; classtype:trojan-activity; sid:100000700; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.251.56.244",nocase; classtype:trojan-activity; sid:100000701; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.251.56.64",nocase; classtype:trojan-activity; sid:100000702; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.251.56.73",nocase; classtype:trojan-activity; sid:100000703; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.251.60.161",nocase; classtype:trojan-activity; sid:100000704; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.251.63.211",nocase; classtype:trojan-activity; sid:100000705; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.26.110.17",nocase; classtype:trojan-activity; sid:100000706; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.26.235.164",nocase; classtype:trojan-activity; sid:100000707; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.27.10.73",nocase; classtype:trojan-activity; sid:100000708; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.63.113.146",nocase; classtype:trojan-activity; sid:100000709; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.63.195.140",nocase; classtype:trojan-activity; sid:100000710; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.63.252.82",nocase; classtype:trojan-activity; sid:100000711; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.63.53.15",nocase; classtype:trojan-activity; sid:100000712; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.87.170.32",nocase; classtype:trojan-activity; sid:100000713; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.90.78.120",nocase; classtype:trojan-activity; sid:100000714; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.93.115.242",nocase; classtype:trojan-activity; sid:100000715; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.93.79.40",nocase; classtype:trojan-activity; sid:100000716; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.176.104.35",nocase; classtype:trojan-activity; sid:100000717; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.176.157.64",nocase; classtype:trojan-activity; sid:100000718; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.176.7.132",nocase; classtype:trojan-activity; sid:100000719; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.211.38.112",nocase; classtype:trojan-activity; sid:100000720; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.223.32.74",nocase; classtype:trojan-activity; sid:100000721; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.223.5.149",nocase; classtype:trojan-activity; sid:100000722; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.223.72.141",nocase; classtype:trojan-activity; sid:100000723; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.128.147",nocase; classtype:trojan-activity; sid:100000724; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.208.215",nocase; classtype:trojan-activity; sid:100000725; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.209.108",nocase; classtype:trojan-activity; sid:100000726; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.214.72",nocase; classtype:trojan-activity; sid:100000727; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.88.146",nocase; classtype:trojan-activity; sid:100000728; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.96.150",nocase; classtype:trojan-activity; sid:100000729; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.96.6",nocase; classtype:trojan-activity; sid:100000730; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.233.165.213",nocase; classtype:trojan-activity; sid:100000731; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.233.221.162",nocase; classtype:trojan-activity; sid:100000732; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.233.65.93",nocase; classtype:trojan-activity; sid:100000733; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.249.136.112",nocase; classtype:trojan-activity; sid:100000734; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.250.51.192",nocase; classtype:trojan-activity; sid:100000735; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.38.189.207",nocase; classtype:trojan-activity; sid:100000736; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.42.125.246",nocase; classtype:trojan-activity; sid:100000737; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.43.180.33",nocase; classtype:trojan-activity; sid:100000738; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.68.245.69",nocase; classtype:trojan-activity; sid:100000739; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.75.50.253",nocase; classtype:trojan-activity; sid:100000740; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.75.70.70",nocase; classtype:trojan-activity; sid:100000741; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.125.92",nocase; classtype:trojan-activity; sid:100000742; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.143.45",nocase; classtype:trojan-activity; sid:100000743; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.218.157",nocase; classtype:trojan-activity; sid:100000744; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.50.203",nocase; classtype:trojan-activity; sid:100000745; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.58.82",nocase; classtype:trojan-activity; sid:100000746; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.73.123",nocase; classtype:trojan-activity; sid:100000747; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.83.79.43",nocase; classtype:trojan-activity; sid:100000748; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.99.179.164",nocase; classtype:trojan-activity; sid:100000749; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.99.183.235",nocase; classtype:trojan-activity; sid:100000750; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.99.239.217",nocase; classtype:trojan-activity; sid:100000751; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.100.40.250",nocase; classtype:trojan-activity; sid:100000752; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.108.188.238",nocase; classtype:trojan-activity; sid:100000753; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.108.252.237",nocase; classtype:trojan-activity; sid:100000754; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.109.34.245",nocase; classtype:trojan-activity; sid:100000755; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.112.22.58",nocase; classtype:trojan-activity; sid:100000756; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.118.251.73",nocase; classtype:trojan-activity; sid:100000757; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.119.52.202",nocase; classtype:trojan-activity; sid:100000758; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.123.219.137",nocase; classtype:trojan-activity; sid:100000759; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.14.143.145",nocase; classtype:trojan-activity; sid:100000760; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.147.213.57",nocase; classtype:trojan-activity; sid:100000761; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.162.109.111",nocase; classtype:trojan-activity; sid:100000762; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.163.144.208",nocase; classtype:trojan-activity; sid:100000763; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.163.93.191",nocase; classtype:trojan-activity; sid:100000764; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.164.18.235",nocase; classtype:trojan-activity; sid:100000765; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.164.31.76",nocase; classtype:trojan-activity; sid:100000766; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.164.74.153",nocase; classtype:trojan-activity; sid:100000767; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.107.93",nocase; classtype:trojan-activity; sid:100000768; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.163.220",nocase; classtype:trojan-activity; sid:100000769; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.174.63",nocase; classtype:trojan-activity; sid:100000770; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.241.222",nocase; classtype:trojan-activity; sid:100000771; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.27.77",nocase; classtype:trojan-activity; sid:100000772; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.68.145",nocase; classtype:trojan-activity; sid:100000773; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.166.170.241",nocase; classtype:trojan-activity; sid:100000774; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.166.19.254",nocase; classtype:trojan-activity; sid:100000775; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.166.97.6",nocase; classtype:trojan-activity; sid:100000776; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.167.1.13",nocase; classtype:trojan-activity; sid:100000777; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.167.2.214",nocase; classtype:trojan-activity; sid:100000778; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.167.26.33",nocase; classtype:trojan-activity; sid:100000779; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.167.63.195",nocase; classtype:trojan-activity; sid:100000780; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.176.231.217",nocase; classtype:trojan-activity; sid:100000781; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.178.201.188",nocase; classtype:trojan-activity; sid:100000782; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.178.248.123",nocase; classtype:trojan-activity; sid:100000783; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.178.249.140",nocase; classtype:trojan-activity; sid:100000784; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.157.219",nocase; classtype:trojan-activity; sid:100000785; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.16.149",nocase; classtype:trojan-activity; sid:100000786; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.170.212",nocase; classtype:trojan-activity; sid:100000787; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.27.213",nocase; classtype:trojan-activity; sid:100000788; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.43.1",nocase; classtype:trojan-activity; sid:100000789; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.75.8",nocase; classtype:trojan-activity; sid:100000790; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.18.38.144",nocase; classtype:trojan-activity; sid:100000791; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.101.151",nocase; classtype:trojan-activity; sid:100000792; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.106.217",nocase; classtype:trojan-activity; sid:100000793; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.108.227",nocase; classtype:trojan-activity; sid:100000794; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.108.79",nocase; classtype:trojan-activity; sid:100000795; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.11.29",nocase; classtype:trojan-activity; sid:100000796; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.231.79",nocase; classtype:trojan-activity; sid:100000797; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.33.161",nocase; classtype:trojan-activity; sid:100000798; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.80.69",nocase; classtype:trojan-activity; sid:100000799; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.94.80",nocase; classtype:trojan-activity; sid:100000800; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.181.124.203",nocase; classtype:trojan-activity; sid:100000801; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.181.43.18",nocase; classtype:trojan-activity; sid:100000802; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.183.109.21",nocase; classtype:trojan-activity; sid:100000803; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.183.115.103",nocase; classtype:trojan-activity; sid:100000804; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.183.9.82",nocase; classtype:trojan-activity; sid:100000805; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.184.14.112",nocase; classtype:trojan-activity; sid:100000806; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.184.172.199",nocase; classtype:trojan-activity; sid:100000807; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.184.172.53",nocase; classtype:trojan-activity; sid:100000808; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.185.102.182",nocase; classtype:trojan-activity; sid:100000809; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.185.237.89",nocase; classtype:trojan-activity; sid:100000810; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.185.39.240",nocase; classtype:trojan-activity; sid:100000811; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.185.43.193",nocase; classtype:trojan-activity; sid:100000812; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.186.22.245",nocase; classtype:trojan-activity; sid:100000813; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.187.195.161",nocase; classtype:trojan-activity; sid:100000814; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.187.220.115",nocase; classtype:trojan-activity; sid:100000815; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.187.62.80",nocase; classtype:trojan-activity; sid:100000816; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.189.137.195",nocase; classtype:trojan-activity; sid:100000817; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.189.227.244",nocase; classtype:trojan-activity; sid:100000818; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.190.211.99",nocase; classtype:trojan-activity; sid:100000819; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.190.240.238",nocase; classtype:trojan-activity; sid:100000820; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.150.85",nocase; classtype:trojan-activity; sid:100000821; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.187.206",nocase; classtype:trojan-activity; sid:100000822; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.215.221",nocase; classtype:trojan-activity; sid:100000823; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.253.206",nocase; classtype:trojan-activity; sid:100000824; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.204.30.144",nocase; classtype:trojan-activity; sid:100000825; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.250.218.177",nocase; classtype:trojan-activity; sid:100000826; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.251.105.221",nocase; classtype:trojan-activity; sid:100000827; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.251.12.85",nocase; classtype:trojan-activity; sid:100000828; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.251.14.251",nocase; classtype:trojan-activity; sid:100000829; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.131.155",nocase; classtype:trojan-activity; sid:100000830; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.143.46",nocase; classtype:trojan-activity; sid:100000831; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.143.71",nocase; classtype:trojan-activity; sid:100000832; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.148.115",nocase; classtype:trojan-activity; sid:100000833; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.155.57",nocase; classtype:trojan-activity; sid:100000834; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.172.28",nocase; classtype:trojan-activity; sid:100000835; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.175.41",nocase; classtype:trojan-activity; sid:100000836; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.206.43",nocase; classtype:trojan-activity; sid:100000837; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.220.170",nocase; classtype:trojan-activity; sid:100000838; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.96.37.55",nocase; classtype:trojan-activity; sid:100000839; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.96.70.116",nocase; classtype:trojan-activity; sid:100000840; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.99.188.187",nocase; classtype:trojan-activity; sid:100000841; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.99.190.152",nocase; classtype:trojan-activity; sid:100000842; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.99.232.62",nocase; classtype:trojan-activity; sid:100000843; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.132.113.2",nocase; classtype:trojan-activity; sid:100000844; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.15.69.83",nocase; classtype:trojan-activity; sid:100000845; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.6",nocase; classtype:trojan-activity; sid:100000846; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.7",nocase; classtype:trojan-activity; sid:100000847; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.8",nocase; classtype:trojan-activity; sid:100000848; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.9",nocase; classtype:trojan-activity; sid:100000849; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.207.39.227",nocase; classtype:trojan-activity; sid:100000850; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.12.144.232",nocase; classtype:trojan-activity; sid:100000851; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.12.153.54",nocase; classtype:trojan-activity; sid:100000852; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.142.222.22",nocase; classtype:trojan-activity; sid:100000853; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.150.213.110",nocase; classtype:trojan-activity; sid:100000854; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.151.248.134",nocase; classtype:trojan-activity; sid:100000855; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.177",nocase; classtype:trojan-activity; sid:100000856; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.178",nocase; classtype:trojan-activity; sid:100000857; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.180",nocase; classtype:trojan-activity; sid:100000858; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.181",nocase; classtype:trojan-activity; sid:100000859; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.183",nocase; classtype:trojan-activity; sid:100000860; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.184",nocase; classtype:trojan-activity; sid:100000861; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.185",nocase; classtype:trojan-activity; sid:100000862; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.186",nocase; classtype:trojan-activity; sid:100000863; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.188",nocase; classtype:trojan-activity; sid:100000864; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.191",nocase; classtype:trojan-activity; sid:100000865; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.193",nocase; classtype:trojan-activity; sid:100000866; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.196",nocase; classtype:trojan-activity; sid:100000867; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.197",nocase; classtype:trojan-activity; sid:100000868; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.198",nocase; classtype:trojan-activity; sid:100000869; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.199",nocase; classtype:trojan-activity; sid:100000870; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.200",nocase; classtype:trojan-activity; sid:100000871; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.201",nocase; classtype:trojan-activity; sid:100000872; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.202",nocase; classtype:trojan-activity; sid:100000873; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.203",nocase; classtype:trojan-activity; sid:100000874; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.204",nocase; classtype:trojan-activity; sid:100000875; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.207",nocase; classtype:trojan-activity; sid:100000876; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.208",nocase; classtype:trojan-activity; sid:100000877; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.209",nocase; classtype:trojan-activity; sid:100000878; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.212",nocase; classtype:trojan-activity; sid:100000879; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.213",nocase; classtype:trojan-activity; sid:100000880; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.215",nocase; classtype:trojan-activity; sid:100000881; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.233",nocase; classtype:trojan-activity; sid:100000882; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.93.227",nocase; classtype:trojan-activity; sid:100000883; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.121.243",nocase; classtype:trojan-activity; sid:100000884; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.206",nocase; classtype:trojan-activity; sid:100000885; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.214",nocase; classtype:trojan-activity; sid:100000886; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.240",nocase; classtype:trojan-activity; sid:100000887; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.243",nocase; classtype:trojan-activity; sid:100000888; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.25",nocase; classtype:trojan-activity; sid:100000889; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.60",nocase; classtype:trojan-activity; sid:100000890; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.127.187",nocase; classtype:trojan-activity; sid:100000891; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.99.127",nocase; classtype:trojan-activity; sid:100000892; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.210.89.79",nocase; classtype:trojan-activity; sid:100000893; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.43.54.218",nocase; classtype:trojan-activity; sid:100000894; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.50.66.60",nocase; classtype:trojan-activity; sid:100000895; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.50.93.115",nocase; classtype:trojan-activity; sid:100000896; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.59.245.212",nocase; classtype:trojan-activity; sid:100000897; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.6.141.142",nocase; classtype:trojan-activity; sid:100000898; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.6.8.11",nocase; classtype:trojan-activity; sid:100000899; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.69.113.208",nocase; classtype:trojan-activity; sid:100000900; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.69.131.51",nocase; classtype:trojan-activity; sid:100000901; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.7.90.104",nocase; classtype:trojan-activity; sid:100000902; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.165.141",nocase; classtype:trojan-activity; sid:100000903; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.169.138",nocase; classtype:trojan-activity; sid:100000904; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.174.165",nocase; classtype:trojan-activity; sid:100000905; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.174.175",nocase; classtype:trojan-activity; sid:100000906; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.186.112",nocase; classtype:trojan-activity; sid:100000907; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.237.129",nocase; classtype:trojan-activity; sid:100000908; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.239.77",nocase; classtype:trojan-activity; sid:100000909; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.86.84.72",nocase; classtype:trojan-activity; sid:100000910; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.9.32.51",nocase; classtype:trojan-activity; sid:100000911; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.100.114.164",nocase; classtype:trojan-activity; sid:100000912; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.100.96.8",nocase; classtype:trojan-activity; sid:100000913; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.121.44.222",nocase; classtype:trojan-activity; sid:100000914; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.123.53.25",nocase; classtype:trojan-activity; sid:100000915; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.127.155.220",nocase; classtype:trojan-activity; sid:100000916; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.141.11.56",nocase; classtype:trojan-activity; sid:100000917; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.15.142.137",nocase; classtype:trojan-activity; sid:100000918; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.151.78.190",nocase; classtype:trojan-activity; sid:100000919; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.159.22.144",nocase; classtype:trojan-activity; sid:100000920; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.16.155.206",nocase; classtype:trojan-activity; sid:100000921; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.17.103.176",nocase; classtype:trojan-activity; sid:100000922; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.170.234.142",nocase; classtype:trojan-activity; sid:100000923; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.185.31.2",nocase; classtype:trojan-activity; sid:100000924; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.190.36.8",nocase; classtype:trojan-activity; sid:100000925; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.205.229.200",nocase; classtype:trojan-activity; sid:100000926; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.225.11.163",nocase; classtype:trojan-activity; sid:100000927; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.226.82.202",nocase; classtype:trojan-activity; sid:100000928; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.23.18.18",nocase; classtype:trojan-activity; sid:100000929; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.230.171.198",nocase; classtype:trojan-activity; sid:100000930; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.231.103.95",nocase; classtype:trojan-activity; sid:100000931; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.237.225.91",nocase; classtype:trojan-activity; sid:100000932; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.238.175.87",nocase; classtype:trojan-activity; sid:100000933; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.239.15.74",nocase; classtype:trojan-activity; sid:100000934; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.24.116.173",nocase; classtype:trojan-activity; sid:100000935; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.25.101.86",nocase; classtype:trojan-activity; sid:100000936; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.254.43.215",nocase; classtype:trojan-activity; sid:100000937; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.61.101.93",nocase; classtype:trojan-activity; sid:100000938; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.61.102.1",nocase; classtype:trojan-activity; sid:100000939; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.61.107.189",nocase; classtype:trojan-activity; sid:100000940; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.61.97.195",nocase; classtype:trojan-activity; sid:100000941; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.61.98.151",nocase; classtype:trojan-activity; sid:100000942; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.88.99.236",nocase; classtype:trojan-activity; sid:100000943; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.100.150.204",nocase; classtype:trojan-activity; sid:100000944; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.137.52.122",nocase; classtype:trojan-activity; sid:100000945; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.160.147.53",nocase; classtype:trojan-activity; sid:100000946; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.192.190.203",nocase; classtype:trojan-activity; sid:100000947; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.194.191.57",nocase; classtype:trojan-activity; sid:100000948; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.199.72.23",nocase; classtype:trojan-activity; sid:100000949; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.199.79.27",nocase; classtype:trojan-activity; sid:100000950; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.199.83.86",nocase; classtype:trojan-activity; sid:100000951; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.202.37.85",nocase; classtype:trojan-activity; sid:100000952; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.202.41.23",nocase; classtype:trojan-activity; sid:100000953; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.252.241.170",nocase; classtype:trojan-activity; sid:100000954; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.252.250.22",nocase; classtype:trojan-activity; sid:100000955; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.254.183.207",nocase; classtype:trojan-activity; sid:100000956; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.254.29.37",nocase; classtype:trojan-activity; sid:100000957; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.254.33.214",nocase; classtype:trojan-activity; sid:100000958; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.0.240.58",nocase; classtype:trojan-activity; sid:100000959; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.10.128.46",nocase; classtype:trojan-activity; sid:100000960; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.10.140.225",nocase; classtype:trojan-activity; sid:100000961; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.10.210.87",nocase; classtype:trojan-activity; sid:100000962; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.10.36.124",nocase; classtype:trojan-activity; sid:100000963; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.10.41.32",nocase; classtype:trojan-activity; sid:100000964; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.11.1.232",nocase; classtype:trojan-activity; sid:100000965; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.11.74.72",nocase; classtype:trojan-activity; sid:100000966; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.124.238",nocase; classtype:trojan-activity; sid:100000967; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.124.244",nocase; classtype:trojan-activity; sid:100000968; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.170.237",nocase; classtype:trojan-activity; sid:100000969; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.182.187",nocase; classtype:trojan-activity; sid:100000970; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.19.248",nocase; classtype:trojan-activity; sid:100000971; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.200.98",nocase; classtype:trojan-activity; sid:100000972; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.238.188",nocase; classtype:trojan-activity; sid:100000973; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.12.238.89",nocase; classtype:trojan-activity; sid:100000974; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.12.3.58",nocase; classtype:trojan-activity; sid:100000975; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.128.128.205",nocase; classtype:trojan-activity; sid:100000976; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.128.133.91",nocase; classtype:trojan-activity; sid:100000977; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.129.84.36",nocase; classtype:trojan-activity; sid:100000978; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.129.88.123",nocase; classtype:trojan-activity; sid:100000979; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.169.45",nocase; classtype:trojan-activity; sid:100000980; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.208.52",nocase; classtype:trojan-activity; sid:100000981; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.23.110",nocase; classtype:trojan-activity; sid:100000982; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.37.182",nocase; classtype:trojan-activity; sid:100000983; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.61.210",nocase; classtype:trojan-activity; sid:100000984; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.131.186.250",nocase; classtype:trojan-activity; sid:100000985; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.132.219.147",nocase; classtype:trojan-activity; sid:100000986; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.133.125.77",nocase; classtype:trojan-activity; sid:100000987; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.133.144.138",nocase; classtype:trojan-activity; sid:100000988; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.133.98.135",nocase; classtype:trojan-activity; sid:100000989; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.134.14.130",nocase; classtype:trojan-activity; sid:100000990; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.134.50.186",nocase; classtype:trojan-activity; sid:100000991; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.135.157.193",nocase; classtype:trojan-activity; sid:100000992; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.135.39.36",nocase; classtype:trojan-activity; sid:100000993; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.135.71.150",nocase; classtype:trojan-activity; sid:100000994; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.101.111",nocase; classtype:trojan-activity; sid:100000995; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.150.79",nocase; classtype:trojan-activity; sid:100000996; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.217.22",nocase; classtype:trojan-activity; sid:100000997; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.235.65",nocase; classtype:trojan-activity; sid:100000998; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.248.97",nocase; classtype:trojan-activity; sid:100000999; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.76.38",nocase; classtype:trojan-activity; sid:100001000; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.88.195",nocase; classtype:trojan-activity; sid:100001001; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.152.42.4",nocase; classtype:trojan-activity; sid:100001002; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.152.43.21",nocase; classtype:trojan-activity; sid:100001003; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.154.94.1",nocase; classtype:trojan-activity; sid:100001004; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.155.118.36",nocase; classtype:trojan-activity; sid:100001005; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.156.136.21",nocase; classtype:trojan-activity; sid:100001006; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.159.137.101",nocase; classtype:trojan-activity; sid:100001007; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.159.31.110",nocase; classtype:trojan-activity; sid:100001008; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.159.8.100",nocase; classtype:trojan-activity; sid:100001009; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.191.173.88",nocase; classtype:trojan-activity; sid:100001010; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.192.101.163",nocase; classtype:trojan-activity; sid:100001011; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.192.194.233",nocase; classtype:trojan-activity; sid:100001012; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.193.149.235",nocase; classtype:trojan-activity; sid:100001013; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.193.53.237",nocase; classtype:trojan-activity; sid:100001014; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.235.37",nocase; classtype:trojan-activity; sid:100001015; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.35.146",nocase; classtype:trojan-activity; sid:100001016; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.52.79",nocase; classtype:trojan-activity; sid:100001017; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.60.238",nocase; classtype:trojan-activity; sid:100001018; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.195.112.240",nocase; classtype:trojan-activity; sid:100001019; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.195.184.191",nocase; classtype:trojan-activity; sid:100001020; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.195.98.141",nocase; classtype:trojan-activity; sid:100001021; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.212.29.154",nocase; classtype:trojan-activity; sid:100001022; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.213.225.130",nocase; classtype:trojan-activity; sid:100001023; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.233.130.162",nocase; classtype:trojan-activity; sid:100001024; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.233.152.249",nocase; classtype:trojan-activity; sid:100001025; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.234.100.219",nocase; classtype:trojan-activity; sid:100001026; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.234.116.110",nocase; classtype:trojan-activity; sid:100001027; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.234.184.57",nocase; classtype:trojan-activity; sid:100001028; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.234.246.103",nocase; classtype:trojan-activity; sid:100001029; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.235.107.135",nocase; classtype:trojan-activity; sid:100001030; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.240.103.89",nocase; classtype:trojan-activity; sid:100001031; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.240.181.57",nocase; classtype:trojan-activity; sid:100001032; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.240.79.61",nocase; classtype:trojan-activity; sid:100001033; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.241.148.58",nocase; classtype:trojan-activity; sid:100001034; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.241.184.124",nocase; classtype:trojan-activity; sid:100001035; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.27.44.219",nocase; classtype:trojan-activity; sid:100001036; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.28.217.23",nocase; classtype:trojan-activity; sid:100001037; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.193.171",nocase; classtype:trojan-activity; sid:100001038; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.44.217",nocase; classtype:trojan-activity; sid:100001039; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.85.76",nocase; classtype:trojan-activity; sid:100001040; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.88.225",nocase; classtype:trojan-activity; sid:100001041; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.92.3",nocase; classtype:trojan-activity; sid:100001042; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.5.123.162",nocase; classtype:trojan-activity; sid:100001043; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.5.13.128",nocase; classtype:trojan-activity; sid:100001044; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.5.178.213",nocase; classtype:trojan-activity; sid:100001045; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.5.27.66",nocase; classtype:trojan-activity; sid:100001046; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.8.253.37",nocase; classtype:trojan-activity; sid:100001047; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.8.254.172",nocase; classtype:trojan-activity; sid:100001048; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.8.40.20",nocase; classtype:trojan-activity; sid:100001049; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.8.41.63",nocase; classtype:trojan-activity; sid:100001050; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.8.62.165",nocase; classtype:trojan-activity; sid:100001051; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.9.110.119",nocase; classtype:trojan-activity; sid:100001052; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.9.243.93",nocase; classtype:trojan-activity; sid:100001053; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.9.245.134",nocase; classtype:trojan-activity; sid:100001054; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.105.105.222",nocase; classtype:trojan-activity; sid:100001055; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.129.162.169",nocase; classtype:trojan-activity; sid:100001056; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.129.221.150",nocase; classtype:trojan-activity; sid:100001057; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.129.76.230",nocase; classtype:trojan-activity; sid:100001058; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.130.167.20",nocase; classtype:trojan-activity; sid:100001059; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.104.82",nocase; classtype:trojan-activity; sid:100001060; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.130.95",nocase; classtype:trojan-activity; sid:100001061; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.136.75",nocase; classtype:trojan-activity; sid:100001062; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.151.135",nocase; classtype:trojan-activity; sid:100001063; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.21.39",nocase; classtype:trojan-activity; sid:100001064; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.26.78",nocase; classtype:trojan-activity; sid:100001065; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.54.33",nocase; classtype:trojan-activity; sid:100001066; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.70.49",nocase; classtype:trojan-activity; sid:100001067; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.72.208",nocase; classtype:trojan-activity; sid:100001068; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.132.110.150",nocase; classtype:trojan-activity; sid:100001069; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.135.34.49",nocase; classtype:trojan-activity; sid:100001070; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.153.236.6",nocase; classtype:trojan-activity; sid:100001071; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.160.126.238",nocase; classtype:trojan-activity; sid:100001072; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.138.104",nocase; classtype:trojan-activity; sid:100001073; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.167.54",nocase; classtype:trojan-activity; sid:100001074; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.65.64",nocase; classtype:trojan-activity; sid:100001075; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.72.102",nocase; classtype:trojan-activity; sid:100001076; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.77.191",nocase; classtype:trojan-activity; sid:100001077; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.90.243",nocase; classtype:trojan-activity; sid:100001078; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.165.123.7",nocase; classtype:trojan-activity; sid:100001079; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.167.186.211",nocase; classtype:trojan-activity; sid:100001080; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.187.111.160",nocase; classtype:trojan-activity; sid:100001081; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.199.56.198",nocase; classtype:trojan-activity; sid:100001082; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.226.24.117",nocase; classtype:trojan-activity; sid:100001083; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.230.174.233",nocase; classtype:trojan-activity; sid:100001084; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.234.6.130",nocase; classtype:trojan-activity; sid:100001085; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.5.92.20",nocase; classtype:trojan-activity; sid:100001086; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.6.0.4",nocase; classtype:trojan-activity; sid:100001087; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.7.254.85",nocase; classtype:trojan-activity; sid:100001088; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.80.46.73",nocase; classtype:trojan-activity; sid:100001089; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.92.132.207",nocase; classtype:trojan-activity; sid:100001090; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.92.148.218",nocase; classtype:trojan-activity; sid:100001091; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.106.125.119",nocase; classtype:trojan-activity; sid:100001092; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.128.28.161",nocase; classtype:trojan-activity; sid:100001093; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.142.93.34",nocase; classtype:trojan-activity; sid:100001094; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.168.10.234",nocase; classtype:trojan-activity; sid:100001095; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.191.113.212",nocase; classtype:trojan-activity; sid:100001096; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.1.127",nocase; classtype:trojan-activity; sid:100001097; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.107.252",nocase; classtype:trojan-activity; sid:100001098; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.113.66",nocase; classtype:trojan-activity; sid:100001099; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.150.131",nocase; classtype:trojan-activity; sid:100001100; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.16.231",nocase; classtype:trojan-activity; sid:100001101; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.163.112",nocase; classtype:trojan-activity; sid:100001102; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.65.120",nocase; classtype:trojan-activity; sid:100001103; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.73.6",nocase; classtype:trojan-activity; sid:100001104; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.74.153",nocase; classtype:trojan-activity; sid:100001105; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.75.22",nocase; classtype:trojan-activity; sid:100001106; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.0.209",nocase; classtype:trojan-activity; sid:100001107; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.106.180",nocase; classtype:trojan-activity; sid:100001108; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.138.208",nocase; classtype:trojan-activity; sid:100001109; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.189.235",nocase; classtype:trojan-activity; sid:100001110; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.191.183",nocase; classtype:trojan-activity; sid:100001111; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.196.151",nocase; classtype:trojan-activity; sid:100001112; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.2.58",nocase; classtype:trojan-activity; sid:100001113; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.204.126",nocase; classtype:trojan-activity; sid:100001114; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.205.197",nocase; classtype:trojan-activity; sid:100001115; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.245.135",nocase; classtype:trojan-activity; sid:100001116; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.6.192",nocase; classtype:trojan-activity; sid:100001117; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.7.204",nocase; classtype:trojan-activity; sid:100001118; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.80.153",nocase; classtype:trojan-activity; sid:100001119; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.86.72",nocase; classtype:trojan-activity; sid:100001120; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.96.53",nocase; classtype:trojan-activity; sid:100001121; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.97.22",nocase; classtype:trojan-activity; sid:100001122; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.42.124.114",nocase; classtype:trojan-activity; sid:100001123; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.42.234.197",nocase; classtype:trojan-activity; sid:100001124; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.42.96.17",nocase; classtype:trojan-activity; sid:100001125; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.42.96.209",nocase; classtype:trojan-activity; sid:100001126; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.42.98.24",nocase; classtype:trojan-activity; sid:100001127; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.106.162",nocase; classtype:trojan-activity; sid:100001128; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.112.123",nocase; classtype:trojan-activity; sid:100001129; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.126.184",nocase; classtype:trojan-activity; sid:100001130; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.136.23",nocase; classtype:trojan-activity; sid:100001131; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.177.48",nocase; classtype:trojan-activity; sid:100001132; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.26.36",nocase; classtype:trojan-activity; sid:100001133; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.34.132",nocase; classtype:trojan-activity; sid:100001134; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.5.247",nocase; classtype:trojan-activity; sid:100001135; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.53.9",nocase; classtype:trojan-activity; sid:100001136; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.93.164",nocase; classtype:trojan-activity; sid:100001137; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.168.169",nocase; classtype:trojan-activity; sid:100001138; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.213.216",nocase; classtype:trojan-activity; sid:100001139; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.248.76",nocase; classtype:trojan-activity; sid:100001140; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.29.38",nocase; classtype:trojan-activity; sid:100001141; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.30.143",nocase; classtype:trojan-activity; sid:100001142; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.42.12",nocase; classtype:trojan-activity; sid:100001143; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.61.172",nocase; classtype:trojan-activity; sid:100001144; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.8.227",nocase; classtype:trojan-activity; sid:100001145; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.45.65.166",nocase; classtype:trojan-activity; sid:100001146; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.46.184.28",nocase; classtype:trojan-activity; sid:100001147; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.46.203.85",nocase; classtype:trojan-activity; sid:100001148; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.46.206.206",nocase; classtype:trojan-activity; sid:100001149; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.193.134",nocase; classtype:trojan-activity; sid:100001150; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.200.11",nocase; classtype:trojan-activity; sid:100001151; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.207.239",nocase; classtype:trojan-activity; sid:100001152; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.209.166",nocase; classtype:trojan-activity; sid:100001153; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.244.201",nocase; classtype:trojan-activity; sid:100001154; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.29.173",nocase; classtype:trojan-activity; sid:100001155; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.36.171",nocase; classtype:trojan-activity; sid:100001156; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.45.218",nocase; classtype:trojan-activity; sid:100001157; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.71.30",nocase; classtype:trojan-activity; sid:100001158; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.90.82",nocase; classtype:trojan-activity; sid:100001159; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.91.51",nocase; classtype:trojan-activity; sid:100001160; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"128.116.133.92",nocase; classtype:trojan-activity; sid:100001161; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"130.255.159.133",nocase; classtype:trojan-activity; sid:100001162; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"134.195.139.4",nocase; classtype:trojan-activity; sid:100001163; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"134.236.252.28",nocase; classtype:trojan-activity; sid:100001164; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"138.99.204.224",nocase; classtype:trojan-activity; sid:100001165; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.159.226.180",nocase; classtype:trojan-activity; sid:100001166; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.170.173.198",nocase; classtype:trojan-activity; sid:100001167; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.170.174.162",nocase; classtype:trojan-activity; sid:100001168; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.216.102.151",nocase; classtype:trojan-activity; sid:100001169; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.227.46.137",nocase; classtype:trojan-activity; sid:100001170; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.102.17.222",nocase; classtype:trojan-activity; sid:100001171; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.102.97.204",nocase; classtype:trojan-activity; sid:100001172; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.136.80.242",nocase; classtype:trojan-activity; sid:100001173; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.138.109.129",nocase; classtype:trojan-activity; sid:100001174; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.138.109.26",nocase; classtype:trojan-activity; sid:100001175; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.138.8.215",nocase; classtype:trojan-activity; sid:100001176; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.138.8.51",nocase; classtype:trojan-activity; sid:100001177; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.155.220.240",nocase; classtype:trojan-activity; sid:100001178; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.155.223.79",nocase; classtype:trojan-activity; sid:100001179; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.169.164.77",nocase; classtype:trojan-activity; sid:100001180; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.189.247.118",nocase; classtype:trojan-activity; sid:100001181; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.205.201.192",nocase; classtype:trojan-activity; sid:100001182; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.37.222.190",nocase; classtype:trojan-activity; sid:100001183; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.45.127.110",nocase; classtype:trojan-activity; sid:100001184; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.46.25.17",nocase; classtype:trojan-activity; sid:100001185; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.46.98.241",nocase; classtype:trojan-activity; sid:100001186; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.55.29.2",nocase; classtype:trojan-activity; sid:100001187; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"142.11.216.5",nocase; classtype:trojan-activity; sid:100001188; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"142.177.56.127",nocase; classtype:trojan-activity; sid:100001189; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"146.71.79.230",nocase; classtype:trojan-activity; sid:100001190; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"148.69.108.177",nocase; classtype:trojan-activity; sid:100001191; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.121",nocase; classtype:trojan-activity; sid:100001192; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.180",nocase; classtype:trojan-activity; sid:100001193; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.182",nocase; classtype:trojan-activity; sid:100001194; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.87",nocase; classtype:trojan-activity; sid:100001195; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.3.36.210",nocase; classtype:trojan-activity; sid:100001196; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"150.116.207.99",nocase; classtype:trojan-activity; sid:100001197; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"151.177.163.87",nocase; classtype:trojan-activity; sid:100001198; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"151.33.230.191",nocase; classtype:trojan-activity; sid:100001199; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"151.51.158.195",nocase; classtype:trojan-activity; sid:100001200; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"151.73.124.231",nocase; classtype:trojan-activity; sid:100001201; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.101.225.96",nocase; classtype:trojan-activity; sid:100001202; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.101.234.167",nocase; classtype:trojan-activity; sid:100001203; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.3.123.47",nocase; classtype:trojan-activity; sid:100001204; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.3.43.136",nocase; classtype:trojan-activity; sid:100001205; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.3.44.44",nocase; classtype:trojan-activity; sid:100001206; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.34.135.92",nocase; classtype:trojan-activity; sid:100001207; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.34.23.76",nocase; classtype:trojan-activity; sid:100001208; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.34.29.28",nocase; classtype:trojan-activity; sid:100001209; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.34.52.74",nocase; classtype:trojan-activity; sid:100001210; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.35.27.49",nocase; classtype:trojan-activity; sid:100001211; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.36.126.35",nocase; classtype:trojan-activity; sid:100001212; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"154.126.178.16",nocase; classtype:trojan-activity; sid:100001213; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"158.101.165.14",nocase; classtype:trojan-activity; sid:100001214; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"158.174.213.128",nocase; classtype:trojan-activity; sid:100001215; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"158.51.125.115",nocase; classtype:trojan-activity; sid:100001216; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"159.224.74.112",nocase; classtype:trojan-activity; sid:100001217; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.191.165.238",nocase; classtype:trojan-activity; sid:100001218; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.191.205.175",nocase; classtype:trojan-activity; sid:100001219; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.191.249.195",nocase; classtype:trojan-activity; sid:100001220; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.194.28.60",nocase; classtype:trojan-activity; sid:100001221; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.209.98.174",nocase; classtype:trojan-activity; sid:100001222; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.212.203.250",nocase; classtype:trojan-activity; sid:100001223; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.195.108",nocase; classtype:trojan-activity; sid:100001224; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.200.233",nocase; classtype:trojan-activity; sid:100001225; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.200.73",nocase; classtype:trojan-activity; sid:100001226; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.203.85",nocase; classtype:trojan-activity; sid:100001227; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.223.16",nocase; classtype:trojan-activity; sid:100001228; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.53.206.228",nocase; classtype:trojan-activity; sid:100001229; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"165.90.16.5",nocase; classtype:trojan-activity; sid:100001230; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"170.78.39.3",nocase; classtype:trojan-activity; sid:100001231; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"170.81.238.178",nocase; classtype:trojan-activity; sid:100001232; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.118.18.184",nocase; classtype:trojan-activity; sid:100001233; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.118.210.67",nocase; classtype:trojan-activity; sid:100001234; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.119.217.149",nocase; classtype:trojan-activity; sid:100001235; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.119.218.208",nocase; classtype:trojan-activity; sid:100001236; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.119.219.150",nocase; classtype:trojan-activity; sid:100001237; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.119.255.96",nocase; classtype:trojan-activity; sid:100001238; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.120.125.147",nocase; classtype:trojan-activity; sid:100001239; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.121.6.162",nocase; classtype:trojan-activity; sid:100001240; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.123.189.154",nocase; classtype:trojan-activity; sid:100001241; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.125.114.254",nocase; classtype:trojan-activity; sid:100001242; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.125.30.233",nocase; classtype:trojan-activity; sid:100001243; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.125.30.93",nocase; classtype:trojan-activity; sid:100001244; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.125.64.223",nocase; classtype:trojan-activity; sid:100001245; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.126.109.145",nocase; classtype:trojan-activity; sid:100001246; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.34.112.42",nocase; classtype:trojan-activity; sid:100001247; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.34.179.178",nocase; classtype:trojan-activity; sid:100001248; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.35.161.234",nocase; classtype:trojan-activity; sid:100001249; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.35.162.156",nocase; classtype:trojan-activity; sid:100001250; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.35.173.151",nocase; classtype:trojan-activity; sid:100001251; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.35.174.198",nocase; classtype:trojan-activity; sid:100001252; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.38.219.189",nocase; classtype:trojan-activity; sid:100001253; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.44.254.4",nocase; classtype:trojan-activity; sid:100001254; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.105.36.168",nocase; classtype:trojan-activity; sid:100001255; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.114.244.127",nocase; classtype:trojan-activity; sid:100001256; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.245.5.185",nocase; classtype:trojan-activity; sid:100001257; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.93.176.137",nocase; classtype:trojan-activity; sid:100001258; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.167.85.89",nocase; classtype:trojan-activity; sid:100001259; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.169.46.85",nocase; classtype:trojan-activity; sid:100001260; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.19.58.108",nocase; classtype:trojan-activity; sid:100001261; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.220.222.227",nocase; classtype:trojan-activity; sid:100001262; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.233.85.171",nocase; classtype:trojan-activity; sid:100001263; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.235.209.70",nocase; classtype:trojan-activity; sid:100001264; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.237.254.251",nocase; classtype:trojan-activity; sid:100001265; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.25.113.8",nocase; classtype:trojan-activity; sid:100001266; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.52.95.134",nocase; classtype:trojan-activity; sid:100001267; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.52.97.25",nocase; classtype:trojan-activity; sid:100001268; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.56.119.108",nocase; classtype:trojan-activity; sid:100001269; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.56.92.166",nocase; classtype:trojan-activity; sid:100001270; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.106.33.85",nocase; classtype:trojan-activity; sid:100001271; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.48.181.23",nocase; classtype:trojan-activity; sid:100001272; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.73.246.193",nocase; classtype:trojan-activity; sid:100001273; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.81.78.7",nocase; classtype:trojan-activity; sid:100001274; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.84.148.29",nocase; classtype:trojan-activity; sid:100001275; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.96.30.156",nocase; classtype:trojan-activity; sid:100001276; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.10.147.167",nocase; classtype:trojan-activity; sid:100001277; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.10.48.233",nocase; classtype:trojan-activity; sid:100001278; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.11.212.203",nocase; classtype:trojan-activity; sid:100001279; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.11.96.155",nocase; classtype:trojan-activity; sid:100001280; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.115.241.87",nocase; classtype:trojan-activity; sid:100001281; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.117.66.74",nocase; classtype:trojan-activity; sid:100001282; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.145.200.216",nocase; classtype:trojan-activity; sid:100001283; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.153.144.2",nocase; classtype:trojan-activity; sid:100001284; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.162.69.13",nocase; classtype:trojan-activity; sid:100001285; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.169.172.216",nocase; classtype:trojan-activity; sid:100001286; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.173.196.162",nocase; classtype:trojan-activity; sid:100001287; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.174.93.57",nocase; classtype:trojan-activity; sid:100001288; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.199.33.139",nocase; classtype:trojan-activity; sid:100001289; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.201.104.192",nocase; classtype:trojan-activity; sid:100001290; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.208.230.8",nocase; classtype:trojan-activity; sid:100001291; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.212.6.169",nocase; classtype:trojan-activity; sid:100001292; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.42.46.118",nocase; classtype:trojan-activity; sid:100001293; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.9.24.110",nocase; classtype:trojan-activity; sid:100001294; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.14",nocase; classtype:trojan-activity; sid:100001295; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.35",nocase; classtype:trojan-activity; sid:100001296; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.63",nocase; classtype:trojan-activity; sid:100001297; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.66",nocase; classtype:trojan-activity; sid:100001298; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.67",nocase; classtype:trojan-activity; sid:100001299; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.104",nocase; classtype:trojan-activity; sid:100001300; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.113",nocase; classtype:trojan-activity; sid:100001301; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.120",nocase; classtype:trojan-activity; sid:100001302; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.128",nocase; classtype:trojan-activity; sid:100001303; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.138",nocase; classtype:trojan-activity; sid:100001304; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.59",nocase; classtype:trojan-activity; sid:100001305; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.65",nocase; classtype:trojan-activity; sid:100001306; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.66",nocase; classtype:trojan-activity; sid:100001307; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.84",nocase; classtype:trojan-activity; sid:100001308; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.88",nocase; classtype:trojan-activity; sid:100001309; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.91",nocase; classtype:trojan-activity; sid:100001310; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.174.139",nocase; classtype:trojan-activity; sid:100001311; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.12.117.70",nocase; classtype:trojan-activity; sid:100001312; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.123.4.115",nocase; classtype:trojan-activity; sid:100001313; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.123.7.115",nocase; classtype:trojan-activity; sid:100001314; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.123.7.127",nocase; classtype:trojan-activity; sid:100001315; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.123.9.243",nocase; classtype:trojan-activity; sid:100001316; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.124.7.225",nocase; classtype:trojan-activity; sid:100001317; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.240.40.142",nocase; classtype:trojan-activity; sid:100001318; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.240.84.106",nocase; classtype:trojan-activity; sid:100001319; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.32.151.180",nocase; classtype:trojan-activity; sid:100001320; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.229.64.218",nocase; classtype:trojan-activity; sid:100001321; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.44.61.243",nocase; classtype:trojan-activity; sid:100001322; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.54.82.154",nocase; classtype:trojan-activity; sid:100001323; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.86.235.143",nocase; classtype:trojan-activity; sid:100001324; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.124.182.187",nocase; classtype:trojan-activity; sid:100001325; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.136.195.90",nocase; classtype:trojan-activity; sid:100001326; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.141.210.251",nocase; classtype:trojan-activity; sid:100001327; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.141.25.82",nocase; classtype:trojan-activity; sid:100001328; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.141.57.166",nocase; classtype:trojan-activity; sid:100001329; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.150.174.65",nocase; classtype:trojan-activity; sid:100001330; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.165.122.141",nocase; classtype:trojan-activity; sid:100001331; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.0.140",nocase; classtype:trojan-activity; sid:100001332; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.109",nocase; classtype:trojan-activity; sid:100001333; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.247",nocase; classtype:trojan-activity; sid:100001334; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.250",nocase; classtype:trojan-activity; sid:100001335; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.80",nocase; classtype:trojan-activity; sid:100001336; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.10.108",nocase; classtype:trojan-activity; sid:100001337; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.10.156",nocase; classtype:trojan-activity; sid:100001338; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.10.26",nocase; classtype:trojan-activity; sid:100001339; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.129",nocase; classtype:trojan-activity; sid:100001340; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.180",nocase; classtype:trojan-activity; sid:100001341; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.190",nocase; classtype:trojan-activity; sid:100001342; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.223",nocase; classtype:trojan-activity; sid:100001343; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.4",nocase; classtype:trojan-activity; sid:100001344; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.101.110",nocase; classtype:trojan-activity; sid:100001345; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.134",nocase; classtype:trojan-activity; sid:100001346; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.136",nocase; classtype:trojan-activity; sid:100001347; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.152",nocase; classtype:trojan-activity; sid:100001348; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.228",nocase; classtype:trojan-activity; sid:100001349; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.232",nocase; classtype:trojan-activity; sid:100001350; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.245",nocase; classtype:trojan-activity; sid:100001351; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.81",nocase; classtype:trojan-activity; sid:100001352; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.103.172",nocase; classtype:trojan-activity; sid:100001353; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.103.91",nocase; classtype:trojan-activity; sid:100001354; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.120",nocase; classtype:trojan-activity; sid:100001355; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.128",nocase; classtype:trojan-activity; sid:100001356; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.153",nocase; classtype:trojan-activity; sid:100001357; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.16",nocase; classtype:trojan-activity; sid:100001358; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.161",nocase; classtype:trojan-activity; sid:100001359; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.169",nocase; classtype:trojan-activity; sid:100001360; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.183",nocase; classtype:trojan-activity; sid:100001361; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.206",nocase; classtype:trojan-activity; sid:100001362; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.220",nocase; classtype:trojan-activity; sid:100001363; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.49",nocase; classtype:trojan-activity; sid:100001364; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.80",nocase; classtype:trojan-activity; sid:100001365; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.111",nocase; classtype:trojan-activity; sid:100001366; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.146",nocase; classtype:trojan-activity; sid:100001367; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.217",nocase; classtype:trojan-activity; sid:100001368; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.245",nocase; classtype:trojan-activity; sid:100001369; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.247",nocase; classtype:trojan-activity; sid:100001370; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.27",nocase; classtype:trojan-activity; sid:100001371; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.49",nocase; classtype:trojan-activity; sid:100001372; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.85",nocase; classtype:trojan-activity; sid:100001373; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.118",nocase; classtype:trojan-activity; sid:100001374; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.18",nocase; classtype:trojan-activity; sid:100001375; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.193",nocase; classtype:trojan-activity; sid:100001376; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.219",nocase; classtype:trojan-activity; sid:100001377; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.37",nocase; classtype:trojan-activity; sid:100001378; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.63",nocase; classtype:trojan-activity; sid:100001379; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.77",nocase; classtype:trojan-activity; sid:100001380; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.87",nocase; classtype:trojan-activity; sid:100001381; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.0",nocase; classtype:trojan-activity; sid:100001382; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.133",nocase; classtype:trojan-activity; sid:100001383; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.83",nocase; classtype:trojan-activity; sid:100001384; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.116",nocase; classtype:trojan-activity; sid:100001385; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.145",nocase; classtype:trojan-activity; sid:100001386; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.148",nocase; classtype:trojan-activity; sid:100001387; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.16",nocase; classtype:trojan-activity; sid:100001388; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.179",nocase; classtype:trojan-activity; sid:100001389; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.18",nocase; classtype:trojan-activity; sid:100001390; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.67",nocase; classtype:trojan-activity; sid:100001391; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.87",nocase; classtype:trojan-activity; sid:100001392; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.109.1",nocase; classtype:trojan-activity; sid:100001393; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.109.77",nocase; classtype:trojan-activity; sid:100001394; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.176",nocase; classtype:trojan-activity; sid:100001395; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.184",nocase; classtype:trojan-activity; sid:100001396; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.204",nocase; classtype:trojan-activity; sid:100001397; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.57",nocase; classtype:trojan-activity; sid:100001398; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.150",nocase; classtype:trojan-activity; sid:100001399; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.155",nocase; classtype:trojan-activity; sid:100001400; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.173",nocase; classtype:trojan-activity; sid:100001401; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.214",nocase; classtype:trojan-activity; sid:100001402; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.221",nocase; classtype:trojan-activity; sid:100001403; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.43",nocase; classtype:trojan-activity; sid:100001404; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.90",nocase; classtype:trojan-activity; sid:100001405; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.97",nocase; classtype:trojan-activity; sid:100001406; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.105",nocase; classtype:trojan-activity; sid:100001407; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.157",nocase; classtype:trojan-activity; sid:100001408; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.16",nocase; classtype:trojan-activity; sid:100001409; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.190",nocase; classtype:trojan-activity; sid:100001410; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.206",nocase; classtype:trojan-activity; sid:100001411; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.36",nocase; classtype:trojan-activity; sid:100001412; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.84",nocase; classtype:trojan-activity; sid:100001413; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.159",nocase; classtype:trojan-activity; sid:100001414; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.26",nocase; classtype:trojan-activity; sid:100001415; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.4",nocase; classtype:trojan-activity; sid:100001416; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.113.130",nocase; classtype:trojan-activity; sid:100001417; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.113.150",nocase; classtype:trojan-activity; sid:100001418; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.113.171",nocase; classtype:trojan-activity; sid:100001419; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.113.174",nocase; classtype:trojan-activity; sid:100001420; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.113.35",nocase; classtype:trojan-activity; sid:100001421; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.113.85",nocase; classtype:trojan-activity; sid:100001422; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.107",nocase; classtype:trojan-activity; sid:100001423; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.211",nocase; classtype:trojan-activity; sid:100001424; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.215",nocase; classtype:trojan-activity; sid:100001425; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.234",nocase; classtype:trojan-activity; sid:100001426; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.238",nocase; classtype:trojan-activity; sid:100001427; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.241",nocase; classtype:trojan-activity; sid:100001428; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.254",nocase; classtype:trojan-activity; sid:100001429; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.27",nocase; classtype:trojan-activity; sid:100001430; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.5",nocase; classtype:trojan-activity; sid:100001431; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.55",nocase; classtype:trojan-activity; sid:100001432; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.63",nocase; classtype:trojan-activity; sid:100001433; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.82",nocase; classtype:trojan-activity; sid:100001434; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.90",nocase; classtype:trojan-activity; sid:100001435; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.99",nocase; classtype:trojan-activity; sid:100001436; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.1",nocase; classtype:trojan-activity; sid:100001437; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.13",nocase; classtype:trojan-activity; sid:100001438; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.142",nocase; classtype:trojan-activity; sid:100001439; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.143",nocase; classtype:trojan-activity; sid:100001440; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.19",nocase; classtype:trojan-activity; sid:100001441; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.221",nocase; classtype:trojan-activity; sid:100001442; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.222",nocase; classtype:trojan-activity; sid:100001443; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.242",nocase; classtype:trojan-activity; sid:100001444; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.35",nocase; classtype:trojan-activity; sid:100001445; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.116.48",nocase; classtype:trojan-activity; sid:100001446; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.116.64",nocase; classtype:trojan-activity; sid:100001447; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.116.87",nocase; classtype:trojan-activity; sid:100001448; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.117.215",nocase; classtype:trojan-activity; sid:100001449; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.117.32",nocase; classtype:trojan-activity; sid:100001450; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.117.51",nocase; classtype:trojan-activity; sid:100001451; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.117.63",nocase; classtype:trojan-activity; sid:100001452; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.117.90",nocase; classtype:trojan-activity; sid:100001453; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.112",nocase; classtype:trojan-activity; sid:100001454; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.192",nocase; classtype:trojan-activity; sid:100001455; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.225",nocase; classtype:trojan-activity; sid:100001456; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.34",nocase; classtype:trojan-activity; sid:100001457; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.60",nocase; classtype:trojan-activity; sid:100001458; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.205",nocase; classtype:trojan-activity; sid:100001459; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.209",nocase; classtype:trojan-activity; sid:100001460; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.86",nocase; classtype:trojan-activity; sid:100001461; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.88",nocase; classtype:trojan-activity; sid:100001462; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.179",nocase; classtype:trojan-activity; sid:100001463; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.252",nocase; classtype:trojan-activity; sid:100001464; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.53",nocase; classtype:trojan-activity; sid:100001465; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.97",nocase; classtype:trojan-activity; sid:100001466; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.120.133",nocase; classtype:trojan-activity; sid:100001467; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.120.184",nocase; classtype:trojan-activity; sid:100001468; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.120.203",nocase; classtype:trojan-activity; sid:100001469; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.120.251",nocase; classtype:trojan-activity; sid:100001470; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.123",nocase; classtype:trojan-activity; sid:100001471; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.155",nocase; classtype:trojan-activity; sid:100001472; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.55",nocase; classtype:trojan-activity; sid:100001473; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.62",nocase; classtype:trojan-activity; sid:100001474; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.68",nocase; classtype:trojan-activity; sid:100001475; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.99",nocase; classtype:trojan-activity; sid:100001476; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.144",nocase; classtype:trojan-activity; sid:100001477; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.172",nocase; classtype:trojan-activity; sid:100001478; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.245",nocase; classtype:trojan-activity; sid:100001479; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.28",nocase; classtype:trojan-activity; sid:100001480; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.113",nocase; classtype:trojan-activity; sid:100001481; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.2",nocase; classtype:trojan-activity; sid:100001482; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.20",nocase; classtype:trojan-activity; sid:100001483; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.223",nocase; classtype:trojan-activity; sid:100001484; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.56",nocase; classtype:trojan-activity; sid:100001485; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.60",nocase; classtype:trojan-activity; sid:100001486; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.109",nocase; classtype:trojan-activity; sid:100001487; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.122",nocase; classtype:trojan-activity; sid:100001488; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.131",nocase; classtype:trojan-activity; sid:100001489; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.141",nocase; classtype:trojan-activity; sid:100001490; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.157",nocase; classtype:trojan-activity; sid:100001491; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.175",nocase; classtype:trojan-activity; sid:100001492; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.211",nocase; classtype:trojan-activity; sid:100001493; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.233",nocase; classtype:trojan-activity; sid:100001494; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.4",nocase; classtype:trojan-activity; sid:100001495; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.79",nocase; classtype:trojan-activity; sid:100001496; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.89",nocase; classtype:trojan-activity; sid:100001497; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.9",nocase; classtype:trojan-activity; sid:100001498; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.118",nocase; classtype:trojan-activity; sid:100001499; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.14",nocase; classtype:trojan-activity; sid:100001500; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.143",nocase; classtype:trojan-activity; sid:100001501; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.153",nocase; classtype:trojan-activity; sid:100001502; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.156",nocase; classtype:trojan-activity; sid:100001503; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.174",nocase; classtype:trojan-activity; sid:100001504; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.219",nocase; classtype:trojan-activity; sid:100001505; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.39",nocase; classtype:trojan-activity; sid:100001506; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.54",nocase; classtype:trojan-activity; sid:100001507; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.101",nocase; classtype:trojan-activity; sid:100001508; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.131",nocase; classtype:trojan-activity; sid:100001509; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.141",nocase; classtype:trojan-activity; sid:100001510; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.167",nocase; classtype:trojan-activity; sid:100001511; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.220",nocase; classtype:trojan-activity; sid:100001512; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.222",nocase; classtype:trojan-activity; sid:100001513; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.237",nocase; classtype:trojan-activity; sid:100001514; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.80",nocase; classtype:trojan-activity; sid:100001515; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.83",nocase; classtype:trojan-activity; sid:100001516; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.109",nocase; classtype:trojan-activity; sid:100001517; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.116",nocase; classtype:trojan-activity; sid:100001518; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.142",nocase; classtype:trojan-activity; sid:100001519; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.15",nocase; classtype:trojan-activity; sid:100001520; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.182",nocase; classtype:trojan-activity; sid:100001521; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.212",nocase; classtype:trojan-activity; sid:100001522; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.230",nocase; classtype:trojan-activity; sid:100001523; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.231",nocase; classtype:trojan-activity; sid:100001524; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.236",nocase; classtype:trojan-activity; sid:100001525; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.63",nocase; classtype:trojan-activity; sid:100001526; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.75",nocase; classtype:trojan-activity; sid:100001527; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.14.106",nocase; classtype:trojan-activity; sid:100001528; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.14.185",nocase; classtype:trojan-activity; sid:100001529; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.14.246",nocase; classtype:trojan-activity; sid:100001530; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.14.28",nocase; classtype:trojan-activity; sid:100001531; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.14.60",nocase; classtype:trojan-activity; sid:100001532; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.17",nocase; classtype:trojan-activity; sid:100001533; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.217",nocase; classtype:trojan-activity; sid:100001534; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.252",nocase; classtype:trojan-activity; sid:100001535; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.35",nocase; classtype:trojan-activity; sid:100001536; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.45",nocase; classtype:trojan-activity; sid:100001537; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.85",nocase; classtype:trojan-activity; sid:100001538; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.1",nocase; classtype:trojan-activity; sid:100001539; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.108",nocase; classtype:trojan-activity; sid:100001540; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.121",nocase; classtype:trojan-activity; sid:100001541; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.17",nocase; classtype:trojan-activity; sid:100001542; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.179",nocase; classtype:trojan-activity; sid:100001543; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.208",nocase; classtype:trojan-activity; sid:100001544; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.97",nocase; classtype:trojan-activity; sid:100001545; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.17.176",nocase; classtype:trojan-activity; sid:100001546; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.17.245",nocase; classtype:trojan-activity; sid:100001547; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.18.238",nocase; classtype:trojan-activity; sid:100001548; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.18.6",nocase; classtype:trojan-activity; sid:100001549; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.18.93",nocase; classtype:trojan-activity; sid:100001550; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.144",nocase; classtype:trojan-activity; sid:100001551; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.150",nocase; classtype:trojan-activity; sid:100001552; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.163",nocase; classtype:trojan-activity; sid:100001553; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.174",nocase; classtype:trojan-activity; sid:100001554; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.242",nocase; classtype:trojan-activity; sid:100001555; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.44",nocase; classtype:trojan-activity; sid:100001556; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.47",nocase; classtype:trojan-activity; sid:100001557; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.110",nocase; classtype:trojan-activity; sid:100001558; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.237",nocase; classtype:trojan-activity; sid:100001559; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.245",nocase; classtype:trojan-activity; sid:100001560; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.41",nocase; classtype:trojan-activity; sid:100001561; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.5",nocase; classtype:trojan-activity; sid:100001562; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.80",nocase; classtype:trojan-activity; sid:100001563; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.117",nocase; classtype:trojan-activity; sid:100001564; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.145",nocase; classtype:trojan-activity; sid:100001565; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.170",nocase; classtype:trojan-activity; sid:100001566; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.21",nocase; classtype:trojan-activity; sid:100001567; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.225",nocase; classtype:trojan-activity; sid:100001568; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.227",nocase; classtype:trojan-activity; sid:100001569; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.237",nocase; classtype:trojan-activity; sid:100001570; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.238",nocase; classtype:trojan-activity; sid:100001571; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.24",nocase; classtype:trojan-activity; sid:100001572; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.38",nocase; classtype:trojan-activity; sid:100001573; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.70",nocase; classtype:trojan-activity; sid:100001574; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.149",nocase; classtype:trojan-activity; sid:100001575; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.184",nocase; classtype:trojan-activity; sid:100001576; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.238",nocase; classtype:trojan-activity; sid:100001577; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.58",nocase; classtype:trojan-activity; sid:100001578; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.76",nocase; classtype:trojan-activity; sid:100001579; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.23.156",nocase; classtype:trojan-activity; sid:100001580; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.23.250",nocase; classtype:trojan-activity; sid:100001581; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.13",nocase; classtype:trojan-activity; sid:100001582; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.138",nocase; classtype:trojan-activity; sid:100001583; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.15",nocase; classtype:trojan-activity; sid:100001584; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.171",nocase; classtype:trojan-activity; sid:100001585; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.227",nocase; classtype:trojan-activity; sid:100001586; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.239",nocase; classtype:trojan-activity; sid:100001587; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.251",nocase; classtype:trojan-activity; sid:100001588; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.117",nocase; classtype:trojan-activity; sid:100001589; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.156",nocase; classtype:trojan-activity; sid:100001590; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.244",nocase; classtype:trojan-activity; sid:100001591; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.28",nocase; classtype:trojan-activity; sid:100001592; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.56",nocase; classtype:trojan-activity; sid:100001593; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.64",nocase; classtype:trojan-activity; sid:100001594; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.77",nocase; classtype:trojan-activity; sid:100001595; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.134",nocase; classtype:trojan-activity; sid:100001596; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.164",nocase; classtype:trojan-activity; sid:100001597; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.168",nocase; classtype:trojan-activity; sid:100001598; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.219",nocase; classtype:trojan-activity; sid:100001599; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.224",nocase; classtype:trojan-activity; sid:100001600; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.246",nocase; classtype:trojan-activity; sid:100001601; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.38",nocase; classtype:trojan-activity; sid:100001602; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.69",nocase; classtype:trojan-activity; sid:100001603; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.122",nocase; classtype:trojan-activity; sid:100001604; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.138",nocase; classtype:trojan-activity; sid:100001605; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.14",nocase; classtype:trojan-activity; sid:100001606; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.167",nocase; classtype:trojan-activity; sid:100001607; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.169",nocase; classtype:trojan-activity; sid:100001608; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.179",nocase; classtype:trojan-activity; sid:100001609; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.199",nocase; classtype:trojan-activity; sid:100001610; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.202",nocase; classtype:trojan-activity; sid:100001611; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.215",nocase; classtype:trojan-activity; sid:100001612; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.225",nocase; classtype:trojan-activity; sid:100001613; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.233",nocase; classtype:trojan-activity; sid:100001614; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.239",nocase; classtype:trojan-activity; sid:100001615; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.241",nocase; classtype:trojan-activity; sid:100001616; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.68",nocase; classtype:trojan-activity; sid:100001617; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.69",nocase; classtype:trojan-activity; sid:100001618; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.84",nocase; classtype:trojan-activity; sid:100001619; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.28.118",nocase; classtype:trojan-activity; sid:100001620; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.28.124",nocase; classtype:trojan-activity; sid:100001621; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.28.128",nocase; classtype:trojan-activity; sid:100001622; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.28.167",nocase; classtype:trojan-activity; sid:100001623; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.28.168",nocase; classtype:trojan-activity; sid:100001624; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.28.8",nocase; classtype:trojan-activity; sid:100001625; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.16",nocase; classtype:trojan-activity; sid:100001626; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.173",nocase; classtype:trojan-activity; sid:100001627; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.174",nocase; classtype:trojan-activity; sid:100001628; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.184",nocase; classtype:trojan-activity; sid:100001629; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.207",nocase; classtype:trojan-activity; sid:100001630; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.116",nocase; classtype:trojan-activity; sid:100001631; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.130",nocase; classtype:trojan-activity; sid:100001632; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.172",nocase; classtype:trojan-activity; sid:100001633; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.190",nocase; classtype:trojan-activity; sid:100001634; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.196",nocase; classtype:trojan-activity; sid:100001635; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.214",nocase; classtype:trojan-activity; sid:100001636; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.56",nocase; classtype:trojan-activity; sid:100001637; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.81",nocase; classtype:trojan-activity; sid:100001638; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.0",nocase; classtype:trojan-activity; sid:100001639; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.213",nocase; classtype:trojan-activity; sid:100001640; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.255",nocase; classtype:trojan-activity; sid:100001641; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.77",nocase; classtype:trojan-activity; sid:100001642; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.31.211",nocase; classtype:trojan-activity; sid:100001643; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.31.232",nocase; classtype:trojan-activity; sid:100001644; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.31.249",nocase; classtype:trojan-activity; sid:100001645; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.31.251",nocase; classtype:trojan-activity; sid:100001646; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.0",nocase; classtype:trojan-activity; sid:100001647; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.105",nocase; classtype:trojan-activity; sid:100001648; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.141",nocase; classtype:trojan-activity; sid:100001649; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.172",nocase; classtype:trojan-activity; sid:100001650; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.196",nocase; classtype:trojan-activity; sid:100001651; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.198",nocase; classtype:trojan-activity; sid:100001652; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.208",nocase; classtype:trojan-activity; sid:100001653; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.211",nocase; classtype:trojan-activity; sid:100001654; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.243",nocase; classtype:trojan-activity; sid:100001655; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.32",nocase; classtype:trojan-activity; sid:100001656; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.42",nocase; classtype:trojan-activity; sid:100001657; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.89",nocase; classtype:trojan-activity; sid:100001658; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.112",nocase; classtype:trojan-activity; sid:100001659; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.118",nocase; classtype:trojan-activity; sid:100001660; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.151",nocase; classtype:trojan-activity; sid:100001661; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.155",nocase; classtype:trojan-activity; sid:100001662; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.161",nocase; classtype:trojan-activity; sid:100001663; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.162",nocase; classtype:trojan-activity; sid:100001664; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.170",nocase; classtype:trojan-activity; sid:100001665; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.174",nocase; classtype:trojan-activity; sid:100001666; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.181",nocase; classtype:trojan-activity; sid:100001667; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.2",nocase; classtype:trojan-activity; sid:100001668; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.216",nocase; classtype:trojan-activity; sid:100001669; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.234",nocase; classtype:trojan-activity; sid:100001670; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.236",nocase; classtype:trojan-activity; sid:100001671; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.239",nocase; classtype:trojan-activity; sid:100001672; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.26",nocase; classtype:trojan-activity; sid:100001673; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.34.96",nocase; classtype:trojan-activity; sid:100001674; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.35.160",nocase; classtype:trojan-activity; sid:100001675; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.35.21",nocase; classtype:trojan-activity; sid:100001676; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.35.215",nocase; classtype:trojan-activity; sid:100001677; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.35.253",nocase; classtype:trojan-activity; sid:100001678; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.35.38",nocase; classtype:trojan-activity; sid:100001679; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.35.83",nocase; classtype:trojan-activity; sid:100001680; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.35.89",nocase; classtype:trojan-activity; sid:100001681; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.0",nocase; classtype:trojan-activity; sid:100001682; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.1",nocase; classtype:trojan-activity; sid:100001683; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.102",nocase; classtype:trojan-activity; sid:100001684; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.112",nocase; classtype:trojan-activity; sid:100001685; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.12",nocase; classtype:trojan-activity; sid:100001686; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.16",nocase; classtype:trojan-activity; sid:100001687; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.199",nocase; classtype:trojan-activity; sid:100001688; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.200",nocase; classtype:trojan-activity; sid:100001689; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.218",nocase; classtype:trojan-activity; sid:100001690; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.22",nocase; classtype:trojan-activity; sid:100001691; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.223",nocase; classtype:trojan-activity; sid:100001692; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.33",nocase; classtype:trojan-activity; sid:100001693; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.88",nocase; classtype:trojan-activity; sid:100001694; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.121",nocase; classtype:trojan-activity; sid:100001695; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.135",nocase; classtype:trojan-activity; sid:100001696; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.159",nocase; classtype:trojan-activity; sid:100001697; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.6",nocase; classtype:trojan-activity; sid:100001698; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.1",nocase; classtype:trojan-activity; sid:100001699; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.126",nocase; classtype:trojan-activity; sid:100001700; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.132",nocase; classtype:trojan-activity; sid:100001701; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.148",nocase; classtype:trojan-activity; sid:100001702; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.162",nocase; classtype:trojan-activity; sid:100001703; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.165",nocase; classtype:trojan-activity; sid:100001704; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.191",nocase; classtype:trojan-activity; sid:100001705; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.7",nocase; classtype:trojan-activity; sid:100001706; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.98",nocase; classtype:trojan-activity; sid:100001707; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.39.167",nocase; classtype:trojan-activity; sid:100001708; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.39.245",nocase; classtype:trojan-activity; sid:100001709; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.222",nocase; classtype:trojan-activity; sid:100001710; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.42",nocase; classtype:trojan-activity; sid:100001711; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.58",nocase; classtype:trojan-activity; sid:100001712; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.95",nocase; classtype:trojan-activity; sid:100001713; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.1",nocase; classtype:trojan-activity; sid:100001714; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.151",nocase; classtype:trojan-activity; sid:100001715; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.166",nocase; classtype:trojan-activity; sid:100001716; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.191",nocase; classtype:trojan-activity; sid:100001717; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.199",nocase; classtype:trojan-activity; sid:100001718; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.226",nocase; classtype:trojan-activity; sid:100001719; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.41",nocase; classtype:trojan-activity; sid:100001720; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.5",nocase; classtype:trojan-activity; sid:100001721; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.67",nocase; classtype:trojan-activity; sid:100001722; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.70",nocase; classtype:trojan-activity; sid:100001723; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.71",nocase; classtype:trojan-activity; sid:100001724; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.73",nocase; classtype:trojan-activity; sid:100001725; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.82",nocase; classtype:trojan-activity; sid:100001726; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.165",nocase; classtype:trojan-activity; sid:100001727; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.178",nocase; classtype:trojan-activity; sid:100001728; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.203",nocase; classtype:trojan-activity; sid:100001729; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.210",nocase; classtype:trojan-activity; sid:100001730; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.216",nocase; classtype:trojan-activity; sid:100001731; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.246",nocase; classtype:trojan-activity; sid:100001732; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.34",nocase; classtype:trojan-activity; sid:100001733; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.162",nocase; classtype:trojan-activity; sid:100001734; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.166",nocase; classtype:trojan-activity; sid:100001735; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.200",nocase; classtype:trojan-activity; sid:100001736; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.211",nocase; classtype:trojan-activity; sid:100001737; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.221",nocase; classtype:trojan-activity; sid:100001738; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.27",nocase; classtype:trojan-activity; sid:100001739; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.31",nocase; classtype:trojan-activity; sid:100001740; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.1",nocase; classtype:trojan-activity; sid:100001741; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.121",nocase; classtype:trojan-activity; sid:100001742; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.125",nocase; classtype:trojan-activity; sid:100001743; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.147",nocase; classtype:trojan-activity; sid:100001744; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.17",nocase; classtype:trojan-activity; sid:100001745; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.176",nocase; classtype:trojan-activity; sid:100001746; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.22",nocase; classtype:trojan-activity; sid:100001747; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.33",nocase; classtype:trojan-activity; sid:100001748; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.44",nocase; classtype:trojan-activity; sid:100001749; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.47",nocase; classtype:trojan-activity; sid:100001750; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.134",nocase; classtype:trojan-activity; sid:100001751; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.143",nocase; classtype:trojan-activity; sid:100001752; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.155",nocase; classtype:trojan-activity; sid:100001753; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.218",nocase; classtype:trojan-activity; sid:100001754; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.22",nocase; classtype:trojan-activity; sid:100001755; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.241",nocase; classtype:trojan-activity; sid:100001756; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.89",nocase; classtype:trojan-activity; sid:100001757; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.90",nocase; classtype:trojan-activity; sid:100001758; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.45.205",nocase; classtype:trojan-activity; sid:100001759; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.45.221",nocase; classtype:trojan-activity; sid:100001760; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.45.224",nocase; classtype:trojan-activity; sid:100001761; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.45.230",nocase; classtype:trojan-activity; sid:100001762; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.187",nocase; classtype:trojan-activity; sid:100001763; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.141",nocase; classtype:trojan-activity; sid:100001764; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.151",nocase; classtype:trojan-activity; sid:100001765; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.48.121",nocase; classtype:trojan-activity; sid:100001766; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.48.195",nocase; classtype:trojan-activity; sid:100001767; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.48.243",nocase; classtype:trojan-activity; sid:100001768; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.107",nocase; classtype:trojan-activity; sid:100001769; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.247",nocase; classtype:trojan-activity; sid:100001770; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.3",nocase; classtype:trojan-activity; sid:100001771; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.98",nocase; classtype:trojan-activity; sid:100001772; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.5.16",nocase; classtype:trojan-activity; sid:100001773; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.5.247",nocase; classtype:trojan-activity; sid:100001774; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.5.251",nocase; classtype:trojan-activity; sid:100001775; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.5.70",nocase; classtype:trojan-activity; sid:100001776; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.131",nocase; classtype:trojan-activity; sid:100001777; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.177",nocase; classtype:trojan-activity; sid:100001778; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.201",nocase; classtype:trojan-activity; sid:100001779; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.218",nocase; classtype:trojan-activity; sid:100001780; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.236",nocase; classtype:trojan-activity; sid:100001781; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.237",nocase; classtype:trojan-activity; sid:100001782; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.47",nocase; classtype:trojan-activity; sid:100001783; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.51.150",nocase; classtype:trojan-activity; sid:100001784; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.51.197",nocase; classtype:trojan-activity; sid:100001785; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.51.202",nocase; classtype:trojan-activity; sid:100001786; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.51.223",nocase; classtype:trojan-activity; sid:100001787; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.51.37",nocase; classtype:trojan-activity; sid:100001788; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.51.66",nocase; classtype:trojan-activity; sid:100001789; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.149",nocase; classtype:trojan-activity; sid:100001790; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.161",nocase; classtype:trojan-activity; sid:100001791; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.79",nocase; classtype:trojan-activity; sid:100001792; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.103",nocase; classtype:trojan-activity; sid:100001793; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.15",nocase; classtype:trojan-activity; sid:100001794; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.186",nocase; classtype:trojan-activity; sid:100001795; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.20",nocase; classtype:trojan-activity; sid:100001796; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.4",nocase; classtype:trojan-activity; sid:100001797; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.5",nocase; classtype:trojan-activity; sid:100001798; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.79",nocase; classtype:trojan-activity; sid:100001799; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.105",nocase; classtype:trojan-activity; sid:100001800; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.205",nocase; classtype:trojan-activity; sid:100001801; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.214",nocase; classtype:trojan-activity; sid:100001802; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.72",nocase; classtype:trojan-activity; sid:100001803; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.101",nocase; classtype:trojan-activity; sid:100001804; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.111",nocase; classtype:trojan-activity; sid:100001805; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.163",nocase; classtype:trojan-activity; sid:100001806; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.204",nocase; classtype:trojan-activity; sid:100001807; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.216",nocase; classtype:trojan-activity; sid:100001808; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.29",nocase; classtype:trojan-activity; sid:100001809; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.41",nocase; classtype:trojan-activity; sid:100001810; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.77",nocase; classtype:trojan-activity; sid:100001811; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.86",nocase; classtype:trojan-activity; sid:100001812; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.103",nocase; classtype:trojan-activity; sid:100001813; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.196",nocase; classtype:trojan-activity; sid:100001814; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.33",nocase; classtype:trojan-activity; sid:100001815; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.75",nocase; classtype:trojan-activity; sid:100001816; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.94",nocase; classtype:trojan-activity; sid:100001817; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.57.141",nocase; classtype:trojan-activity; sid:100001818; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.57.178",nocase; classtype:trojan-activity; sid:100001819; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.57.192",nocase; classtype:trojan-activity; sid:100001820; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.57.7",nocase; classtype:trojan-activity; sid:100001821; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.58.117",nocase; classtype:trojan-activity; sid:100001822; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.58.141",nocase; classtype:trojan-activity; sid:100001823; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.58.223",nocase; classtype:trojan-activity; sid:100001824; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.142",nocase; classtype:trojan-activity; sid:100001825; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.161",nocase; classtype:trojan-activity; sid:100001826; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.229",nocase; classtype:trojan-activity; sid:100001827; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.33",nocase; classtype:trojan-activity; sid:100001828; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.46",nocase; classtype:trojan-activity; sid:100001829; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.54",nocase; classtype:trojan-activity; sid:100001830; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.91",nocase; classtype:trojan-activity; sid:100001831; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.134",nocase; classtype:trojan-activity; sid:100001832; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.151",nocase; classtype:trojan-activity; sid:100001833; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.154",nocase; classtype:trojan-activity; sid:100001834; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.162",nocase; classtype:trojan-activity; sid:100001835; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.171",nocase; classtype:trojan-activity; sid:100001836; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.60.154",nocase; classtype:trojan-activity; sid:100001837; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.60.181",nocase; classtype:trojan-activity; sid:100001838; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.60.32",nocase; classtype:trojan-activity; sid:100001839; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.60.99",nocase; classtype:trojan-activity; sid:100001840; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.151",nocase; classtype:trojan-activity; sid:100001841; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.156",nocase; classtype:trojan-activity; sid:100001842; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.219",nocase; classtype:trojan-activity; sid:100001843; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.229",nocase; classtype:trojan-activity; sid:100001844; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.234",nocase; classtype:trojan-activity; sid:100001845; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.253",nocase; classtype:trojan-activity; sid:100001846; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.40",nocase; classtype:trojan-activity; sid:100001847; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.96",nocase; classtype:trojan-activity; sid:100001848; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.110",nocase; classtype:trojan-activity; sid:100001849; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.115",nocase; classtype:trojan-activity; sid:100001850; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.43",nocase; classtype:trojan-activity; sid:100001851; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.63.185",nocase; classtype:trojan-activity; sid:100001852; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.63.21",nocase; classtype:trojan-activity; sid:100001853; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.63.218",nocase; classtype:trojan-activity; sid:100001854; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.116",nocase; classtype:trojan-activity; sid:100001855; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.12",nocase; classtype:trojan-activity; sid:100001856; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.142",nocase; classtype:trojan-activity; sid:100001857; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.158",nocase; classtype:trojan-activity; sid:100001858; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.30",nocase; classtype:trojan-activity; sid:100001859; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.66",nocase; classtype:trojan-activity; sid:100001860; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.65.115",nocase; classtype:trojan-activity; sid:100001861; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.65.136",nocase; classtype:trojan-activity; sid:100001862; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.65.171",nocase; classtype:trojan-activity; sid:100001863; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.65.223",nocase; classtype:trojan-activity; sid:100001864; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.65.70",nocase; classtype:trojan-activity; sid:100001865; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.65.95",nocase; classtype:trojan-activity; sid:100001866; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.65.96",nocase; classtype:trojan-activity; sid:100001867; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.105",nocase; classtype:trojan-activity; sid:100001868; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.170",nocase; classtype:trojan-activity; sid:100001869; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.177",nocase; classtype:trojan-activity; sid:100001870; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.186",nocase; classtype:trojan-activity; sid:100001871; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.199",nocase; classtype:trojan-activity; sid:100001872; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.211",nocase; classtype:trojan-activity; sid:100001873; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.228",nocase; classtype:trojan-activity; sid:100001874; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.237",nocase; classtype:trojan-activity; sid:100001875; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.93",nocase; classtype:trojan-activity; sid:100001876; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.0",nocase; classtype:trojan-activity; sid:100001877; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.184",nocase; classtype:trojan-activity; sid:100001878; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.185",nocase; classtype:trojan-activity; sid:100001879; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.201",nocase; classtype:trojan-activity; sid:100001880; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.254",nocase; classtype:trojan-activity; sid:100001881; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.31",nocase; classtype:trojan-activity; sid:100001882; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.109",nocase; classtype:trojan-activity; sid:100001883; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.126",nocase; classtype:trojan-activity; sid:100001884; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.166",nocase; classtype:trojan-activity; sid:100001885; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.170",nocase; classtype:trojan-activity; sid:100001886; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.227",nocase; classtype:trojan-activity; sid:100001887; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.232",nocase; classtype:trojan-activity; sid:100001888; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.29",nocase; classtype:trojan-activity; sid:100001889; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.44",nocase; classtype:trojan-activity; sid:100001890; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.66",nocase; classtype:trojan-activity; sid:100001891; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.83",nocase; classtype:trojan-activity; sid:100001892; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.111",nocase; classtype:trojan-activity; sid:100001893; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.119",nocase; classtype:trojan-activity; sid:100001894; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.128",nocase; classtype:trojan-activity; sid:100001895; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.138",nocase; classtype:trojan-activity; sid:100001896; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.149",nocase; classtype:trojan-activity; sid:100001897; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.188",nocase; classtype:trojan-activity; sid:100001898; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.205",nocase; classtype:trojan-activity; sid:100001899; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.77",nocase; classtype:trojan-activity; sid:100001900; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.7.163",nocase; classtype:trojan-activity; sid:100001901; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.119",nocase; classtype:trojan-activity; sid:100001902; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.12",nocase; classtype:trojan-activity; sid:100001903; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.147",nocase; classtype:trojan-activity; sid:100001904; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.18",nocase; classtype:trojan-activity; sid:100001905; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.200",nocase; classtype:trojan-activity; sid:100001906; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.38",nocase; classtype:trojan-activity; sid:100001907; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.53",nocase; classtype:trojan-activity; sid:100001908; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.54",nocase; classtype:trojan-activity; sid:100001909; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.148",nocase; classtype:trojan-activity; sid:100001910; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.153",nocase; classtype:trojan-activity; sid:100001911; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.185",nocase; classtype:trojan-activity; sid:100001912; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.196",nocase; classtype:trojan-activity; sid:100001913; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.22",nocase; classtype:trojan-activity; sid:100001914; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.55",nocase; classtype:trojan-activity; sid:100001915; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.63",nocase; classtype:trojan-activity; sid:100001916; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.84",nocase; classtype:trojan-activity; sid:100001917; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.89",nocase; classtype:trojan-activity; sid:100001918; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.113",nocase; classtype:trojan-activity; sid:100001919; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.13",nocase; classtype:trojan-activity; sid:100001920; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.164",nocase; classtype:trojan-activity; sid:100001921; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.173",nocase; classtype:trojan-activity; sid:100001922; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.196",nocase; classtype:trojan-activity; sid:100001923; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.222",nocase; classtype:trojan-activity; sid:100001924; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.47",nocase; classtype:trojan-activity; sid:100001925; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.75",nocase; classtype:trojan-activity; sid:100001926; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.91",nocase; classtype:trojan-activity; sid:100001927; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.98",nocase; classtype:trojan-activity; sid:100001928; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.73.220",nocase; classtype:trojan-activity; sid:100001929; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.74.182",nocase; classtype:trojan-activity; sid:100001930; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.74.48",nocase; classtype:trojan-activity; sid:100001931; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.75.135",nocase; classtype:trojan-activity; sid:100001932; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.75.181",nocase; classtype:trojan-activity; sid:100001933; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.75.19",nocase; classtype:trojan-activity; sid:100001934; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.75.209",nocase; classtype:trojan-activity; sid:100001935; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.75.249",nocase; classtype:trojan-activity; sid:100001936; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.75.54",nocase; classtype:trojan-activity; sid:100001937; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.75.84",nocase; classtype:trojan-activity; sid:100001938; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.75.87",nocase; classtype:trojan-activity; sid:100001939; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.109",nocase; classtype:trojan-activity; sid:100001940; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.167",nocase; classtype:trojan-activity; sid:100001941; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.187",nocase; classtype:trojan-activity; sid:100001942; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.214",nocase; classtype:trojan-activity; sid:100001943; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.215",nocase; classtype:trojan-activity; sid:100001944; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.217",nocase; classtype:trojan-activity; sid:100001945; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.24",nocase; classtype:trojan-activity; sid:100001946; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.77.132",nocase; classtype:trojan-activity; sid:100001947; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.77.145",nocase; classtype:trojan-activity; sid:100001948; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.77.46",nocase; classtype:trojan-activity; sid:100001949; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.77.47",nocase; classtype:trojan-activity; sid:100001950; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.77.95",nocase; classtype:trojan-activity; sid:100001951; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.106",nocase; classtype:trojan-activity; sid:100001952; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.202",nocase; classtype:trojan-activity; sid:100001953; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.233",nocase; classtype:trojan-activity; sid:100001954; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.46",nocase; classtype:trojan-activity; sid:100001955; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.76",nocase; classtype:trojan-activity; sid:100001956; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.79.156",nocase; classtype:trojan-activity; sid:100001957; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.79.227",nocase; classtype:trojan-activity; sid:100001958; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.79.24",nocase; classtype:trojan-activity; sid:100001959; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.79.247",nocase; classtype:trojan-activity; sid:100001960; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.79.45",nocase; classtype:trojan-activity; sid:100001961; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.79.77",nocase; classtype:trojan-activity; sid:100001962; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.8.100",nocase; classtype:trojan-activity; sid:100001963; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.8.165",nocase; classtype:trojan-activity; sid:100001964; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.8.199",nocase; classtype:trojan-activity; sid:100001965; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.8.205",nocase; classtype:trojan-activity; sid:100001966; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.8.217",nocase; classtype:trojan-activity; sid:100001967; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.8.254",nocase; classtype:trojan-activity; sid:100001968; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.237",nocase; classtype:trojan-activity; sid:100001969; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.244",nocase; classtype:trojan-activity; sid:100001970; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.79",nocase; classtype:trojan-activity; sid:100001971; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.86",nocase; classtype:trojan-activity; sid:100001972; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.1",nocase; classtype:trojan-activity; sid:100001973; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.141",nocase; classtype:trojan-activity; sid:100001974; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.15",nocase; classtype:trojan-activity; sid:100001975; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.152",nocase; classtype:trojan-activity; sid:100001976; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.17",nocase; classtype:trojan-activity; sid:100001977; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.194",nocase; classtype:trojan-activity; sid:100001978; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.216",nocase; classtype:trojan-activity; sid:100001979; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.226",nocase; classtype:trojan-activity; sid:100001980; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.244",nocase; classtype:trojan-activity; sid:100001981; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.50",nocase; classtype:trojan-activity; sid:100001982; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.82",nocase; classtype:trojan-activity; sid:100001983; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.82.61",nocase; classtype:trojan-activity; sid:100001984; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.83.147",nocase; classtype:trojan-activity; sid:100001985; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.83.196",nocase; classtype:trojan-activity; sid:100001986; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.102",nocase; classtype:trojan-activity; sid:100001987; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.109",nocase; classtype:trojan-activity; sid:100001988; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.148",nocase; classtype:trojan-activity; sid:100001989; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.159",nocase; classtype:trojan-activity; sid:100001990; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.215",nocase; classtype:trojan-activity; sid:100001991; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.42",nocase; classtype:trojan-activity; sid:100001992; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.153",nocase; classtype:trojan-activity; sid:100001993; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.165",nocase; classtype:trojan-activity; sid:100001994; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.183",nocase; classtype:trojan-activity; sid:100001995; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.190",nocase; classtype:trojan-activity; sid:100001996; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.229",nocase; classtype:trojan-activity; sid:100001997; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.87",nocase; classtype:trojan-activity; sid:100001998; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.9",nocase; classtype:trojan-activity; sid:100001999; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.86.119",nocase; classtype:trojan-activity; sid:100002000; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.86.218",nocase; classtype:trojan-activity; sid:100002001; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.107",nocase; classtype:trojan-activity; sid:100002002; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.123",nocase; classtype:trojan-activity; sid:100002003; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.162",nocase; classtype:trojan-activity; sid:100002004; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.253",nocase; classtype:trojan-activity; sid:100002005; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.90",nocase; classtype:trojan-activity; sid:100002006; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.180",nocase; classtype:trojan-activity; sid:100002007; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.181",nocase; classtype:trojan-activity; sid:100002008; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.78",nocase; classtype:trojan-activity; sid:100002009; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.89.130",nocase; classtype:trojan-activity; sid:100002010; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.89.19",nocase; classtype:trojan-activity; sid:100002011; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.89.37",nocase; classtype:trojan-activity; sid:100002012; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.89.51",nocase; classtype:trojan-activity; sid:100002013; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.178",nocase; classtype:trojan-activity; sid:100002014; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.183",nocase; classtype:trojan-activity; sid:100002015; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.215",nocase; classtype:trojan-activity; sid:100002016; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.217",nocase; classtype:trojan-activity; sid:100002017; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.245",nocase; classtype:trojan-activity; sid:100002018; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.45",nocase; classtype:trojan-activity; sid:100002019; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.80",nocase; classtype:trojan-activity; sid:100002020; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.84",nocase; classtype:trojan-activity; sid:100002021; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.95",nocase; classtype:trojan-activity; sid:100002022; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.115",nocase; classtype:trojan-activity; sid:100002023; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.160",nocase; classtype:trojan-activity; sid:100002024; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.178",nocase; classtype:trojan-activity; sid:100002025; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.187",nocase; classtype:trojan-activity; sid:100002026; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.21",nocase; classtype:trojan-activity; sid:100002027; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.212",nocase; classtype:trojan-activity; sid:100002028; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.4",nocase; classtype:trojan-activity; sid:100002029; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.8",nocase; classtype:trojan-activity; sid:100002030; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.15",nocase; classtype:trojan-activity; sid:100002031; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.165",nocase; classtype:trojan-activity; sid:100002032; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.172",nocase; classtype:trojan-activity; sid:100002033; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.191",nocase; classtype:trojan-activity; sid:100002034; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.253",nocase; classtype:trojan-activity; sid:100002035; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.47",nocase; classtype:trojan-activity; sid:100002036; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.58",nocase; classtype:trojan-activity; sid:100002037; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.71",nocase; classtype:trojan-activity; sid:100002038; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.96",nocase; classtype:trojan-activity; sid:100002039; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.132",nocase; classtype:trojan-activity; sid:100002040; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.186",nocase; classtype:trojan-activity; sid:100002041; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.201",nocase; classtype:trojan-activity; sid:100002042; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.208",nocase; classtype:trojan-activity; sid:100002043; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.215",nocase; classtype:trojan-activity; sid:100002044; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.224",nocase; classtype:trojan-activity; sid:100002045; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.231",nocase; classtype:trojan-activity; sid:100002046; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.248",nocase; classtype:trojan-activity; sid:100002047; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.45",nocase; classtype:trojan-activity; sid:100002048; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.143",nocase; classtype:trojan-activity; sid:100002049; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.150",nocase; classtype:trojan-activity; sid:100002050; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.155",nocase; classtype:trojan-activity; sid:100002051; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.198",nocase; classtype:trojan-activity; sid:100002052; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.225",nocase; classtype:trojan-activity; sid:100002053; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.245",nocase; classtype:trojan-activity; sid:100002054; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.31",nocase; classtype:trojan-activity; sid:100002055; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.4",nocase; classtype:trojan-activity; sid:100002056; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.45",nocase; classtype:trojan-activity; sid:100002057; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.6",nocase; classtype:trojan-activity; sid:100002058; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.116",nocase; classtype:trojan-activity; sid:100002059; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.184",nocase; classtype:trojan-activity; sid:100002060; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.195",nocase; classtype:trojan-activity; sid:100002061; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.238",nocase; classtype:trojan-activity; sid:100002062; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.40",nocase; classtype:trojan-activity; sid:100002063; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.147",nocase; classtype:trojan-activity; sid:100002064; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.227",nocase; classtype:trojan-activity; sid:100002065; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.244",nocase; classtype:trojan-activity; sid:100002066; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.249",nocase; classtype:trojan-activity; sid:100002067; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.4",nocase; classtype:trojan-activity; sid:100002068; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.89",nocase; classtype:trojan-activity; sid:100002069; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.99",nocase; classtype:trojan-activity; sid:100002070; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.96.13",nocase; classtype:trojan-activity; sid:100002071; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.96.180",nocase; classtype:trojan-activity; sid:100002072; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.96.195",nocase; classtype:trojan-activity; sid:100002073; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.96.24",nocase; classtype:trojan-activity; sid:100002074; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.96.6",nocase; classtype:trojan-activity; sid:100002075; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.97.111",nocase; classtype:trojan-activity; sid:100002076; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.97.181",nocase; classtype:trojan-activity; sid:100002077; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.97.243",nocase; classtype:trojan-activity; sid:100002078; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.98.140",nocase; classtype:trojan-activity; sid:100002079; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.98.228",nocase; classtype:trojan-activity; sid:100002080; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.98.254",nocase; classtype:trojan-activity; sid:100002081; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.98.50",nocase; classtype:trojan-activity; sid:100002082; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.98.68",nocase; classtype:trojan-activity; sid:100002083; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.108",nocase; classtype:trojan-activity; sid:100002084; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.123",nocase; classtype:trojan-activity; sid:100002085; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.130",nocase; classtype:trojan-activity; sid:100002086; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.22",nocase; classtype:trojan-activity; sid:100002087; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.45",nocase; classtype:trojan-activity; sid:100002088; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.75",nocase; classtype:trojan-activity; sid:100002089; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.8",nocase; classtype:trojan-activity; sid:100002090; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.91",nocase; classtype:trojan-activity; sid:100002091; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.19.183.14",nocase; classtype:trojan-activity; sid:100002092; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.205.101.33",nocase; classtype:trojan-activity; sid:100002093; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.21.164.68",nocase; classtype:trojan-activity; sid:100002094; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.217.8.194",nocase; classtype:trojan-activity; sid:100002095; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.22.117.102",nocase; classtype:trojan-activity; sid:100002096; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.222.252.130",nocase; classtype:trojan-activity; sid:100002097; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.34.183.30",nocase; classtype:trojan-activity; sid:100002098; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.92.246.246",nocase; classtype:trojan-activity; sid:100002099; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.93.112.88",nocase; classtype:trojan-activity; sid:100002100; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.95.115.33",nocase; classtype:trojan-activity; sid:100002101; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.159.58.134",nocase; classtype:trojan-activity; sid:100002102; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.4.187.39",nocase; classtype:trojan-activity; sid:100002103; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.48.156.252",nocase; classtype:trojan-activity; sid:100002104; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.60.84.7",nocase; classtype:trojan-activity; sid:100002105; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.99.210.161",nocase; classtype:trojan-activity; sid:100002106; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.109.36.244",nocase; classtype:trojan-activity; sid:100002107; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.111.101.141",nocase; classtype:trojan-activity; sid:100002108; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.114.111.153",nocase; classtype:trojan-activity; sid:100002109; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.116.203.220",nocase; classtype:trojan-activity; sid:100002110; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.120.149.106",nocase; classtype:trojan-activity; sid:100002111; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.122.13.227",nocase; classtype:trojan-activity; sid:100002112; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.125.155.69",nocase; classtype:trojan-activity; sid:100002113; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.125.44.194",nocase; classtype:trojan-activity; sid:100002114; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.157.66.204",nocase; classtype:trojan-activity; sid:100002115; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.175.93.52",nocase; classtype:trojan-activity; sid:100002116; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.105.41",nocase; classtype:trojan-activity; sid:100002117; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.110.243",nocase; classtype:trojan-activity; sid:100002118; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.165.230",nocase; classtype:trojan-activity; sid:100002119; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.214.171",nocase; classtype:trojan-activity; sid:100002120; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.34.51",nocase; classtype:trojan-activity; sid:100002121; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.96.248",nocase; classtype:trojan-activity; sid:100002122; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.177.104.65",nocase; classtype:trojan-activity; sid:100002123; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.177.242.73",nocase; classtype:trojan-activity; sid:100002124; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.218.5.171",nocase; classtype:trojan-activity; sid:100002125; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.248.80.38",nocase; classtype:trojan-activity; sid:100002126; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.66.111.36",nocase; classtype:trojan-activity; sid:100002127; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.66.53.93",nocase; classtype:trojan-activity; sid:100002128; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.94.170.166",nocase; classtype:trojan-activity; sid:100002129; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.112.138.154",nocase; classtype:trojan-activity; sid:100002130; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.112.218.238",nocase; classtype:trojan-activity; sid:100002131; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.112.218.6",nocase; classtype:trojan-activity; sid:100002132; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.143.60.163",nocase; classtype:trojan-activity; sid:100002133; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.174.63.114",nocase; classtype:trojan-activity; sid:100002134; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.193.107.10",nocase; classtype:trojan-activity; sid:100002135; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.199.170.210",nocase; classtype:trojan-activity; sid:100002136; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.199.170.222",nocase; classtype:trojan-activity; sid:100002137; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.199.170.230",nocase; classtype:trojan-activity; sid:100002138; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.199.170.240",nocase; classtype:trojan-activity; sid:100002139; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.210.45.42",nocase; classtype:trojan-activity; sid:100002140; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.215.47.82",nocase; classtype:trojan-activity; sid:100002141; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.224.242.131",nocase; classtype:trojan-activity; sid:100002142; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.49.236.4",nocase; classtype:trojan-activity; sid:100002143; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.49.59.162",nocase; classtype:trojan-activity; sid:100002144; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.112.0.33",nocase; classtype:trojan-activity; sid:100002145; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.112.15.49",nocase; classtype:trojan-activity; sid:100002146; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.112.39.201",nocase; classtype:trojan-activity; sid:100002147; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.112.52.131",nocase; classtype:trojan-activity; sid:100002148; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.113.0.79",nocase; classtype:trojan-activity; sid:100002149; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.113.222.154",nocase; classtype:trojan-activity; sid:100002150; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.113.24.21",nocase; classtype:trojan-activity; sid:100002151; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.106.207",nocase; classtype:trojan-activity; sid:100002152; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.122.228",nocase; classtype:trojan-activity; sid:100002153; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.202.186",nocase; classtype:trojan-activity; sid:100002154; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.31.65",nocase; classtype:trojan-activity; sid:100002155; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.50.124",nocase; classtype:trojan-activity; sid:100002156; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.50.93",nocase; classtype:trojan-activity; sid:100002157; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.64.27",nocase; classtype:trojan-activity; sid:100002158; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.70.177",nocase; classtype:trojan-activity; sid:100002159; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.93.165",nocase; classtype:trojan-activity; sid:100002160; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.94.255",nocase; classtype:trojan-activity; sid:100002161; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.101.82",nocase; classtype:trojan-activity; sid:100002162; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.104.125",nocase; classtype:trojan-activity; sid:100002163; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.110.31",nocase; classtype:trojan-activity; sid:100002164; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.44.70",nocase; classtype:trojan-activity; sid:100002165; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.49.171",nocase; classtype:trojan-activity; sid:100002166; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.60.73",nocase; classtype:trojan-activity; sid:100002167; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.61.252",nocase; classtype:trojan-activity; sid:100002168; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.65.157",nocase; classtype:trojan-activity; sid:100002169; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.65.245",nocase; classtype:trojan-activity; sid:100002170; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.68.40",nocase; classtype:trojan-activity; sid:100002171; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.69.37",nocase; classtype:trojan-activity; sid:100002172; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.69.47",nocase; classtype:trojan-activity; sid:100002173; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.94.196",nocase; classtype:trojan-activity; sid:100002174; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.99.17",nocase; classtype:trojan-activity; sid:100002175; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.155.204",nocase; classtype:trojan-activity; sid:100002176; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.25.120",nocase; classtype:trojan-activity; sid:100002177; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.26.235",nocase; classtype:trojan-activity; sid:100002178; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.27.150",nocase; classtype:trojan-activity; sid:100002179; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.29.74",nocase; classtype:trojan-activity; sid:100002180; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.43.27",nocase; classtype:trojan-activity; sid:100002181; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.118.140.117",nocase; classtype:trojan-activity; sid:100002182; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.100.228",nocase; classtype:trojan-activity; sid:100002183; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.14.252",nocase; classtype:trojan-activity; sid:100002184; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.166.208",nocase; classtype:trojan-activity; sid:100002185; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.211.69",nocase; classtype:trojan-activity; sid:100002186; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.220.48",nocase; classtype:trojan-activity; sid:100002187; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.227.82",nocase; classtype:trojan-activity; sid:100002188; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.229.96",nocase; classtype:trojan-activity; sid:100002189; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.236.21",nocase; classtype:trojan-activity; sid:100002190; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.50.155",nocase; classtype:trojan-activity; sid:100002191; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.81.33",nocase; classtype:trojan-activity; sid:100002192; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.10.21",nocase; classtype:trojan-activity; sid:100002193; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.16.22",nocase; classtype:trojan-activity; sid:100002194; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.16.46",nocase; classtype:trojan-activity; sid:100002195; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.37.251",nocase; classtype:trojan-activity; sid:100002196; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.43.0",nocase; classtype:trojan-activity; sid:100002197; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.101.100",nocase; classtype:trojan-activity; sid:100002198; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.109.190",nocase; classtype:trojan-activity; sid:100002199; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.125.170",nocase; classtype:trojan-activity; sid:100002200; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.129.232",nocase; classtype:trojan-activity; sid:100002201; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.131.69",nocase; classtype:trojan-activity; sid:100002202; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.133.200",nocase; classtype:trojan-activity; sid:100002203; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.135.160",nocase; classtype:trojan-activity; sid:100002204; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.148.236",nocase; classtype:trojan-activity; sid:100002205; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.157.221",nocase; classtype:trojan-activity; sid:100002206; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.200.151",nocase; classtype:trojan-activity; sid:100002207; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.206.132",nocase; classtype:trojan-activity; sid:100002208; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.219.239",nocase; classtype:trojan-activity; sid:100002209; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.233.191",nocase; classtype:trojan-activity; sid:100002210; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.249.26",nocase; classtype:trojan-activity; sid:100002211; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.68.100",nocase; classtype:trojan-activity; sid:100002212; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.81.241",nocase; classtype:trojan-activity; sid:100002213; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.92.113",nocase; classtype:trojan-activity; sid:100002214; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.93.174",nocase; classtype:trojan-activity; sid:100002215; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.98.21",nocase; classtype:trojan-activity; sid:100002216; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.122.170.19",nocase; classtype:trojan-activity; sid:100002217; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.122.220.203",nocase; classtype:trojan-activity; sid:100002218; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.122.229.102",nocase; classtype:trojan-activity; sid:100002219; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.122.245.2",nocase; classtype:trojan-activity; sid:100002220; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.122.249.24",nocase; classtype:trojan-activity; sid:100002221; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.124.188.23",nocase; classtype:trojan-activity; sid:100002222; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.124.53.111",nocase; classtype:trojan-activity; sid:100002223; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.113.127",nocase; classtype:trojan-activity; sid:100002224; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.117.41",nocase; classtype:trojan-activity; sid:100002225; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.124.47",nocase; classtype:trojan-activity; sid:100002226; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.126.203",nocase; classtype:trojan-activity; sid:100002227; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.127.40",nocase; classtype:trojan-activity; sid:100002228; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.139.193",nocase; classtype:trojan-activity; sid:100002229; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.139.66",nocase; classtype:trojan-activity; sid:100002230; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.140.30",nocase; classtype:trojan-activity; sid:100002231; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.178.187",nocase; classtype:trojan-activity; sid:100002232; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.82.29",nocase; classtype:trojan-activity; sid:100002233; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.83.79",nocase; classtype:trojan-activity; sid:100002234; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.87.58",nocase; classtype:trojan-activity; sid:100002235; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.95.209",nocase; classtype:trojan-activity; sid:100002236; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.155.157",nocase; classtype:trojan-activity; sid:100002237; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.166.232",nocase; classtype:trojan-activity; sid:100002238; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.210.107",nocase; classtype:trojan-activity; sid:100002239; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.6.12",nocase; classtype:trojan-activity; sid:100002240; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.78.61",nocase; classtype:trojan-activity; sid:100002241; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.87.72",nocase; classtype:trojan-activity; sid:100002242; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.91.161",nocase; classtype:trojan-activity; sid:100002243; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.172.36.164",nocase; classtype:trojan-activity; sid:100002244; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.207.219.164",nocase; classtype:trojan-activity; sid:100002245; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.233.0.252",nocase; classtype:trojan-activity; sid:100002246; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.235.252.31",nocase; classtype:trojan-activity; sid:100002247; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.53.197.62",nocase; classtype:trojan-activity; sid:100002248; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.88.235.221",nocase; classtype:trojan-activity; sid:100002249; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.105.104.83",nocase; classtype:trojan-activity; sid:100002250; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.105.225.154",nocase; classtype:trojan-activity; sid:100002251; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.109.169.45",nocase; classtype:trojan-activity; sid:100002252; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.11.238.228",nocase; classtype:trojan-activity; sid:100002253; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.136.252.233",nocase; classtype:trojan-activity; sid:100002254; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.150.138.131",nocase; classtype:trojan-activity; sid:100002255; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.16.208.172",nocase; classtype:trojan-activity; sid:100002256; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.187.163.176",nocase; classtype:trojan-activity; sid:100002257; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.188.151.225",nocase; classtype:trojan-activity; sid:100002258; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.188.180.116",nocase; classtype:trojan-activity; sid:100002259; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.188.180.68",nocase; classtype:trojan-activity; sid:100002260; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.188.76.196",nocase; classtype:trojan-activity; sid:100002261; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.83.14.35",nocase; classtype:trojan-activity; sid:100002262; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.83.15.116",nocase; classtype:trojan-activity; sid:100002263; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.83.23.138",nocase; classtype:trojan-activity; sid:100002264; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.83.99.36",nocase; classtype:trojan-activity; sid:100002265; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.92.195.140",nocase; classtype:trojan-activity; sid:100002266; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.95.147.102",nocase; classtype:trojan-activity; sid:100002267; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.97.22.14",nocase; classtype:trojan-activity; sid:100002268; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"184.164.185.41",nocase; classtype:trojan-activity; sid:100002269; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"184.74.149.230",nocase; classtype:trojan-activity; sid:100002270; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.106.209.68",nocase; classtype:trojan-activity; sid:100002271; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.107.3.8",nocase; classtype:trojan-activity; sid:100002272; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.172.110.235",nocase; classtype:trojan-activity; sid:100002273; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.181.10.234",nocase; classtype:trojan-activity; sid:100002274; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.200.241.196",nocase; classtype:trojan-activity; sid:100002275; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.112",nocase; classtype:trojan-activity; sid:100002276; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.54",nocase; classtype:trojan-activity; sid:100002277; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.77",nocase; classtype:trojan-activity; sid:100002278; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.93",nocase; classtype:trojan-activity; sid:100002279; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.219.133.122",nocase; classtype:trojan-activity; sid:100002280; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.221.3.244",nocase; classtype:trojan-activity; sid:100002281; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.228.141.74",nocase; classtype:trojan-activity; sid:100002282; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.239.243.77",nocase; classtype:trojan-activity; sid:100002283; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.26.113.95",nocase; classtype:trojan-activity; sid:100002284; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.43.19.151",nocase; classtype:trojan-activity; sid:100002285; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.55.1.182",nocase; classtype:trojan-activity; sid:100002286; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.68.230.207",nocase; classtype:trojan-activity; sid:100002287; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.81.157.186",nocase; classtype:trojan-activity; sid:100002288; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.217.185",nocase; classtype:trojan-activity; sid:100002289; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.217.213",nocase; classtype:trojan-activity; sid:100002290; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.160",nocase; classtype:trojan-activity; sid:100002291; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.161",nocase; classtype:trojan-activity; sid:100002292; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.219",nocase; classtype:trojan-activity; sid:100002293; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.80",nocase; classtype:trojan-activity; sid:100002294; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.90.166.56",nocase; classtype:trojan-activity; sid:100002295; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.151.144.85",nocase; classtype:trojan-activity; sid:100002296; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.219.164",nocase; classtype:trojan-activity; sid:100002297; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.243.112",nocase; classtype:trojan-activity; sid:100002298; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.243.77",nocase; classtype:trojan-activity; sid:100002299; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.253.150",nocase; classtype:trojan-activity; sid:100002300; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.225.120.173",nocase; classtype:trojan-activity; sid:100002301; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.227.148.107",nocase; classtype:trojan-activity; sid:100002302; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.28.60.184",nocase; classtype:trojan-activity; sid:100002303; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.4.125.48",nocase; classtype:trojan-activity; sid:100002304; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.73.188.132",nocase; classtype:trojan-activity; sid:100002305; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.12.10.98",nocase; classtype:trojan-activity; sid:100002306; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.188.124.229",nocase; classtype:trojan-activity; sid:100002307; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.212.200.162",nocase; classtype:trojan-activity; sid:100002308; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.56.88.170",nocase; classtype:trojan-activity; sid:100002309; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.75.218.102",nocase; classtype:trojan-activity; sid:100002310; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.10.21.14",nocase; classtype:trojan-activity; sid:100002311; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.10.231.246",nocase; classtype:trojan-activity; sid:100002312; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.113.81.17",nocase; classtype:trojan-activity; sid:100002313; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.127.224.149",nocase; classtype:trojan-activity; sid:100002314; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.127.224.61",nocase; classtype:trojan-activity; sid:100002315; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.127.227.99",nocase; classtype:trojan-activity; sid:100002316; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.127.230.133",nocase; classtype:trojan-activity; sid:100002317; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.127.231.226",nocase; classtype:trojan-activity; sid:100002318; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.127.231.55",nocase; classtype:trojan-activity; sid:100002319; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.127.235.232",nocase; classtype:trojan-activity; sid:100002320; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.127.235.70",nocase; classtype:trojan-activity; sid:100002321; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.127.235.71",nocase; classtype:trojan-activity; sid:100002322; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.127.254.114",nocase; classtype:trojan-activity; sid:100002323; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.13.179.87",nocase; classtype:trojan-activity; sid:100002324; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.138.200.32",nocase; classtype:trojan-activity; sid:100002325; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.152.41.141",nocase; classtype:trojan-activity; sid:100002326; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.169.178.50",nocase; classtype:trojan-activity; sid:100002327; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.169.199.59",nocase; classtype:trojan-activity; sid:100002328; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.169.30.30",nocase; classtype:trojan-activity; sid:100002329; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.169.36.163",nocase; classtype:trojan-activity; sid:100002330; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.242.167.159",nocase; classtype:trojan-activity; sid:100002331; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.242.242.144",nocase; classtype:trojan-activity; sid:100002332; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.81.100.83",nocase; classtype:trojan-activity; sid:100002333; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.83.202.25",nocase; classtype:trojan-activity; sid:100002334; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.93.233.223",nocase; classtype:trojan-activity; sid:100002335; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"189.222.157.241",nocase; classtype:trojan-activity; sid:100002336; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"19.dbstrony.pl",nocase; classtype:trojan-activity; sid:100002337; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.0.42.106",nocase; classtype:trojan-activity; sid:100002338; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.110.161.252",nocase; classtype:trojan-activity; sid:100002339; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.111.151.164",nocase; classtype:trojan-activity; sid:100002340; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.119.207.58",nocase; classtype:trojan-activity; sid:100002341; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.12.99.194",nocase; classtype:trojan-activity; sid:100002342; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.121.194.18",nocase; classtype:trojan-activity; sid:100002343; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.160",nocase; classtype:trojan-activity; sid:100002344; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.3",nocase; classtype:trojan-activity; sid:100002345; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.37",nocase; classtype:trojan-activity; sid:100002346; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.41",nocase; classtype:trojan-activity; sid:100002347; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.42",nocase; classtype:trojan-activity; sid:100002348; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.130.15.212",nocase; classtype:trojan-activity; sid:100002349; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.130.20.14",nocase; classtype:trojan-activity; sid:100002350; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.141.117.41",nocase; classtype:trojan-activity; sid:100002351; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.147.16.184",nocase; classtype:trojan-activity; sid:100002352; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.159.240.9",nocase; classtype:trojan-activity; sid:100002353; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.187.55.150",nocase; classtype:trojan-activity; sid:100002354; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.210.214.130",nocase; classtype:trojan-activity; sid:100002355; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.213.177.39",nocase; classtype:trojan-activity; sid:100002356; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.213.226.63",nocase; classtype:trojan-activity; sid:100002357; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.213.49.207",nocase; classtype:trojan-activity; sid:100002358; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.214.24.194",nocase; classtype:trojan-activity; sid:100002359; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.216.140.123",nocase; classtype:trojan-activity; sid:100002360; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.35.225.36",nocase; classtype:trojan-activity; sid:100002361; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.65.206.162",nocase; classtype:trojan-activity; sid:100002362; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.92.4.231",nocase; classtype:trojan-activity; sid:100002363; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.98.37.135",nocase; classtype:trojan-activity; sid:100002364; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.98.37.200",nocase; classtype:trojan-activity; sid:100002365; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.98.41.33",nocase; classtype:trojan-activity; sid:100002366; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"191.255.248.220",nocase; classtype:trojan-activity; sid:100002367; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.210.175.130",nocase; classtype:trojan-activity; sid:100002368; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.210.241.200",nocase; classtype:trojan-activity; sid:100002369; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.185.106",nocase; classtype:trojan-activity; sid:100002370; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.209.27",nocase; classtype:trojan-activity; sid:100002371; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.228.67",nocase; classtype:trojan-activity; sid:100002372; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.3.73.205",nocase; classtype:trojan-activity; sid:100002373; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.99.240.77",nocase; classtype:trojan-activity; sid:100002374; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"193.228.135.144",nocase; classtype:trojan-activity; sid:100002375; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"193.91.131.237",nocase; classtype:trojan-activity; sid:100002376; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.152.35.139",nocase; classtype:trojan-activity; sid:100002377; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.38.20.199",nocase; classtype:trojan-activity; sid:100002378; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.123.208.140",nocase; classtype:trojan-activity; sid:100002379; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.123.213.154",nocase; classtype:trojan-activity; sid:100002380; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.139.126.51",nocase; classtype:trojan-activity; sid:100002381; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.228.231.218",nocase; classtype:trojan-activity; sid:100002382; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.24.94.187",nocase; classtype:trojan-activity; sid:100002383; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.64.163.103",nocase; classtype:trojan-activity; sid:100002384; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.202.26.182",nocase; classtype:trojan-activity; sid:100002385; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.218.48.82",nocase; classtype:trojan-activity; sid:100002386; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.221.148.90",nocase; classtype:trojan-activity; sid:100002387; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.221.166.203",nocase; classtype:trojan-activity; sid:100002388; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"197.159.2.106",nocase; classtype:trojan-activity; sid:100002389; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"197.50.27.115",nocase; classtype:trojan-activity; sid:100002390; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.133.218",nocase; classtype:trojan-activity; sid:100002391; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.251.105",nocase; classtype:trojan-activity; sid:100002392; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.46.201.76",nocase; classtype:trojan-activity; sid:100002393; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.46.202.7",nocase; classtype:trojan-activity; sid:100002394; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1am.co.nz",nocase; classtype:trojan-activity; sid:100002395; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.229.89.119",nocase; classtype:trojan-activity; sid:100002396; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.37.203.65",nocase; classtype:trojan-activity; sid:100002397; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.45.111.158",nocase; classtype:trojan-activity; sid:100002398; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.45.4.24",nocase; classtype:trojan-activity; sid:100002399; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.55.125.182",nocase; classtype:trojan-activity; sid:100002400; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.55.92.184",nocase; classtype:trojan-activity; sid:100002401; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.83.152.16",nocase; classtype:trojan-activity; sid:100002402; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"20.dbstrony.pl",nocase; classtype:trojan-activity; sid:100002403; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.105.167.98",nocase; classtype:trojan-activity; sid:100002404; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.111.189.70",nocase; classtype:trojan-activity; sid:100002405; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.194.4.24",nocase; classtype:trojan-activity; sid:100002406; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.2.161.171",nocase; classtype:trojan-activity; sid:100002407; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.30.132.50",nocase; classtype:trojan-activity; sid:100002408; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.142.147.89",nocase; classtype:trojan-activity; sid:100002409; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.184.163.170",nocase; classtype:trojan-activity; sid:100002410; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.184.248.190",nocase; classtype:trojan-activity; sid:100002411; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.187.102.73",nocase; classtype:trojan-activity; sid:100002412; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.193.17.190",nocase; classtype:trojan-activity; sid:100002413; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.203.221.20",nocase; classtype:trojan-activity; sid:100002414; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.215.84.97",nocase; classtype:trojan-activity; sid:100002415; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.218.97.142",nocase; classtype:trojan-activity; sid:100002416; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.107.233.41",nocase; classtype:trojan-activity; sid:100002417; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.111.131.91",nocase; classtype:trojan-activity; sid:100002418; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.150.176.100",nocase; classtype:trojan-activity; sid:100002419; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.164.150.115",nocase; classtype:trojan-activity; sid:100002420; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.166.217.54",nocase; classtype:trojan-activity; sid:100002421; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.169.234.47",nocase; classtype:trojan-activity; sid:100002422; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.169.234.52",nocase; classtype:trojan-activity; sid:100002423; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.169.234.56",nocase; classtype:trojan-activity; sid:100002424; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.178.113.26",nocase; classtype:trojan-activity; sid:100002425; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.29.95.12",nocase; classtype:trojan-activity; sid:100002426; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.4.124.58",nocase; classtype:trojan-activity; sid:100002427; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.51.176.114",nocase; classtype:trojan-activity; sid:100002428; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.51.191.174",nocase; classtype:trojan-activity; sid:100002429; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.74.236.9",nocase; classtype:trojan-activity; sid:100002430; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.109.201.243",nocase; classtype:trojan-activity; sid:100002431; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.130.69.205",nocase; classtype:trojan-activity; sid:100002432; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.170.105.156",nocase; classtype:trojan-activity; sid:100002433; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.170.115.82",nocase; classtype:trojan-activity; sid:100002434; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.189.156.107",nocase; classtype:trojan-activity; sid:100002435; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.202.248.237",nocase; classtype:trojan-activity; sid:100002436; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.204.232.18",nocase; classtype:trojan-activity; sid:100002437; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.229.21.56",nocase; classtype:trojan-activity; sid:100002438; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.236.190.28",nocase; classtype:trojan-activity; sid:100002439; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.238.86.202",nocase; classtype:trojan-activity; sid:100002440; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.70.166.107",nocase; classtype:trojan-activity; sid:100002441; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.77.80.159",nocase; classtype:trojan-activity; sid:100002442; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.80.119.166",nocase; classtype:trojan-activity; sid:100002443; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.80.171.138",nocase; classtype:trojan-activity; sid:100002444; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.82.36.34",nocase; classtype:trojan-activity; sid:100002445; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.93.6.28",nocase; classtype:trojan-activity; sid:100002446; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"204.195.116.171",nocase; classtype:trojan-activity; sid:100002447; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"205.185.115.74",nocase; classtype:trojan-activity; sid:100002448; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"205.185.123.217",nocase; classtype:trojan-activity; sid:100002449; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"206.47.41.166",nocase; classtype:trojan-activity; sid:100002450; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"207.200.247.187",nocase; classtype:trojan-activity; sid:100002451; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"207.44.28.234",nocase; classtype:trojan-activity; sid:100002452; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"207.5.32.6",nocase; classtype:trojan-activity; sid:100002453; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"208.163.58.18",nocase; classtype:trojan-activity; sid:100002454; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.133.223.130",nocase; classtype:trojan-activity; sid:100002455; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.141.39.50",nocase; classtype:trojan-activity; sid:100002456; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.141.40.190",nocase; classtype:trojan-activity; sid:100002457; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.141.40.31",nocase; classtype:trojan-activity; sid:100002458; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.145.60.38",nocase; classtype:trojan-activity; sid:100002459; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.124.149.19",nocase; classtype:trojan-activity; sid:100002460; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.216.152.122",nocase; classtype:trojan-activity; sid:100002461; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.216.153.142",nocase; classtype:trojan-activity; sid:100002462; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.57.234.131",nocase; classtype:trojan-activity; sid:100002463; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.57.237.70",nocase; classtype:trojan-activity; sid:100002464; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.68.242.114",nocase; classtype:trojan-activity; sid:100002465; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.96.116.236",nocase; classtype:trojan-activity; sid:100002466; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.116.220.37",nocase; classtype:trojan-activity; sid:100002467; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.172.11.169",nocase; classtype:trojan-activity; sid:100002468; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.179.243.103",nocase; classtype:trojan-activity; sid:100002469; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.187.132.204",nocase; classtype:trojan-activity; sid:100002470; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.187.75.220",nocase; classtype:trojan-activity; sid:100002471; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.204.215.157",nocase; classtype:trojan-activity; sid:100002472; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.210.66.179",nocase; classtype:trojan-activity; sid:100002473; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.210.93.93",nocase; classtype:trojan-activity; sid:100002474; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.216.66.105",nocase; classtype:trojan-activity; sid:100002475; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.237.114.96",nocase; classtype:trojan-activity; sid:100002476; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.237.120.13",nocase; classtype:trojan-activity; sid:100002477; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.238.83.238",nocase; classtype:trojan-activity; sid:100002478; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.247.113.49",nocase; classtype:trojan-activity; sid:100002479; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.247.5.96",nocase; classtype:trojan-activity; sid:100002480; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.32.122.110",nocase; classtype:trojan-activity; sid:100002481; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.36.174.137",nocase; classtype:trojan-activity; sid:100002482; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.47.102.51",nocase; classtype:trojan-activity; sid:100002483; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.51.174.149",nocase; classtype:trojan-activity; sid:100002484; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.122.86.105",nocase; classtype:trojan-activity; sid:100002485; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.143.227.22",nocase; classtype:trojan-activity; sid:100002486; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.156.215.178",nocase; classtype:trojan-activity; sid:100002487; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.46.197.114",nocase; classtype:trojan-activity; sid:100002488; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.56.197.230",nocase; classtype:trojan-activity; sid:100002489; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.119.74.202",nocase; classtype:trojan-activity; sid:100002490; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.123.206.197",nocase; classtype:trojan-activity; sid:100002491; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.135.178.253",nocase; classtype:trojan-activity; sid:100002492; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.14.173.117",nocase; classtype:trojan-activity; sid:100002493; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.149.182.113",nocase; classtype:trojan-activity; sid:100002494; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.149.190.193",nocase; classtype:trojan-activity; sid:100002495; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.104.12",nocase; classtype:trojan-activity; sid:100002496; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.104.20",nocase; classtype:trojan-activity; sid:100002497; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.104.99",nocase; classtype:trojan-activity; sid:100002498; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.100",nocase; classtype:trojan-activity; sid:100002499; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.199",nocase; classtype:trojan-activity; sid:100002500; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.225",nocase; classtype:trojan-activity; sid:100002501; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.226",nocase; classtype:trojan-activity; sid:100002502; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.237",nocase; classtype:trojan-activity; sid:100002503; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.51",nocase; classtype:trojan-activity; sid:100002504; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.79",nocase; classtype:trojan-activity; sid:100002505; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.114.107",nocase; classtype:trojan-activity; sid:100002506; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.114.36",nocase; classtype:trojan-activity; sid:100002507; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.11",nocase; classtype:trojan-activity; sid:100002508; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.15",nocase; classtype:trojan-activity; sid:100002509; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.26",nocase; classtype:trojan-activity; sid:100002510; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.71",nocase; classtype:trojan-activity; sid:100002511; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.116.149",nocase; classtype:trojan-activity; sid:100002512; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.116.160",nocase; classtype:trojan-activity; sid:100002513; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.116.164",nocase; classtype:trojan-activity; sid:100002514; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.116.203",nocase; classtype:trojan-activity; sid:100002515; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.116.249",nocase; classtype:trojan-activity; sid:100002516; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.116.33",nocase; classtype:trojan-activity; sid:100002517; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.116.85",nocase; classtype:trojan-activity; sid:100002518; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.117.97",nocase; classtype:trojan-activity; sid:100002519; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.118.10",nocase; classtype:trojan-activity; sid:100002520; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.118.144",nocase; classtype:trojan-activity; sid:100002521; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.118.238",nocase; classtype:trojan-activity; sid:100002522; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.119.24",nocase; classtype:trojan-activity; sid:100002523; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.131",nocase; classtype:trojan-activity; sid:100002524; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.243",nocase; classtype:trojan-activity; sid:100002525; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.60",nocase; classtype:trojan-activity; sid:100002526; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.61",nocase; classtype:trojan-activity; sid:100002527; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.7",nocase; classtype:trojan-activity; sid:100002528; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.96",nocase; classtype:trojan-activity; sid:100002529; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.127.178",nocase; classtype:trojan-activity; sid:100002530; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.127.217",nocase; classtype:trojan-activity; sid:100002531; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.127.46",nocase; classtype:trojan-activity; sid:100002532; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.189.178.163",nocase; classtype:trojan-activity; sid:100002533; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.240.218.15",nocase; classtype:trojan-activity; sid:100002534; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.249.156.189",nocase; classtype:trojan-activity; sid:100002535; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.27.8.6",nocase; classtype:trojan-activity; sid:100002536; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.80.44.17",nocase; classtype:trojan-activity; sid:100002537; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.87.87.173",nocase; classtype:trojan-activity; sid:100002538; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.92.254.214",nocase; classtype:trojan-activity; sid:100002539; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.92.254.52",nocase; classtype:trojan-activity; sid:100002540; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.92.255.36",nocase; classtype:trojan-activity; sid:100002541; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.92.255.84",nocase; classtype:trojan-activity; sid:100002542; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.12.93.132",nocase; classtype:trojan-activity; sid:100002543; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.127.185.150",nocase; classtype:trojan-activity; sid:100002544; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.170.240.98",nocase; classtype:trojan-activity; sid:100002545; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.183.54.169",nocase; classtype:trojan-activity; sid:100002546; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.24.72.12",nocase; classtype:trojan-activity; sid:100002547; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.36.12.98",nocase; classtype:trojan-activity; sid:100002548; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"217.11.75.162",nocase; classtype:trojan-activity; sid:100002549; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"217.127.133.214",nocase; classtype:trojan-activity; sid:100002550; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.104.175.64",nocase; classtype:trojan-activity; sid:100002551; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.215.243.65",nocase; classtype:trojan-activity; sid:100002552; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.238.246.3",nocase; classtype:trojan-activity; sid:100002553; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.255.226.166",nocase; classtype:trojan-activity; sid:100002554; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.28.160.174",nocase; classtype:trojan-activity; sid:100002555; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.207.119",nocase; classtype:trojan-activity; sid:100002556; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.227.133",nocase; classtype:trojan-activity; sid:100002557; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.68.35",nocase; classtype:trojan-activity; sid:100002558; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.81.81",nocase; classtype:trojan-activity; sid:100002559; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.48.135.50",nocase; classtype:trojan-activity; sid:100002560; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.56.93.129",nocase; classtype:trojan-activity; sid:100002561; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.57.53.55",nocase; classtype:trojan-activity; sid:100002562; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.58.3.119",nocase; classtype:trojan-activity; sid:100002563; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.58.3.38",nocase; classtype:trojan-activity; sid:100002564; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.59.116.203",nocase; classtype:trojan-activity; sid:100002565; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.72.198.15",nocase; classtype:trojan-activity; sid:100002566; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.72.248.42",nocase; classtype:trojan-activity; sid:100002567; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.79.103.159",nocase; classtype:trojan-activity; sid:100002568; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.104.209",nocase; classtype:trojan-activity; sid:100002569; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.119.145",nocase; classtype:trojan-activity; sid:100002570; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.182.197",nocase; classtype:trojan-activity; sid:100002571; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.102.14",nocase; classtype:trojan-activity; sid:100002572; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.14.17",nocase; classtype:trojan-activity; sid:100002573; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.24.246",nocase; classtype:trojan-activity; sid:100002574; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.26.37",nocase; classtype:trojan-activity; sid:100002575; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.28.41",nocase; classtype:trojan-activity; sid:100002576; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.31.15",nocase; classtype:trojan-activity; sid:100002577; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.31.67",nocase; classtype:trojan-activity; sid:100002578; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.9.202",nocase; classtype:trojan-activity; sid:100002579; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.97.226",nocase; classtype:trojan-activity; sid:100002580; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.156.21.73",nocase; classtype:trojan-activity; sid:100002581; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.139.165",nocase; classtype:trojan-activity; sid:100002582; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.146.200",nocase; classtype:trojan-activity; sid:100002583; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.150.91",nocase; classtype:trojan-activity; sid:100002584; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.162.205",nocase; classtype:trojan-activity; sid:100002585; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.17.8",nocase; classtype:trojan-activity; sid:100002586; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.177.232",nocase; classtype:trojan-activity; sid:100002587; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.178.201",nocase; classtype:trojan-activity; sid:100002588; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.183.29",nocase; classtype:trojan-activity; sid:100002589; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.202.66",nocase; classtype:trojan-activity; sid:100002590; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.215.242",nocase; classtype:trojan-activity; sid:100002591; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.221.133",nocase; classtype:trojan-activity; sid:100002592; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.32.244",nocase; classtype:trojan-activity; sid:100002593; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.64.251",nocase; classtype:trojan-activity; sid:100002594; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.241.6.180",nocase; classtype:trojan-activity; sid:100002595; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.1.148",nocase; classtype:trojan-activity; sid:100002596; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.1.84",nocase; classtype:trojan-activity; sid:100002597; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.163.7",nocase; classtype:trojan-activity; sid:100002598; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.171.144",nocase; classtype:trojan-activity; sid:100002599; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.245.63",nocase; classtype:trojan-activity; sid:100002600; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.251.32",nocase; classtype:trojan-activity; sid:100002601; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.5.140",nocase; classtype:trojan-activity; sid:100002602; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.69.71.186",nocase; classtype:trojan-activity; sid:100002603; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.80.217.209",nocase; classtype:trojan-activity; sid:100002604; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.85.145.194",nocase; classtype:trojan-activity; sid:100002605; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"21robo.com",nocase; classtype:trojan-activity; sid:100002606; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.118.168.155",nocase; classtype:trojan-activity; sid:100002607; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.126.237.74",nocase; classtype:trojan-activity; sid:100002608; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.173.160.53",nocase; classtype:trojan-activity; sid:100002609; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.200.22.163",nocase; classtype:trojan-activity; sid:100002610; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.71.239.115",nocase; classtype:trojan-activity; sid:100002611; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.0.16.221",nocase; classtype:trojan-activity; sid:100002612; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.1.162.82",nocase; classtype:trojan-activity; sid:100002613; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.124.78.15",nocase; classtype:trojan-activity; sid:100002614; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.14.122.127",nocase; classtype:trojan-activity; sid:100002615; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.14.182.157",nocase; classtype:trojan-activity; sid:100002616; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.14.46.33",nocase; classtype:trojan-activity; sid:100002617; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.14.58.84",nocase; classtype:trojan-activity; sid:100002618; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.124.188",nocase; classtype:trojan-activity; sid:100002619; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.153.17",nocase; classtype:trojan-activity; sid:100002620; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.160.67",nocase; classtype:trojan-activity; sid:100002621; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.194.218",nocase; classtype:trojan-activity; sid:100002622; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.199.35",nocase; classtype:trojan-activity; sid:100002623; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.218.173",nocase; classtype:trojan-activity; sid:100002624; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.234.159",nocase; classtype:trojan-activity; sid:100002625; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.234.175",nocase; classtype:trojan-activity; sid:100002626; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.54.237",nocase; classtype:trojan-activity; sid:100002627; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.157.191.178",nocase; classtype:trojan-activity; sid:100002628; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.160.136.213",nocase; classtype:trojan-activity; sid:100002629; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.160.177.104",nocase; classtype:trojan-activity; sid:100002630; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.160.177.107",nocase; classtype:trojan-activity; sid:100002631; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.160.177.224",nocase; classtype:trojan-activity; sid:100002632; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.196.12.96",nocase; classtype:trojan-activity; sid:100002633; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.208.4.71",nocase; classtype:trojan-activity; sid:100002634; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.214.130.147",nocase; classtype:trojan-activity; sid:100002635; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.214.146.73",nocase; classtype:trojan-activity; sid:100002636; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.214.162.109",nocase; classtype:trojan-activity; sid:100002637; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.214.224.184",nocase; classtype:trojan-activity; sid:100002638; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.116.167",nocase; classtype:trojan-activity; sid:100002639; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.184.31",nocase; classtype:trojan-activity; sid:100002640; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.237.220",nocase; classtype:trojan-activity; sid:100002641; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.239.162",nocase; classtype:trojan-activity; sid:100002642; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.252.64",nocase; classtype:trojan-activity; sid:100002643; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.8.64",nocase; classtype:trojan-activity; sid:100002644; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.232.1.82",nocase; classtype:trojan-activity; sid:100002645; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.232.179.70",nocase; classtype:trojan-activity; sid:100002646; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.235.137.36",nocase; classtype:trojan-activity; sid:100002647; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.235.142.206",nocase; classtype:trojan-activity; sid:100002648; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.112.125",nocase; classtype:trojan-activity; sid:100002649; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.32.88",nocase; classtype:trojan-activity; sid:100002650; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.34.43",nocase; classtype:trojan-activity; sid:100002651; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.43.223",nocase; classtype:trojan-activity; sid:100002652; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.68.16",nocase; classtype:trojan-activity; sid:100002653; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.108.17.64",nocase; classtype:trojan-activity; sid:100002654; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.119.65.145",nocase; classtype:trojan-activity; sid:100002655; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.132.125.138",nocase; classtype:trojan-activity; sid:100002656; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.133.102.202",nocase; classtype:trojan-activity; sid:100002657; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.133.103.120",nocase; classtype:trojan-activity; sid:100002658; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.133.105.87",nocase; classtype:trojan-activity; sid:100002659; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.135.113.41",nocase; classtype:trojan-activity; sid:100002660; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.135.219.29",nocase; classtype:trojan-activity; sid:100002661; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.135.26.161",nocase; classtype:trojan-activity; sid:100002662; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.136.21.126",nocase; classtype:trojan-activity; sid:100002663; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.136.218.233",nocase; classtype:trojan-activity; sid:100002664; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.136.231.197",nocase; classtype:trojan-activity; sid:100002665; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.136.49.252",nocase; classtype:trojan-activity; sid:100002666; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.101.251",nocase; classtype:trojan-activity; sid:100002667; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.113.184",nocase; classtype:trojan-activity; sid:100002668; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.120.3",nocase; classtype:trojan-activity; sid:100002669; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.121.127",nocase; classtype:trojan-activity; sid:100002670; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.136.241",nocase; classtype:trojan-activity; sid:100002671; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.137.5",nocase; classtype:trojan-activity; sid:100002672; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.137.94",nocase; classtype:trojan-activity; sid:100002673; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.138.252",nocase; classtype:trojan-activity; sid:100002674; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.139.170",nocase; classtype:trojan-activity; sid:100002675; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.148.192",nocase; classtype:trojan-activity; sid:100002676; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.152.35",nocase; classtype:trojan-activity; sid:100002677; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.172.250",nocase; classtype:trojan-activity; sid:100002678; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.175.242",nocase; classtype:trojan-activity; sid:100002679; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.186.150",nocase; classtype:trojan-activity; sid:100002680; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.221.128",nocase; classtype:trojan-activity; sid:100002681; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.5.150",nocase; classtype:trojan-activity; sid:100002682; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.72.146",nocase; classtype:trojan-activity; sid:100002683; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.8.96",nocase; classtype:trojan-activity; sid:100002684; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.81.67",nocase; classtype:trojan-activity; sid:100002685; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.137.188",nocase; classtype:trojan-activity; sid:100002686; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.143.84",nocase; classtype:trojan-activity; sid:100002687; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.203.22",nocase; classtype:trojan-activity; sid:100002688; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.232.159",nocase; classtype:trojan-activity; sid:100002689; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.96.79",nocase; classtype:trojan-activity; sid:100002690; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.139.59.63",nocase; classtype:trojan-activity; sid:100002691; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.10.235",nocase; classtype:trojan-activity; sid:100002692; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.117.221",nocase; classtype:trojan-activity; sid:100002693; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.161.11",nocase; classtype:trojan-activity; sid:100002694; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.163.112",nocase; classtype:trojan-activity; sid:100002695; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.17.245",nocase; classtype:trojan-activity; sid:100002696; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.209.222",nocase; classtype:trojan-activity; sid:100002697; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.219.212",nocase; classtype:trojan-activity; sid:100002698; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.39.66",nocase; classtype:trojan-activity; sid:100002699; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.120.17",nocase; classtype:trojan-activity; sid:100002700; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.147.104",nocase; classtype:trojan-activity; sid:100002701; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.150.38",nocase; classtype:trojan-activity; sid:100002702; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.40.136",nocase; classtype:trojan-activity; sid:100002703; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.40.2",nocase; classtype:trojan-activity; sid:100002704; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.41.155",nocase; classtype:trojan-activity; sid:100002705; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.45.153",nocase; classtype:trojan-activity; sid:100002706; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.45.255",nocase; classtype:trojan-activity; sid:100002707; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.60.251",nocase; classtype:trojan-activity; sid:100002708; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.85.128",nocase; classtype:trojan-activity; sid:100002709; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.142.162.164",nocase; classtype:trojan-activity; sid:100002710; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.142.192.66",nocase; classtype:trojan-activity; sid:100002711; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.142.209.7",nocase; classtype:trojan-activity; sid:100002712; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.142.65.30",nocase; classtype:trojan-activity; sid:100002713; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.184.129.122",nocase; classtype:trojan-activity; sid:100002714; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.185.116.233",nocase; classtype:trojan-activity; sid:100002715; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.186.20.19",nocase; classtype:trojan-activity; sid:100002716; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.187.9.178",nocase; classtype:trojan-activity; sid:100002717; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.211.72.66",nocase; classtype:trojan-activity; sid:100002718; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.218.220.219",nocase; classtype:trojan-activity; sid:100002719; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.236.85.220",nocase; classtype:trojan-activity; sid:100002720; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.238.230.7",nocase; classtype:trojan-activity; sid:100002721; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.239.83.232",nocase; classtype:trojan-activity; sid:100002722; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.248.64.253",nocase; classtype:trojan-activity; sid:100002723; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.64.16.239",nocase; classtype:trojan-activity; sid:100002724; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.83.150.240",nocase; classtype:trojan-activity; sid:100002725; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.92.9.126",nocase; classtype:trojan-activity; sid:100002726; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.99.171.192",nocase; classtype:trojan-activity; sid:100002727; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.166.117.210",nocase; classtype:trojan-activity; sid:100002728; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.167.118.17",nocase; classtype:trojan-activity; sid:100002729; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.175.121.249",nocase; classtype:trojan-activity; sid:100002730; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.212.225.68",nocase; classtype:trojan-activity; sid:100002731; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.212.234.84",nocase; classtype:trojan-activity; sid:100002732; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.212.252.180",nocase; classtype:trojan-activity; sid:100002733; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.212.5.29",nocase; classtype:trojan-activity; sid:100002734; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.212.57.78",nocase; classtype:trojan-activity; sid:100002735; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.212.73.175",nocase; classtype:trojan-activity; sid:100002736; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.213.164.81",nocase; classtype:trojan-activity; sid:100002737; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.125.186.135",nocase; classtype:trojan-activity; sid:100002738; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.126.120.25",nocase; classtype:trojan-activity; sid:100002739; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.228.143.58",nocase; classtype:trojan-activity; sid:100002740; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.24.213.121",nocase; classtype:trojan-activity; sid:100002741; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.243.149.13",nocase; classtype:trojan-activity; sid:100002742; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.243.21.167",nocase; classtype:trojan-activity; sid:100002743; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.81.246.58",nocase; classtype:trojan-activity; sid:100002744; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.95.89.21",nocase; classtype:trojan-activity; sid:100002745; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.103.74.180",nocase; classtype:trojan-activity; sid:100002746; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.11.141.134",nocase; classtype:trojan-activity; sid:100002747; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.119.158.74",nocase; classtype:trojan-activity; sid:100002748; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.137.147.95",nocase; classtype:trojan-activity; sid:100002749; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.152.235.88",nocase; classtype:trojan-activity; sid:100002750; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.158.25.98",nocase; classtype:trojan-activity; sid:100002751; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.176.206.12",nocase; classtype:trojan-activity; sid:100002752; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.184.1.41",nocase; classtype:trojan-activity; sid:100002753; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.192.191.109",nocase; classtype:trojan-activity; sid:100002754; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.225.114.161",nocase; classtype:trojan-activity; sid:100002755; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.227.190.78",nocase; classtype:trojan-activity; sid:100002756; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.35.245.52",nocase; classtype:trojan-activity; sid:100002757; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.39.181.18",nocase; classtype:trojan-activity; sid:100002758; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.39.34.242",nocase; classtype:trojan-activity; sid:100002759; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.42.229.143",nocase; classtype:trojan-activity; sid:100002760; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.45.4.1",nocase; classtype:trojan-activity; sid:100002761; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.51.91.113",nocase; classtype:trojan-activity; sid:100002762; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.53.163.10",nocase; classtype:trojan-activity; sid:100002763; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.53.163.9",nocase; classtype:trojan-activity; sid:100002764; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.dbstrony.pl",nocase; classtype:trojan-activity; sid:100002765; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.1.245.16",nocase; classtype:trojan-activity; sid:100002766; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.1.245.7",nocase; classtype:trojan-activity; sid:100002767; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.105.106.201",nocase; classtype:trojan-activity; sid:100002768; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.105.152.107",nocase; classtype:trojan-activity; sid:100002769; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.116.84.57",nocase; classtype:trojan-activity; sid:100002770; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.12.245.238",nocase; classtype:trojan-activity; sid:100002771; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.13.83.77",nocase; classtype:trojan-activity; sid:100002772; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.14.211.219",nocase; classtype:trojan-activity; sid:100002773; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.141.218.17",nocase; classtype:trojan-activity; sid:100002774; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.147.29.52",nocase; classtype:trojan-activity; sid:100002775; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.147.40.128",nocase; classtype:trojan-activity; sid:100002776; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.153.132.82",nocase; classtype:trojan-activity; sid:100002777; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.153.207.1",nocase; classtype:trojan-activity; sid:100002778; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.184.244.14",nocase; classtype:trojan-activity; sid:100002779; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.184.54.199",nocase; classtype:trojan-activity; sid:100002780; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.187.248.22",nocase; classtype:trojan-activity; sid:100002781; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.193.196.190",nocase; classtype:trojan-activity; sid:100002782; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.193.217.210",nocase; classtype:trojan-activity; sid:100002783; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.194.149.142",nocase; classtype:trojan-activity; sid:100002784; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.194.158.229",nocase; classtype:trojan-activity; sid:100002785; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.194.166.45",nocase; classtype:trojan-activity; sid:100002786; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.194.192.66",nocase; classtype:trojan-activity; sid:100002787; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.194.210.20",nocase; classtype:trojan-activity; sid:100002788; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.194.224.96",nocase; classtype:trojan-activity; sid:100002789; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.197.17.88",nocase; classtype:trojan-activity; sid:100002790; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.197.22.217",nocase; classtype:trojan-activity; sid:100002791; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.197.23.215",nocase; classtype:trojan-activity; sid:100002792; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.197.24.175",nocase; classtype:trojan-activity; sid:100002793; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.199.232.65",nocase; classtype:trojan-activity; sid:100002794; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.199.3.194",nocase; classtype:trojan-activity; sid:100002795; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.199.34.48",nocase; classtype:trojan-activity; sid:100002796; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.200.140.229",nocase; classtype:trojan-activity; sid:100002797; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.200.23.62",nocase; classtype:trojan-activity; sid:100002798; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.200.32.146",nocase; classtype:trojan-activity; sid:100002799; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.202.182.201",nocase; classtype:trojan-activity; sid:100002800; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.202.21.57",nocase; classtype:trojan-activity; sid:100002801; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.202.66.46",nocase; classtype:trojan-activity; sid:100002802; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.102.12",nocase; classtype:trojan-activity; sid:100002803; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.126.194",nocase; classtype:trojan-activity; sid:100002804; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.154.105",nocase; classtype:trojan-activity; sid:100002805; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.165.138",nocase; classtype:trojan-activity; sid:100002806; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.185.42",nocase; classtype:trojan-activity; sid:100002807; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.185.48",nocase; classtype:trojan-activity; sid:100002808; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.213.79",nocase; classtype:trojan-activity; sid:100002809; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.234.76",nocase; classtype:trojan-activity; sid:100002810; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.246.96",nocase; classtype:trojan-activity; sid:100002811; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.255.42",nocase; classtype:trojan-activity; sid:100002812; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.28.115",nocase; classtype:trojan-activity; sid:100002813; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.4.188",nocase; classtype:trojan-activity; sid:100002814; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.54.217",nocase; classtype:trojan-activity; sid:100002815; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.87.75",nocase; classtype:trojan-activity; sid:100002816; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.94.134",nocase; classtype:trojan-activity; sid:100002817; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.204.253.74",nocase; classtype:trojan-activity; sid:100002818; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.205.178.110",nocase; classtype:trojan-activity; sid:100002819; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.136.101",nocase; classtype:trojan-activity; sid:100002820; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.14.137",nocase; classtype:trojan-activity; sid:100002821; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.148.106",nocase; classtype:trojan-activity; sid:100002822; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.154.122",nocase; classtype:trojan-activity; sid:100002823; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.185.118",nocase; classtype:trojan-activity; sid:100002824; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.26.218",nocase; classtype:trojan-activity; sid:100002825; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.81.66",nocase; classtype:trojan-activity; sid:100002826; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.83.48",nocase; classtype:trojan-activity; sid:100002827; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.97.81",nocase; classtype:trojan-activity; sid:100002828; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.207.155.31",nocase; classtype:trojan-activity; sid:100002829; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.207.194.254",nocase; classtype:trojan-activity; sid:100002830; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.207.199.162",nocase; classtype:trojan-activity; sid:100002831; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.152.10",nocase; classtype:trojan-activity; sid:100002832; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.160.177",nocase; classtype:trojan-activity; sid:100002833; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.164.18",nocase; classtype:trojan-activity; sid:100002834; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.166.13",nocase; classtype:trojan-activity; sid:100002835; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.201.212",nocase; classtype:trojan-activity; sid:100002836; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.247.130",nocase; classtype:trojan-activity; sid:100002837; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.34.2",nocase; classtype:trojan-activity; sid:100002838; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.92.64",nocase; classtype:trojan-activity; sid:100002839; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.209.160.222",nocase; classtype:trojan-activity; sid:100002840; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.209.231.15",nocase; classtype:trojan-activity; sid:100002841; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.209.60.21",nocase; classtype:trojan-activity; sid:100002842; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.21.159.174",nocase; classtype:trojan-activity; sid:100002843; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.107.125",nocase; classtype:trojan-activity; sid:100002844; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.127.11",nocase; classtype:trojan-activity; sid:100002845; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.172.245",nocase; classtype:trojan-activity; sid:100002846; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.234.28",nocase; classtype:trojan-activity; sid:100002847; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.236.134",nocase; classtype:trojan-activity; sid:100002848; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.63.243",nocase; classtype:trojan-activity; sid:100002849; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.211.251.162",nocase; classtype:trojan-activity; sid:100002850; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.104.201",nocase; classtype:trojan-activity; sid:100002851; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.109.105",nocase; classtype:trojan-activity; sid:100002852; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.109.58",nocase; classtype:trojan-activity; sid:100002853; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.175.208",nocase; classtype:trojan-activity; sid:100002854; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.220.5",nocase; classtype:trojan-activity; sid:100002855; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.255.202",nocase; classtype:trojan-activity; sid:100002856; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.255.6",nocase; classtype:trojan-activity; sid:100002857; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.84.74",nocase; classtype:trojan-activity; sid:100002858; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.214.37.129",nocase; classtype:trojan-activity; sid:100002859; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.139.242",nocase; classtype:trojan-activity; sid:100002860; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.190.172",nocase; classtype:trojan-activity; sid:100002861; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.212.209",nocase; classtype:trojan-activity; sid:100002862; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.253.149",nocase; classtype:trojan-activity; sid:100002863; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.34.242",nocase; classtype:trojan-activity; sid:100002864; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.38.166",nocase; classtype:trojan-activity; sid:100002865; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.71.243",nocase; classtype:trojan-activity; sid:100002866; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.98.242",nocase; classtype:trojan-activity; sid:100002867; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.144.66",nocase; classtype:trojan-activity; sid:100002868; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.193.217",nocase; classtype:trojan-activity; sid:100002869; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.197.193",nocase; classtype:trojan-activity; sid:100002870; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.225.28",nocase; classtype:trojan-activity; sid:100002871; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.234.98",nocase; classtype:trojan-activity; sid:100002872; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.46.85",nocase; classtype:trojan-activity; sid:100002873; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.58.120",nocase; classtype:trojan-activity; sid:100002874; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.95.56",nocase; classtype:trojan-activity; sid:100002875; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.217.120.226",nocase; classtype:trojan-activity; sid:100002876; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.217.133.53",nocase; classtype:trojan-activity; sid:100002877; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.217.155.141",nocase; classtype:trojan-activity; sid:100002878; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.217.191.58",nocase; classtype:trojan-activity; sid:100002879; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.217.31.245",nocase; classtype:trojan-activity; sid:100002880; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.217.76.48",nocase; classtype:trojan-activity; sid:100002881; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.218.180.172",nocase; classtype:trojan-activity; sid:100002882; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.218.219.228",nocase; classtype:trojan-activity; sid:100002883; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.218.248.121",nocase; classtype:trojan-activity; sid:100002884; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.132.71",nocase; classtype:trojan-activity; sid:100002885; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.151.83",nocase; classtype:trojan-activity; sid:100002886; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.160.112",nocase; classtype:trojan-activity; sid:100002887; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.172.175",nocase; classtype:trojan-activity; sid:100002888; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.173.180",nocase; classtype:trojan-activity; sid:100002889; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.176.72",nocase; classtype:trojan-activity; sid:100002890; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.184.94",nocase; classtype:trojan-activity; sid:100002891; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.192.223",nocase; classtype:trojan-activity; sid:100002892; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.83.244",nocase; classtype:trojan-activity; sid:100002893; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.220.243.172",nocase; classtype:trojan-activity; sid:100002894; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.220.40.189",nocase; classtype:trojan-activity; sid:100002895; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.220.85.168",nocase; classtype:trojan-activity; sid:100002896; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.221.239.223",nocase; classtype:trojan-activity; sid:100002897; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.222.241.223",nocase; classtype:trojan-activity; sid:100002898; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.222.249.105",nocase; classtype:trojan-activity; sid:100002899; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.222.249.210",nocase; classtype:trojan-activity; sid:100002900; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.222.42.189",nocase; classtype:trojan-activity; sid:100002901; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.222.50.170",nocase; classtype:trojan-activity; sid:100002902; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.223.242.164",nocase; classtype:trojan-activity; sid:100002903; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.223.44.106",nocase; classtype:trojan-activity; sid:100002904; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.24.28.134",nocase; classtype:trojan-activity; sid:100002905; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.127.129",nocase; classtype:trojan-activity; sid:100002906; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.129.198",nocase; classtype:trojan-activity; sid:100002907; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.154.13",nocase; classtype:trojan-activity; sid:100002908; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.2.30",nocase; classtype:trojan-activity; sid:100002909; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.212.124",nocase; classtype:trojan-activity; sid:100002910; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.58.5",nocase; classtype:trojan-activity; sid:100002911; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.36.143.238",nocase; classtype:trojan-activity; sid:100002912; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.41.159.216",nocase; classtype:trojan-activity; sid:100002913; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.41.36.15",nocase; classtype:trojan-activity; sid:100002914; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.41.38.79",nocase; classtype:trojan-activity; sid:100002915; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.46.45.90",nocase; classtype:trojan-activity; sid:100002916; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.5.38.169",nocase; classtype:trojan-activity; sid:100002917; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.5.41.251",nocase; classtype:trojan-activity; sid:100002918; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.5.42.169",nocase; classtype:trojan-activity; sid:100002919; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.6.196.172",nocase; classtype:trojan-activity; sid:100002920; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.0.98.131",nocase; classtype:trojan-activity; sid:100002921; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.11.51.57",nocase; classtype:trojan-activity; sid:100002922; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.13.23.180",nocase; classtype:trojan-activity; sid:100002923; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.154.234.3",nocase; classtype:trojan-activity; sid:100002924; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.124.130",nocase; classtype:trojan-activity; sid:100002925; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.179.83",nocase; classtype:trojan-activity; sid:100002926; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.184.59",nocase; classtype:trojan-activity; sid:100002927; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.191.243",nocase; classtype:trojan-activity; sid:100002928; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.194.67",nocase; classtype:trojan-activity; sid:100002929; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.216.132",nocase; classtype:trojan-activity; sid:100002930; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.219.28",nocase; classtype:trojan-activity; sid:100002931; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.24.115",nocase; classtype:trojan-activity; sid:100002932; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.30.65",nocase; classtype:trojan-activity; sid:100002933; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.60.234",nocase; classtype:trojan-activity; sid:100002934; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.63.203",nocase; classtype:trojan-activity; sid:100002935; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.65.233",nocase; classtype:trojan-activity; sid:100002936; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.94.16",nocase; classtype:trojan-activity; sid:100002937; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.179.201.26",nocase; classtype:trojan-activity; sid:100002938; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.195.84.250",nocase; classtype:trojan-activity; sid:100002939; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.204.174.180",nocase; classtype:trojan-activity; sid:100002940; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.210.20.138",nocase; classtype:trojan-activity; sid:100002941; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.210.20.177",nocase; classtype:trojan-activity; sid:100002942; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.28.7.159",nocase; classtype:trojan-activity; sid:100002943; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.30.119.23",nocase; classtype:trojan-activity; sid:100002944; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"32.208.157.193",nocase; classtype:trojan-activity; sid:100002945; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"32792.prolocksmithwinterpark.com",nocase; classtype:trojan-activity; sid:100002946; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"35.184.169.169",nocase; classtype:trojan-activity; sid:100002947; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.108.231.218",nocase; classtype:trojan-activity; sid:100002948; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.109.132.50",nocase; classtype:trojan-activity; sid:100002949; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.250.203.246",nocase; classtype:trojan-activity; sid:100002950; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.157.225",nocase; classtype:trojan-activity; sid:100002951; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.18.18",nocase; classtype:trojan-activity; sid:100002952; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.19.88",nocase; classtype:trojan-activity; sid:100002953; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.51.244",nocase; classtype:trojan-activity; sid:100002954; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.255.90.219",nocase; classtype:trojan-activity; sid:100002955; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.32.203.118",nocase; classtype:trojan-activity; sid:100002956; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.32.25.158",nocase; classtype:trojan-activity; sid:100002957; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.33.128.60",nocase; classtype:trojan-activity; sid:100002958; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.33.160.167",nocase; classtype:trojan-activity; sid:100002959; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.36.243.67",nocase; classtype:trojan-activity; sid:100002960; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.66.105.159",nocase; classtype:trojan-activity; sid:100002961; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.66.111.203",nocase; classtype:trojan-activity; sid:100002962; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.66.133.125",nocase; classtype:trojan-activity; sid:100002963; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.66.139.36",nocase; classtype:trojan-activity; sid:100002964; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.67.152.161",nocase; classtype:trojan-activity; sid:100002965; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.89.18.133",nocase; classtype:trojan-activity; sid:100002966; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.91.89.187",nocase; classtype:trojan-activity; sid:100002967; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.96.187.93",nocase; classtype:trojan-activity; sid:100002968; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"360.lcy2zzx.pw",nocase; classtype:trojan-activity; sid:100002969; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"360down7.miiyun.cn",nocase; classtype:trojan-activity; sid:100002970; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.222.98.51",nocase; classtype:trojan-activity; sid:100002971; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.233.60.68",nocase; classtype:trojan-activity; sid:100002972; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.34.179.221",nocase; classtype:trojan-activity; sid:100002973; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.34.180.172",nocase; classtype:trojan-activity; sid:100002974; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.44.238.35",nocase; classtype:trojan-activity; sid:100002975; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.49.229.154",nocase; classtype:trojan-activity; sid:100002976; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.49.230.152",nocase; classtype:trojan-activity; sid:100002977; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.52.117.132",nocase; classtype:trojan-activity; sid:100002978; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.54.14.36",nocase; classtype:trojan-activity; sid:100002979; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"38.77.14.237",nocase; classtype:trojan-activity; sid:100002980; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"38.81.149.108",nocase; classtype:trojan-activity; sid:100002981; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.113.245.254",nocase; classtype:trojan-activity; sid:100002982; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.113.98.136",nocase; classtype:trojan-activity; sid:100002983; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.114.137.102",nocase; classtype:trojan-activity; sid:100002984; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.117.31.162",nocase; classtype:trojan-activity; sid:100002985; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.162.104.119",nocase; classtype:trojan-activity; sid:100002986; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.64.28.214",nocase; classtype:trojan-activity; sid:100002987; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.65.171.29",nocase; classtype:trojan-activity; sid:100002988; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.65.196.34",nocase; classtype:trojan-activity; sid:100002989; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.65.59.160",nocase; classtype:trojan-activity; sid:100002990; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.66.129.163",nocase; classtype:trojan-activity; sid:100002991; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.66.85.187",nocase; classtype:trojan-activity; sid:100002992; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.104.83",nocase; classtype:trojan-activity; sid:100002993; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.125.186",nocase; classtype:trojan-activity; sid:100002994; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.146.60",nocase; classtype:trojan-activity; sid:100002995; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.148.163",nocase; classtype:trojan-activity; sid:100002996; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.92.131",nocase; classtype:trojan-activity; sid:100002997; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.68.124.76",nocase; classtype:trojan-activity; sid:100002998; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.68.249.255",nocase; classtype:trojan-activity; sid:100002999; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.72.130.114",nocase; classtype:trojan-activity; sid:100003000; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.72.167.202",nocase; classtype:trojan-activity; sid:100003001; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.72.67.64",nocase; classtype:trojan-activity; sid:100003002; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.10.198",nocase; classtype:trojan-activity; sid:100003003; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.163.231",nocase; classtype:trojan-activity; sid:100003004; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.183.14",nocase; classtype:trojan-activity; sid:100003005; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.203.225",nocase; classtype:trojan-activity; sid:100003006; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.74.104.228",nocase; classtype:trojan-activity; sid:100003007; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.74.21.201",nocase; classtype:trojan-activity; sid:100003008; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.74.28.89",nocase; classtype:trojan-activity; sid:100003009; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.74.31.192",nocase; classtype:trojan-activity; sid:100003010; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.74.68.182",nocase; classtype:trojan-activity; sid:100003011; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.76.194.65",nocase; classtype:trojan-activity; sid:100003012; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.76.79.43",nocase; classtype:trojan-activity; sid:100003013; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.76.97.16",nocase; classtype:trojan-activity; sid:100003014; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.113.201",nocase; classtype:trojan-activity; sid:100003015; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.114.45",nocase; classtype:trojan-activity; sid:100003016; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.136.47",nocase; classtype:trojan-activity; sid:100003017; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.14.27",nocase; classtype:trojan-activity; sid:100003018; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.150.203",nocase; classtype:trojan-activity; sid:100003019; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.197.81",nocase; classtype:trojan-activity; sid:100003020; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.209.209",nocase; classtype:trojan-activity; sid:100003021; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.94.189",nocase; classtype:trojan-activity; sid:100003022; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.95.50",nocase; classtype:trojan-activity; sid:100003023; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.107.66",nocase; classtype:trojan-activity; sid:100003024; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.166.31",nocase; classtype:trojan-activity; sid:100003025; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.218.46",nocase; classtype:trojan-activity; sid:100003026; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.62.43",nocase; classtype:trojan-activity; sid:100003027; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.90.92",nocase; classtype:trojan-activity; sid:100003028; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.91.244",nocase; classtype:trojan-activity; sid:100003029; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.93.171",nocase; classtype:trojan-activity; sid:100003030; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.127.214",nocase; classtype:trojan-activity; sid:100003031; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.188.238",nocase; classtype:trojan-activity; sid:100003032; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.191.137",nocase; classtype:trojan-activity; sid:100003033; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.205.255",nocase; classtype:trojan-activity; sid:100003034; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.24.54",nocase; classtype:trojan-activity; sid:100003035; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.34.26",nocase; classtype:trojan-activity; sid:100003036; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.36.151",nocase; classtype:trojan-activity; sid:100003037; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.124.33",nocase; classtype:trojan-activity; sid:100003038; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.130.19",nocase; classtype:trojan-activity; sid:100003039; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.251.0",nocase; classtype:trojan-activity; sid:100003040; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.27.15",nocase; classtype:trojan-activity; sid:100003041; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.29.231",nocase; classtype:trojan-activity; sid:100003042; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.82.86.105",nocase; classtype:trojan-activity; sid:100003043; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.83.94.11",nocase; classtype:trojan-activity; sid:100003044; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.84.157.52",nocase; classtype:trojan-activity; sid:100003045; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.84.34.217",nocase; classtype:trojan-activity; sid:100003046; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.84.95.200",nocase; classtype:trojan-activity; sid:100003047; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.85.54.191",nocase; classtype:trojan-activity; sid:100003048; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.129.233",nocase; classtype:trojan-activity; sid:100003049; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.13.0",nocase; classtype:trojan-activity; sid:100003050; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.170.209",nocase; classtype:trojan-activity; sid:100003051; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.184.164",nocase; classtype:trojan-activity; sid:100003052; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.211.20",nocase; classtype:trojan-activity; sid:100003053; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.234.187",nocase; classtype:trojan-activity; sid:100003054; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.248.91",nocase; classtype:trojan-activity; sid:100003055; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.60.98",nocase; classtype:trojan-activity; sid:100003056; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.66.24",nocase; classtype:trojan-activity; sid:100003057; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.76.9",nocase; classtype:trojan-activity; sid:100003058; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.78.228",nocase; classtype:trojan-activity; sid:100003059; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.87.63.58",nocase; classtype:trojan-activity; sid:100003060; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.87.93.109",nocase; classtype:trojan-activity; sid:100003061; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.141.172",nocase; classtype:trojan-activity; sid:100003062; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.155.96",nocase; classtype:trojan-activity; sid:100003063; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.233.131",nocase; classtype:trojan-activity; sid:100003064; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.39.222",nocase; classtype:trojan-activity; sid:100003065; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.41.73",nocase; classtype:trojan-activity; sid:100003066; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.67.238",nocase; classtype:trojan-activity; sid:100003067; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.72.9",nocase; classtype:trojan-activity; sid:100003068; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.146.198",nocase; classtype:trojan-activity; sid:100003069; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.146.36",nocase; classtype:trojan-activity; sid:100003070; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.157.140",nocase; classtype:trojan-activity; sid:100003071; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.63.23",nocase; classtype:trojan-activity; sid:100003072; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.90.86.212",nocase; classtype:trojan-activity; sid:100003073; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.139.209.46",nocase; classtype:trojan-activity; sid:100003074; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.165.130.43",nocase; classtype:trojan-activity; sid:100003075; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.190.63.174",nocase; classtype:trojan-activity; sid:100003076; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.193.192.100",nocase; classtype:trojan-activity; sid:100003077; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.219.185.171",nocase; classtype:trojan-activity; sid:100003078; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.230.31.58",nocase; classtype:trojan-activity; sid:100003079; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.72.203.82",nocase; classtype:trojan-activity; sid:100003080; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.76.157.2",nocase; classtype:trojan-activity; sid:100003081; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.18.147",nocase; classtype:trojan-activity; sid:100003082; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.18.148",nocase; classtype:trojan-activity; sid:100003083; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.18.200",nocase; classtype:trojan-activity; sid:100003084; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.18.71",nocase; classtype:trojan-activity; sid:100003085; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.21.35",nocase; classtype:trojan-activity; sid:100003086; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.21.40",nocase; classtype:trojan-activity; sid:100003087; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.5.103",nocase; classtype:trojan-activity; sid:100003088; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.5.104",nocase; classtype:trojan-activity; sid:100003089; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.5.198",nocase; classtype:trojan-activity; sid:100003090; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.5.237",nocase; classtype:trojan-activity; sid:100003091; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.176.112.72",nocase; classtype:trojan-activity; sid:100003092; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.202.101.147",nocase; classtype:trojan-activity; sid:100003093; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.128.210",nocase; classtype:trojan-activity; sid:100003094; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.168.142",nocase; classtype:trojan-activity; sid:100003095; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.168.97",nocase; classtype:trojan-activity; sid:100003096; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.170.140",nocase; classtype:trojan-activity; sid:100003097; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.179.49",nocase; classtype:trojan-activity; sid:100003098; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.181.121",nocase; classtype:trojan-activity; sid:100003099; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.183.11",nocase; classtype:trojan-activity; sid:100003100; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.209.156",nocase; classtype:trojan-activity; sid:100003101; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.212.124",nocase; classtype:trojan-activity; sid:100003102; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.218.16",nocase; classtype:trojan-activity; sid:100003103; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.233.247",nocase; classtype:trojan-activity; sid:100003104; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.235.4",nocase; classtype:trojan-activity; sid:100003105; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.37.186",nocase; classtype:trojan-activity; sid:100003106; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.37.44",nocase; classtype:trojan-activity; sid:100003107; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.43.25",nocase; classtype:trojan-activity; sid:100003108; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.64.34",nocase; classtype:trojan-activity; sid:100003109; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.66.246",nocase; classtype:trojan-activity; sid:100003110; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.70.213",nocase; classtype:trojan-activity; sid:100003111; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.76.168",nocase; classtype:trojan-activity; sid:100003112; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.76.198",nocase; classtype:trojan-activity; sid:100003113; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.8.136",nocase; classtype:trojan-activity; sid:100003114; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.91.8",nocase; classtype:trojan-activity; sid:100003115; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.225.24.101",nocase; classtype:trojan-activity; sid:100003116; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.225.240.244",nocase; classtype:trojan-activity; sid:100003117; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.225.250.39",nocase; classtype:trojan-activity; sid:100003118; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.226.76.62",nocase; classtype:trojan-activity; sid:100003119; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.227.179.209",nocase; classtype:trojan-activity; sid:100003120; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.227.204.4",nocase; classtype:trojan-activity; sid:100003121; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.227.66.88",nocase; classtype:trojan-activity; sid:100003122; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.198.102",nocase; classtype:trojan-activity; sid:100003123; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.60.114",nocase; classtype:trojan-activity; sid:100003124; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.65.201",nocase; classtype:trojan-activity; sid:100003125; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.70.126",nocase; classtype:trojan-activity; sid:100003126; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.70.231",nocase; classtype:trojan-activity; sid:100003127; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.76.135",nocase; classtype:trojan-activity; sid:100003128; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.230.100.114",nocase; classtype:trojan-activity; sid:100003129; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.230.228.78",nocase; classtype:trojan-activity; sid:100003130; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.230.57.145",nocase; classtype:trojan-activity; sid:100003131; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.230.66.255",nocase; classtype:trojan-activity; sid:100003132; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.230.82.44",nocase; classtype:trojan-activity; sid:100003133; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.230.88.107",nocase; classtype:trojan-activity; sid:100003134; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.230.93.169",nocase; classtype:trojan-activity; sid:100003135; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.231.66.174",nocase; classtype:trojan-activity; sid:100003136; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.232.102.163",nocase; classtype:trojan-activity; sid:100003137; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.232.170.117",nocase; classtype:trojan-activity; sid:100003138; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.232.226.16",nocase; classtype:trojan-activity; sid:100003139; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.234.166.242",nocase; classtype:trojan-activity; sid:100003140; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.234.180.136",nocase; classtype:trojan-activity; sid:100003141; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.234.255.20",nocase; classtype:trojan-activity; sid:100003142; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.235.124.55",nocase; classtype:trojan-activity; sid:100003143; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.235.160.215",nocase; classtype:trojan-activity; sid:100003144; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.235.169.85",nocase; classtype:trojan-activity; sid:100003145; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.235.23.163",nocase; classtype:trojan-activity; sid:100003146; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.235.66.249",nocase; classtype:trojan-activity; sid:100003147; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.235.83.180",nocase; classtype:trojan-activity; sid:100003148; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.236.148.201",nocase; classtype:trojan-activity; sid:100003149; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.236.212.174",nocase; classtype:trojan-activity; sid:100003150; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.236.212.83",nocase; classtype:trojan-activity; sid:100003151; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.236.215.63",nocase; classtype:trojan-activity; sid:100003152; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.236.236.179",nocase; classtype:trojan-activity; sid:100003153; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.237.54.162",nocase; classtype:trojan-activity; sid:100003154; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.238.175.61",nocase; classtype:trojan-activity; sid:100003155; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.238.191.210",nocase; classtype:trojan-activity; sid:100003156; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.238.241.239",nocase; classtype:trojan-activity; sid:100003157; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.238.59.222",nocase; classtype:trojan-activity; sid:100003158; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.239.192.128",nocase; classtype:trojan-activity; sid:100003159; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.239.207.166",nocase; classtype:trojan-activity; sid:100003160; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.239.42.135",nocase; classtype:trojan-activity; sid:100003161; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.242.200.90",nocase; classtype:trojan-activity; sid:100003162; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.52.180.36",nocase; classtype:trojan-activity; sid:100003163; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.56.15.227",nocase; classtype:trojan-activity; sid:100003164; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.61.99.155",nocase; classtype:trojan-activity; sid:100003165; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.84.14.5",nocase; classtype:trojan-activity; sid:100003166; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"43.230.156.44",nocase; classtype:trojan-activity; sid:100003167; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"43.230.207.204",nocase; classtype:trojan-activity; sid:100003168; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"43.241.106.183",nocase; classtype:trojan-activity; sid:100003169; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"43.252.8.94",nocase; classtype:trojan-activity; sid:100003170; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.112.203.218",nocase; classtype:trojan-activity; sid:100003171; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.130.138.66",nocase; classtype:trojan-activity; sid:100003172; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.133.1.137",nocase; classtype:trojan-activity; sid:100003173; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.133.1.242",nocase; classtype:trojan-activity; sid:100003174; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.133.203.192",nocase; classtype:trojan-activity; sid:100003175; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.135.134.228",nocase; classtype:trojan-activity; sid:100003176; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.14.149.182",nocase; classtype:trojan-activity; sid:100003177; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.14.149.204",nocase; classtype:trojan-activity; sid:100003178; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.14.149.244",nocase; classtype:trojan-activity; sid:100003179; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.14.149.66",nocase; classtype:trojan-activity; sid:100003180; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.141.84.182",nocase; classtype:trojan-activity; sid:100003181; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.141.84.184",nocase; classtype:trojan-activity; sid:100003182; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.65",nocase; classtype:trojan-activity; sid:100003183; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.148.10.47",nocase; classtype:trojan-activity; sid:100003184; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.15.143.158",nocase; classtype:trojan-activity; sid:100003185; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.164.140.133",nocase; classtype:trojan-activity; sid:100003186; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.165.215.19",nocase; classtype:trojan-activity; sid:100003187; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.108.116",nocase; classtype:trojan-activity; sid:100003188; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.108.248",nocase; classtype:trojan-activity; sid:100003189; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.111.16",nocase; classtype:trojan-activity; sid:100003190; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.178.101.22",nocase; classtype:trojan-activity; sid:100003191; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.201.165.164",nocase; classtype:trojan-activity; sid:100003192; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.22.209.58",nocase; classtype:trojan-activity; sid:100003193; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.23.22.186",nocase; classtype:trojan-activity; sid:100003194; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.27.253.137",nocase; classtype:trojan-activity; sid:100003195; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.33.112.19",nocase; classtype:trojan-activity; sid:100003196; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.51.104.59",nocase; classtype:trojan-activity; sid:100003197; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.81.235.31",nocase; classtype:trojan-activity; sid:100003198; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.9.148.37",nocase; classtype:trojan-activity; sid:100003199; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.151.155.218",nocase; classtype:trojan-activity; sid:100003200; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.172.75.231",nocase; classtype:trojan-activity; sid:100003201; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.175.184.121",nocase; classtype:trojan-activity; sid:100003202; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.182.173.246",nocase; classtype:trojan-activity; sid:100003203; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.182.173.247",nocase; classtype:trojan-activity; sid:100003204; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.20.63.218",nocase; classtype:trojan-activity; sid:100003205; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.201.214.64",nocase; classtype:trojan-activity; sid:100003206; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.201.38.162",nocase; classtype:trojan-activity; sid:100003207; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.21.153.231",nocase; classtype:trojan-activity; sid:100003208; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.214.27.4",nocase; classtype:trojan-activity; sid:100003209; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.24.130.254",nocase; classtype:trojan-activity; sid:100003210; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.243.179.115",nocase; classtype:trojan-activity; sid:100003211; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.249.33.79",nocase; classtype:trojan-activity; sid:100003212; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.25.242.211",nocase; classtype:trojan-activity; sid:100003213; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.42.118.86",nocase; classtype:trojan-activity; sid:100003214; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.42.86.128",nocase; classtype:trojan-activity; sid:100003215; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.97.76.242",nocase; classtype:trojan-activity; sid:100003216; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.145.152.26",nocase; classtype:trojan-activity; sid:100003217; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.151.23.172",nocase; classtype:trojan-activity; sid:100003218; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.157.97.71",nocase; classtype:trojan-activity; sid:100003219; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.16.131.51",nocase; classtype:trojan-activity; sid:100003220; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.197.0.119",nocase; classtype:trojan-activity; sid:100003221; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.21.202.98",nocase; classtype:trojan-activity; sid:100003222; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.223.167.153",nocase; classtype:trojan-activity; sid:100003223; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.46.231.38",nocase; classtype:trojan-activity; sid:100003224; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.142.162.113",nocase; classtype:trojan-activity; sid:100003225; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.142.87.36",nocase; classtype:trojan-activity; sid:100003226; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.143.43.93",nocase; classtype:trojan-activity; sid:100003227; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.156.35.166",nocase; classtype:trojan-activity; sid:100003228; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.158.201.200",nocase; classtype:trojan-activity; sid:100003229; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.159.20.121",nocase; classtype:trojan-activity; sid:100003230; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.159.21.3",nocase; classtype:trojan-activity; sid:100003231; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.174.182.99",nocase; classtype:trojan-activity; sid:100003232; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.213.170.49",nocase; classtype:trojan-activity; sid:100003233; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.213.178.183",nocase; classtype:trojan-activity; sid:100003234; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.213.179.129",nocase; classtype:trojan-activity; sid:100003235; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.68.221.252",nocase; classtype:trojan-activity; sid:100003236; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.68.249.121",nocase; classtype:trojan-activity; sid:100003237; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.70.15.16",nocase; classtype:trojan-activity; sid:100003238; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.70.2.100",nocase; classtype:trojan-activity; sid:100003239; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.181.135.114",nocase; classtype:trojan-activity; sid:100003240; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.2.70.50",nocase; classtype:trojan-activity; sid:100003241; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.53.146.179",nocase; classtype:trojan-activity; sid:100003242; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.8.10.62",nocase; classtype:trojan-activity; sid:100003243; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.115.174.102",nocase; classtype:trojan-activity; sid:100003244; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.121.91.255",nocase; classtype:trojan-activity; sid:100003245; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.252.47.29",nocase; classtype:trojan-activity; sid:100003246; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"51.171.146.13",nocase; classtype:trojan-activity; sid:100003247; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"51.222.56.159",nocase; classtype:trojan-activity; sid:100003248; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"54.253.194.14",nocase; classtype:trojan-activity; sid:100003249; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"54.36.114.136",nocase; classtype:trojan-activity; sid:100003250; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"54.36.180.122",nocase; classtype:trojan-activity; sid:100003251; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"54.37.93.29",nocase; classtype:trojan-activity; sid:100003252; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.114.246.26",nocase; classtype:trojan-activity; sid:100003253; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.115.162.92",nocase; classtype:trojan-activity; sid:100003254; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.115.174.4",nocase; classtype:trojan-activity; sid:100003255; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.125.191.4",nocase; classtype:trojan-activity; sid:100003256; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.126.247.118",nocase; classtype:trojan-activity; sid:100003257; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.142.166.120",nocase; classtype:trojan-activity; sid:100003258; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.142.200.124",nocase; classtype:trojan-activity; sid:100003259; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.143.142.142",nocase; classtype:trojan-activity; sid:100003260; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.18.103.109",nocase; classtype:trojan-activity; sid:100003261; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.217.171.157",nocase; classtype:trojan-activity; sid:100003262; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.218.67.253",nocase; classtype:trojan-activity; sid:100003263; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.22.212.107",nocase; classtype:trojan-activity; sid:100003264; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.226.129.29",nocase; classtype:trojan-activity; sid:100003265; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.229.194.122",nocase; classtype:trojan-activity; sid:100003266; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.23.245.24",nocase; classtype:trojan-activity; sid:100003267; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.230.89.42",nocase; classtype:trojan-activity; sid:100003268; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.232.155.37",nocase; classtype:trojan-activity; sid:100003269; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.238.42.192",nocase; classtype:trojan-activity; sid:100003270; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.240.147.97",nocase; classtype:trojan-activity; sid:100003271; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.241.57.237",nocase; classtype:trojan-activity; sid:100003272; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.241.78.55",nocase; classtype:trojan-activity; sid:100003273; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.112.16",nocase; classtype:trojan-activity; sid:100003274; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.116.2",nocase; classtype:trojan-activity; sid:100003275; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.117.188",nocase; classtype:trojan-activity; sid:100003276; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.140.132",nocase; classtype:trojan-activity; sid:100003277; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.142.137",nocase; classtype:trojan-activity; sid:100003278; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.142.174",nocase; classtype:trojan-activity; sid:100003279; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.149.117",nocase; classtype:trojan-activity; sid:100003280; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.150.204",nocase; classtype:trojan-activity; sid:100003281; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.150.244",nocase; classtype:trojan-activity; sid:100003282; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.153.194",nocase; classtype:trojan-activity; sid:100003283; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.154.55",nocase; classtype:trojan-activity; sid:100003284; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.154.66",nocase; classtype:trojan-activity; sid:100003285; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.76.206",nocase; classtype:trojan-activity; sid:100003286; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.79.25",nocase; classtype:trojan-activity; sid:100003287; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.15.148",nocase; classtype:trojan-activity; sid:100003288; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.18.244",nocase; classtype:trojan-activity; sid:100003289; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.22.210",nocase; classtype:trojan-activity; sid:100003290; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.72.121",nocase; classtype:trojan-activity; sid:100003291; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.74.124",nocase; classtype:trojan-activity; sid:100003292; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.74.248",nocase; classtype:trojan-activity; sid:100003293; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.77.227",nocase; classtype:trojan-activity; sid:100003294; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.79.134",nocase; classtype:trojan-activity; sid:100003295; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.80.23",nocase; classtype:trojan-activity; sid:100003296; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.86.85",nocase; classtype:trojan-activity; sid:100003297; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.88.207",nocase; classtype:trojan-activity; sid:100003298; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.252.177.212",nocase; classtype:trojan-activity; sid:100003299; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.252.177.66",nocase; classtype:trojan-activity; sid:100003300; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.252.178.167",nocase; classtype:trojan-activity; sid:100003301; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.252.178.55",nocase; classtype:trojan-activity; sid:100003302; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.253.14.46",nocase; classtype:trojan-activity; sid:100003303; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.255.140.156",nocase; classtype:trojan-activity; sid:100003304; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.255.43.163",nocase; classtype:trojan-activity; sid:100003305; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.48.154.143",nocase; classtype:trojan-activity; sid:100003306; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.50.178.137",nocase; classtype:trojan-activity; sid:100003307; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.50.221.148",nocase; classtype:trojan-activity; sid:100003308; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.72.165.153",nocase; classtype:trojan-activity; sid:100003309; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.72.165.39",nocase; classtype:trojan-activity; sid:100003310; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.76.151.51",nocase; classtype:trojan-activity; sid:100003311; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.97.201.45",nocase; classtype:trojan-activity; sid:100003312; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.97.206.33",nocase; classtype:trojan-activity; sid:100003313; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.0.211.161",nocase; classtype:trojan-activity; sid:100003314; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.102.168.189",nocase; classtype:trojan-activity; sid:100003315; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.151.202.3",nocase; classtype:trojan-activity; sid:100003316; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.151.214.4",nocase; classtype:trojan-activity; sid:100003317; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.151.237.51",nocase; classtype:trojan-activity; sid:100003318; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.151.246.125",nocase; classtype:trojan-activity; sid:100003319; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.29.133.229",nocase; classtype:trojan-activity; sid:100003320; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.30.12.254",nocase; classtype:trojan-activity; sid:100003321; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.58.104.244",nocase; classtype:trojan-activity; sid:100003322; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.58.117.226",nocase; classtype:trojan-activity; sid:100003323; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.7.124.148",nocase; classtype:trojan-activity; sid:100003324; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.8.35.22",nocase; classtype:trojan-activity; sid:100003325; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.89.243.76",nocase; classtype:trojan-activity; sid:100003326; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.92.176.136",nocase; classtype:trojan-activity; sid:100003327; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.92.178.202",nocase; classtype:trojan-activity; sid:100003328; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.92.18.175",nocase; classtype:trojan-activity; sid:100003329; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.92.182.177",nocase; classtype:trojan-activity; sid:100003330; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.92.216.255",nocase; classtype:trojan-activity; sid:100003331; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.93.17.196",nocase; classtype:trojan-activity; sid:100003332; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.93.17.204",nocase; classtype:trojan-activity; sid:100003333; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.93.17.72",nocase; classtype:trojan-activity; sid:100003334; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.93.19.11",nocase; classtype:trojan-activity; sid:100003335; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.93.23.154",nocase; classtype:trojan-activity; sid:100003336; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.93.23.215",nocase; classtype:trojan-activity; sid:100003337; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.93.23.23",nocase; classtype:trojan-activity; sid:100003338; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.93.23.7",nocase; classtype:trojan-activity; sid:100003339; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.94.180.237",nocase; classtype:trojan-activity; sid:100003340; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.96.36.131",nocase; classtype:trojan-activity; sid:100003341; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.96.36.137",nocase; classtype:trojan-activity; sid:100003342; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.96.39.91",nocase; classtype:trojan-activity; sid:100003343; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.97.168.110",nocase; classtype:trojan-activity; sid:100003344; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.97.170.16",nocase; classtype:trojan-activity; sid:100003345; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.97.175.101",nocase; classtype:trojan-activity; sid:100003346; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.97.175.96",nocase; classtype:trojan-activity; sid:100003347; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.97.193.118",nocase; classtype:trojan-activity; sid:100003348; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.99.137.46",nocase; classtype:trojan-activity; sid:100003349; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.99.138.222",nocase; classtype:trojan-activity; sid:100003350; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.99.139.252",nocase; classtype:trojan-activity; sid:100003351; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.99.139.66",nocase; classtype:trojan-activity; sid:100003352; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.99.141.103",nocase; classtype:trojan-activity; sid:100003353; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.99.141.219",nocase; classtype:trojan-activity; sid:100003354; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.99.142.43",nocase; classtype:trojan-activity; sid:100003355; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.99.188.93",nocase; classtype:trojan-activity; sid:100003356; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.99.41.26",nocase; classtype:trojan-activity; sid:100003357; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.99.43.225",nocase; classtype:trojan-activity; sid:100003358; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.99.46.7",nocase; classtype:trojan-activity; sid:100003359; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.99.47.64",nocase; classtype:trojan-activity; sid:100003360; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.13.61.12",nocase; classtype:trojan-activity; sid:100003361; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.14.48.221",nocase; classtype:trojan-activity; sid:100003362; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.162.122.36",nocase; classtype:trojan-activity; sid:100003363; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.162.160.200",nocase; classtype:trojan-activity; sid:100003364; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.164.130.220",nocase; classtype:trojan-activity; sid:100003365; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.17.12.143",nocase; classtype:trojan-activity; sid:100003366; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.176.249.56",nocase; classtype:trojan-activity; sid:100003367; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.20.217.142",nocase; classtype:trojan-activity; sid:100003368; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.208.135.42",nocase; classtype:trojan-activity; sid:100003369; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.122.57",nocase; classtype:trojan-activity; sid:100003370; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.186.185",nocase; classtype:trojan-activity; sid:100003371; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.216.23",nocase; classtype:trojan-activity; sid:100003372; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.33.5",nocase; classtype:trojan-activity; sid:100003373; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.211.19.63",nocase; classtype:trojan-activity; sid:100003374; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.211.6.112",nocase; classtype:trojan-activity; sid:100003375; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.211.7.166",nocase; classtype:trojan-activity; sid:100003376; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.100.83",nocase; classtype:trojan-activity; sid:100003377; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.162.152",nocase; classtype:trojan-activity; sid:100003378; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.206.246",nocase; classtype:trojan-activity; sid:100003379; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.218.31",nocase; classtype:trojan-activity; sid:100003380; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.220.167",nocase; classtype:trojan-activity; sid:100003381; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.23.84",nocase; classtype:trojan-activity; sid:100003382; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.254.178",nocase; classtype:trojan-activity; sid:100003383; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.213.162.59",nocase; classtype:trojan-activity; sid:100003384; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.213.58.188",nocase; classtype:trojan-activity; sid:100003385; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.213.83.55",nocase; classtype:trojan-activity; sid:100003386; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.214.93.166",nocase; classtype:trojan-activity; sid:100003387; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.215.165.64",nocase; classtype:trojan-activity; sid:100003388; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.215.195.111",nocase; classtype:trojan-activity; sid:100003389; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.215.207.11",nocase; classtype:trojan-activity; sid:100003390; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.215.219.108",nocase; classtype:trojan-activity; sid:100003391; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.215.4.239",nocase; classtype:trojan-activity; sid:100003392; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.216.95.211",nocase; classtype:trojan-activity; sid:100003393; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.217.177.196",nocase; classtype:trojan-activity; sid:100003394; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.217.86.208",nocase; classtype:trojan-activity; sid:100003395; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.220.22.89",nocase; classtype:trojan-activity; sid:100003396; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.25.115.48",nocase; classtype:trojan-activity; sid:100003397; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.25.76.224",nocase; classtype:trojan-activity; sid:100003398; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.15.104",nocase; classtype:trojan-activity; sid:100003399; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.39.88",nocase; classtype:trojan-activity; sid:100003400; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.42.72",nocase; classtype:trojan-activity; sid:100003401; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.44.99",nocase; classtype:trojan-activity; sid:100003402; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.51.127",nocase; classtype:trojan-activity; sid:100003403; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.60.174",nocase; classtype:trojan-activity; sid:100003404; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.8.81",nocase; classtype:trojan-activity; sid:100003405; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.7.10.121",nocase; classtype:trojan-activity; sid:100003406; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.7.136.8",nocase; classtype:trojan-activity; sid:100003407; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.7.202.153",nocase; classtype:trojan-activity; sid:100003408; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.7.99.254",nocase; classtype:trojan-activity; sid:100003409; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.102.243.124",nocase; classtype:trojan-activity; sid:100003410; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.162.169.210",nocase; classtype:trojan-activity; sid:100003411; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.162.55.42",nocase; classtype:trojan-activity; sid:100003412; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.163.129.97",nocase; classtype:trojan-activity; sid:100003413; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.164.96.98",nocase; classtype:trojan-activity; sid:100003414; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.167.211.218",nocase; classtype:trojan-activity; sid:100003415; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.168.139.87",nocase; classtype:trojan-activity; sid:100003416; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.179.171.60",nocase; classtype:trojan-activity; sid:100003417; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.179.91.194",nocase; classtype:trojan-activity; sid:100003418; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.179.91.230",nocase; classtype:trojan-activity; sid:100003419; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.179.93.79",nocase; classtype:trojan-activity; sid:100003420; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.18.112.48",nocase; classtype:trojan-activity; sid:100003421; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.192.73.253",nocase; classtype:trojan-activity; sid:100003422; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.213.118.28",nocase; classtype:trojan-activity; sid:100003423; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.247.224.66",nocase; classtype:trojan-activity; sid:100003424; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.253.94.230",nocase; classtype:trojan-activity; sid:100003425; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.3.126.128",nocase; classtype:trojan-activity; sid:100003426; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.3.144.90",nocase; classtype:trojan-activity; sid:100003427; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.3.147.175",nocase; classtype:trojan-activity; sid:100003428; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.47.220.169",nocase; classtype:trojan-activity; sid:100003429; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.102.61",nocase; classtype:trojan-activity; sid:100003430; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.103.144",nocase; classtype:trojan-activity; sid:100003431; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.11.87",nocase; classtype:trojan-activity; sid:100003432; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.157.4",nocase; classtype:trojan-activity; sid:100003433; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.159.231",nocase; classtype:trojan-activity; sid:100003434; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.195.226",nocase; classtype:trojan-activity; sid:100003435; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.212.191",nocase; classtype:trojan-activity; sid:100003436; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.243.169",nocase; classtype:trojan-activity; sid:100003437; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.247.208",nocase; classtype:trojan-activity; sid:100003438; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.30.49",nocase; classtype:trojan-activity; sid:100003439; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.35.86",nocase; classtype:trojan-activity; sid:100003440; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.43.174",nocase; classtype:trojan-activity; sid:100003441; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.48.112",nocase; classtype:trojan-activity; sid:100003442; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.9.166",nocase; classtype:trojan-activity; sid:100003443; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.97.134",nocase; classtype:trojan-activity; sid:100003444; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.99.183",nocase; classtype:trojan-activity; sid:100003445; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.100.87",nocase; classtype:trojan-activity; sid:100003446; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.121.19",nocase; classtype:trojan-activity; sid:100003447; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.251.243",nocase; classtype:trojan-activity; sid:100003448; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.62.169",nocase; classtype:trojan-activity; sid:100003449; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.73.171",nocase; classtype:trojan-activity; sid:100003450; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.74.27",nocase; classtype:trojan-activity; sid:100003451; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.81.18",nocase; classtype:trojan-activity; sid:100003452; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.83.14",nocase; classtype:trojan-activity; sid:100003453; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.86.195",nocase; classtype:trojan-activity; sid:100003454; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.172.248",nocase; classtype:trojan-activity; sid:100003455; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.41.143",nocase; classtype:trojan-activity; sid:100003456; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.64.104",nocase; classtype:trojan-activity; sid:100003457; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.77.175",nocase; classtype:trojan-activity; sid:100003458; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.56.180.67",nocase; classtype:trojan-activity; sid:100003459; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.56.181.7",nocase; classtype:trojan-activity; sid:100003460; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.57.96.116",nocase; classtype:trojan-activity; sid:100003461; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.58.170.60",nocase; classtype:trojan-activity; sid:100003462; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.58.73.220",nocase; classtype:trojan-activity; sid:100003463; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.61.218.23",nocase; classtype:trojan-activity; sid:100003464; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.65.172.121",nocase; classtype:trojan-activity; sid:100003465; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.0.22",nocase; classtype:trojan-activity; sid:100003466; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.104.46",nocase; classtype:trojan-activity; sid:100003467; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.110.59",nocase; classtype:trojan-activity; sid:100003468; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.132.195",nocase; classtype:trojan-activity; sid:100003469; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.132.86",nocase; classtype:trojan-activity; sid:100003470; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.255.60",nocase; classtype:trojan-activity; sid:100003471; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.45.130",nocase; classtype:trojan-activity; sid:100003472; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.98.144.75",nocase; classtype:trojan-activity; sid:100003473; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.1.98.131",nocase; classtype:trojan-activity; sid:100003474; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.117.124.114",nocase; classtype:trojan-activity; sid:100003475; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.141.73.58",nocase; classtype:trojan-activity; sid:100003476; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.219.131.205",nocase; classtype:trojan-activity; sid:100003477; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.219.143.46",nocase; classtype:trojan-activity; sid:100003478; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.219.227.31",nocase; classtype:trojan-activity; sid:100003479; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.31.126.33",nocase; classtype:trojan-activity; sid:100003480; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.38.149.66",nocase; classtype:trojan-activity; sid:100003481; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.38.222.98",nocase; classtype:trojan-activity; sid:100003482; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.43.207.148",nocase; classtype:trojan-activity; sid:100003483; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.90.165.236",nocase; classtype:trojan-activity; sid:100003484; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"63.245.122.93",nocase; classtype:trojan-activity; sid:100003485; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"64.233.154.99",nocase; classtype:trojan-activity; sid:100003486; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.125.128.196",nocase; classtype:trojan-activity; sid:100003487; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.21.58.252",nocase; classtype:trojan-activity; sid:100003488; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.26.155.131",nocase; classtype:trojan-activity; sid:100003489; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.35.61.255",nocase; classtype:trojan-activity; sid:100003490; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.153.233.87",nocase; classtype:trojan-activity; sid:100003491; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.207.93.46",nocase; classtype:trojan-activity; sid:100003492; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.229.214.115",nocase; classtype:trojan-activity; sid:100003493; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.57.55.210",nocase; classtype:trojan-activity; sid:100003494; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.74.7.197",nocase; classtype:trojan-activity; sid:100003495; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.91.21.31",nocase; classtype:trojan-activity; sid:100003496; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.97.181.196",nocase; classtype:trojan-activity; sid:100003497; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.97.181.213",nocase; classtype:trojan-activity; sid:100003498; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.221.107.75",nocase; classtype:trojan-activity; sid:100003499; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.245.151.203",nocase; classtype:trojan-activity; sid:100003500; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.3.169.223",nocase; classtype:trojan-activity; sid:100003501; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.8.138.101",nocase; classtype:trojan-activity; sid:100003502; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.81.98.111",nocase; classtype:trojan-activity; sid:100003503; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.82.242.243",nocase; classtype:trojan-activity; sid:100003504; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.83.49.234",nocase; classtype:trojan-activity; sid:100003505; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.84.138.165",nocase; classtype:trojan-activity; sid:100003506; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.148.103.248",nocase; classtype:trojan-activity; sid:100003507; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.151.244.128",nocase; classtype:trojan-activity; sid:100003508; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.174.182.226",nocase; classtype:trojan-activity; sid:100003509; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.175.107.153",nocase; classtype:trojan-activity; sid:100003510; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.188.144.143",nocase; classtype:trojan-activity; sid:100003511; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.204.88.29",nocase; classtype:trojan-activity; sid:100003512; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.205.106.84",nocase; classtype:trojan-activity; sid:100003513; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.205.119.241",nocase; classtype:trojan-activity; sid:100003514; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.78.33.33",nocase; classtype:trojan-activity; sid:100003515; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.115.37.205",nocase; classtype:trojan-activity; sid:100003516; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.120.237.255",nocase; classtype:trojan-activity; sid:100003517; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.123.245.151",nocase; classtype:trojan-activity; sid:100003518; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.124.231.110",nocase; classtype:trojan-activity; sid:100003519; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.127.214.47",nocase; classtype:trojan-activity; sid:100003520; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.146.232.34",nocase; classtype:trojan-activity; sid:100003521; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.165.173.49",nocase; classtype:trojan-activity; sid:100003522; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.196.158.227",nocase; classtype:trojan-activity; sid:100003523; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.222.157.166",nocase; classtype:trojan-activity; sid:100003524; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.229.0.133",nocase; classtype:trojan-activity; sid:100003525; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.63.73.234",nocase; classtype:trojan-activity; sid:100003526; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.75.115.194",nocase; classtype:trojan-activity; sid:100003527; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.75.227.186",nocase; classtype:trojan-activity; sid:100003528; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.76.240.206",nocase; classtype:trojan-activity; sid:100003529; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.115.31.30",nocase; classtype:trojan-activity; sid:100003530; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.118.240.88",nocase; classtype:trojan-activity; sid:100003531; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.167.10.180",nocase; classtype:trojan-activity; sid:100003532; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.236.190.250",nocase; classtype:trojan-activity; sid:100003533; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.25.5.105",nocase; classtype:trojan-activity; sid:100003534; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.33.144.248",nocase; classtype:trojan-activity; sid:100003535; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.93.129.118",nocase; classtype:trojan-activity; sid:100003536; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.127.148.69",nocase; classtype:trojan-activity; sid:100003537; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.146.190.91",nocase; classtype:trojan-activity; sid:100003538; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.204.63.239",nocase; classtype:trojan-activity; sid:100003539; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.29.48.164",nocase; classtype:trojan-activity; sid:100003540; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.34.191.213",nocase; classtype:trojan-activity; sid:100003541; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.40.234.166",nocase; classtype:trojan-activity; sid:100003542; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.43.2.122",nocase; classtype:trojan-activity; sid:100003543; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.43.235.106",nocase; classtype:trojan-activity; sid:100003544; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.47.133.58",nocase; classtype:trojan-activity; sid:100003545; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.71.60.69",nocase; classtype:trojan-activity; sid:100003546; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.85.106.211",nocase; classtype:trojan-activity; sid:100003547; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.17.22.30",nocase; classtype:trojan-activity; sid:100003548; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.186.139.38",nocase; classtype:trojan-activity; sid:100003549; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.189.180.98",nocase; classtype:trojan-activity; sid:100003550; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.214.69.226",nocase; classtype:trojan-activity; sid:100003551; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.229.230.118",nocase; classtype:trojan-activity; sid:100003552; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.229.35.40",nocase; classtype:trojan-activity; sid:100003553; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.31.40.122",nocase; classtype:trojan-activity; sid:100003554; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"73.204.216.103",nocase; classtype:trojan-activity; sid:100003555; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.101.1.159",nocase; classtype:trojan-activity; sid:100003556; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.108.224.112",nocase; classtype:trojan-activity; sid:100003557; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.194.117.165",nocase; classtype:trojan-activity; sid:100003558; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.195.115.176",nocase; classtype:trojan-activity; sid:100003559; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.199.84.77",nocase; classtype:trojan-activity; sid:100003560; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.75.165.81",nocase; classtype:trojan-activity; sid:100003561; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"75.127.141.52",nocase; classtype:trojan-activity; sid:100003562; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"75.176.213.114",nocase; classtype:trojan-activity; sid:100003563; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"75.82.36.220",nocase; classtype:trojan-activity; sid:100003564; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"75.83.102.27",nocase; classtype:trojan-activity; sid:100003565; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"75.99.213.61",nocase; classtype:trojan-activity; sid:100003566; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.108.199.153",nocase; classtype:trojan-activity; sid:100003567; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.170.11.82",nocase; classtype:trojan-activity; sid:100003568; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.178.22.145",nocase; classtype:trojan-activity; sid:100003569; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.250.199.133",nocase; classtype:trojan-activity; sid:100003570; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.254.129.227",nocase; classtype:trojan-activity; sid:100003571; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.84.134.33",nocase; classtype:trojan-activity; sid:100003572; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.95.12.137",nocase; classtype:trojan-activity; sid:100003573; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.237.25.210",nocase; classtype:trojan-activity; sid:100003574; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.71.50.153",nocase; classtype:trojan-activity; sid:100003575; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.71.52.220",nocase; classtype:trojan-activity; sid:100003576; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.79.191.32",nocase; classtype:trojan-activity; sid:100003577; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.89.203.238",nocase; classtype:trojan-activity; sid:100003578; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.179.225.254",nocase; classtype:trojan-activity; sid:100003579; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.187.141.144",nocase; classtype:trojan-activity; sid:100003580; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.187.240.125",nocase; classtype:trojan-activity; sid:100003581; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.187.41.200",nocase; classtype:trojan-activity; sid:100003582; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.188.168.64",nocase; classtype:trojan-activity; sid:100003583; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.188.188.141",nocase; classtype:trojan-activity; sid:100003584; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.189.104.157",nocase; classtype:trojan-activity; sid:100003585; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.189.176.163",nocase; classtype:trojan-activity; sid:100003586; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.23.172.81",nocase; classtype:trojan-activity; sid:100003587; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.72.231.120",nocase; classtype:trojan-activity; sid:100003588; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.8.225.77",nocase; classtype:trojan-activity; sid:100003589; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.11.195.121",nocase; classtype:trojan-activity; sid:100003590; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.13.49.221",nocase; classtype:trojan-activity; sid:100003591; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.130.253.13",nocase; classtype:trojan-activity; sid:100003592; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.147.123.48",nocase; classtype:trojan-activity; sid:100003593; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.170.31.56",nocase; classtype:trojan-activity; sid:100003594; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.175.42.244",nocase; classtype:trojan-activity; sid:100003595; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.21.84.63",nocase; classtype:trojan-activity; sid:100003596; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.22.176.145",nocase; classtype:trojan-activity; sid:100003597; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.7.170.58",nocase; classtype:trojan-activity; sid:100003598; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.79.58.94",nocase; classtype:trojan-activity; sid:100003599; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.8.70.162",nocase; classtype:trojan-activity; sid:100003600; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.9.88.185",nocase; classtype:trojan-activity; sid:100003601; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.107.89.207",nocase; classtype:trojan-activity; sid:100003602; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.19.101.218",nocase; classtype:trojan-activity; sid:100003603; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.211.181.77",nocase; classtype:trojan-activity; sid:100003604; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.217.12.7",nocase; classtype:trojan-activity; sid:100003605; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.99.128.61",nocase; classtype:trojan-activity; sid:100003606; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.136.146.213",nocase; classtype:trojan-activity; sid:100003607; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.165.44.109",nocase; classtype:trojan-activity; sid:100003608; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.191.40.58",nocase; classtype:trojan-activity; sid:100003609; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.198.7.22",nocase; classtype:trojan-activity; sid:100003610; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.213.111.60",nocase; classtype:trojan-activity; sid:100003611; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.213.141.184",nocase; classtype:trojan-activity; sid:100003612; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.213.166.175",nocase; classtype:trojan-activity; sid:100003613; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.215.199.29",nocase; classtype:trojan-activity; sid:100003614; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.218.187.113",nocase; classtype:trojan-activity; sid:100003615; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.218.195.216",nocase; classtype:trojan-activity; sid:100003616; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.237.128.200",nocase; classtype:trojan-activity; sid:100003617; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.246.225.203",nocase; classtype:trojan-activity; sid:100003618; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.92.36.96",nocase; classtype:trojan-activity; sid:100003619; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.103.108.72",nocase; classtype:trojan-activity; sid:100003620; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.135.196.130",nocase; classtype:trojan-activity; sid:100003621; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.166.212.178",nocase; classtype:trojan-activity; sid:100003622; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.166.85.112",nocase; classtype:trojan-activity; sid:100003623; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.207.61.194",nocase; classtype:trojan-activity; sid:100003624; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.209.250.155",nocase; classtype:trojan-activity; sid:100003625; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.211.156.38",nocase; classtype:trojan-activity; sid:100003626; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.62.110.252",nocase; classtype:trojan-activity; sid:100003627; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.62.53.77",nocase; classtype:trojan-activity; sid:100003628; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.138.72",nocase; classtype:trojan-activity; sid:100003629; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.139.92",nocase; classtype:trojan-activity; sid:100003630; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.154.214",nocase; classtype:trojan-activity; sid:100003631; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.187.109",nocase; classtype:trojan-activity; sid:100003632; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.100.54",nocase; classtype:trojan-activity; sid:100003633; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.106.65",nocase; classtype:trojan-activity; sid:100003634; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.108.172",nocase; classtype:trojan-activity; sid:100003635; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.131.158",nocase; classtype:trojan-activity; sid:100003636; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.19.42",nocase; classtype:trojan-activity; sid:100003637; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.197.254",nocase; classtype:trojan-activity; sid:100003638; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.215.149",nocase; classtype:trojan-activity; sid:100003639; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.232.68",nocase; classtype:trojan-activity; sid:100003640; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.234.195",nocase; classtype:trojan-activity; sid:100003641; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.246.96",nocase; classtype:trojan-activity; sid:100003642; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.28.57",nocase; classtype:trojan-activity; sid:100003643; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.4.57",nocase; classtype:trojan-activity; sid:100003644; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.55.84",nocase; classtype:trojan-activity; sid:100003645; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.73.245",nocase; classtype:trojan-activity; sid:100003646; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.9.62",nocase; classtype:trojan-activity; sid:100003647; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.98.51",nocase; classtype:trojan-activity; sid:100003648; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.165.237.163",nocase; classtype:trojan-activity; sid:100003649; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.234.147.99",nocase; classtype:trojan-activity; sid:100003650; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.234.218.42",nocase; classtype:trojan-activity; sid:100003651; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.242.253.154",nocase; classtype:trojan-activity; sid:100003652; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.252.9.37",nocase; classtype:trojan-activity; sid:100003653; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.210.219.208",nocase; classtype:trojan-activity; sid:100003654; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.210.219.213",nocase; classtype:trojan-activity; sid:100003655; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.212.219.127",nocase; classtype:trojan-activity; sid:100003656; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.214.103.73",nocase; classtype:trojan-activity; sid:100003657; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.228.50.118",nocase; classtype:trojan-activity; sid:100003658; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.228.95.204",nocase; classtype:trojan-activity; sid:100003659; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.238.24.35",nocase; classtype:trojan-activity; sid:100003660; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.247.83.74",nocase; classtype:trojan-activity; sid:100003661; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.254.39.129",nocase; classtype:trojan-activity; sid:100003662; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.33.111.227",nocase; classtype:trojan-activity; sid:100003663; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.38.152.148",nocase; classtype:trojan-activity; sid:100003664; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.40.127.242",nocase; classtype:trojan-activity; sid:100003665; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.42.20.217",nocase; classtype:trojan-activity; sid:100003666; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com",nocase; classtype:trojan-activity; sid:100003667; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.11.216",nocase; classtype:trojan-activity; sid:100003668; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.123.251",nocase; classtype:trojan-activity; sid:100003669; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.135.187",nocase; classtype:trojan-activity; sid:100003670; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.208.25",nocase; classtype:trojan-activity; sid:100003671; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.224.141",nocase; classtype:trojan-activity; sid:100003672; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.241.2",nocase; classtype:trojan-activity; sid:100003673; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.214.149.236",nocase; classtype:trojan-activity; sid:100003674; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.64.181.50",nocase; classtype:trojan-activity; sid:100003675; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.74.215.180",nocase; classtype:trojan-activity; sid:100003676; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.97.130.227",nocase; classtype:trojan-activity; sid:100003677; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.97.195.129",nocase; classtype:trojan-activity; sid:100003678; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.98.40.5",nocase; classtype:trojan-activity; sid:100003679; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"86.35.43.220",nocase; classtype:trojan-activity; sid:100003680; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"87.121.98.51",nocase; classtype:trojan-activity; sid:100003681; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"87.61.89.40",nocase; classtype:trojan-activity; sid:100003682; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.119.171.253",nocase; classtype:trojan-activity; sid:100003683; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.2.208.71",nocase; classtype:trojan-activity; sid:100003684; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.2.219.179",nocase; classtype:trojan-activity; sid:100003685; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.225.222.128",nocase; classtype:trojan-activity; sid:100003686; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.247.96.19",nocase; classtype:trojan-activity; sid:100003687; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.248.136.231",nocase; classtype:trojan-activity; sid:100003688; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.248.51.139",nocase; classtype:trojan-activity; sid:100003689; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.249.244.180",nocase; classtype:trojan-activity; sid:100003690; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.250.204.12",nocase; classtype:trojan-activity; sid:100003691; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.250.226.26",nocase; classtype:trojan-activity; sid:100003692; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.250.254.90",nocase; classtype:trojan-activity; sid:100003693; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.37.171.141",nocase; classtype:trojan-activity; sid:100003694; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.122.183.130",nocase; classtype:trojan-activity; sid:100003695; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.136.197.170",nocase; classtype:trojan-activity; sid:100003696; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.29.213.33",nocase; classtype:trojan-activity; sid:100003697; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.35.62.96",nocase; classtype:trojan-activity; sid:100003698; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.40.85.166",nocase; classtype:trojan-activity; sid:100003699; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.40.87.5",nocase; classtype:trojan-activity; sid:100003700; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"8poieq.bn.files.1drv.com",nocase; classtype:trojan-activity; sid:100003701; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"90.152.144.139",nocase; classtype:trojan-activity; sid:100003702; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.177.139.132",nocase; classtype:trojan-activity; sid:100003703; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.187.103.32",nocase; classtype:trojan-activity; sid:100003704; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.212.150.241",nocase; classtype:trojan-activity; sid:100003705; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.212.150.243",nocase; classtype:trojan-activity; sid:100003706; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.217.104.185",nocase; classtype:trojan-activity; sid:100003707; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.233.112.188",nocase; classtype:trojan-activity; sid:100003708; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.234.60.94",nocase; classtype:trojan-activity; sid:100003709; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.239.168.83",nocase; classtype:trojan-activity; sid:100003710; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.244.114.198",nocase; classtype:trojan-activity; sid:100003711; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.244.169.139",nocase; classtype:trojan-activity; sid:100003712; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.92.16.244",nocase; classtype:trojan-activity; sid:100003713; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.98.4.181",nocase; classtype:trojan-activity; sid:100003714; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.113.192.30",nocase; classtype:trojan-activity; sid:100003715; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.113.195.115",nocase; classtype:trojan-activity; sid:100003716; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.114.191.82",nocase; classtype:trojan-activity; sid:100003717; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.241.78.114",nocase; classtype:trojan-activity; sid:100003718; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.27.246.202",nocase; classtype:trojan-activity; sid:100003719; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.85.18.138",nocase; classtype:trojan-activity; sid:100003720; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.171.157.73",nocase; classtype:trojan-activity; sid:100003721; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.21.224.154",nocase; classtype:trojan-activity; sid:100003722; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.39.115.176",nocase; classtype:trojan-activity; sid:100003723; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.41.137.16",nocase; classtype:trojan-activity; sid:100003724; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.41.182.249",nocase; classtype:trojan-activity; sid:100003725; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.41.206.56",nocase; classtype:trojan-activity; sid:100003726; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.57.43.233",nocase; classtype:trojan-activity; sid:100003727; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.73.99.102",nocase; classtype:trojan-activity; sid:100003728; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.136.69.199",nocase; classtype:trojan-activity; sid:100003729; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.143.53.34",nocase; classtype:trojan-activity; sid:100003730; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.154.17.170",nocase; classtype:trojan-activity; sid:100003731; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.154.82.190",nocase; classtype:trojan-activity; sid:100003732; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.200.16.22",nocase; classtype:trojan-activity; sid:100003733; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.224.83.208",nocase; classtype:trojan-activity; sid:100003734; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.43.139.153",nocase; classtype:trojan-activity; sid:100003735; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.53.120.109",nocase; classtype:trojan-activity; sid:100003736; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.132.129.250",nocase; classtype:trojan-activity; sid:100003737; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.154.20.231",nocase; classtype:trojan-activity; sid:100003738; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.158.19.130",nocase; classtype:trojan-activity; sid:100003739; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.170.113.52",nocase; classtype:trojan-activity; sid:100003740; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.170.201.34",nocase; classtype:trojan-activity; sid:100003741; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.181.155.112",nocase; classtype:trojan-activity; sid:100003742; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.214.52.64",nocase; classtype:trojan-activity; sid:100003743; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.53.229.84",nocase; classtype:trojan-activity; sid:100003744; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.54.11.179",nocase; classtype:trojan-activity; sid:100003745; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.60.146.134",nocase; classtype:trojan-activity; sid:100003746; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.60.6.114",nocase; classtype:trojan-activity; sid:100003747; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.66.196.63",nocase; classtype:trojan-activity; sid:100003748; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.9.120.40",nocase; classtype:trojan-activity; sid:100003749; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"96.239.73.246",nocase; classtype:trojan-activity; sid:100003750; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"96.47.147.169",nocase; classtype:trojan-activity; sid:100003751; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"97.68.140.254",nocase; classtype:trojan-activity; sid:100003752; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"97.96.199.75",nocase; classtype:trojan-activity; sid:100003753; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.0.210.218",nocase; classtype:trojan-activity; sid:100003754; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.0.239.142",nocase; classtype:trojan-activity; sid:100003755; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.113.239.207",nocase; classtype:trojan-activity; sid:100003756; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.116.72.119",nocase; classtype:trojan-activity; sid:100003757; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.128.147.115",nocase; classtype:trojan-activity; sid:100003758; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.178.242.44",nocase; classtype:trojan-activity; sid:100003759; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.249.236.11",nocase; classtype:trojan-activity; sid:100003760; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.28.200.139",nocase; classtype:trojan-activity; sid:100003761; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.30.24.54",nocase; classtype:trojan-activity; sid:100003762; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"99.150.245.203",nocase; classtype:trojan-activity; sid:100003763; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"99.33.195.164",nocase; classtype:trojan-activity; sid:100003764; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"99centsdigitals.com",nocase; classtype:trojan-activity; sid:100003765; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abcd.bg",nocase; classtype:trojan-activity; sid:100003766; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abclicks.in",nocase; classtype:trojan-activity; sid:100003767; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abissnet.net",nocase; classtype:trojan-activity; sid:100003768; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aboveandbelow.com.au",nocase; classtype:trojan-activity; sid:100003769; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"absoftechworld.com",nocase; classtype:trojan-activity; sid:100003770; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"absupplies.co.uk",nocase; classtype:trojan-activity; sid:100003771; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abyssos.eu",nocase; classtype:trojan-activity; sid:100003772; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"acbick.com",nocase; classtype:trojan-activity; sid:100003773; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"accounts.thesmarttechhub.com",nocase; classtype:trojan-activity; sid:100003774; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aceeprc.com.aceeprc.com",nocase; classtype:trojan-activity; sid:100003775; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"acellr.co.uk",nocase; classtype:trojan-activity; sid:100003776; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aclassapart.in",nocase; classtype:trojan-activity; sid:100003777; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"acteon.com.ar",nocase; classtype:trojan-activity; sid:100003778; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"activateyourdiscount.com",nocase; classtype:trojan-activity; sid:100003779; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"activecost.com.au",nocase; classtype:trojan-activity; sid:100003780; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"adamorinmusic.com",nocase; classtype:trojan-activity; sid:100003781; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"addahealingmusic.com",nocase; classtype:trojan-activity; sid:100003782; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"adithimedia.com",nocase; classtype:trojan-activity; sid:100003783; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"adithimedia.memengers.com",nocase; classtype:trojan-activity; sid:100003784; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"admin.erapor.smk-alasror.net",nocase; classtype:trojan-activity; sid:100003785; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"admin.gentbcn.org",nocase; classtype:trojan-activity; sid:100003786; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"admin.grandoceanvilla.com",nocase; classtype:trojan-activity; sid:100003787; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"adventureexplorer.in",nocase; classtype:trojan-activity; sid:100003788; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aeropilates.cl",nocase; classtype:trojan-activity; sid:100003789; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"afrimedspecialist.com",nocase; classtype:trojan-activity; sid:100003790; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agemn.co.za",nocase; classtype:trojan-activity; sid:100003791; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agenciadigitalwdys.com",nocase; classtype:trojan-activity; sid:100003792; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agenciatabletshouse.com.br",nocase; classtype:trojan-activity; sid:100003793; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agenda.gmelloinformatica.com.br",nocase; classtype:trojan-activity; sid:100003794; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agentt.ac.ug",nocase; classtype:trojan-activity; sid:100003795; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agile8studio.com",nocase; classtype:trojan-activity; sid:100003796; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agmcarpetcare.co.uk",nocase; classtype:trojan-activity; sid:100003797; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aiqtest.com",nocase; classtype:trojan-activity; sid:100003798; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ajpharmaholding.com",nocase; classtype:trojan-activity; sid:100003799; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ajstudiollc.com",nocase; classtype:trojan-activity; sid:100003800; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aktyd05.top",nocase; classtype:trojan-activity; sid:100003801; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"al-wahd.com",nocase; classtype:trojan-activity; sid:100003802; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alasdemariposas.org",nocase; classtype:trojan-activity; sid:100003803; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alemelektronik.com",nocase; classtype:trojan-activity; sid:100003804; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alena1971.es",nocase; classtype:trojan-activity; sid:100003805; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alertlauncher.fr",nocase; classtype:trojan-activity; sid:100003806; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alexdubai.com.aldiabsteel.com",nocase; classtype:trojan-activity; sid:100003807; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alka.institute",nocase; classtype:trojan-activity; sid:100003808; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"allforcreative.com.au",nocase; classtype:trojan-activity; sid:100003809; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alltheway.travel",nocase; classtype:trojan-activity; sid:100003810; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alpaylar.com.tr",nocase; classtype:trojan-activity; sid:100003811; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"am-concepts.ca",nocase; classtype:trojan-activity; sid:100003812; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amamontajes.com",nocase; classtype:trojan-activity; sid:100003813; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amarresdeamorymaestroshechiceros.com",nocase; classtype:trojan-activity; sid:100003814; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amarteargentina.com.ar",nocase; classtype:trojan-activity; sid:100003815; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amenyan.zouri.jp",nocase; classtype:trojan-activity; sid:100003816; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amos524.org",nocase; classtype:trojan-activity; sid:100003817; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anantam.net.in",nocase; classtype:trojan-activity; sid:100003818; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andreelapeyre.com",nocase; classtype:trojan-activity; sid:100003819; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andremaraisbeleggings.co.za",nocase; classtype:trojan-activity; sid:100003820; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andres.ac.ug",nocase; classtype:trojan-activity; sid:100003821; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andres.ug",nocase; classtype:trojan-activity; sid:100003822; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andreshconcejal.solucioneslink.com",nocase; classtype:trojan-activity; sid:100003823; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"angelazgheibld.com",nocase; classtype:trojan-activity; sid:100003824; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"angelsdetour.com",nocase; classtype:trojan-activity; sid:100003825; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"angloteste.bigprime.com.br",nocase; classtype:trojan-activity; sid:100003826; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anhung1102.vn",nocase; classtype:trojan-activity; sid:100003827; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anysbergbiltong.co.za",nocase; classtype:trojan-activity; sid:100003828; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"apartamentoscitta.com",nocase; classtype:trojan-activity; sid:100003829; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"api-ms.cobainaja.id",nocase; classtype:trojan-activity; sid:100003830; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"api.cstdevs.com",nocase; classtype:trojan-activity; sid:100003831; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"api.quocbao.biz",nocase; classtype:trojan-activity; sid:100003832; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"api.sampy.io",nocase; classtype:trojan-activity; sid:100003833; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aplicativoparasindicato.com.br",nocase; classtype:trojan-activity; sid:100003834; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"apoolcondo.com",nocase; classtype:trojan-activity; sid:100003835; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"app.adsensearticle.com",nocase; classtype:trojan-activity; sid:100003836; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"app.explicitsurveys.co.uk",nocase; classtype:trojan-activity; sid:100003837; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"app.prerana.info",nocase; classtype:trojan-activity; sid:100003838; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"apps.saintsoporte.com",nocase; classtype:trojan-activity; sid:100003839; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aras.iuc.ac",nocase; classtype:trojan-activity; sid:100003840; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"areyoulivingwell.com",nocase; classtype:trojan-activity; sid:100003841; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"arsapetrolab.com",nocase; classtype:trojan-activity; sid:100003842; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"artedibujoyarquitectura.com",nocase; classtype:trojan-activity; sid:100003843; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ask-regard.call-save.biz",nocase; classtype:trojan-activity; sid:100003844; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"atfile.com",nocase; classtype:trojan-activity; sid:100003845; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"athenacapsg.com",nocase; classtype:trojan-activity; sid:100003846; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"atlasconcreteworks.com",nocase; classtype:trojan-activity; sid:100003847; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"attach.66rpg.com",nocase; classtype:trojan-activity; sid:100003848; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"atteuqpotentialunlimited.com",nocase; classtype:trojan-activity; sid:100003849; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"augustair.com",nocase; classtype:trojan-activity; sid:100003850; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aulist.com",nocase; classtype:trojan-activity; sid:100003851; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"australiafashions.com",nocase; classtype:trojan-activity; sid:100003852; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"automaticrefreshments.com",nocase; classtype:trojan-activity; sid:100003853; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"avadhanagames.com",nocase; classtype:trojan-activity; sid:100003854; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"avissrilanka.com",nocase; classtype:trojan-activity; sid:100003855; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ayamallah.com",nocase; classtype:trojan-activity; sid:100003856; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"azmeasurement.com",nocase; classtype:trojan-activity; sid:100003857; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"azraktours.com",nocase; classtype:trojan-activity; sid:100003858; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"b2b.toptanakaryakit.com.tr",nocase; classtype:trojan-activity; sid:100003859; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"backgrounds.pk",nocase; classtype:trojan-activity; sid:100003860; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"backup.agewsage.com",nocase; classtype:trojan-activity; sid:100003861; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"badeggdesign.com",nocase; classtype:trojan-activity; sid:100003862; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bangkok-orchids.com",nocase; classtype:trojan-activity; sid:100003863; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bary.sz4h.com",nocase; classtype:trojan-activity; sid:100003864; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"basma.com.kw",nocase; classtype:trojan-activity; sid:100003865; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bausch.kr-atlas.monaxikoslykos@zytrox.tk",nocase; classtype:trojan-activity; sid:100003866; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bavhome.com",nocase; classtype:trojan-activity; sid:100003867; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bbia.co.uk",nocase; classtype:trojan-activity; sid:100003868; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bcmt.elin.co.za",nocase; classtype:trojan-activity; sid:100003869; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bcrg.co.za",nocase; classtype:trojan-activity; sid:100003870; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bearcatpumps.com.cn",nocase; classtype:trojan-activity; sid:100003871; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"beatyamerican.com",nocase; classtype:trojan-activity; sid:100003872; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"beautincollagen.rs",nocase; classtype:trojan-activity; sid:100003873; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bekape.co.id",nocase; classtype:trojan-activity; sid:100003874; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bespokeweddings.ie",nocase; classtype:trojan-activity; sid:100003875; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bestcarenepal.com",nocase; classtype:trojan-activity; sid:100003876; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"betone.co.kr",nocase; classtype:trojan-activity; sid:100003877; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"betycopaints.com",nocase; classtype:trojan-activity; sid:100003878; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"beveragesmiami.solucioneslink.com",nocase; classtype:trojan-activity; sid:100003879; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bilbosaquet.ug",nocase; classtype:trojan-activity; sid:100003880; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bilhen.co.za",nocase; classtype:trojan-activity; sid:100003881; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"billing.rahitechnosoft.com",nocase; classtype:trojan-activity; sid:100003882; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"birdi.elin.co.za",nocase; classtype:trojan-activity; sid:100003883; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"birminghamlink.org",nocase; classtype:trojan-activity; sid:100003884; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.callensaxen.com",nocase; classtype:trojan-activity; sid:100003885; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.oyinblogs.com",nocase; classtype:trojan-activity; sid:100003886; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.takbelit.com",nocase; classtype:trojan-activity; sid:100003887; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bmlifestyle.co.uk",nocase; classtype:trojan-activity; sid:100003888; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bnrnews.id",nocase; classtype:trojan-activity; sid:100003889; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bodenstein.co.za",nocase; classtype:trojan-activity; sid:100003890; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bolnicaloznica.rs",nocase; classtype:trojan-activity; sid:100003891; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"booksearch.com",nocase; classtype:trojan-activity; sid:100003892; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bounces.mi-fs.com",nocase; classtype:trojan-activity; sid:100003893; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bpo.correct.go.th",nocase; classtype:trojan-activity; sid:100003894; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bradleyinstitute.co.za",nocase; classtype:trojan-activity; sid:100003895; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brandtrust.com.pk",nocase; classtype:trojan-activity; sid:100003896; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brendanquine.com",nocase; classtype:trojan-activity; sid:100003897; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brideofmessiah.com",nocase; classtype:trojan-activity; sid:100003898; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bridesofmaldives.com",nocase; classtype:trojan-activity; sid:100003899; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brightmega.com",nocase; classtype:trojan-activity; sid:100003900; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brightonrooms.co.uk",nocase; classtype:trojan-activity; sid:100003901; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brightstarshop.com",nocase; classtype:trojan-activity; sid:100003902; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"browardinsurancemiami.solucioneslink.com",nocase; classtype:trojan-activity; sid:100003903; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bt2.elin.co.za",nocase; classtype:trojan-activity; sid:100003904; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"btdapi.robotake.com",nocase; classtype:trojan-activity; sid:100003905; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bucrinsuranlceonlines.com",nocase; classtype:trojan-activity; sid:100003906; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"buenavista.co",nocase; classtype:trojan-activity; sid:100003907; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"buigiaphat.com.vn",nocase; classtype:trojan-activity; sid:100003908; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bullseyemedia.in",nocase; classtype:trojan-activity; sid:100003909; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"busandvanrentalmalaysia.com",nocase; classtype:trojan-activity; sid:100003910; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"buscascolegios.diit.cl",nocase; classtype:trojan-activity; sid:100003911; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"business.softberg.ro",nocase; classtype:trojan-activity; sid:100003912; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"buyingmusiconline.com",nocase; classtype:trojan-activity; sid:100003913; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"buypropertyfast.com",nocase; classtype:trojan-activity; sid:100003914; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bwsr.eu",nocase; classtype:trojan-activity; sid:100003915; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"c.oooooooooo.ga",nocase; classtype:trojan-activity; sid:100003916; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"c0140529.ferozo.com",nocase; classtype:trojan-activity; sid:100003917; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cacapavaonline.sdserver144.com.br",nocase; classtype:trojan-activity; sid:100003918; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"callbury.in",nocase; classtype:trojan-activity; sid:100003919; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"camminachetipassa.it",nocase; classtype:trojan-activity; sid:100003920; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"campusvirtual.cepsanjuanbosco.net.pe",nocase; classtype:trojan-activity; sid:100003921; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cancer.educandome.co",nocase; classtype:trojan-activity; sid:100003922; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"capitalgroup-kw.com",nocase; classtype:trojan-activity; sid:100003923; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"capitalnewsagency.com",nocase; classtype:trojan-activity; sid:100003924; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"capoeiraventrelivre.com",nocase; classtype:trojan-activity; sid:100003925; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cashyinvestment.org",nocase; classtype:trojan-activity; sid:100003926; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"casoauditores.com",nocase; classtype:trojan-activity; sid:100003927; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"catchperch.com",nocase; classtype:trojan-activity; sid:100003928; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"catchpoolshetlands.co.uk",nocase; classtype:trojan-activity; sid:100003929; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cazyacustomfurniture.com",nocase; classtype:trojan-activity; sid:100003930; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ccauthority.net",nocase; classtype:trojan-activity; sid:100003931; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdaonline.com.ar",nocase; classtype:trojan-activity; sid:100003932; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cec.asso.ac-amiens.fr",nocase; classtype:trojan-activity; sid:100003933; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cellas.sk",nocase; classtype:trojan-activity; sid:100003934; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cendekiabinaaksara.com",nocase; classtype:trojan-activity; sid:100003935; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cespol-bote.com.mx",nocase; classtype:trojan-activity; sid:100003936; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cfs5.tistory.com",nocase; classtype:trojan-activity; sid:100003937; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ch.rmu.ac.th",nocase; classtype:trojan-activity; sid:100003938; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"changematterscounselling.com",nocase; classtype:trojan-activity; sid:100003939; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chardhamdodham.com",nocase; classtype:trojan-activity; sid:100003940; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cheacrilnsurances.com",nocase; classtype:trojan-activity; sid:100003941; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chealablilitycarinsurances.com",nocase; classtype:trojan-activity; sid:100003942; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chezalice.co.za",nocase; classtype:trojan-activity; sid:100003943; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"childselect.com",nocase; classtype:trojan-activity; sid:100003944; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chinhdropfile.myvnc.com",nocase; classtype:trojan-activity; sid:100003945; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chinhdropfile80.myvnc.com",nocase; classtype:trojan-activity; sid:100003946; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chipmania.it",nocase; classtype:trojan-activity; sid:100003947; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cible-energy.com",nocase; classtype:trojan-activity; sid:100003948; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cifeer.net",nocase; classtype:trojan-activity; sid:100003949; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"citycapproperty.ru",nocase; classtype:trojan-activity; sid:100003950; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cityglobalgospel.com",nocase; classtype:trojan-activity; sid:100003951; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"civi.istmejia.com",nocase; classtype:trojan-activity; sid:100003952; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cleanbydesignllc.com",nocase; classtype:trojan-activity; sid:100003953; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"clim34000.fr",nocase; classtype:trojan-activity; sid:100003954; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cloud.fc.co.mz",nocase; classtype:trojan-activity; sid:100003955; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"codsambal.com",nocase; classtype:trojan-activity; sid:100003956; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"colinde.pricesne.com",nocase; classtype:trojan-activity; sid:100003957; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"colorpak.pl",nocase; classtype:trojan-activity; sid:100003958; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"competancy.indigoconsult.net",nocase; classtype:trojan-activity; sid:100003959; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"conceptimagine.ro",nocase; classtype:trojan-activity; sid:100003960; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"config.cqhbkjzx.com",nocase; classtype:trojan-activity; sid:100003961; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"constructoralyon.com",nocase; classtype:trojan-activity; sid:100003962; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"consulateins.solucioneslink.com",nocase; classtype:trojan-activity; sid:100003963; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"contributeindustry.com",nocase; classtype:trojan-activity; sid:100003964; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"controladoradeplagasmm.com",nocase; classtype:trojan-activity; sid:100003965; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"copelandscapes.com",nocase; classtype:trojan-activity; sid:100003966; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"corporativos.com.co",nocase; classtype:trojan-activity; sid:100003967; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"coulsongraphics.com",nocase; classtype:trojan-activity; sid:100003968; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"coutler.newreadermedia.net",nocase; classtype:trojan-activity; sid:100003969; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"covid19.cyberschool.or.id",nocase; classtype:trojan-activity; sid:100003970; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cr-sq.com",nocase; classtype:trojan-activity; sid:100003971; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crearechile.cl",nocase; classtype:trojan-activity; sid:100003972; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"creationskateboards.com",nocase; classtype:trojan-activity; sid:100003973; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crecerco.com",nocase; classtype:trojan-activity; sid:100003974; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crittersbythebay.com",nocase; classtype:trojan-activity; sid:100003975; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crm.notariavieitoyvelamazan.com",nocase; classtype:trojan-activity; sid:100003976; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crmmanivela.net",nocase; classtype:trojan-activity; sid:100003977; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crscorretordeimoveis.com.br",nocase; classtype:trojan-activity; sid:100003978; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cse-engineer.com",nocase; classtype:trojan-activity; sid:100003979; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"csnserver.com",nocase; classtype:trojan-activity; sid:100003980; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cubescargoexpress.com",nocase; classtype:trojan-activity; sid:100003981; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cubrebocasenpuebla.com.mx",nocase; classtype:trojan-activity; sid:100003982; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"curasoles.co.za",nocase; classtype:trojan-activity; sid:100003983; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"currantmedia.com",nocase; classtype:trojan-activity; sid:100003984; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cwa.mx",nocase; classtype:trojan-activity; sid:100003985; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cyber.searchkero.com",nocase; classtype:trojan-activity; sid:100003986; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cyclomove.com",nocase; classtype:trojan-activity; sid:100003987; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cynkon.kairoscs.net",nocase; classtype:trojan-activity; sid:100003988; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"czas.dbstrony.pl",nocase; classtype:trojan-activity; sid:100003989; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"czsl.91756.cn",nocase; classtype:trojan-activity; sid:100003990; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"d.powerofwish.com",nocase; classtype:trojan-activity; sid:100003991; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"d9.99ddd.com",nocase; classtype:trojan-activity; sid:100003992; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"da.alibuf.com",nocase; classtype:trojan-activity; sid:100003993; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"damagedessentialtelecommunications.testmail4.repl.co",nocase; classtype:trojan-activity; sid:100003994; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dandyair.com",nocase; classtype:trojan-activity; sid:100003995; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dannexgh.com",nocase; classtype:trojan-activity; sid:100003996; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dartoonpictures.com",nocase; classtype:trojan-activity; sid:100003997; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"data.cdevelop.org",nocase; classtype:trojan-activity; sid:100003998; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"data.over-blog-kiwi.com",nocase; classtype:trojan-activity; sid:100003999; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"datapolish.com",nocase; classtype:trojan-activity; sid:100004000; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dating.khokhas.co.za",nocase; classtype:trojan-activity; sid:100004001; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"datsom.vn",nocase; classtype:trojan-activity; sid:100004002; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"daunhotq10.com",nocase; classtype:trojan-activity; sid:100004003; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"davethompson.me.uk",nocase; classtype:trojan-activity; sid:100004004; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"davidmcguinness.info",nocase; classtype:trojan-activity; sid:100004005; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dayspringdaisies.com",nocase; classtype:trojan-activity; sid:100004006; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dd.qiyuea.cn",nocase; classtype:trojan-activity; sid:100004007; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"de.gsearch.com.de",nocase; classtype:trojan-activity; sid:100004008; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"decifrar.com.br",nocase; classtype:trojan-activity; sid:100004009; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"deigratia2.elin.co.za",nocase; classtype:trojan-activity; sid:100004010; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dekovizyon.com",nocase; classtype:trojan-activity; sid:100004011; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"demo-cliente.mindcreative.com.br",nocase; classtype:trojan-activity; sid:100004012; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"demo6.hiites.com",nocase; classtype:trojan-activity; sid:100004013; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dent-estet.com",nocase; classtype:trojan-activity; sid:100004014; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dental.xiaoxiao.media",nocase; classtype:trojan-activity; sid:100004015; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dentalalliance.se",nocase; classtype:trojan-activity; sid:100004016; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"designerliving.co.za",nocase; classtype:trojan-activity; sid:100004017; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"desiringhands.com",nocase; classtype:trojan-activity; sid:100004018; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"despertaresi.com.br",nocase; classtype:trojan-activity; sid:100004019; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"destinymc.co.za",nocase; classtype:trojan-activity; sid:100004020; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"detorre.es",nocase; classtype:trojan-activity; sid:100004021; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dev-interestingtech.pantheonsite.io",nocase; classtype:trojan-activity; sid:100004022; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dev.sebpo.net",nocase; classtype:trojan-activity; sid:100004023; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dezcom.com",nocase; classtype:trojan-activity; sid:100004024; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dfcf.91756.cn",nocase; classtype:trojan-activity; sid:100004025; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dfsfcsfcdsfsdvcfsvcscv.com",nocase; classtype:trojan-activity; sid:100004026; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"diamantenegro.mi-fs.com",nocase; classtype:trojan-activity; sid:100004027; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dienmayminhhung.com",nocase; classtype:trojan-activity; sid:100004028; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"digilib.dianhusada.ac.id",nocase; classtype:trojan-activity; sid:100004029; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"djking.f3322.net",nocase; classtype:trojan-activity; sid:100004030; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.1003b.56a.com",nocase; classtype:trojan-activity; sid:100004031; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.198424.com",nocase; classtype:trojan-activity; sid:100004032; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.installcdn-aws.com",nocase; classtype:trojan-activity; sid:100004033; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.packetstormsecurity.net",nocase; classtype:trojan-activity; sid:100004034; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.rina-roleplay.com",nocase; classtype:trojan-activity; sid:100004035; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.zkytech.com",nocase; classtype:trojan-activity; sid:100004036; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dns.cyberium.cc",nocase; classtype:trojan-activity; sid:100004037; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dockerupdate.anondns.net",nocase; classtype:trojan-activity; sid:100004038; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docman.orientalservices.in",nocase; classtype:trojan-activity; sid:100004039; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dodsonimaging.com",nocase; classtype:trojan-activity; sid:100004040; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dokan.blueberrytec.com",nocase; classtype:trojan-activity; sid:100004041; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dom-chel74.ru",nocase; classtype:trojan-activity; sid:100004042; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dom.daf.free.fr",nocase; classtype:trojan-activity; sid:100004043; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"doncedyhall.com",nocase; classtype:trojan-activity; sid:100004044; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"donghobinhminh.com",nocase; classtype:trojan-activity; sid:100004045; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dongphuctop.com",nocase; classtype:trojan-activity; sid:100004046; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"donwnloasecury.ath.cx",nocase; classtype:trojan-activity; sid:100004047; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dosame.com",nocase; classtype:trojan-activity; sid:100004048; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dosman.pl",nocase; classtype:trojan-activity; sid:100004049; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dovberger.com",nocase; classtype:trojan-activity; sid:100004050; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.flash-plays.com",nocase; classtype:trojan-activity; sid:100004051; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.pcclear.com",nocase; classtype:trojan-activity; sid:100004052; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.posti-fi-fsa.top",nocase; classtype:trojan-activity; sid:100004053; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.posti-fi-fwa.top",nocase; classtype:trojan-activity; sid:100004054; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.udashi.com",nocase; classtype:trojan-activity; sid:100004055; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.webbora.com",nocase; classtype:trojan-activity; sid:100004056; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down1.arpun.com",nocase; classtype:trojan-activity; sid:100004057; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.caihong.com",nocase; classtype:trojan-activity; sid:100004058; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.doumaibiji.cn",nocase; classtype:trojan-activity; sid:100004059; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.exrnybuf.cn",nocase; classtype:trojan-activity; sid:100004060; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.kaobeitu.com",nocase; classtype:trojan-activity; sid:100004061; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.pdf00.cn",nocase; classtype:trojan-activity; sid:100004062; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.rising.com.cn",nocase; classtype:trojan-activity; sid:100004063; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.skycn.com",nocase; classtype:trojan-activity; sid:100004064; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.zjsyawqj.cn",nocase; classtype:trojan-activity; sid:100004065; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"downloads.jxtsteel.cn",nocase; classtype:trojan-activity; sid:100004066; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dragonsknot.com",nocase; classtype:trojan-activity; sid:100004067; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drbaby.com.sa",nocase; classtype:trojan-activity; sid:100004068; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drohnen.ensenanzainteligente.com",nocase; classtype:trojan-activity; sid:100004069; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drools-moved.46999.n3.nabble.com",nocase; classtype:trojan-activity; sid:100004070; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drrohanfonseca.com",nocase; classtype:trojan-activity; sid:100004071; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drsha.innovativesolutions.mobi",nocase; classtype:trojan-activity; sid:100004072; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dsenterprize.co.za",nocase; classtype:trojan-activity; sid:100004073; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dsspainting.com",nocase; classtype:trojan-activity; sid:100004074; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"du-wizards.com",nocase; classtype:trojan-activity; sid:100004075; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"duque.guantanameratravel.com",nocase; classtype:trojan-activity; sid:100004076; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dutapp.wisolve.co.za",nocase; classtype:trojan-activity; sid:100004077; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"duvalcharter.dekitout.com",nocase; classtype:trojan-activity; sid:100004078; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dx.qqyewu.com",nocase; classtype:trojan-activity; sid:100004079; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dzinestudio87.co.uk",nocase; classtype:trojan-activity; sid:100004080; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"e-commerce.saleensuporte.com.br",nocase; classtype:trojan-activity; sid:100004081; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"e.sldov.ru",nocase; classtype:trojan-activity; sid:100004082; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ebruyatkin.com",nocase; classtype:trojan-activity; sid:100004083; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"econews.treegle.org",nocase; classtype:trojan-activity; sid:100004084; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"edelweissdecoration.com",nocase; classtype:trojan-activity; sid:100004085; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"efficientegroup.com",nocase; classtype:trojan-activity; sid:100004086; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"elliot.newreadermedia.net",nocase; classtype:trojan-activity; sid:100004087; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"emaids.co.za",nocase; classtype:trojan-activity; sid:100004088; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"en.baoend.com",nocase; classtype:trojan-activity; sid:100004089; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"enc-tech.com",nocase; classtype:trojan-activity; sid:100004090; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"endurotanzania.co.tz",nocase; classtype:trojan-activity; sid:100004091; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"enkonooh.com",nocase; classtype:trojan-activity; sid:100004092; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ennovate.elin.co.za",nocase; classtype:trojan-activity; sid:100004093; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"enriquecendocomconsorcio.com.br",nocase; classtype:trojan-activity; sid:100004094; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"envios.petpienso.cl",nocase; classtype:trojan-activity; sid:100004095; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"equimination.ee",nocase; classtype:trojan-activity; sid:100004096; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"es.paymelist.com",nocase; classtype:trojan-activity; sid:100004097; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"escola.probommar.org.br",nocase; classtype:trojan-activity; sid:100004098; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"esnconsultants.com",nocase; classtype:trojan-activity; sid:100004099; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"essentia.org.br",nocase; classtype:trojan-activity; sid:100004100; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"eubanks7.com",nocase; classtype:trojan-activity; sid:100004101; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"evidencemarketing.ca",nocase; classtype:trojan-activity; sid:100004102; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exilum.com",nocase; classtype:trojan-activity; sid:100004103; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exitoalfaomega.co",nocase; classtype:trojan-activity; sid:100004104; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"extrovertoffers.com",nocase; classtype:trojan-activity; sid:100004105; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"f1sol.com",nocase; classtype:trojan-activity; sid:100004106; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"familydentist.site",nocase; classtype:trojan-activity; sid:100004107; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"farmaciasdrogaminas.com.br",nocase; classtype:trojan-activity; sid:100004108; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"farmnatural.in",nocase; classtype:trojan-activity; sid:100004109; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"faveraprojects.com",nocase; classtype:trojan-activity; sid:100004110; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fc.co.mz",nocase; classtype:trojan-activity; sid:100004111; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"felicienne.nl",nocase; classtype:trojan-activity; sid:100004112; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fi.bonitastores.com",nocase; classtype:trojan-activity; sid:100004113; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"files.martellexpress.us",nocase; classtype:trojan-activity; sid:100004114; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"files6.uludagbilisim.com",nocase; classtype:trojan-activity; sid:100004115; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"filmotainment.com",nocase; classtype:trojan-activity; sid:100004116; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"final.makkahkmcc.com",nocase; classtype:trojan-activity; sid:100004117; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fkd.derpcity.ru",nocase; classtype:trojan-activity; sid:100004118; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"flintspin.com",nocase; classtype:trojan-activity; sid:100004119; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"flyingbuddhadesign.com",nocase; classtype:trojan-activity; sid:100004120; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fmjplastering.co.uk",nocase; classtype:trojan-activity; sid:100004121; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fms.buladde.or.ug",nocase; classtype:trojan-activity; sid:100004122; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"foothills.com.br",nocase; classtype:trojan-activity; sid:100004123; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"footweardirect.elin.co.za",nocase; classtype:trojan-activity; sid:100004124; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"formestore.evencsoft.co",nocase; classtype:trojan-activity; sid:100004125; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"forum.mdb.nu",nocase; classtype:trojan-activity; sid:100004126; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fotoobjetivo.com",nocase; classtype:trojan-activity; sid:100004127; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"foundationrepairhoustontx.net",nocase; classtype:trojan-activity; sid:100004128; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"foxeps.com.br",nocase; classtype:trojan-activity; sid:100004129; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"freecnetdownload.com",nocase; classtype:trojan-activity; sid:100004130; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"freedombookshop.tickme.lk",nocase; classtype:trojan-activity; sid:100004131; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"freisites.com.br",nocase; classtype:trojan-activity; sid:100004132; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ftp.n3twork30cm.ml",nocase; classtype:trojan-activity; sid:100004133; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fullelectronica.com.ar",nocase; classtype:trojan-activity; sid:100004134; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"funletters.net",nocase; classtype:trojan-activity; sid:100004135; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fusionfiresolutions.com",nocase; classtype:trojan-activity; sid:100004136; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"futuregraphics.com.ar",nocase; classtype:trojan-activity; sid:100004137; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gahanassociates.com",nocase; classtype:trojan-activity; sid:100004138; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gametwogame.com",nocase; classtype:trojan-activity; sid:100004139; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"garayvidalabogados.com",nocase; classtype:trojan-activity; sid:100004140; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"garciadogshow.com",nocase; classtype:trojan-activity; sid:100004141; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"garenanow.myvnc.com",nocase; classtype:trojan-activity; sid:100004142; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"garenanow4.myvnc.com",nocase; classtype:trojan-activity; sid:100004143; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gbbulls.co.uk",nocase; classtype:trojan-activity; sid:100004144; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gcpc.co.id.chronoscurtain.com",nocase; classtype:trojan-activity; sid:100004145; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gcrcorporation.com",nocase; classtype:trojan-activity; sid:100004146; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"generaldeviales.com",nocase; classtype:trojan-activity; sid:100004147; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gfmodd1.webselffiles01.com",nocase; classtype:trojan-activity; sid:100004148; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gfold1.webselffiles01.com",nocase; classtype:trojan-activity; sid:100004149; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ghettohub.co.za",nocase; classtype:trojan-activity; sid:100004150; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ghislain.dartois.pagesperso-orange.fr",nocase; classtype:trojan-activity; sid:100004151; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"giadungg7.com",nocase; classtype:trojan-activity; sid:100004152; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"giddos.ga",nocase; classtype:trojan-activity; sid:100004153; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"giteletropical.com",nocase; classtype:trojan-activity; sid:100004154; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"globaltask.ar",nocase; classtype:trojan-activity; sid:100004155; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"glowinmedia.co.ke",nocase; classtype:trojan-activity; sid:100004156; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gmtransformationacademy.com",nocase; classtype:trojan-activity; sid:100004157; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gmvadmission.org",nocase; classtype:trojan-activity; sid:100004158; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gnimelf.net",nocase; classtype:trojan-activity; sid:100004159; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gnscrew.ro",nocase; classtype:trojan-activity; sid:100004160; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gold.investforex.id",nocase; classtype:trojan-activity; sid:100004161; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldcake.co.id",nocase; classtype:trojan-activity; sid:100004162; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldcoastoffice365.com",nocase; classtype:trojan-activity; sid:100004163; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldcoastoffice365.com.au",nocase; classtype:trojan-activity; sid:100004164; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldcupmortgage.com",nocase; classtype:trojan-activity; sid:100004165; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"golden-memories-funerals.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004166; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldmen.in",nocase; classtype:trojan-activity; sid:100004167; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gracejukes.com",nocase; classtype:trojan-activity; sid:100004168; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"grupoinmare.com",nocase; classtype:trojan-activity; sid:100004169; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gruposelt.000webhostapp.com",nocase; classtype:trojan-activity; sid:100004170; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gs.monerorx.com",nocase; classtype:trojan-activity; sid:100004171; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gulfac-house.com",nocase; classtype:trojan-activity; sid:100004172; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gvpcdpgc.edu.in",nocase; classtype:trojan-activity; sid:100004173; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"habbotips.free.fr",nocase; classtype:trojan-activity; sid:100004174; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hagebakken.no",nocase; classtype:trojan-activity; sid:100004175; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"harrisauto.no",nocase; classtype:trojan-activity; sid:100004176; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"harshraval.in",nocase; classtype:trojan-activity; sid:100004177; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hd11315.com",nocase; classtype:trojan-activity; sid:100004178; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hdkamera2003.hu",nocase; classtype:trojan-activity; sid:100004179; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hdrest.fastlinktz.com",nocase; classtype:trojan-activity; sid:100004180; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hds.sz4h.com",nocase; classtype:trojan-activity; sid:100004181; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"healthy20.net",nocase; classtype:trojan-activity; sid:100004182; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hechiceriadeamormaestrabelen.com.hechiceriadeamormaestrabelen.com",nocase; classtype:trojan-activity; sid:100004183; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hellogorgeous.com.au",nocase; classtype:trojan-activity; sid:100004184; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"help.hizuko.com",nocase; classtype:trojan-activity; sid:100004185; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"herchinfitout.com.sg",nocase; classtype:trojan-activity; sid:100004186; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hhaward.org",nocase; classtype:trojan-activity; sid:100004187; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"highlandroadcoc.com",nocase; classtype:trojan-activity; sid:100004188; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"highlandslasvegas.atakdev.com",nocase; classtype:trojan-activity; sid:100004189; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hindi.factsriver.com",nocase; classtype:trojan-activity; sid:100004190; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hiptool.net",nocase; classtype:trojan-activity; sid:100004191; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hitpe.com",nocase; classtype:trojan-activity; sid:100004192; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hitstation.nl",nocase; classtype:trojan-activity; sid:100004193; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hmpmall.co.kr",nocase; classtype:trojan-activity; sid:100004194; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hoagietesting10.com",nocase; classtype:trojan-activity; sid:100004195; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hoayeuthuong-my.sharepoint.com",nocase; classtype:trojan-activity; sid:100004196; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"homefindersolutions.com",nocase; classtype:trojan-activity; sid:100004197; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hongluosi.com",nocase; classtype:trojan-activity; sid:100004198; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hookedupboatclub.com",nocase; classtype:trojan-activity; sid:100004199; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hostelkielce.com",nocase; classtype:trojan-activity; sid:100004200; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hostzaa.com",nocase; classtype:trojan-activity; sid:100004201; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"houstonshutters.site",nocase; classtype:trojan-activity; sid:100004202; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hr2019.vrcom7.com",nocase; classtype:trojan-activity; sid:100004203; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hseda.com",nocase; classtype:trojan-activity; sid:100004204; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hsmwebapp.com",nocase; classtype:trojan-activity; sid:100004205; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"htownbars.com",nocase; classtype:trojan-activity; sid:100004206; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hubtech.co.za",nocase; classtype:trojan-activity; sid:100004207; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"huequito.evencsoft.co",nocase; classtype:trojan-activity; sid:100004208; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hunggiang.vn",nocase; classtype:trojan-activity; sid:100004209; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"husamiyahschool.com",nocase; classtype:trojan-activity; sid:100004210; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iam313.com",nocase; classtype:trojan-activity; sid:100004211; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"icon.shatangmu.cn",nocase; classtype:trojan-activity; sid:100004212; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idea-secure-login.com",nocase; classtype:trojan-activity; sid:100004213; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idilsoft.com",nocase; classtype:trojan-activity; sid:100004214; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idj.no",nocase; classtype:trojan-activity; sid:100004215; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idvindia.com",nocase; classtype:trojan-activity; sid:100004216; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iesanjosemonitos.edu.co",nocase; classtype:trojan-activity; sid:100004217; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ikexpert.com",nocase; classtype:trojan-activity; sid:100004218; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ilrafrica.com",nocase; classtype:trojan-activity; sid:100004219; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"imbueautoworx.co.za",nocase; classtype:trojan-activity; sid:100004220; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"imperiumtherapy.co.za",nocase; classtype:trojan-activity; sid:100004221; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"in-tune2016.com",nocase; classtype:trojan-activity; sid:100004222; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"incodimsa.com",nocase; classtype:trojan-activity; sid:100004223; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"incrediblepixels.com",nocase; classtype:trojan-activity; sid:100004224; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"incredicole.com",nocase; classtype:trojan-activity; sid:100004225; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"industriasyuli.com",nocase; classtype:trojan-activity; sid:100004226; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"infair.vn",nocase; classtype:trojan-activity; sid:100004227; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"infovator.com",nocase; classtype:trojan-activity; sid:100004228; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"innatosbrand.com",nocase; classtype:trojan-activity; sid:100004229; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"inodesthetotaldesigners.com",nocase; classtype:trojan-activity; sid:100004230; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"inovations.searchkero.com",nocase; classtype:trojan-activity; sid:100004231; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"inrajahmundry.co.in",nocase; classtype:trojan-activity; sid:100004232; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"insignificantfinecore.testmail4.repl.co",nocase; classtype:trojan-activity; sid:100004233; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"instvisionmexico.edu.mx",nocase; classtype:trojan-activity; sid:100004234; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"intellectsmart.in",nocase; classtype:trojan-activity; sid:100004235; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"intersel-idf.org",nocase; classtype:trojan-activity; sid:100004236; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"intuitiveideas.com.my",nocase; classtype:trojan-activity; sid:100004237; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"inversiones.arrayanfinanciero.cl",nocase; classtype:trojan-activity; sid:100004238; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"invest.xpcorporative.com.br",nocase; classtype:trojan-activity; sid:100004239; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ipmes.ma",nocase; classtype:trojan-activity; sid:100004240; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iremart.es",nocase; classtype:trojan-activity; sid:100004241; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iris101.co.uk",nocase; classtype:trojan-activity; sid:100004242; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iscamenabe.com",nocase; classtype:trojan-activity; sid:100004243; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iso-dubai.net",nocase; classtype:trojan-activity; sid:100004244; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"israrulhaq.me",nocase; classtype:trojan-activity; sid:100004245; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"isrorg.com",nocase; classtype:trojan-activity; sid:100004246; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"issmbour.falllo.com",nocase; classtype:trojan-activity; sid:100004247; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"isso.ps",nocase; classtype:trojan-activity; sid:100004248; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"it123.ru",nocase; classtype:trojan-activity; sid:100004249; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"itc-demo.softgig.co.ke",nocase; classtype:trojan-activity; sid:100004250; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"itconsultus.com.co",nocase; classtype:trojan-activity; sid:100004251; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jamesjorgensen.newreadermedia.net",nocase; classtype:trojan-activity; sid:100004252; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jamiekaylive.com",nocase; classtype:trojan-activity; sid:100004253; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jamshed.pk",nocase; classtype:trojan-activity; sid:100004254; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jansen-heesch.nl",nocase; classtype:trojan-activity; sid:100004255; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jathra.co.uk",nocase; classtype:trojan-activity; sid:100004256; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jay.diamondrelationscrm.us",nocase; classtype:trojan-activity; sid:100004257; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jebs.net.au",nocase; classtype:trojan-activity; sid:100004258; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jeffdahlke.com",nocase; classtype:trojan-activity; sid:100004259; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jhayesconsulting.com",nocase; classtype:trojan-activity; sid:100004260; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jiaoyuzixun.cn",nocase; classtype:trojan-activity; sid:100004261; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jing-da.com.tw",nocase; classtype:trojan-activity; sid:100004262; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jktnet.xyz",nocase; classtype:trojan-activity; sid:100004263; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jmcomputacion.com.ar",nocase; classtype:trojan-activity; sid:100004264; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jmtc.91756.cn",nocase; classtype:trojan-activity; sid:100004265; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jnanbharati.com",nocase; classtype:trojan-activity; sid:100004266; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jobs.thebeessolution.com",nocase; classtype:trojan-activity; sid:100004267; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"joelbonissilver.com",nocase; classtype:trojan-activity; sid:100004268; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"join.cl8movement.co.za",nocase; classtype:trojan-activity; sid:100004269; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"josegene.com",nocase; classtype:trojan-activity; sid:100004270; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"josuarochoa.com",nocase; classtype:trojan-activity; sid:100004271; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jpwoodfordco.com",nocase; classtype:trojan-activity; sid:100004272; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"julietlaser.site",nocase; classtype:trojan-activity; sid:100004273; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jumpmanualjacobhiller.com",nocase; classtype:trojan-activity; sid:100004274; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jumpnjamchicago.com",nocase; classtype:trojan-activity; sid:100004275; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jupiter.toxsl.in",nocase; classtype:trojan-activity; sid:100004276; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jurgensen.newreadermedia.net",nocase; classtype:trojan-activity; sid:100004277; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"justinscott.com.au",nocase; classtype:trojan-activity; sid:100004278; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kaizenjanitorial.com",nocase; classtype:trojan-activity; sid:100004279; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kalawatihomes.com",nocase; classtype:trojan-activity; sid:100004280; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kalpataru-elitus-mulund.thakkers.in",nocase; classtype:trojan-activity; sid:100004281; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"karer.by",nocase; classtype:trojan-activity; sid:100004282; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"katanvetov.co.il",nocase; classtype:trojan-activity; sid:100004283; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kbdom.com",nocase; classtype:trojan-activity; sid:100004284; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kensingtondriving.com",nocase; classtype:trojan-activity; sid:100004285; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kevinjewelry.com.co",nocase; classtype:trojan-activity; sid:100004286; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"keywatch.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004287; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kingssa.co.za",nocase; classtype:trojan-activity; sid:100004288; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kjcpromo.com",nocase; classtype:trojan-activity; sid:100004289; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kleinendeli.co.za",nocase; classtype:trojan-activity; sid:100004290; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"korrectconceptservices.com",nocase; classtype:trojan-activity; sid:100004291; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ktb.sch.id",nocase; classtype:trojan-activity; sid:100004292; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kubatoglubaklava.com.tr",nocase; classtype:trojan-activity; sid:100004293; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kumaralok.in",nocase; classtype:trojan-activity; sid:100004294; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kwanfromhongkong.com",nocase; classtype:trojan-activity; sid:100004295; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kz.sldov.ru",nocase; classtype:trojan-activity; sid:100004296; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lacasadelosalebrijes.com",nocase; classtype:trojan-activity; sid:100004297; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ladylabonde.com",nocase; classtype:trojan-activity; sid:100004298; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lameguard.ru",nocase; classtype:trojan-activity; sid:100004299; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"landing.yetiapp.ec",nocase; classtype:trojan-activity; sid:100004300; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"laodongnhat.vn",nocase; classtype:trojan-activity; sid:100004301; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"laravel.pointersoftwares.com.br",nocase; classtype:trojan-activity; sid:100004302; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lasermobilesounds.co.uk",nocase; classtype:trojan-activity; sid:100004303; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lauratomismith.com",nocase; classtype:trojan-activity; sid:100004304; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lautarosanmiguel.com",nocase; classtype:trojan-activity; sid:100004305; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lawforall.edu.lk",nocase; classtype:trojan-activity; sid:100004306; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lceventos.net",nocase; classtype:trojan-activity; sid:100004307; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ld.mediaget.com",nocase; classtype:trojan-activity; sid:100004308; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ldgcorp.com",nocase; classtype:trojan-activity; sid:100004309; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"learning.real-academy.net",nocase; classtype:trojan-activity; sid:100004310; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"leasiacherise.com",nocase; classtype:trojan-activity; sid:100004311; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"leczkregoslup.acelero.pl",nocase; classtype:trojan-activity; sid:100004312; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"legend.nu",nocase; classtype:trojan-activity; sid:100004313; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"leluibuffet.com.br",nocase; classtype:trojan-activity; sid:100004314; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lestesteux.ca",nocase; classtype:trojan-activity; sid:100004315; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"libantravel.pl",nocase; classtype:trojan-activity; sid:100004316; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"library.arihantmbainstitute.ac.in",nocase; classtype:trojan-activity; sid:100004317; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"library.uib.ac.id",nocase; classtype:trojan-activity; sid:100004318; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lickmylash.com",nocase; classtype:trojan-activity; sid:100004319; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lidoraggiodisole.it",nocase; classtype:trojan-activity; sid:100004320; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lifebeam.elin.co.za",nocase; classtype:trojan-activity; sid:100004321; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lindnerelektroanlagen.de",nocase; classtype:trojan-activity; sid:100004322; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"linkintec.cn",nocase; classtype:trojan-activity; sid:100004323; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"litroxlitro.com",nocase; classtype:trojan-activity; sid:100004324; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"livetrack.in",nocase; classtype:trojan-activity; sid:100004325; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lloydsindian.co.uk",nocase; classtype:trojan-activity; sid:100004326; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lm.stagingarea.co.za",nocase; classtype:trojan-activity; sid:100004327; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lmaancha.co.il",nocase; classtype:trojan-activity; sid:100004328; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lms.cstdevs.com",nocase; classtype:trojan-activity; sid:100004329; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lms.login2.in",nocase; classtype:trojan-activity; sid:100004330; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lmvirtualbookkeeping.com",nocase; classtype:trojan-activity; sid:100004331; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lnt-rejuve-360.thakkers.in",nocase; classtype:trojan-activity; sid:100004332; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"location-voitures.ma",nocase; classtype:trojan-activity; sid:100004333; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"login.trezor.com.stockfootagesindia.com",nocase; classtype:trojan-activity; sid:100004334; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"logotypfabriken.se",nocase; classtype:trojan-activity; sid:100004335; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lotix.de",nocase; classtype:trojan-activity; sid:100004336; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lotusanddragonfly.com",nocase; classtype:trojan-activity; sid:100004337; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lp.definerisco.com",nocase; classtype:trojan-activity; sid:100004338; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lp.difusodesign.com",nocase; classtype:trojan-activity; sid:100004339; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lp.juancamilogarciareyes.com",nocase; classtype:trojan-activity; sid:100004340; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lp.tecnimasdecolombia.com.co",nocase; classtype:trojan-activity; sid:100004341; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"luckybrownie.com",nocase; classtype:trojan-activity; sid:100004342; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"luminouspneuma.com",nocase; classtype:trojan-activity; sid:100004343; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"luxomodels.com",nocase; classtype:trojan-activity; sid:100004344; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"m-technics.kz",nocase; classtype:trojan-activity; sid:100004345; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"m.estudiomoros.com.ar",nocase; classtype:trojan-activity; sid:100004346; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"madicon.co.za",nocase; classtype:trojan-activity; sid:100004347; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"magianegramagiablancayamarres.com",nocase; classtype:trojan-activity; sid:100004348; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mail.bs-eiendomme.co.za",nocase; classtype:trojan-activity; sid:100004349; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mail.jeffsono.org",nocase; classtype:trojan-activity; sid:100004350; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"maksi.feb.unib.ac.id",nocase; classtype:trojan-activity; sid:100004351; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"malaya.tv",nocase; classtype:trojan-activity; sid:100004352; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"malwarecoding.github.io",nocase; classtype:trojan-activity; sid:100004353; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"managed.oss-cn-beijing.aliyuncs.com",nocase; classtype:trojan-activity; sid:100004354; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"manantialesdelnorte.uy",nocase; classtype:trojan-activity; sid:100004355; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"manivelasst.com",nocase; classtype:trojan-activity; sid:100004356; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marcapinyo.ru",nocase; classtype:trojan-activity; sid:100004357; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marcusthepoet.com",nocase; classtype:trojan-activity; sid:100004358; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mario-sunjic.com",nocase; classtype:trojan-activity; sid:100004359; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mariobrown.net",nocase; classtype:trojan-activity; sid:100004360; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mariotessarollo.com",nocase; classtype:trojan-activity; sid:100004361; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marketinfosales.com",nocase; classtype:trojan-activity; sid:100004362; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marketing.enexusgroup.com.au",nocase; classtype:trojan-activity; sid:100004363; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marksidfgs.ug",nocase; classtype:trojan-activity; sid:100004364; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"masjidhabeebiyarazviya.mysunni.com",nocase; classtype:trojan-activity; sid:100004365; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"materialescantu.com",nocase; classtype:trojan-activity; sid:100004366; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"matinal-nominal.pt",nocase; classtype:trojan-activity; sid:100004367; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"matruchhaya.co.in",nocase; classtype:trojan-activity; sid:100004368; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mattysplayground.com",nocase; classtype:trojan-activity; sid:100004369; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"maxtox.com.pk",nocase; classtype:trojan-activity; sid:100004370; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mbgrm.com",nocase; classtype:trojan-activity; sid:100004371; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mbsolutions.ge",nocase; classtype:trojan-activity; sid:100004372; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mdasa.elin.co.za",nocase; classtype:trojan-activity; sid:100004373; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"medevlb.org",nocase; classtype:trojan-activity; sid:100004374; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"media-server.skyinternet.com.pk",nocase; classtype:trojan-activity; sid:100004375; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mediamaster.co.za",nocase; classtype:trojan-activity; sid:100004376; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"medianews.ge",nocase; classtype:trojan-activity; sid:100004377; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"medistaffconsulting.com",nocase; classtype:trojan-activity; sid:100004378; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"meeweb.com",nocase; classtype:trojan-activity; sid:100004379; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"megamart.afnan-amc.com",nocase; classtype:trojan-activity; sid:100004380; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"merbay.ru",nocase; classtype:trojan-activity; sid:100004381; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"merkathink.com",nocase; classtype:trojan-activity; sid:100004382; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mertlog.com",nocase; classtype:trojan-activity; sid:100004383; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"metalin-cr.com",nocase; classtype:trojan-activity; sid:100004384; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mettaanand.org",nocase; classtype:trojan-activity; sid:100004385; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"meuoculosnanet.com.br",nocase; classtype:trojan-activity; sid:100004386; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mfevr.com",nocase; classtype:trojan-activity; sid:100004387; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mhkdhotbot.myvnc.com",nocase; classtype:trojan-activity; sid:100004388; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mhkdhotbot80.myvnc.com",nocase; classtype:trojan-activity; sid:100004389; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"micalle.com.au",nocase; classtype:trojan-activity; sid:100004390; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"michaelphilip.com",nocase; classtype:trojan-activity; sid:100004391; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"michimal2.000webhostapp.com",nocase; classtype:trojan-activity; sid:100004392; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"microblading.mirliandias.com.br",nocase; classtype:trojan-activity; sid:100004393; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"microcomm-group.com",nocase; classtype:trojan-activity; sid:100004394; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"midlandtexasconstruction.com",nocase; classtype:trojan-activity; sid:100004395; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mindfulbuildingandliving.com",nocase; classtype:trojan-activity; sid:100004396; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mingguanwms.com",nocase; classtype:trojan-activity; sid:100004397; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"minuevavida.org",nocase; classtype:trojan-activity; sid:100004398; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mirror.mypage.sk",nocase; classtype:trojan-activity; sid:100004399; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mis.nbcc.ac.th",nocase; classtype:trojan-activity; sid:100004400; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"misterson.com",nocase; classtype:trojan-activity; sid:100004401; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mixr.at",nocase; classtype:trojan-activity; sid:100004402; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mkontakt.az",nocase; classtype:trojan-activity; sid:100004403; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mktf.mx",nocase; classtype:trojan-activity; sid:100004404; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mmogollon.com.mx",nocase; classtype:trojan-activity; sid:100004405; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mncarteam.com",nocase; classtype:trojan-activity; sid:100004406; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"modelhouseturkey.com",nocase; classtype:trojan-activity; sid:100004407; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"modernmanna.org",nocase; classtype:trojan-activity; sid:100004408; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"monetization.business",nocase; classtype:trojan-activity; sid:100004409; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"moninediy.com",nocase; classtype:trojan-activity; sid:100004410; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mopai.sg",nocase; classtype:trojan-activity; sid:100004411; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"motorcomunicacion.com",nocase; classtype:trojan-activity; sid:100004412; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mtspsmjeli.sch.id",nocase; classtype:trojan-activity; sid:100004413; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"muzimbiti.xigubo.co.mz",nocase; classtype:trojan-activity; sid:100004414; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mxpiqw.am.files.1drv.com",nocase; classtype:trojan-activity; sid:100004415; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mydatebook.in",nocase; classtype:trojan-activity; sid:100004416; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mymlql.com",nocase; classtype:trojan-activity; sid:100004417; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"myritz.vettickal.com",nocase; classtype:trojan-activity; sid:100004418; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"myscape.in",nocase; classtype:trojan-activity; sid:100004419; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mysura.it",nocase; classtype:trojan-activity; sid:100004420; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"namnyak.co.ke",nocase; classtype:trojan-activity; sid:100004421; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nap.mgsservers.com",nocase; classtype:trojan-activity; sid:100004422; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"navayurveda.in",nocase; classtype:trojan-activity; sid:100004423; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nec-i.com",nocase; classtype:trojan-activity; sid:100004424; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nelitrianggraeni.000webhostapp.com",nocase; classtype:trojan-activity; sid:100004425; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nerve.untergrund.net",nocase; classtype:trojan-activity; sid:100004426; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nettube.com.br",nocase; classtype:trojan-activity; sid:100004427; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"networkwheels.co.za",nocase; classtype:trojan-activity; sid:100004428; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"neuroenergy.fahadjutt.com",nocase; classtype:trojan-activity; sid:100004429; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"neuromedic.com.br",nocase; classtype:trojan-activity; sid:100004430; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"neverseenshop.com.mx",nocase; classtype:trojan-activity; sid:100004431; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newinfinitysynergy.com",nocase; classtype:trojan-activity; sid:100004432; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"news.dbstrony.pl",nocase; classtype:trojan-activity; sid:100004433; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newtreedesign.co.uk",nocase; classtype:trojan-activity; sid:100004434; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newtrendeg.com",nocase; classtype:trojan-activity; sid:100004435; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newvisionopticallab.com",nocase; classtype:trojan-activity; sid:100004436; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newxing.com",nocase; classtype:trojan-activity; sid:100004437; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nextdigitalday.ru",nocase; classtype:trojan-activity; sid:100004438; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ngdaycare.co.za",nocase; classtype:trojan-activity; sid:100004439; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nguyenkekhuyen.com",nocase; classtype:trojan-activity; sid:100004440; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nhorangtreem.com",nocase; classtype:trojan-activity; sid:100004441; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nicolas.ug",nocase; classtype:trojan-activity; sid:100004442; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nidhi.iexist.in",nocase; classtype:trojan-activity; sid:100004443; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nikanpolimer.ir",nocase; classtype:trojan-activity; sid:100004444; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nilinkeji.com",nocase; classtype:trojan-activity; sid:100004445; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nisacooks.com",nocase; classtype:trojan-activity; sid:100004446; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"njtiledesigncenter.com",nocase; classtype:trojan-activity; sid:100004447; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nobius.org",nocase; classtype:trojan-activity; sid:100004448; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nocalnoodle.elin.co.za",nocase; classtype:trojan-activity; sid:100004449; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nomadicbees.com",nocase; classtype:trojan-activity; sid:100004450; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nonnarina.ax",nocase; classtype:trojan-activity; sid:100004451; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"notamuzikaletleri.com",nocase; classtype:trojan-activity; sid:100004452; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"notif1.priruz.co.in",nocase; classtype:trojan-activity; sid:100004453; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ns1.the-widyantos.com",nocase; classtype:trojan-activity; sid:100004454; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nsb.org.uk",nocase; classtype:trojan-activity; sid:100004455; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nsheldon.co.uk",nocase; classtype:trojan-activity; sid:100004456; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nurmarkaz.org",nocase; classtype:trojan-activity; sid:100004457; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nuthuassociates.com",nocase; classtype:trojan-activity; sid:100004458; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nuwagi.com",nocase; classtype:trojan-activity; sid:100004459; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nyeh2o.com.au",nocase; classtype:trojan-activity; sid:100004460; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oakleyandfriends.co.uk",nocase; classtype:trojan-activity; sid:100004461; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"obseques-conseils.com",nocase; classtype:trojan-activity; sid:100004462; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ocean.tecnasulstore.com.br",nocase; classtype:trojan-activity; sid:100004463; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ohsewgorgeous.co.uk",nocase; classtype:trojan-activity; sid:100004464; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oleholeh.memangbeda.website",nocase; classtype:trojan-activity; sid:100004465; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"olirecords.mixture.ltd",nocase; classtype:trojan-activity; sid:100004466; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"olooom.com",nocase; classtype:trojan-activity; sid:100004467; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omaromatic.com",nocase; classtype:trojan-activity; sid:100004468; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omega.az",nocase; classtype:trojan-activity; sid:100004469; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oms.pappai.com",nocase; classtype:trojan-activity; sid:100004470; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omscoc.pappai.com",nocase; classtype:trojan-activity; sid:100004471; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedigitalcard.granvizionnecorp.com",nocase; classtype:trojan-activity; sid:100004472; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.listifyapp.co",nocase; classtype:trojan-activity; sid:100004473; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"online.creedglobal.in",nocase; classtype:trojan-activity; sid:100004474; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onlinestatis.bar",nocase; classtype:trojan-activity; sid:100004475; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"open.warehousesaas.co.uk",nocase; classtype:trojan-activity; sid:100004476; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"opolis.io",nocase; classtype:trojan-activity; sid:100004477; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"optimus.com.sg",nocase; classtype:trojan-activity; sid:100004478; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"optitechsa.co.za",nocase; classtype:trojan-activity; sid:100004479; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"order.bizpeed.com",nocase; classtype:trojan-activity; sid:100004480; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"orientgatewayltd.com",nocase; classtype:trojan-activity; sid:100004481; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"orion445.com",nocase; classtype:trojan-activity; sid:100004482; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ottimade.com",nocase; classtype:trojan-activity; sid:100004483; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ourteam.searchkero.com",nocase; classtype:trojan-activity; sid:100004484; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ozemag.com",nocase; classtype:trojan-activity; sid:100004485; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"p1.lingpao8.com",nocase; classtype:trojan-activity; sid:100004486; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"p3.zbjimg.com",nocase; classtype:trojan-activity; sid:100004487; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"p6.zbjimg.com",nocase; classtype:trojan-activity; sid:100004488; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pablobrothel.com.ar",nocase; classtype:trojan-activity; sid:100004489; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pacificgroup.ws",nocase; classtype:trojan-activity; sid:100004490; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pacwebdesigns.com",nocase; classtype:trojan-activity; sid:100004491; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pagos.krayem.com.mx",nocase; classtype:trojan-activity; sid:100004492; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"palochusvet.szm.com",nocase; classtype:trojan-activity; sid:100004493; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"parallel.rockvideos.at",nocase; classtype:trojan-activity; sid:100004494; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"parejasfelices.mi-fs.com",nocase; classtype:trojan-activity; sid:100004495; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"parkhussion.com",nocase; classtype:trojan-activity; sid:100004496; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pastorpaulocosta.com",nocase; classtype:trojan-activity; sid:100004497; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"patch2.51lg.com",nocase; classtype:trojan-activity; sid:100004498; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"patch2.99ddd.com",nocase; classtype:trojan-activity; sid:100004499; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"patch3.99ddd.com",nocase; classtype:trojan-activity; sid:100004500; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"paths.elin.co.za",nocase; classtype:trojan-activity; sid:100004501; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"paulmercier.biz",nocase; classtype:trojan-activity; sid:100004502; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"payerrealty.com",nocase; classtype:trojan-activity; sid:100004503; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pcsoori.com",nocase; classtype:trojan-activity; sid:100004504; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pd.oceaniarp.net",nocase; classtype:trojan-activity; sid:100004505; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"perpus.onlineman7-jombang.sch.id",nocase; classtype:trojan-activity; sid:100004506; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"perpustekim.untirta.ac.id",nocase; classtype:trojan-activity; sid:100004507; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pestoclean.co.uk",nocase; classtype:trojan-activity; sid:100004508; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"petercollie.com",nocase; classtype:trojan-activity; sid:100004509; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ph4s.ru",nocase; classtype:trojan-activity; sid:100004510; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"phenhuong.sanpham.online",nocase; classtype:trojan-activity; sid:100004511; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"phittc.com",nocase; classtype:trojan-activity; sid:100004512; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"photo360.kubooking.com",nocase; classtype:trojan-activity; sid:100004513; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"photographytipsclub.com",nocase; classtype:trojan-activity; sid:100004514; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pink99.com",nocase; classtype:trojan-activity; sid:100004515; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"plasfan.ind.br",nocase; classtype:trojan-activity; sid:100004516; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pmglance.startwriteup.com",nocase; classtype:trojan-activity; sid:100004517; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pokojewewladyslawowie.pl",nocase; classtype:trojan-activity; sid:100004518; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pole.com.vc",nocase; classtype:trojan-activity; sid:100004519; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pool.phxdir.com",nocase; classtype:trojan-activity; sid:100004520; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pooltablemoversdenver.net",nocase; classtype:trojan-activity; sid:100004521; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"posmicrosystems.com",nocase; classtype:trojan-activity; sid:100004522; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"poulman.panagiotopoulos-tours.gr",nocase; classtype:trojan-activity; sid:100004523; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ppdb.smk-ciptaskill.sch.id",nocase; classtype:trojan-activity; sid:100004524; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pptvideotemplates.com",nocase; classtype:trojan-activity; sid:100004525; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prestasicash.com.ar",nocase; classtype:trojan-activity; sid:100004526; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prestigehomeautomation.net",nocase; classtype:trojan-activity; sid:100004527; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prishaartcreations.com",nocase; classtype:trojan-activity; sid:100004528; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"production.sparshims.com",nocase; classtype:trojan-activity; sid:100004529; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"productprecise.com",nocase; classtype:trojan-activity; sid:100004530; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prof-dr-ahmedalmoatasem.com",nocase; classtype:trojan-activity; sid:100004531; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"programaoperadoronline.com.br",nocase; classtype:trojan-activity; sid:100004532; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"project.exquitec.com",nocase; classtype:trojan-activity; sid:100004533; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"promotoradescomplica.com.br",nocase; classtype:trojan-activity; sid:100004534; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"promoversdubai.com",nocase; classtype:trojan-activity; sid:100004535; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"propertiq.elin.co.za",nocase; classtype:trojan-activity; sid:100004536; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"propertiq2.elin.co.za",nocase; classtype:trojan-activity; sid:100004537; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prosoc.nl",nocase; classtype:trojan-activity; sid:100004538; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prostar.priruz.co.in",nocase; classtype:trojan-activity; sid:100004539; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prosyarmakassar.com",nocase; classtype:trojan-activity; sid:100004540; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"provence.elin.co.za",nocase; classtype:trojan-activity; sid:100004541; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prueba.danielluza.com",nocase; classtype:trojan-activity; sid:100004542; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pujashoppe.in",nocase; classtype:trojan-activity; sid:100004543; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"punchdialogues.com",nocase; classtype:trojan-activity; sid:100004544; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"punjabdevelopersassociation.com.pk",nocase; classtype:trojan-activity; sid:100004545; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"purefoe.top",nocase; classtype:trojan-activity; sid:100004546; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qadir.tickfa.ir",nocase; classtype:trojan-activity; sid:100004547; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qatarglobalconsulting.com",nocase; classtype:trojan-activity; sid:100004548; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qmsled.com",nocase; classtype:trojan-activity; sid:100004549; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"quartier-midi.be",nocase; classtype:trojan-activity; sid:100004550; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"querocar.com",nocase; classtype:trojan-activity; sid:100004551; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rachmat-assuhaimi.my.id",nocase; classtype:trojan-activity; sid:100004552; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rainbowisp.info",nocase; classtype:trojan-activity; sid:100004553; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raodigitalmedia.com",nocase; classtype:trojan-activity; sid:100004554; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rarlabarchiver.ac",nocase; classtype:trojan-activity; sid:100004555; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rasadbar.ir",nocase; classtype:trojan-activity; sid:100004556; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rashika.ascarvalho.co.za",nocase; classtype:trojan-activity; sid:100004557; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ratemyfenancialadvisor.com",nocase; classtype:trojan-activity; sid:100004558; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ravenproductionsltd.com",nocase; classtype:trojan-activity; sid:100004559; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rc.ixiaoyang.cn",nocase; classtype:trojan-activity; sid:100004560; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"readymmade.com",nocase; classtype:trojan-activity; sid:100004561; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"realtheprocess.co",nocase; classtype:trojan-activity; sid:100004562; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"redchillicrackers.com",nocase; classtype:trojan-activity; sid:100004563; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"reifenquick.de",nocase; classtype:trojan-activity; sid:100004564; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"relaxindulge.co.nz",nocase; classtype:trojan-activity; sid:100004565; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"renehavis.com.ua",nocase; classtype:trojan-activity; sid:100004566; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"repatriacioncolombia.com",nocase; classtype:trojan-activity; sid:100004567; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"res.uf1.cn",nocase; classtype:trojan-activity; sid:100004568; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"reseller.digimitra.in",nocase; classtype:trojan-activity; sid:100004569; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"resuco.net",nocase; classtype:trojan-activity; sid:100004570; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rezkabum.ru",nocase; classtype:trojan-activity; sid:100004571; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rhema.com.sg",nocase; classtype:trojan-activity; sid:100004572; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"richancyber.info",nocase; classtype:trojan-activity; sid:100004573; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"richmondminerals.co.zm",nocase; classtype:trojan-activity; sid:100004574; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rinaefoundation.org.za",nocase; classtype:trojan-activity; sid:100004575; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rinkaisystem-ht.com",nocase; classtype:trojan-activity; sid:100004576; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"riverfox.co.za",nocase; classtype:trojan-activity; sid:100004577; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rkcable.co.in",nocase; classtype:trojan-activity; sid:100004578; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rkverify.securestudies.com",nocase; classtype:trojan-activity; sid:100004579; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"roadfurylifts.com",nocase; classtype:trojan-activity; sid:100004580; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"robertmcardle.com",nocase; classtype:trojan-activity; sid:100004581; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"robertsinclair.net",nocase; classtype:trojan-activity; sid:100004582; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"robinhood-sports.com",nocase; classtype:trojan-activity; sid:100004583; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"romanianpoints.com",nocase; classtype:trojan-activity; sid:100004584; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ronnietucker.co.uk",nocase; classtype:trojan-activity; sid:100004585; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"roomsvc.servegate.kr",nocase; classtype:trojan-activity; sid:100004586; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"roshan.academy",nocase; classtype:trojan-activity; sid:100004587; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"roshnijewellery.com",nocase; classtype:trojan-activity; sid:100004588; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rs-toolkit.mikestclair.org",nocase; classtype:trojan-activity; sid:100004589; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rsgym.net",nocase; classtype:trojan-activity; sid:100004590; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rubazar.pro",nocase; classtype:trojan-activity; sid:100004591; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rubycityvietnam.com",nocase; classtype:trojan-activity; sid:100004592; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ruch.newreadermedia.net",nocase; classtype:trojan-activity; sid:100004593; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ruisgood.ru",nocase; classtype:trojan-activity; sid:100004594; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ruwadalkuwait.com",nocase; classtype:trojan-activity; sid:100004595; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rzminc.com",nocase; classtype:trojan-activity; sid:100004596; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"s.51shijuan.com",nocase; classtype:trojan-activity; sid:100004597; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"s.thechinesemuslim.com",nocase; classtype:trojan-activity; sid:100004598; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sacredscentsonline.com",nocase; classtype:trojan-activity; sid:100004599; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"safcol-colors.com",nocase; classtype:trojan-activity; sid:100004600; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"safehubsecurity.ca",nocase; classtype:trojan-activity; sid:100004601; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"safety.nanotechproautocare.com",nocase; classtype:trojan-activity; sid:100004602; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sahathaikasetpan.com",nocase; classtype:trojan-activity; sid:100004603; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"saisoftwareinc.com",nocase; classtype:trojan-activity; sid:100004604; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"salecorner.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004605; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sandovalgraphics.com",nocase; classtype:trojan-activity; sid:100004606; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"santebarleyshop.jakewebtechs.ml",nocase; classtype:trojan-activity; sid:100004607; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"santyago.org",nocase; classtype:trojan-activity; sid:100004608; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sarakem.cl",nocase; classtype:trojan-activity; sid:100004609; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sasystemsuk.com",nocase; classtype:trojan-activity; sid:100004610; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"savasaachi.systems",nocase; classtype:trojan-activity; sid:100004611; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"savingchintu.com",nocase; classtype:trojan-activity; sid:100004612; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"scarfaceindustries.com",nocase; classtype:trojan-activity; sid:100004613; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"scglobal.co.th",nocase; classtype:trojan-activity; sid:100004614; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"schalke04rss.de",nocase; classtype:trojan-activity; sid:100004615; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"scheff.com",nocase; classtype:trojan-activity; sid:100004616; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"schoolbustracker.softgig.co.ke",nocase; classtype:trojan-activity; sid:100004617; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sec-doc-w.com",nocase; classtype:trojan-activity; sid:100004618; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"secure-doc-reader.com",nocase; classtype:trojan-activity; sid:100004619; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sefp-boispro.fr",nocase; classtype:trojan-activity; sid:100004620; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"segalsmetals.elin.co.za",nocase; classtype:trojan-activity; sid:100004621; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sellmyphonela.com",nocase; classtype:trojan-activity; sid:100004622; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"selltechtoday.com",nocase; classtype:trojan-activity; sid:100004623; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"senbiaojita.com",nocase; classtype:trojan-activity; sid:100004624; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sentierodelviandante.ml",nocase; classtype:trojan-activity; sid:100004625; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"serendibsourcing.com",nocase; classtype:trojan-activity; sid:100004626; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"servicemhkd.myvnc.com",nocase; classtype:trojan-activity; sid:100004627; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"servicemhkd80.myvnc.com",nocase; classtype:trojan-activity; sid:100004628; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"serviciovirtual.com.ar",nocase; classtype:trojan-activity; sid:100004629; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"seyranikenger.com.tr",nocase; classtype:trojan-activity; sid:100004630; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sgessy.com.br",nocase; classtype:trojan-activity; sid:100004631; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shaheentbfoundation.com",nocase; classtype:trojan-activity; sid:100004632; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shahikhana.cstdevs.com",nocase; classtype:trojan-activity; sid:100004633; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sharkrigs.com",nocase; classtype:trojan-activity; sid:100004634; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sharpelevators.in",nocase; classtype:trojan-activity; sid:100004635; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shembefoundation.com",nocase; classtype:trojan-activity; sid:100004636; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shivakunwar.com.np",nocase; classtype:trojan-activity; sid:100004637; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shoblasaathitrust.org",nocase; classtype:trojan-activity; sid:100004638; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shooka-co.com",nocase; classtype:trojan-activity; sid:100004639; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shop.clarostudio.ro",nocase; classtype:trojan-activity; sid:100004640; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shop.goldspot.agency",nocase; classtype:trojan-activity; sid:100004641; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shopsofe.com",nocase; classtype:trojan-activity; sid:100004642; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shrushtiinfotech.com",nocase; classtype:trojan-activity; sid:100004643; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sibernetix.fr",nocase; classtype:trojan-activity; sid:100004644; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"siddharthpanditpautra.com",nocase; classtype:trojan-activity; sid:100004645; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sige.brisainformatica.com.br",nocase; classtype:trojan-activity; sid:100004646; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"signatureads.co.in",nocase; classtype:trojan-activity; sid:100004647; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"siili.net",nocase; classtype:trojan-activity; sid:100004648; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"simoneporzi.it",nocase; classtype:trojan-activity; sid:100004649; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"simplithy.co.uk",nocase; classtype:trojan-activity; sid:100004650; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sindicato1ucm.cl",nocase; classtype:trojan-activity; sid:100004651; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sinergidwireka.com",nocase; classtype:trojan-activity; sid:100004652; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sipahielektrik.com",nocase; classtype:trojan-activity; sid:100004653; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"siperb.in",nocase; classtype:trojan-activity; sid:100004654; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sistelligent.com",nocase; classtype:trojan-activity; sid:100004655; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"site.sjc.co.ke",nocase; classtype:trojan-activity; sid:100004656; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"skkksolo.beweiretail.com",nocase; classtype:trojan-activity; sid:100004657; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"skyflyfares.com",nocase; classtype:trojan-activity; sid:100004658; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"skyscan.com",nocase; classtype:trojan-activity; sid:100004659; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smarthouseforum.ru",nocase; classtype:trojan-activity; sid:100004660; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smarts.tj",nocase; classtype:trojan-activity; sid:100004661; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smartzedu.com",nocase; classtype:trojan-activity; sid:100004662; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smokeandgrowrichtour.com",nocase; classtype:trojan-activity; sid:100004663; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smokesolutionindia.com",nocase; classtype:trojan-activity; sid:100004664; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sobethuacademy.com",nocase; classtype:trojan-activity; sid:100004665; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"soft.110route.com",nocase; classtype:trojan-activity; sid:100004666; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"soft.officelabo.net",nocase; classtype:trojan-activity; sid:100004667; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sohs.conceptechs.info",nocase; classtype:trojan-activity; sid:100004668; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"solar.amazingtribe.lk",nocase; classtype:trojan-activity; sid:100004669; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"solo2.dbstrony.pl",nocase; classtype:trojan-activity; sid:100004670; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"somcorbera.cat",nocase; classtype:trojan-activity; sid:100004671; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"somir.com.mx",nocase; classtype:trojan-activity; sid:100004672; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"soralapps.com",nocase; classtype:trojan-activity; sid:100004673; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sorteio.orgaostalita.com.br",nocase; classtype:trojan-activity; sid:100004674; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sota-france.fr",nocase; classtype:trojan-activity; sid:100004675; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sowingminerals.cl",nocase; classtype:trojan-activity; sid:100004676; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"space.proactint.org",nocase; classtype:trojan-activity; sid:100004677; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spaceframe.mobi.space-frame.co.za",nocase; classtype:trojan-activity; sid:100004678; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"specfloors.net",nocase; classtype:trojan-activity; sid:100004679; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"special-key.cf",nocase; classtype:trojan-activity; sid:100004680; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spent.com.pl",nocase; classtype:trojan-activity; sid:100004681; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spetsesyachtcharter.gr",nocase; classtype:trojan-activity; sid:100004682; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spititourism.com",nocase; classtype:trojan-activity; sid:100004683; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spittinfire.com",nocase; classtype:trojan-activity; sid:100004684; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sports-net.de",nocase; classtype:trojan-activity; sid:100004685; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"src1.minibai.com",nocase; classtype:trojan-activity; sid:100004686; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sreenivasapaintingworks.com",nocase; classtype:trojan-activity; sid:100004687; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sriglobalit.com",nocase; classtype:trojan-activity; sid:100004688; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"srvmanos.no-ip.info",nocase; classtype:trojan-activity; sid:100004689; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ss.monita.co.id",nocase; classtype:trojan-activity; sid:100004690; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"staging.apparelpunch.com",nocase; classtype:trojan-activity; sid:100004691; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"starcountry.net",nocase; classtype:trojan-activity; sid:100004692; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"static.3001.net",nocase; classtype:trojan-activity; sid:100004693; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"statsres.com",nocase; classtype:trojan-activity; sid:100004694; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"statssound.com",nocase; classtype:trojan-activity; sid:100004695; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"statsspot.com",nocase; classtype:trojan-activity; sid:100004696; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"statsvilla.com",nocase; classtype:trojan-activity; sid:100004697; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stattilion.bar",nocase; classtype:trojan-activity; sid:100004698; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stiepancasetia.ac.id",nocase; classtype:trojan-activity; sid:100004699; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stott-thompson.co.uk",nocase; classtype:trojan-activity; sid:100004700; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stratexec.co.za",nocase; classtype:trojan-activity; sid:100004701; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"streetdemo.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004702; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"suboldesign.com",nocase; classtype:trojan-activity; sid:100004703; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sumerians.org",nocase; classtype:trojan-activity; sid:100004704; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sunbrero.com.au",nocase; classtype:trojan-activity; sid:100004705; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sunmarkholidays.com",nocase; classtype:trojan-activity; sid:100004706; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"supermercadostia.com",nocase; classtype:trojan-activity; sid:100004707; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"support-4-free.com",nocase; classtype:trojan-activity; sid:100004708; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"support.clz.kr",nocase; classtype:trojan-activity; sid:100004709; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"supportit.online",nocase; classtype:trojan-activity; sid:100004710; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sw.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004711; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sweaty.dk",nocase; classtype:trojan-activity; sid:100004712; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sweet-diet.com",nocase; classtype:trojan-activity; sid:100004713; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"swentsai.com",nocase; classtype:trojan-activity; sid:100004714; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"swiftlogisticseg.com",nocase; classtype:trojan-activity; sid:100004715; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"swwbia.com",nocase; classtype:trojan-activity; sid:100004716; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"syedpro.dezinetimes.com",nocase; classtype:trojan-activity; sid:100004717; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"syracusecoffee.com",nocase; classtype:trojan-activity; sid:100004718; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sys.pbmadu.co.id",nocase; classtype:trojan-activity; sid:100004719; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"systemsecuritylock.com",nocase; classtype:trojan-activity; sid:100004720; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sytraders.co",nocase; classtype:trojan-activity; sid:100004721; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"t.honker.info",nocase; classtype:trojan-activity; sid:100004722; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tacticohosting.com",nocase; classtype:trojan-activity; sid:100004723; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tadoo.ca",nocase; classtype:trojan-activity; sid:100004724; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tafsantoursandtravels.com",nocase; classtype:trojan-activity; sid:100004725; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tallyinvoicecustomization.com",nocase; classtype:trojan-activity; sid:100004726; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"taltus.co.uk",nocase; classtype:trojan-activity; sid:100004727; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tapalkoedacoffee.com",nocase; classtype:trojan-activity; sid:100004728; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tarravalleyfoods.com.au",nocase; classtype:trojan-activity; sid:100004729; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"taurus.ug",nocase; classtype:trojan-activity; sid:100004730; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"taxicabsrilanka.com",nocase; classtype:trojan-activity; sid:100004731; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"taxpos.com",nocase; classtype:trojan-activity; sid:100004732; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tc.snpsresidential.com",nocase; classtype:trojan-activity; sid:100004733; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tcy.198424.com",nocase; classtype:trojan-activity; sid:100004734; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tdsp.yngw518.com",nocase; classtype:trojan-activity; sid:100004735; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tech332.synology.me",nocase; classtype:trojan-activity; sid:100004736; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"techgms.com",nocase; classtype:trojan-activity; sid:100004737; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"technogreen.crmmanivela.com",nocase; classtype:trojan-activity; sid:100004738; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"technohub.searchkero.com",nocase; classtype:trojan-activity; sid:100004739; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tecnicaencolectores.com.mx",nocase; classtype:trojan-activity; sid:100004740; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"teduae.com",nocase; classtype:trojan-activity; sid:100004741; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"teleargentina.com",nocase; classtype:trojan-activity; sid:100004742; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"telescopelms.com",nocase; classtype:trojan-activity; sid:100004743; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"telmed.cl",nocase; classtype:trojan-activity; sid:100004744; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"temptmag.com",nocase; classtype:trojan-activity; sid:100004745; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tennisafrica.com",nocase; classtype:trojan-activity; sid:100004746; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tentandoserfitness.000webhostapp.com",nocase; classtype:trojan-activity; sid:100004747; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tepresto.net.pe",nocase; classtype:trojan-activity; sid:100004748; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.adventser.com",nocase; classtype:trojan-activity; sid:100004749; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.letraele.es",nocase; classtype:trojan-activity; sid:100004750; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.wanepghana.org",nocase; classtype:trojan-activity; sid:100004751; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test1.asistencia247.com",nocase; classtype:trojan-activity; sid:100004752; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test1.milenial.id",nocase; classtype:trojan-activity; sid:100004753; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test1.tenplusone.my",nocase; classtype:trojan-activity; sid:100004754; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test2.basis-web.com",nocase; classtype:trojan-activity; sid:100004755; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test2.marrenconstruction.ie",nocase; classtype:trojan-activity; sid:100004756; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"testing.clickitsolutionsmw.com",nocase; classtype:trojan-activity; sid:100004757; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"testing.thinkingcorp.in",nocase; classtype:trojan-activity; sid:100004758; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"testnew.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004759; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"teteaffiche.stephanebillon.com",nocase; classtype:trojan-activity; sid:100004760; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tewoerd.eu",nocase; classtype:trojan-activity; sid:100004761; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"textile.softberg.ro",nocase; classtype:trojan-activity; sid:100004762; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"texts.bfftexts.com",nocase; classtype:trojan-activity; sid:100004763; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"texturesbyvinita.com",nocase; classtype:trojan-activity; sid:100004764; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tharringtonsponsorship.com",nocase; classtype:trojan-activity; sid:100004765; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thecleaningladiespdx.com",nocase; classtype:trojan-activity; sid:100004766; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thecreativecafe.co.uk",nocase; classtype:trojan-activity; sid:100004767; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thefuturelife.in",nocase; classtype:trojan-activity; sid:100004768; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thehighlightinterior.com",nocase; classtype:trojan-activity; sid:100004769; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thehouseofpragya.com",nocase; classtype:trojan-activity; sid:100004770; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thekassia.co.uk",nocase; classtype:trojan-activity; sid:100004771; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thelaunchpadteam.com",nocase; classtype:trojan-activity; sid:100004772; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thelekhak.com",nocase; classtype:trojan-activity; sid:100004773; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thelogicalgroup.co.uk",nocase; classtype:trojan-activity; sid:100004774; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thesummitpc.net",nocase; classtype:trojan-activity; sid:100004775; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"theurbantutors.com",nocase; classtype:trojan-activity; sid:100004776; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thosewebbs.com",nocase; classtype:trojan-activity; sid:100004777; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thriveink.com",nocase; classtype:trojan-activity; sid:100004778; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tianangdep.com",nocase; classtype:trojan-activity; sid:100004779; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tickfood.tickme.lk",nocase; classtype:trojan-activity; sid:100004780; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tickjobs.tickme.lk",nocase; classtype:trojan-activity; sid:100004781; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tickmart.tickme.lk",nocase; classtype:trojan-activity; sid:100004782; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"timegonebuy.com",nocase; classtype:trojan-activity; sid:100004783; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tksb.net",nocase; classtype:trojan-activity; sid:100004784; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tlcc.com.gt",nocase; classtype:trojan-activity; sid:100004785; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"todoapp.cstdevs.com",nocase; classtype:trojan-activity; sid:100004786; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tonydong.com",nocase; classtype:trojan-activity; sid:100004787; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tonyzone.com",nocase; classtype:trojan-activity; sid:100004788; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tooba.tenplusone.my",nocase; classtype:trojan-activity; sid:100004789; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"topcell9.com",nocase; classtype:trojan-activity; sid:100004790; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"topicsnepal.com",nocase; classtype:trojan-activity; sid:100004791; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"toplevel.com.br",nocase; classtype:trojan-activity; sid:100004792; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"torresquinterocorp.com",nocase; classtype:trojan-activity; sid:100004793; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"towme.services",nocase; classtype:trojan-activity; sid:100004794; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"toyotacollege.ac.th",nocase; classtype:trojan-activity; sid:100004795; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tpef.lsoftdemo.com",nocase; classtype:trojan-activity; sid:100004796; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tpke.hu",nocase; classtype:trojan-activity; sid:100004797; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tradezone.ejuicysolutions.com",nocase; classtype:trojan-activity; sid:100004798; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"translaterjemah.com",nocase; classtype:trojan-activity; sid:100004799; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"travel.travelwadi.com",nocase; classtype:trojan-activity; sid:100004800; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"travelwithmanta.co.za",nocase; classtype:trojan-activity; sid:100004801; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"trezors.io.mahlongwa.com",nocase; classtype:trojan-activity; sid:100004802; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"triplonet.com.br",nocase; classtype:trojan-activity; sid:100004803; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"troki.com.co",nocase; classtype:trojan-activity; sid:100004804; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tropics.codeleek.net",nocase; classtype:trojan-activity; sid:100004805; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"trudelfavreau.com",nocase; classtype:trojan-activity; sid:100004806; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tsd.jxwan.com",nocase; classtype:trojan-activity; sid:100004807; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tulli.info",nocase; classtype:trojan-activity; sid:100004808; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tupperware.michaelroberge.ca",nocase; classtype:trojan-activity; sid:100004809; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"turanggaresources.com",nocase; classtype:trojan-activity; sid:100004810; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tushartyagiji.digitalswagger.in",nocase; classtype:trojan-activity; sid:100004811; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uat.indianfilmzone.com",nocase; classtype:trojan-activity; sid:100004812; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ublretailerdemo.cstdevs.com",nocase; classtype:trojan-activity; sid:100004813; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"udesk.searchkero.com",nocase; classtype:trojan-activity; sid:100004814; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ugprs-ubih.org",nocase; classtype:trojan-activity; sid:100004815; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ultimate-24.de",nocase; classtype:trojan-activity; sid:100004816; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"umwelt-kirchhof.de",nocase; classtype:trojan-activity; sid:100004817; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"unicorpbrunei.com",nocase; classtype:trojan-activity; sid:100004818; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uniengrisb.com",nocase; classtype:trojan-activity; sid:100004819; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"unisoftcc.com",nocase; classtype:trojan-activity; sid:100004820; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"unitedpestsolutionstx.com",nocase; classtype:trojan-activity; sid:100004821; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"unyazitelecom.com",nocase; classtype:trojan-activity; sid:100004822; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"upcbpta.com",nocase; classtype:trojan-activity; sid:100004823; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"urbane.dezinetimes.com",nocase; classtype:trojan-activity; sid:100004824; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"useformoney.000webhostapp.com",nocase; classtype:trojan-activity; sid:100004825; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"usmadetshirts.com",nocase; classtype:trojan-activity; sid:100004826; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uss.ac.th",nocase; classtype:trojan-activity; sid:100004827; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uzzepay.com.br",nocase; classtype:trojan-activity; sid:100004828; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vanzare.cabanabrazi2.ro",nocase; classtype:trojan-activity; sid:100004829; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vbcargo.hu",nocase; classtype:trojan-activity; sid:100004830; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vcah.co.uk",nocase; classtype:trojan-activity; sid:100004831; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vegadelcasero.cl",nocase; classtype:trojan-activity; sid:100004832; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vendas.lidiacarmeli.com.br",nocase; classtype:trojan-activity; sid:100004833; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"verify.aicosoft.com",nocase; classtype:trojan-activity; sid:100004834; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vfocus.net",nocase; classtype:trojan-activity; sid:100004835; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vidmattic.com",nocase; classtype:trojan-activity; sid:100004836; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vienen.gblix.srv.br",nocase; classtype:trojan-activity; sid:100004837; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"villamarand.com",nocase; classtype:trojan-activity; sid:100004838; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"villatera.com",nocase; classtype:trojan-activity; sid:100004839; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"violinstop.com",nocase; classtype:trojan-activity; sid:100004840; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"viraltalking.com",nocase; classtype:trojan-activity; sid:100004841; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"visions.alnisamart.com",nocase; classtype:trojan-activity; sid:100004842; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"visualhome.cl",nocase; classtype:trojan-activity; sid:100004843; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vitoriamodaintima.com.br",nocase; classtype:trojan-activity; sid:100004844; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vivationdesign.com",nocase; classtype:trojan-activity; sid:100004845; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"viveirodoiscorregos.com.br",nocase; classtype:trojan-activity; sid:100004846; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vksales.com",nocase; classtype:trojan-activity; sid:100004847; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vokasi.ub.ac.id",nocase; classtype:trojan-activity; sid:100004848; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vologroup.com.br",nocase; classtype:trojan-activity; sid:100004849; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"voteyouramerica.dekitout.com",nocase; classtype:trojan-activity; sid:100004850; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vstsample.com",nocase; classtype:trojan-activity; sid:100004851; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vtube.fadlymotivator.com",nocase; classtype:trojan-activity; sid:100004852; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vvsskmodinationalschool.com",nocase; classtype:trojan-activity; sid:100004853; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wahrewah.nl",nocase; classtype:trojan-activity; sid:100004854; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wanepliberia.org",nocase; classtype:trojan-activity; sid:100004855; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wanepniger.org",nocase; classtype:trojan-activity; sid:100004856; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"weareactum.com",nocase; classtype:trojan-activity; sid:100004857; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.eng.ubu.ac.th",nocase; classtype:trojan-activity; sid:100004858; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.geomegasoft.net",nocase; classtype:trojan-activity; sid:100004859; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.newinnovationtechnology.com",nocase; classtype:trojan-activity; sid:100004860; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.smarts-works.com",nocase; classtype:trojan-activity; sid:100004861; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.thebeessolution.com",nocase; classtype:trojan-activity; sid:100004862; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"webgis.perumdasolo.com",nocase; classtype:trojan-activity; sid:100004863; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"webmailwindstreamnetmessagesecureapp1rqr.ga",nocase; classtype:trojan-activity; sid:100004864; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"webpresario.com",nocase; classtype:trojan-activity; sid:100004865; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"website-work.com",nocase; classtype:trojan-activity; sid:100004866; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"weinsteincounseling.com",nocase; classtype:trojan-activity; sid:100004867; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wexfashion.com",nocase; classtype:trojan-activity; sid:100004868; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"whcms.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004869; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"whiteglovetailgate.com",nocase; classtype:trojan-activity; sid:100004870; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"whiteresponse.com",nocase; classtype:trojan-activity; sid:100004871; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wi522012.ferozo.com",nocase; classtype:trojan-activity; sid:100004872; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wikalen.co.za",nocase; classtype:trojan-activity; sid:100004873; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wildnights.co.uk",nocase; classtype:trojan-activity; sid:100004874; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wildtrust.mediadevstaging.com",nocase; classtype:trojan-activity; sid:100004875; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wimbamusica.com",nocase; classtype:trojan-activity; sid:100004876; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"windcomtechnologies.com",nocase; classtype:trojan-activity; sid:100004877; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"winnercircle.it",nocase; classtype:trojan-activity; sid:100004878; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wishesconcierge.com",nocase; classtype:trojan-activity; sid:100004879; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"woezon.agency",nocase; classtype:trojan-activity; sid:100004880; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wolfgang-brodte.de",nocase; classtype:trojan-activity; sid:100004881; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"woodsytech.com",nocase; classtype:trojan-activity; sid:100004882; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wordpress.saleensuporte.com.br",nocase; classtype:trojan-activity; sid:100004883; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wozata.000webhostapp.com",nocase; classtype:trojan-activity; sid:100004884; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wp.readhere.in",nocase; classtype:trojan-activity; sid:100004885; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wpdemo.101clients.com.au",nocase; classtype:trojan-activity; sid:100004886; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"writtendeer.com",nocase; classtype:trojan-activity; sid:100004887; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ws5588.f3322.net",nocase; classtype:trojan-activity; sid:100004888; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wyklej.pl",nocase; classtype:trojan-activity; sid:100004889; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"x2vn.com",nocase; classtype:trojan-activity; sid:100004890; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xia.beihaixue.com",nocase; classtype:trojan-activity; sid:100004891; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xixaoclothing.com",nocase; classtype:trojan-activity; sid:100004892; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xk.996is.com",nocase; classtype:trojan-activity; sid:100004893; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xmp.myracingaccounts.com",nocase; classtype:trojan-activity; sid:100004894; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xn--80akinnkiib6h.xn--90ais",nocase; classtype:trojan-activity; sid:100004895; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xn--polimerbizmimarlk-rvc.com",nocase; classtype:trojan-activity; sid:100004896; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ybom.urbanolab.com",nocase; classtype:trojan-activity; sid:100004897; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yeichner.com",nocase; classtype:trojan-activity; sid:100004898; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ylfpremium.com",nocase; classtype:trojan-activity; sid:100004899; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yoast.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004900; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"youtubetrainingacademy.com",nocase; classtype:trojan-activity; sid:100004901; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yskadvisors.com",nocase; classtype:trojan-activity; sid:100004902; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yummyyogaudaipur.com",nocase; classtype:trojan-activity; sid:100004903; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yzkzixun.com",nocase; classtype:trojan-activity; sid:100004904; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"zytrox.tk",nocase; classtype:trojan-activity; sid:100004905; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"zz.690tx.com",nocase; classtype:trojan-activity; sid:100004906; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.indexsinas.me:811",nocase; http_uri; content:"/64.exe",nocase; classtype:trojan-activity; sid:100004907; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.indexsinas.me:811",nocase; http_uri; content:"/86.exe",nocase; classtype:trojan-activity; sid:100004908; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.indexsinas.me:811",nocase; http_uri; content:"/c64.exe",nocase; classtype:trojan-activity; sid:100004909; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"akwer03.top",nocase; http_uri; content:"/downfiles/file.exe",nocase; classtype:trojan-activity; sid:100004910; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amumufree.weebly.com",nocase; http_uri; content:"/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe",nocase; classtype:trojan-activity; sid:100004911; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"analogx.com",nocase; http_uri; content:"/files/proxyi.exe",nocase; classtype:trojan-activity; sid:100004912; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe",nocase; classtype:trojan-activity; sid:100004913; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/densjons/bro/downloads/rew.exe",nocase; classtype:trojan-activity; sid:100004914; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/dvdfv/anjj/downloads/jami.exe",nocase; classtype:trojan-activity; sid:100004915; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/jpavelski/chpock/downloads/4.exe",nocase; classtype:trojan-activity; sid:100004916; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/jpavelski/chpock/downloads/6.exe",nocase; classtype:trojan-activity; sid:100004917; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/clr.exe",nocase; classtype:trojan-activity; sid:100004918; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/clr3.exe",nocase; classtype:trojan-activity; sid:100004919; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/instaler.exe",nocase; classtype:trojan-activity; sid:100004920; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/installer.exe",nocase; classtype:trojan-activity; sid:100004921; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/updatej.exe",nocase; classtype:trojan-activity; sid:100004922; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/updatev.exe",nocase; classtype:trojan-activity; sid:100004923; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/work.exe",nocase; classtype:trojan-activity; sid:100004924; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/player2012/rumpa1/downloads/component.exe",nocase; classtype:trojan-activity; sid:100004925; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/player2012/rumpa1/downloads/nordvpnsetup.exe",nocase; classtype:trojan-activity; sid:100004926; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/player2012/rumpa1/downloads/regsvc.exe",nocase; classtype:trojan-activity; sid:100004927; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/skygaming/updates/downloads/update.exe",nocase; classtype:trojan-activity; sid:100004928; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/001.txt",nocase; classtype:trojan-activity; sid:100004929; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1488.txt",nocase; classtype:trojan-activity; sid:100004930; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1_cr.txt",nocase; classtype:trojan-activity; sid:100004931; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1cr.txt",nocase; classtype:trojan-activity; sid:100004932; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1fc2d.txt",nocase; classtype:trojan-activity; sid:100004933; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/26a5.txt",nocase; classtype:trojan-activity; sid:100004934; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/6e7_2021-01-19_18-04.txt",nocase; classtype:trojan-activity; sid:100004935; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/abjects.txt",nocase; classtype:trojan-activity; sid:100004936; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/attached.txt",nocase; classtype:trojan-activity; sid:100004937; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/b7f2c.exe",nocase; classtype:trojan-activity; sid:100004938; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/battletext.txt",nocase; classtype:trojan-activity; sid:100004939; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/bkghj_nowin.exe",nocase; classtype:trojan-activity; sid:100004940; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/bsdasdasd333.exe",nocase; classtype:trojan-activity; sid:100004941; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build.txt",nocase; classtype:trojan-activity; sid:100004942; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build_makros.exe",nocase; classtype:trojan-activity; sid:100004943; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build_silent.txt",nocase; classtype:trojan-activity; sid:100004944; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build_sup.txt",nocase; classtype:trojan-activity; sid:100004945; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildcmobiler.exe",nocase; classtype:trojan-activity; sid:100004946; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildcmobiler.txt",nocase; classtype:trojan-activity; sid:100004947; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildcr.txt",nocase; classtype:trojan-activity; sid:100004948; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildss.txt",nocase; classtype:trojan-activity; sid:100004949; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/clientnik.txt",nocase; classtype:trojan-activity; sid:100004950; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/clientrevers.txt",nocase; classtype:trojan-activity; sid:100004951; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/dcrat.exe",nocase; classtype:trojan-activity; sid:100004952; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/dllservices.exe",nocase; classtype:trojan-activity; sid:100004953; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/dllservices2.exe",nocase; classtype:trojan-activity; sid:100004954; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/exe_morris.mcdermott.exe",nocase; classtype:trojan-activity; sid:100004955; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/hans.txt",nocase; classtype:trojan-activity; sid:100004956; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/hulu.txt",nocase; classtype:trojan-activity; sid:100004957; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelfive.txt",nocase; classtype:trojan-activity; sid:100004958; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelfour.txt",nocase; classtype:trojan-activity; sid:100004959; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelone.txt",nocase; classtype:trojan-activity; sid:100004960; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelthree.txt",nocase; classtype:trojan-activity; sid:100004961; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/inteltwo.txt",nocase; classtype:trojan-activity; sid:100004962; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/jjuufksfn.exe",nocase; classtype:trojan-activity; sid:100004963; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/kleiman.exe",nocase; classtype:trojan-activity; sid:100004964; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/lucky_fixed.exe",nocase; classtype:trojan-activity; sid:100004965; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/notepadplus.txt",nocase; classtype:trojan-activity; sid:100004966; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/osiris_qqkz_nauto.exe",nocase; classtype:trojan-activity; sid:100004967; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/out.exe",nocase; classtype:trojan-activity; sid:100004968; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/out.txt",nocase; classtype:trojan-activity; sid:100004969; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/pacbe_bin.txt",nocase; classtype:trojan-activity; sid:100004970; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/putty.txt",nocase; classtype:trojan-activity; sid:100004971; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/rockethcd.txt",nocase; classtype:trojan-activity; sid:100004972; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/scvhost900.exe",nocase; classtype:trojan-activity; sid:100004973; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/sessionwin.exe",nocase; classtype:trojan-activity; sid:100004974; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/siliculose.txt",nocase; classtype:trojan-activity; sid:100004975; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/statemobi.txt",nocase; classtype:trojan-activity; sid:100004976; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/stealers.exe",nocase; classtype:trojan-activity; sid:100004977; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/stealers2.exe",nocase; classtype:trojan-activity; sid:100004978; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/stgedo.exe",nocase; classtype:trojan-activity; sid:100004979; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/svcperf.txt",nocase; classtype:trojan-activity; sid:100004980; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/symptomaticshon5.exe",nocase; classtype:trojan-activity; sid:100004981; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/taurjok.txt",nocase; classtype:trojan-activity; sid:100004982; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/taurusbabac.exe",nocase; classtype:trojan-activity; sid:100004983; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/telekiller.exe",nocase; classtype:trojan-activity; sid:100004984; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/updateanddr.txt",nocase; classtype:trojan-activity; sid:100004985; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/updateandr.txt",nocase; classtype:trojan-activity; sid:100004986; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/vhajeja.txt",nocase; classtype:trojan-activity; sid:100004987; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/word.txt",nocase; classtype:trojan-activity; sid:100004988; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/www.txt",nocase; classtype:trojan-activity; sid:100004989; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/xlsd.txt",nocase; classtype:trojan-activity; sid:100004990; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/teaserex/tease/downloads/b_kfmhkk172.bin",nocase; classtype:trojan-activity; sid:100004991; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/teaserex/tease/downloads/macro_xmprohiq27.bin",nocase; classtype:trojan-activity; sid:100004992; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cd.textfiles.com",nocase; http_uri; content:"/hmatrix/data/hack1226.exe",nocase; classtype:trojan-activity; sid:100004993; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq",nocase; classtype:trojan-activity; sid:100004994; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/816070119281131570/816070273254162442/all.txt",nocase; classtype:trojan-activity; sid:100004995; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/823355293043261515/823692323514482788/inquiry_-_rfq_hmg_u66_sw5558_pdf.iso",nocase; classtype:trojan-activity; sid:100004996; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chiptune.com",nocase; http_uri; content:"/razor/rzr-winner_intro.zip",nocase; classtype:trojan-activity; sid:100004997; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cloudme.com",nocase; http_uri; content:"/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz",nocase; classtype:trojan-activity; sid:100004998; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cloudme.com",nocase; http_uri; content:"/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar",nocase; classtype:trojan-activity; sid:100004999; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"codeload.github.com",nocase; http_uri; content:"/meteoradminz/hidden-tear/zip/master",nocase; classtype:trojan-activity; sid:100005000; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"colfincas.com",nocase; http_uri; content:"/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/",nocase; classtype:trojan-activity; sid:100005001; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"d.ttr3p.com",nocase; http_uri; content:"/kr.bin",nocase; classtype:trojan-activity; sid:100005002; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"deepfreedom.org",nocase; http_uri; content:"/qz0h69.pdf",nocase; classtype:trojan-activity; sid:100005003; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com.it-barcelona.com",nocase; http_uri; content:"/frm0reseen/prntscrnofamzorderid.jpg.exe",nocase; classtype:trojan-activity; sid:100005004; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=0byfg0_4xbjgnwvuyev9ltuh4rmm",nocase; classtype:trojan-activity; sid:100005005; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=13vodfxml9fg8kcnexuafh64dzmnqv8ch",nocase; classtype:trojan-activity; sid:100005006; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=14l8sj2dqo04ozum88tvuy74yfcwk5fnf",nocase; classtype:trojan-activity; sid:100005007; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=15bd1dksg4pkrxehoczi7e0uok4vblz4e",nocase; classtype:trojan-activity; sid:100005008; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=167imxqgc8ehepa1gisxa6q6ifcjxceox",nocase; classtype:trojan-activity; sid:100005009; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=17xvn-rlhei5n9f6unuqqb_wh84u4w5cx",nocase; classtype:trojan-activity; sid:100005010; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1_vz7veeec-juwt23g9d9wjuid2kusew7",nocase; classtype:trojan-activity; sid:100005011; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1a-herfdxr6xamxeabcdao0mqw9bimrig",nocase; classtype:trojan-activity; sid:100005012; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1aphk_vq7gtn368zxpd5bg5rv8nk0bnhn",nocase; classtype:trojan-activity; sid:100005013; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1aqhdbelnscyjygigfopt7x_oafaqgwg1",nocase; classtype:trojan-activity; sid:100005014; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1cf8d3ljsfn3toddczqtkkbhrd5g00cjg",nocase; classtype:trojan-activity; sid:100005015; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben",nocase; classtype:trojan-activity; sid:100005016; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1cynoc3t9rp-xvso3jcmx_prwppp8u-dv",nocase; classtype:trojan-activity; sid:100005017; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1d8fykmpewc_4yurihjh_cdehkdp_nuik",nocase; classtype:trojan-activity; sid:100005018; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1dgcin9vevl9f63cbhbkmc_gpa2b0zlrh",nocase; classtype:trojan-activity; sid:100005019; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1do7c-fjuscbueu0un2dbxe3-pnwdufb_",nocase; classtype:trojan-activity; sid:100005020; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1eqnvgn0qkunp7t6crk8oj7_e7rh5qxwi",nocase; classtype:trojan-activity; sid:100005021; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1f3kxfcvbpaaexgnchpvmyoxkcdmickjj",nocase; classtype:trojan-activity; sid:100005022; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1gsmk1t_yigh7jablxkuhbmmh93vwgikb",nocase; classtype:trojan-activity; sid:100005023; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1hmud67vsl-shqddzpxniqmyj92iynyis",nocase; classtype:trojan-activity; sid:100005024; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1ik-x4_bsr5dbocs9j1ryg1ybw75fqu8t",nocase; classtype:trojan-activity; sid:100005025; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1in-rhdrss2qsjqj8xffb1hbwi9znp4je",nocase; classtype:trojan-activity; sid:100005026; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1iwc-lf99neesk6mvvo2al4futbmyoiev",nocase; classtype:trojan-activity; sid:100005027; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr",nocase; classtype:trojan-activity; sid:100005028; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1jgykopezccdq3q5qprmkl1zdl1auymkq",nocase; classtype:trojan-activity; sid:100005029; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1lplk8rixxuboakkmut_qgzn92bkoulna",nocase; classtype:trojan-activity; sid:100005030; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1mug8m5o6kl_bx68x8cuxmzhn0gxnc7ki",nocase; classtype:trojan-activity; sid:100005031; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1n8o4hbvi7o9ks9jqhofny7okposfaz4y",nocase; classtype:trojan-activity; sid:100005032; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1nindqtjvyyzz-qk-hqa9gls5ccwhys-e",nocase; classtype:trojan-activity; sid:100005033; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1nio_cdsggt4zv1kdrpubrfpd0pzsyffd",nocase; classtype:trojan-activity; sid:100005034; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1nsyqwodoi1t9-i29arbxwe7fkafjydsz",nocase; classtype:trojan-activity; sid:100005035; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1nwctbvlr_1bewpvgdbmuhnny-zi6kp1l",nocase; classtype:trojan-activity; sid:100005036; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1o2dcrdwgu91moicmterbx9avcl9cavy1",nocase; classtype:trojan-activity; sid:100005037; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1o4lh97cmfnztr_hkocnwiucy5l6oskpy",nocase; classtype:trojan-activity; sid:100005038; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1oabvvnazifkxktvt-izbcdqpb7dm6nrw",nocase; classtype:trojan-activity; sid:100005039; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1oys1nkexzsuci6pfghowlbpwaw-_btxk",nocase; classtype:trojan-activity; sid:100005040; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1prxtn1juykhcr_9ilw-vtirv5anyeoej",nocase; classtype:trojan-activity; sid:100005041; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1pzywywxrwl2plk82nuodgvmcckpzrufb",nocase; classtype:trojan-activity; sid:100005042; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1q0uxhnzfs4j91rxz5x45iov8tjkomsgr",nocase; classtype:trojan-activity; sid:100005043; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1q9vzzhu-n9cu8ixdginpzaxxgvb1lrjv",nocase; classtype:trojan-activity; sid:100005044; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1qk8_jouqbnrfkky7x1aqunudfyl6fjii",nocase; classtype:trojan-activity; sid:100005045; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1qxv3i0dwy_cdx2bm1lqx6ef0qjwmhbpk",nocase; classtype:trojan-activity; sid:100005046; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1qzmi4jvter0_cwexcp4grjhxvr7lep5k",nocase; classtype:trojan-activity; sid:100005047; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1r-kstukxtxjqxlwypgd764dw-puj_7fz",nocase; classtype:trojan-activity; sid:100005048; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1r-zn6o95qzworq8e4fhz637bfuoxayby",nocase; classtype:trojan-activity; sid:100005049; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1rcykjynwhlc487sn1vwcsmjse_ctlrox",nocase; classtype:trojan-activity; sid:100005050; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1rdxnm_kxegbwlojlucu4qiff7kyax3oi",nocase; classtype:trojan-activity; sid:100005051; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1s9tu6akdxquy7cezquljtb2yarci99ab",nocase; classtype:trojan-activity; sid:100005052; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1serasql3bw7nc-sllzyrishnhodmefyf",nocase; classtype:trojan-activity; sid:100005053; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1shuxviwx167elbuz8mfcjc2bk99zzov_",nocase; classtype:trojan-activity; sid:100005054; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1sjzynfvpwdcwsr1p3w_q8-6ktsqiwadx",nocase; classtype:trojan-activity; sid:100005055; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1sogqqdapgyioillf7u62widsprhw3cjh",nocase; classtype:trojan-activity; sid:100005056; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1t1bd_itjnhsmozdl9was0gouehujm1fn",nocase; classtype:trojan-activity; sid:100005057; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1tfra7fzrjl2vdj73hcmcru5ynuqmz61g",nocase; classtype:trojan-activity; sid:100005058; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1tsmbsikhechaqedk6nktlfzasus_tghw",nocase; classtype:trojan-activity; sid:100005059; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1ur9qebooqc-mjcdzn9wcbavocumdlosm",nocase; classtype:trojan-activity; sid:100005060; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1uvtmu3-hcryp3rskqnpkiodcjuchtz55",nocase; classtype:trojan-activity; sid:100005061; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1v4ima0sfnmboxmyoklp4g0_uehaj22x2",nocase; classtype:trojan-activity; sid:100005062; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1vevblftithattyguwyjot1p0wptg7l5t",nocase; classtype:trojan-activity; sid:100005063; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1vl9gje5llm7ja3dadct9okr6bzbmijc3",nocase; classtype:trojan-activity; sid:100005064; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1vvvujegfrgey39w6y3ybwpptl1guwf8a",nocase; classtype:trojan-activity; sid:100005065; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1ws2ptumptku-imi9sv_k5g4fhsx30gnl",nocase; classtype:trojan-activity; sid:100005066; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1wtxdbb1fm9ozinx09a63-o-tn4ssgzpw",nocase; classtype:trojan-activity; sid:100005067; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1xbeqbw67xz4iqpu8dgmdrlkpa6kzotes",nocase; classtype:trojan-activity; sid:100005068; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1xdpxbb9gifdrugqxmg2_06xygbfq-x2k",nocase; classtype:trojan-activity; sid:100005069; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e",nocase; classtype:trojan-activity; sid:100005070; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1xu9wvl5ktadwfxd94dicuej6y_j6kf8-",nocase; classtype:trojan-activity; sid:100005071; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1yawygcfjs9inzoiwagqfcn3utaywxmwi",nocase; classtype:trojan-activity; sid:100005072; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1ycggxvacywdkt3jvqbpxpz9cyjcwvl_c",nocase; classtype:trojan-activity; sid:100005073; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1yhflwpk3yeyrdhlhanctlind-5j24iwv",nocase; classtype:trojan-activity; sid:100005074; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1ys9rupdqvnhvrngizxfzstzcos0dlx-u",nocase; classtype:trojan-activity; sid:100005075; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1z6wmqtnaa-jtpm5bqkb3ebi_btjcvmat",nocase; classtype:trojan-activity; sid:100005076; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1zbclvhabervgfryoyqklo4_oe6icd8sr",nocase; classtype:trojan-activity; sid:100005077; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1zor7cinphnazfkldkthucb2h8jthlh9d",nocase; classtype:trojan-activity; sid:100005078; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1zsghzos5foggoqxq6w12xeqvanhccdyk",nocase; classtype:trojan-activity; sid:100005079; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?id=148pt6v0nlg8yoim7w6in7dpixkzaacbg&export=download&authuser=0",nocase; classtype:trojan-activity; sid:100005080; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drpamelageorge.com",nocase; http_uri; content:"/wp-includes/1zilg/",nocase; classtype:trojan-activity; sid:100005081; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drpamelageorge.com",nocase; http_uri; content:"/wp-includes/qcgfmfvh/",nocase; classtype:trojan-activity; sid:100005082; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"e-mudhra.com",nocase; http_uri; content:"/downloads/emclick.zip",nocase; classtype:trojan-activity; sid:100005083; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"evertkok.nl",nocase; http_uri; content:"/informatica/informatica-actief/hoofdstuk1/extrasoftware/getallen.exe",nocase; classtype:trojan-activity; sid:100005084; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"evertkok.nl",nocase; http_uri; content:"/informatica/informatica-actief/hoofdstuk2/software/hksetup.exe",nocase; classtype:trojan-activity; sid:100005085; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"expeditionquest.com",nocase; http_uri; content:"/register/phpcaptcha/images/19dnqhg1p/sbhvtqlysxhxn/",nocase; classtype:trojan-activity; sid:100005086; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"expeditionquest.com",nocase; http_uri; content:"/register/phpcaptcha/images/35egphpl5uzpvdmz9bncmvon3p/",nocase; classtype:trojan-activity; sid:100005087; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"expeditionquest.com",nocase; http_uri; content:"/x/",nocase; classtype:trojan-activity; sid:100005088; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf/",nocase; classtype:trojan-activity; sid:100005089; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf//",nocase; classtype:trojan-activity; sid:100005090; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf///",nocase; classtype:trojan-activity; sid:100005091; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf////",nocase; classtype:trojan-activity; sid:100005092; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"file.elecfans.com",nocase; http_uri; content:"/web1/m00/8f/36/o4ybafy-2m2aarfzaahkaiik5pi122.exe",nocase; classtype:trojan-activity; sid:100005093; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"files.constantcontact.com",nocase; http_uri; content:"/4cb7cebd101/e5fb4174-ab23-48e8-bf05-e80ec5fa2169.xls",nocase; classtype:trojan-activity; sid:100005094; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"files.constantcontact.com",nocase; http_uri; content:"/ee304de9001/7e533e73-e272-4a44-9d9e-138cab64bf19.docx",nocase; classtype:trojan-activity; sid:100005095; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gist.githubusercontent.com",nocase; http_uri; content:"/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe",nocase; classtype:trojan-activity; sid:100005096; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hqdecig.com",nocase; http_uri; content:"/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/",nocase; classtype:trojan-activity; sid:100005097; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hsecaravans.co.uk",nocase; http_uri; content:"/wp-admin/suy/",nocase; classtype:trojan-activity; sid:100005098; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ia801802.us.archive.org",nocase; http_uri; content:"/19/items/startup_20210219/startup.txt",nocase; classtype:trojan-activity; sid:100005099; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ie-best.net",nocase; http_uri; content:"/online-timer-kvhxz/ilxl/",nocase; classtype:trojan-activity; sid:100005100; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"indonesias.me:9998",nocase; http_uri; content:"/64.exe",nocase; classtype:trojan-activity; sid:100005101; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"indonesias.me:9998",nocase; http_uri; content:"/c64.exe",nocase; classtype:trojan-activity; sid:100005102; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jcedu.org",nocase; http_uri; content:"/ebook/cs17.exe",nocase; classtype:trojan-activity; sid:100005103; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jointings.org",nocase; http_uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/1",nocase; classtype:trojan-activity; sid:100005104; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jointings.org",nocase; http_uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/2",nocase; classtype:trojan-activity; sid:100005105; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jointings.org",nocase; http_uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/3",nocase; classtype:trojan-activity; sid:100005106; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"karmakoincodes.weebly.com",nocase; http_uri; content:"/uploads/3/2/8/8/3288864/karma_koin_codes.exe",nocase; classtype:trojan-activity; sid:100005107; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kotakwarna.co.id",nocase; http_uri; content:"/dg/etrac/nf4emwz/",nocase; classtype:trojan-activity; sid:100005108; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kuaizip.com",nocase; http_uri; content:"/down/affiliate/kuaizip_setup_10029.exe",nocase; classtype:trojan-activity; sid:100005109; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"linuxforensicsbook.com.s3.amazonaws.com",nocase; http_uri; content:"/linuxforensicscode.zip",nocase; classtype:trojan-activity; sid:100005110; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"minpic.de",nocase; http_uri; content:"/k/big5/1giof6/",nocase; classtype:trojan-activity; sid:100005111; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"my.cloudme.com",nocase; http_uri; content:"/v1/ws2/:gianni1962/:ie6setup/ie6setup.exe",nocase; classtype:trojan-activity; sid:100005112; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nch.com.au",nocase; http_uri; content:"/components/aacenc.exe",nocase; classtype:trojan-activity; sid:100005113; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nch.com.au",nocase; http_uri; content:"/components/doxillionsetup.exe",nocase; classtype:trojan-activity; sid:100005114; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newyarlfm.weebly.com",nocase; http_uri; content:"/uploads/4/1/6/6/4166984/keygen.exe",nocase; classtype:trojan-activity; sid:100005115; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nhipcauytevietnhat.com",nocase; http_uri; content:"/efficiency-all-iuehb/bjug3jyhuyilwhcqs3ykssaqqw7tpyvmypb91wtzdbluio1ekope5vrbbcx8zhdar9yt/",nocase; classtype:trojan-activity; sid:100005116; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"note.youdao.com",nocase; http_uri; content:"/yws/api/personal/file/web3a243b322cf83ca7cae587a92916bac7?method=download&inline=true&sharekey=649ac0bb5d5b13d15cbf50b2609e193a",nocase; classtype:trojan-activity; sid:100005117; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oldschoolvalue.s3.amazonaws.com",nocase; http_uri; content:"/spreadsheets/osv_stock_valuation-sample-dummy.exe",nocase; classtype:trojan-activity; sid:100005118; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=81445407a9f44d37!197&authkey=apuz15kftzlrysa",nocase; classtype:trojan-activity; sid:100005119; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=81445407a9f44d37!198&authkey=ags5rgb15_esaqq",nocase; classtype:trojan-activity; sid:100005120; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=b4c15a27928f663b!229&authkey=aiarm61fwmd_npe",nocase; classtype:trojan-activity; sid:100005121; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=b4c15a27928f663b!230&authkey=ancu1eabetiubzg",nocase; classtype:trojan-activity; sid:100005122; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=b4c15a27928f663b!231&authkey=ai9h3sk_luxran0",nocase; classtype:trojan-activity; sid:100005123; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=!aase4ma0-vo_cls&cid=4df11eda676a355f&resid=4df11eda676a355f!140",nocase; classtype:trojan-activity; sid:100005124; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=!akd6uxvljtlvpxu&cid=4df11eda676a355f&resid=4df11eda676a355f!130",nocase; classtype:trojan-activity; sid:100005125; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135",nocase; classtype:trojan-activity; sid:100005126; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=adf5p_kn8rjf29y&cid=34224e3e49966a27&resid=34224e3e49966a27%211732",nocase; classtype:trojan-activity; sid:100005127; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=013413cfbbbcfae4&resid=13413cfbbbcfae4%211656&authkey=ai9wpcp_k9okgk4",nocase; classtype:trojan-activity; sid:100005128; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c!111&authkey=aemrwamaaaiyyjc",nocase; classtype:trojan-activity; sid:100005129; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c%21111&authkey=aemrwamaaaiyyjc",nocase; classtype:trojan-activity; sid:100005130; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0175cdbe2d2944c5&resid=175cdbe2d2944c5%21107&authkey=al6uptubjmmugo0",nocase; classtype:trojan-activity; sid:100005131; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!157&authkey=aagcsm7chqez6uu",nocase; classtype:trojan-activity; sid:100005132; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!158&authkey=amsoii5nr6pomhc",nocase; classtype:trojan-activity; sid:100005133; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21157&authkey=aagcsm7chqez6uu",nocase; classtype:trojan-activity; sid:100005134; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21158&authkey=amsoii5nr6pomhc",nocase; classtype:trojan-activity; sid:100005135; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=023f39d21b700310&resid=23f39d21b700310%211204&authkey=an2utsuaopn0fhc",nocase; classtype:trojan-activity; sid:100005136; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211177&authkey=am0i98nwgvzgqvq",nocase; classtype:trojan-activity; sid:100005137; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211183&authkey=anv33trmzmi5cko",nocase; classtype:trojan-activity; sid:100005138; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw",nocase; classtype:trojan-activity; sid:100005139; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=03286724f74117f9&resid=3286724f74117f9!1179&authkey=acr-_rvrgp39kk4",nocase; classtype:trojan-activity; sid:100005140; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=03286724f74117f9&resid=3286724f74117f9%211179&authkey=acr-_rvrgp39kk4",nocase; classtype:trojan-activity; sid:100005141; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=032ce380af7ab389&resid=32ce380af7ab389!210&authkey=akcynbtc0h3ui7e",nocase; classtype:trojan-activity; sid:100005142; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=032ce380af7ab389&resid=32ce380af7ab389%21210&authkey=akcynbtc0h3ui7e",nocase; classtype:trojan-activity; sid:100005143; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48",nocase; classtype:trojan-activity; sid:100005144; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq",nocase; classtype:trojan-activity; sid:100005145; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg",nocase; classtype:trojan-activity; sid:100005146; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw",nocase; classtype:trojan-activity; sid:100005147; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq",nocase; classtype:trojan-activity; sid:100005148; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!273&authkey=ae2m69e5nu3rrea",nocase; classtype:trojan-activity; sid:100005149; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21273&authkey=ae2m69e5nu3rrea",nocase; classtype:trojan-activity; sid:100005150; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21274&authkey=acqg0akutoxdpgo",nocase; classtype:trojan-activity; sid:100005151; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0e26b39babdbf63c&resid=e26b39babdbf63c%21137&authkey=anshbgxg1_qa2h4",nocase; classtype:trojan-activity; sid:100005152; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242!309&authkey=alfe36drai1zmwc",nocase; classtype:trojan-activity; sid:100005153; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242%21309&authkey=alfe36drai1zmwc",nocase; classtype:trojan-activity; sid:100005154; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21123&authkey=aco5hiwppfq8vrw",nocase; classtype:trojan-activity; sid:100005155; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21124&authkey=ai6sfa2z-kqf6x0",nocase; classtype:trojan-activity; sid:100005156; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=115bffdddaa40942&resid=115bffdddaa40942!540&authkey=aamhnqgfdtdsoxk",nocase; classtype:trojan-activity; sid:100005157; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=115bffdddaa40942&resid=115bffdddaa40942%21540&authkey=aamhnqgfdtdsoxk",nocase; classtype:trojan-activity; sid:100005158; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a",nocase; classtype:trojan-activity; sid:100005159; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=13b301f1cb48f8cd&resid=13b301f1cb48f8cd%21106&authkey=aiae3olcs4lulz4",nocase; classtype:trojan-activity; sid:100005160; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte",nocase; classtype:trojan-activity; sid:100005161; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7%21118&authkey=antash3ig98aqte",nocase; classtype:trojan-activity; sid:100005162; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e!348&authkey=ahnjoxa4ufoxa54",nocase; classtype:trojan-activity; sid:100005163; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e%21348&authkey=ahnjoxa4ufoxa54",nocase; classtype:trojan-activity; sid:100005164; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!126&authkey=ad4yflrisq6d82g",nocase; classtype:trojan-activity; sid:100005165; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!129&authkey=apqoonsrce0ari4",nocase; classtype:trojan-activity; sid:100005166; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21126&authkey=ad4yflrisq6d82g",nocase; classtype:trojan-activity; sid:100005167; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21129&authkey=apqoonsrce0ari4",nocase; classtype:trojan-activity; sid:100005168; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=196e83840ef8c152&resid=196e83840ef8c152%21107&authkey=ah2lhjyd0ukjcve",nocase; classtype:trojan-activity; sid:100005169; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1a162e8fcaaef5fa&resid=1a162e8fcaaef5fa%215495&authkey=aic7rmj1cm3rt2w",nocase; classtype:trojan-activity; sid:100005170; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558!8182&authkey=aautw8tvzxr5v3a",nocase; classtype:trojan-activity; sid:100005171; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558%218182&authkey=aautw8tvzxr5v3a",nocase; classtype:trojan-activity; sid:100005172; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1cbd82dd55d70086&resid=1cbd82dd55d70086%212526&authkey=aogaboensav3jrg",nocase; classtype:trojan-activity; sid:100005173; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1dbdf62bc3c2b05b&resid=1dbdf62bc3c2b05b!134&authkey=ape6bhxn7c89z60",nocase; classtype:trojan-activity; sid:100005174; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg",nocase; classtype:trojan-activity; sid:100005175; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4",nocase; classtype:trojan-activity; sid:100005176; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c",nocase; classtype:trojan-activity; sid:100005177; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2184cd6093fdd997&resid=2184cd6093fdd997!136&authkey=agsnq9l7ncf4p-w",nocase; classtype:trojan-activity; sid:100005178; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2184cd6093fdd997&resid=2184cd6093fdd997!137&authkey=aawcijw8fv4m-8g",nocase; classtype:trojan-activity; sid:100005179; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2184cd6093fdd997&resid=2184cd6093fdd997%21136&authkey=agsnq9l7ncf4p-w",nocase; classtype:trojan-activity; sid:100005180; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2184cd6093fdd997&resid=2184cd6093fdd997%21137&authkey=aawcijw8fv4m-8g",nocase; classtype:trojan-activity; sid:100005181; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!123&authkey=am1rcmkppbht8v0",nocase; classtype:trojan-activity; sid:100005182; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!124&authkey=am5sltharf-j_cc",nocase; classtype:trojan-activity; sid:100005183; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!125&authkey=acgvgbbuowodg4c",nocase; classtype:trojan-activity; sid:100005184; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21122&authkey=aa2f8su-5bfjlvs",nocase; classtype:trojan-activity; sid:100005185; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0",nocase; classtype:trojan-activity; sid:100005186; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0&c=3ii9gcd&r=7azia71ojgc8rxd0dmkukm&k=7s1&s=htgxfkpr86ttvokhkcn3enmimk12ewqfiglklz23spd",nocase; classtype:trojan-activity; sid:100005187; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21124&authkey=am5sltharf-j_cc",nocase; classtype:trojan-activity; sid:100005188; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21125&authkey=acgvgbbuowodg4c",nocase; classtype:trojan-activity; sid:100005189; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21154&authkey=alkjikpdfxvm8po",nocase; classtype:trojan-activity; sid:100005190; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21155&authkey=afu-yax_gxxddoe",nocase; classtype:trojan-activity; sid:100005191; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21156&authkey=alqvv8nixrvsqrk",nocase; classtype:trojan-activity; sid:100005192; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f!191&authkey=ajvumpkzpla_nca",nocase; classtype:trojan-activity; sid:100005193; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f%21191&authkey=ajvumpkzpla_nca",nocase; classtype:trojan-activity; sid:100005194; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=26bbd7d5ad88dd29&resid=26bbd7d5ad88dd29%21115&authkey=acipfa3gbiqqcvu",nocase; classtype:trojan-activity; sid:100005195; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=26f87316a7e32bb5&resid=26f87316a7e32bb5%21106&authkey=aepqo5hlkxn1t1k",nocase; classtype:trojan-activity; sid:100005196; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2831401bbac0235e&resid=2831401bbac0235e%211037&authkey=aagnkp6l76yhrlo",nocase; classtype:trojan-activity; sid:100005197; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!182&authkey=apogh8yf-fj8xvk",nocase; classtype:trojan-activity; sid:100005198; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!183&authkey=am4thhgmi0nlxei",nocase; classtype:trojan-activity; sid:100005199; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!185&authkey=akttgkvu39ugyte",nocase; classtype:trojan-activity; sid:100005200; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21182&authkey=apogh8yf-fj8xvk",nocase; classtype:trojan-activity; sid:100005201; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21183&authkey=am4thhgmi0nlxei",nocase; classtype:trojan-activity; sid:100005202; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21185&authkey=akttgkvu39ugyte",nocase; classtype:trojan-activity; sid:100005203; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2894380eb084b79e&resid=2894380eb084b79e%21253&authkey=aimqerwvuylzjga",nocase; classtype:trojan-activity; sid:100005204; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2992e4d36c2a7dae&resid=2992e4d36c2a7dae%21132&authkey=af05vsjkocy8lly",nocase; classtype:trojan-activity; sid:100005205; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2b6e98d9e0cf1a17&resid=2b6e98d9e0cf1a17!2471&authkey=ai5r4hqy9i0g1qs",nocase; classtype:trojan-activity; sid:100005206; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2b6e98d9e0cf1a17&resid=2b6e98d9e0cf1a17%212471&authkey=ai5r4hqy9i0g1qs",nocase; classtype:trojan-activity; sid:100005207; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c1abc526306a6e1&resid=2c1abc526306a6e1%21106&authkey=adjthwhvjkbioc0",nocase; classtype:trojan-activity; sid:100005208; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21109&authkey=aopcxq3owfiv620",nocase; classtype:trojan-activity; sid:100005209; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21114&authkey=ajzoj0ujggsnxlo",nocase; classtype:trojan-activity; sid:100005210; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21115&authkey=aglznnsx71tbe9e",nocase; classtype:trojan-activity; sid:100005211; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37!183&authkey=akon9i9zzhusiuk",nocase; classtype:trojan-activity; sid:100005212; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37%21183&authkey=akon9i9zzhusiuk",nocase; classtype:trojan-activity; sid:100005213; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f01a497b687285e&resid=2f01a497b687285e!734&authkey=aiumuxtp3phppy4",nocase; classtype:trojan-activity; sid:100005214; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f01a497b687285e&resid=2f01a497b687285e%21734&authkey=aiumuxtp3phppy4",nocase; classtype:trojan-activity; sid:100005215; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!116&authkey=!abwledjhfsqwap4",nocase; classtype:trojan-activity; sid:100005216; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!121&authkey=!aa0qbuuss-wb13w",nocase; classtype:trojan-activity; sid:100005217; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1!119&authkey=apmakx2cqb9rimu",nocase; classtype:trojan-activity; sid:100005218; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21118&authkey=acrl2iiem-zjer8",nocase; classtype:trojan-activity; sid:100005219; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21119&authkey=apmakx2cqb9rimu",nocase; classtype:trojan-activity; sid:100005220; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2ffaa48ef4bec51a&resid=2ffaa48ef4bec51a%21107&authkey=aiohrvrc3uuo_cw",nocase; classtype:trojan-activity; sid:100005221; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=30e33fc2c147c72f&resid=30e33fc2c147c72f!2742&authkey=ajviks-nvgb4gqs",nocase; classtype:trojan-activity; sid:100005222; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=30e33fc2c147c72f&resid=30e33fc2c147c72f!2743&authkey=ao4um908kkhavqg",nocase; classtype:trojan-activity; sid:100005223; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=30e33fc2c147c72f&resid=30e33fc2c147c72f%212742&authkey=ajviks-nvgb4gqs",nocase; classtype:trojan-activity; sid:100005224; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=30e33fc2c147c72f&resid=30e33fc2c147c72f%212743&authkey=ao4um908kkhavqg",nocase; classtype:trojan-activity; sid:100005225; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!320&authkey=aooujzuf408dclw",nocase; classtype:trojan-activity; sid:100005226; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!321&authkey=almpxnbtsbzauna",nocase; classtype:trojan-activity; sid:100005227; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21320&authkey=aooujzuf408dclw",nocase; classtype:trojan-activity; sid:100005228; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21321&authkey=almpxnbtsbzauna",nocase; classtype:trojan-activity; sid:100005229; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3164ddeba70d2263&resid=3164ddeba70d2263%21106&authkey=afkvqrm4zoor8qq",nocase; classtype:trojan-activity; sid:100005230; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=31771958ea3373a1&resid=31771958ea3373a1%21108&authkey=aiofxduo9rdb_-o",nocase; classtype:trojan-activity; sid:100005231; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=34207675f7506d94&resid=34207675f7506d94%21137&authkey=angxnhqpe2x5koc",nocase; classtype:trojan-activity; sid:100005232; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0",nocase; classtype:trojan-activity; sid:100005233; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa",nocase; classtype:trojan-activity; sid:100005234; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa",nocase; classtype:trojan-activity; sid:100005235; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c!139&authkey=ap4bbakgkikau-a",nocase; classtype:trojan-activity; sid:100005236; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c%21139&authkey=ap4bbakgkikau-a",nocase; classtype:trojan-activity; sid:100005237; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!198&authkey=acyz0gbpl6bp9mo",nocase; classtype:trojan-activity; sid:100005238; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!199&authkey=admaszabh84m8ou",nocase; classtype:trojan-activity; sid:100005239; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e%21198&authkey=acyz0gbpl6bp9mo",nocase; classtype:trojan-activity; sid:100005240; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e%21199&authkey=admaszabh84m8ou",nocase; classtype:trojan-activity; sid:100005241; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!152&authkey=am09sv26njxzyn0",nocase; classtype:trojan-activity; sid:100005242; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!153&authkey=ajs0jkoeqkqjrze",nocase; classtype:trojan-activity; sid:100005243; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21152&authkey=am09sv26njxzyn0",nocase; classtype:trojan-activity; sid:100005244; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21153&authkey=ajs0jkoeqkqjrze",nocase; classtype:trojan-activity; sid:100005245; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3a1715e2cb964f25&resid=3a1715e2cb964f25%213713&authkey=aortxmfnibnoqkk",nocase; classtype:trojan-activity; sid:100005246; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237!963&authkey=aewqwrtr9szefem",nocase; classtype:trojan-activity; sid:100005247; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237!965&authkey=aaayllvoxl-rbdi",nocase; classtype:trojan-activity; sid:100005248; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237!966&authkey=apsg26pur_hpk6k",nocase; classtype:trojan-activity; sid:100005249; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237!971&authkey=amfm0a4mjjup0o8",nocase; classtype:trojan-activity; sid:100005250; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237!973&authkey=acfwvefa0v7myb4",nocase; classtype:trojan-activity; sid:100005251; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237!975&authkey=ajreyx8ik2l5uxm",nocase; classtype:trojan-activity; sid:100005252; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237!976&authkey=alpmp7w4cfupsvu",nocase; classtype:trojan-activity; sid:100005253; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237!977&authkey=adju1b_cnsxdxni",nocase; classtype:trojan-activity; sid:100005254; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21965&authkey=aaayllvoxl-rbdi",nocase; classtype:trojan-activity; sid:100005255; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21966&authkey=apsg26pur_hpk6k",nocase; classtype:trojan-activity; sid:100005256; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21971&authkey=amfm0a4mjjup0o8",nocase; classtype:trojan-activity; sid:100005257; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21975&authkey=ajreyx8ik2l5uxm",nocase; classtype:trojan-activity; sid:100005258; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21976&authkey=alpmp7w4cfupsvu",nocase; classtype:trojan-activity; sid:100005259; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21977&authkey=adju1b_cnsxdxni",nocase; classtype:trojan-activity; sid:100005260; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21978&authkey=agg7tntwzgctq7s",nocase; classtype:trojan-activity; sid:100005261; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21432&authkey=aa_npsupyqb2kge",nocase; classtype:trojan-activity; sid:100005262; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21435&authkey=admsjhgpkbtcqzs",nocase; classtype:trojan-activity; sid:100005263; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog",nocase; classtype:trojan-activity; sid:100005264; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f%21154&authkey=aasj15d0g_p2pog",nocase; classtype:trojan-activity; sid:100005265; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f!134&authkey=aaipzy8nllirlky",nocase; classtype:trojan-activity; sid:100005266; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f%21134&authkey=aaipzy8nllirlky",nocase; classtype:trojan-activity; sid:100005267; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=40cbf21d67b770f7&resid=40cbf21d67b770f7%21140&authkey=ah0uewz9k7-lzd0",nocase; classtype:trojan-activity; sid:100005268; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2!106&authkey=aoigmqhuw6vqijm",nocase; classtype:trojan-activity; sid:100005269; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2%21106&authkey=aoigmqhuw6vqijm",nocase; classtype:trojan-activity; sid:100005270; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21108&authkey=akr9cesktucbqik",nocase; classtype:trojan-activity; sid:100005271; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21109&authkey=adzxmpjk-etbkjq",nocase; classtype:trojan-activity; sid:100005272; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=45f0213456d899c0&resid=45f0213456d899c0%211133&authkey=alwgkm79xod8hpy",nocase; classtype:trojan-activity; sid:100005273; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa!450&authkey=ahw0j-cme0jg6pw",nocase; classtype:trojan-activity; sid:100005274; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa%21450&authkey=ahw0j-cme0jg6pw",nocase; classtype:trojan-activity; sid:100005275; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=489dd700ea74963a&resid=489dd700ea74963a%21206&authkey=acgkmxuk000jse8",nocase; classtype:trojan-activity; sid:100005276; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=489dd700ea74963a&resid=489dd700ea74963a%21210&authkey=aotjil_l-s-xh1c",nocase; classtype:trojan-activity; sid:100005277; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ada4e22fff3e13&resid=48ada4e22fff3e13%21421&authkey=acd1sidm8c5fk0y",nocase; classtype:trojan-activity; sid:100005278; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13805&authkey=ae-zbfo2uwln_gg",nocase; classtype:trojan-activity; sid:100005279; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13806&authkey=aakiq-ymrjjodns",nocase; classtype:trojan-activity; sid:100005280; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113805&authkey=ae-zbfo2uwln_gg",nocase; classtype:trojan-activity; sid:100005281; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113806&authkey=aakiq-ymrjjodns",nocase; classtype:trojan-activity; sid:100005282; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4ab7eafa48707b54&resid=4ab7eafa48707b54%21105&authkey=amb4gnkdn8igw8y",nocase; classtype:trojan-activity; sid:100005283; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4b676ea3ff139b93&resid=4b676ea3ff139b93!133&authkey=amfix63glytflgo",nocase; classtype:trojan-activity; sid:100005284; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21127&authkey=ablg20r-aat_ob4",nocase; classtype:trojan-activity; sid:100005285; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21131&authkey=akbwlkrrtso_bqm",nocase; classtype:trojan-activity; sid:100005286; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4df11eda676a355f&resid=4df11eda676a355f!130&authkey=!akd6uxvljtlvpxu",nocase; classtype:trojan-activity; sid:100005287; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b!108&authkey=anbjpqxg-iwr4g8",nocase; classtype:trojan-activity; sid:100005288; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b%21108&authkey=anbjpqxg-iwr4g8",nocase; classtype:trojan-activity; sid:100005289; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc",nocase; classtype:trojan-activity; sid:100005290; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y",nocase; classtype:trojan-activity; sid:100005291; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21105&authkey=ajkwu0e9dzantl8",nocase; classtype:trojan-activity; sid:100005292; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21107&authkey=apd9um4_12-kpe0",nocase; classtype:trojan-activity; sid:100005293; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21116&authkey=anbj_rrcgyturjc",nocase; classtype:trojan-activity; sid:100005294; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21119&authkey=amrs3-3hsvcmtfs",nocase; classtype:trojan-activity; sid:100005295; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21158&authkey=aodderdrnvhruts",nocase; classtype:trojan-activity; sid:100005296; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21161&authkey=agdsfxdnre82jjc",nocase; classtype:trojan-activity; sid:100005297; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21192&authkey=agn2xvrvup-xvtg",nocase; classtype:trojan-activity; sid:100005298; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21206&authkey=ai1r52mhtbdnm2y",nocase; classtype:trojan-activity; sid:100005299; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21247&authkey=ae6weny1fa4pday",nocase; classtype:trojan-activity; sid:100005300; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21252&authkey=aphl0oi4r6lrty0",nocase; classtype:trojan-activity; sid:100005301; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21257&authkey=afnyvqwcghnyoas",nocase; classtype:trojan-activity; sid:100005302; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21265&authkey=abxqdhlwiurjvve",nocase; classtype:trojan-activity; sid:100005303; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21271&authkey=ae5qwlr5ceeptmy",nocase; classtype:trojan-activity; sid:100005304; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21272&authkey=ahrqeoaynibwt14",nocase; classtype:trojan-activity; sid:100005305; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21275&authkey=af_sgsaxsmaxg7i",nocase; classtype:trojan-activity; sid:100005306; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21289&authkey=angyngbqixtrjaa",nocase; classtype:trojan-activity; sid:100005307; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu",nocase; classtype:trojan-activity; sid:100005308; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c",nocase; classtype:trojan-activity; sid:100005309; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21306&authkey=ahpivoukyerzcjy",nocase; classtype:trojan-activity; sid:100005310; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21314&authkey=aex2uv2-eiofr8q",nocase; classtype:trojan-activity; sid:100005311; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21332&authkey=ad0jmjxgbaebvbm",nocase; classtype:trojan-activity; sid:100005312; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21335&authkey=ah0vupcfbdfa6g4",nocase; classtype:trojan-activity; sid:100005313; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21357&authkey=ap8sswuqjjjexho",nocase; classtype:trojan-activity; sid:100005314; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21366&authkey=aoblpmbmx7o_v18",nocase; classtype:trojan-activity; sid:100005315; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21379&authkey=air-bsjj46et47q",nocase; classtype:trojan-activity; sid:100005316; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21389&authkey=aduenohuq_rbyhm",nocase; classtype:trojan-activity; sid:100005317; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21391&authkey=aa15sw51njbn_na",nocase; classtype:trojan-activity; sid:100005318; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21392&authkey=abp0heeg6ybn0lk",nocase; classtype:trojan-activity; sid:100005319; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21393&authkey=aa1pmur8sy8xtwe",nocase; classtype:trojan-activity; sid:100005320; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212718&authkey=aie0v1d-cusuabi",nocase; classtype:trojan-activity; sid:100005321; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212725&authkey=aanrz9et3bym3lc",nocase; classtype:trojan-activity; sid:100005322; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212728&authkey=ahsmbkltfrwgqjc",nocase; classtype:trojan-activity; sid:100005323; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!395&authkey=alwvub_yhtogjxw",nocase; classtype:trojan-activity; sid:100005324; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!398&authkey=abaa_tjd7ohh4so",nocase; classtype:trojan-activity; sid:100005325; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!406&authkey=aarnp48wumgu6tq",nocase; classtype:trojan-activity; sid:100005326; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!415&authkey=aglzsd6-g0nzj7s",nocase; classtype:trojan-activity; sid:100005327; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!420&authkey=akk5droung_ecww",nocase; classtype:trojan-activity; sid:100005328; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!440&authkey=ai7-dpr11wnzyq8",nocase; classtype:trojan-activity; sid:100005329; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21395&authkey=alwvub_yhtogjxw",nocase; classtype:trojan-activity; sid:100005330; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21398&authkey=abaa_tjd7ohh4so",nocase; classtype:trojan-activity; sid:100005331; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21406&authkey=aarnp48wumgu6tq",nocase; classtype:trojan-activity; sid:100005332; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21415&authkey=aglzsd6-g0nzj7s",nocase; classtype:trojan-activity; sid:100005333; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21420&authkey=akk5droung_ecww",nocase; classtype:trojan-activity; sid:100005334; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21440&authkey=ai7-dpr11wnzyq8",nocase; classtype:trojan-activity; sid:100005335; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211121&authkey=al_fmezwfay4za4",nocase; classtype:trojan-activity; sid:100005336; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211122&authkey=anz_q5njlanv2mu",nocase; classtype:trojan-activity; sid:100005337; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21110&authkey=akars6koxqzdwgi",nocase; classtype:trojan-activity; sid:100005338; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21112&authkey=aadare1gec7nzy8",nocase; classtype:trojan-activity; sid:100005339; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8",nocase; classtype:trojan-activity; sid:100005340; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8&em=2",nocase; classtype:trojan-activity; sid:100005341; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d%21109&authkey=adriswrtwdpbuc8&em=2",nocase; classtype:trojan-activity; sid:100005342; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53c5e6b8f6893887&resid=53c5e6b8f6893887!802&authkey=aapuufivkn2zwu8",nocase; classtype:trojan-activity; sid:100005343; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!106&authkey=anzlf1ksptbqok8",nocase; classtype:trojan-activity; sid:100005344; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!107&authkey=ag4dr58jrjuxfyq",nocase; classtype:trojan-activity; sid:100005345; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21106&authkey=anzlf1ksptbqok8",nocase; classtype:trojan-activity; sid:100005346; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21107&authkey=ag4dr58jrjuxfyq",nocase; classtype:trojan-activity; sid:100005347; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g",nocase; classtype:trojan-activity; sid:100005348; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum",nocase; classtype:trojan-activity; sid:100005349; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5521b68dc17baf21&resid=5521b68dc17baf21%21129&authkey=ajdr2dbh-9h63wa",nocase; classtype:trojan-activity; sid:100005350; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi",nocase; classtype:trojan-activity; sid:100005351; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613!157&authkey=an55tjzt-9vbjfy",nocase; classtype:trojan-activity; sid:100005352; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613%21156&authkey=agiuawekkbxb_4o",nocase; classtype:trojan-activity; sid:100005353; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=55c9feaf3907aae5&resid=55c9feaf3907aae5%21208&authkey=adwuyrapfdzkyoa",nocase; classtype:trojan-activity; sid:100005354; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950!280&authkey=advq4p3xhfhinq8",nocase; classtype:trojan-activity; sid:100005355; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950%21280&authkey=advq4p3xhfhinq8",nocase; classtype:trojan-activity; sid:100005356; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5629da828892367d&resid=5629da828892367d!803&authkey=aphjbq-bsg7ohpc",nocase; classtype:trojan-activity; sid:100005357; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21383&authkey=adldpuaya7kj1dk",nocase; classtype:trojan-activity; sid:100005358; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21384&authkey=alsuxvtsof32vea",nocase; classtype:trojan-activity; sid:100005359; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3599&authkey=am4yicme6lrjpki",nocase; classtype:trojan-activity; sid:100005360; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3604&authkey=al6pb71mtq4jr1s",nocase; classtype:trojan-activity; sid:100005361; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213599&authkey=am4yicme6lrjpki",nocase; classtype:trojan-activity; sid:100005362; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213604&authkey=al6pb71mtq4jr1s",nocase; classtype:trojan-activity; sid:100005363; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b!68197&authkey=aowpm7ocl_21-oc",nocase; classtype:trojan-activity; sid:100005364; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b%2168197&authkey=aowpm7ocl_21-oc",nocase; classtype:trojan-activity; sid:100005365; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=59389d626d829e8c&resid=59389d626d829e8c%212940&authkey=anx1ngd27vqeiwo",nocase; classtype:trojan-activity; sid:100005366; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211568&authkey=aemrnwoi75oflva",nocase; classtype:trojan-activity; sid:100005367; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211572&authkey=aelz-gxlrxcwtnc",nocase; classtype:trojan-activity; sid:100005368; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211573&authkey=ahksfdvda0doles",nocase; classtype:trojan-activity; sid:100005369; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg",nocase; classtype:trojan-activity; sid:100005370; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai",nocase; classtype:trojan-activity; sid:100005371; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!407&authkey=adnh8af-rvoxlcc",nocase; classtype:trojan-activity; sid:100005372; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21406&authkey=aeyeq5j9zfepgai",nocase; classtype:trojan-activity; sid:100005373; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21407&authkey=adnh8af-rvoxlcc",nocase; classtype:trojan-activity; sid:100005374; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21892&authkey=apwphufzjdtsedw",nocase; classtype:trojan-activity; sid:100005375; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8",nocase; classtype:trojan-activity; sid:100005376; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21121&authkey=adjzlorvgx_ezhq",nocase; classtype:trojan-activity; sid:100005377; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21123&authkey=ancfnepawtbmnug",nocase; classtype:trojan-activity; sid:100005378; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21124&authkey=ao7bknnuodxtfua",nocase; classtype:trojan-activity; sid:100005379; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21126&authkey=an6sswp8an1kfoe",nocase; classtype:trojan-activity; sid:100005380; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6196314c52185efc&resid=6196314c52185efc%21106&authkey=ape4rx1hrtmrxxe",nocase; classtype:trojan-activity; sid:100005381; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!490&authkey=aljraz5ktivqax4",nocase; classtype:trojan-activity; sid:100005382; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!491&authkey=aopwdha2wyjx0aa",nocase; classtype:trojan-activity; sid:100005383; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!492&authkey=akwg8p5adkpjm5w",nocase; classtype:trojan-activity; sid:100005384; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!493&authkey=aeg__7wcf7esydo",nocase; classtype:trojan-activity; sid:100005385; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21490&authkey=aljraz5ktivqax4",nocase; classtype:trojan-activity; sid:100005386; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21491&authkey=aopwdha2wyjx0aa",nocase; classtype:trojan-activity; sid:100005387; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21492&authkey=akwg8p5adkpjm5w",nocase; classtype:trojan-activity; sid:100005388; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21493&authkey=aeg__7wcf7esydo",nocase; classtype:trojan-activity; sid:100005389; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi",nocase; classtype:trojan-activity; sid:100005390; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e",nocase; classtype:trojan-activity; sid:100005391; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1094&authkey=anqjzd7pr18fu90",nocase; classtype:trojan-activity; sid:100005392; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211094&authkey=anqjzd7pr18fu90",nocase; classtype:trojan-activity; sid:100005393; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21129&authkey=ak5szbnikeklmzk",nocase; classtype:trojan-activity; sid:100005394; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21132&authkey=ad3ia_1wkq0lyd4",nocase; classtype:trojan-activity; sid:100005395; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6608a4dea9ff5918&resid=6608a4dea9ff5918%21399&authkey=aoya7flv_s9toxo",nocase; classtype:trojan-activity; sid:100005396; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2%21505&authkey=ag7xi3lcnvi_hji",nocase; classtype:trojan-activity; sid:100005397; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad!1421&authkey=adixg2-asekemjw",nocase; classtype:trojan-activity; sid:100005398; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad%211421&authkey=adixg2-asekemjw",nocase; classtype:trojan-activity; sid:100005399; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213096&authkey=aob-cm9vv6erxqg",nocase; classtype:trojan-activity; sid:100005400; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213097&authkey=abcuevfyu6pdw70",nocase; classtype:trojan-activity; sid:100005401; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=69b503a3f081a183&resid=69b503a3f081a183%21111&authkey=aazm9wlg1rvgzoc",nocase; classtype:trojan-activity; sid:100005402; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!112&authkey=aasndgbcwol3mys",nocase; classtype:trojan-activity; sid:100005403; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!113&authkey=ak3tzu1lg4uuh5m",nocase; classtype:trojan-activity; sid:100005404; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21112&authkey=aasndgbcwol3mys",nocase; classtype:trojan-activity; sid:100005405; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21113&authkey=ak3tzu1lg4uuh5m",nocase; classtype:trojan-activity; sid:100005406; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21108&authkey=ameouv2jdxo5obw",nocase; classtype:trojan-activity; sid:100005407; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21119&authkey=aazzzrl7mv2xbwq",nocase; classtype:trojan-activity; sid:100005408; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a7b40a2bc530c6c&resid=6a7b40a2bc530c6c%21112&authkey=afuov36rbymlvxm",nocase; classtype:trojan-activity; sid:100005409; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3!118&authkey=aepf8f3mfmlsng0",nocase; classtype:trojan-activity; sid:100005410; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3%21118&authkey=aepf8f3mfmlsng0",nocase; classtype:trojan-activity; sid:100005411; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b61e983f930f79f&resid=6b61e983f930f79f!540&authkey=ap2n5w41ifew0i8",nocase; classtype:trojan-activity; sid:100005412; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7!1154&authkey=acnbdscb8-rbmcu",nocase; classtype:trojan-activity; sid:100005413; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7%211154&authkey=acnbdscb8-rbmcu",nocase; classtype:trojan-activity; sid:100005414; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21106&authkey=apvhok6edhtogfu",nocase; classtype:trojan-activity; sid:100005415; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21115&authkey=amc_k1nnlywdc4i",nocase; classtype:trojan-activity; sid:100005416; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=724b5c509337556e&resid=724b5c509337556e%21908&authkey=agcbb3nakpteyam",nocase; classtype:trojan-activity; sid:100005417; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7285f51e65036769&resid=7285f51e65036769%21264&authkey=akyjvrz006qlble",nocase; classtype:trojan-activity; sid:100005418; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21243&authkey=apivjmxivosek60",nocase; classtype:trojan-activity; sid:100005419; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21256&authkey=adljht0ogfq775k",nocase; classtype:trojan-activity; sid:100005420; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21260&authkey=aig6cydr4_e-qj8",nocase; classtype:trojan-activity; sid:100005421; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21262&authkey=ak4fiz1-a1ks8rg",nocase; classtype:trojan-activity; sid:100005422; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21264&authkey=aizkjymvlgqwpte",nocase; classtype:trojan-activity; sid:100005423; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=77518d098ad4dfb0&resid=77518d098ad4dfb0%21939&authkey=akzqobxxxn89z34",nocase; classtype:trojan-activity; sid:100005424; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w",nocase; classtype:trojan-activity; sid:100005425; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta",nocase; classtype:trojan-activity; sid:100005426; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21117&authkey=aivf1ddcvvu22em",nocase; classtype:trojan-activity; sid:100005427; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21210&authkey=agpl0pgvft8faaa",nocase; classtype:trojan-activity; sid:100005428; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21211&authkey=anxavz-oaf9pv_c",nocase; classtype:trojan-activity; sid:100005429; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto",nocase; classtype:trojan-activity; sid:100005430; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum",nocase; classtype:trojan-activity; sid:100005431; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto",nocase; classtype:trojan-activity; sid:100005432; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21120&authkey=ajj7ueqjvobgfum",nocase; classtype:trojan-activity; sid:100005433; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c1fc7da38ab958e&resid=7c1fc7da38ab958e!146&authkey=aktmjqz8n4s_sbm",nocase; classtype:trojan-activity; sid:100005434; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125575&authkey=ahnmpmvzshrwoyq",nocase; classtype:trojan-activity; sid:100005435; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125579&authkey=amhnrbwecb4hp_k",nocase; classtype:trojan-activity; sid:100005436; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5295&authkey=aasceqj1mdodeuo",nocase; classtype:trojan-activity; sid:100005437; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5296&authkey=ank3vz5syaf6bny",nocase; classtype:trojan-activity; sid:100005438; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5298&authkey=albzyizuqczfv9s",nocase; classtype:trojan-activity; sid:100005439; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215295&authkey=aasceqj1mdodeuo",nocase; classtype:trojan-activity; sid:100005440; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215296&authkey=ank3vz5syaf6bny",nocase; classtype:trojan-activity; sid:100005441; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215298&authkey=albzyizuqczfv9s",nocase; classtype:trojan-activity; sid:100005442; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7d109f249b512466&resid=7d109f249b512466!543&authkey=acqc4xjghclmwbs",nocase; classtype:trojan-activity; sid:100005443; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b!183&authkey=aggjy50pjuecoli",nocase; classtype:trojan-activity; sid:100005444; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21181&authkey=ama3betib0dac18",nocase; classtype:trojan-activity; sid:100005445; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21183&authkey=aggjy50pjuecoli",nocase; classtype:trojan-activity; sid:100005446; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!443&authkey=abue79u9di9axjm",nocase; classtype:trojan-activity; sid:100005447; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!444&authkey=abzxvycu0ggtmg8",nocase; classtype:trojan-activity; sid:100005448; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0%21443&authkey=abue79u9di9axjm",nocase; classtype:trojan-activity; sid:100005449; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0%21444&authkey=abzxvycu0ggtmg8",nocase; classtype:trojan-activity; sid:100005450; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7e81645429ac5a22&resid=7e81645429ac5a22%21105&authkey=aa691jwf5wqi80c",nocase; classtype:trojan-activity; sid:100005451; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7fed4fbea32e3c1e&resid=7fed4fbea32e3c1e%21107&authkey=aeoxfycpolifch0",nocase; classtype:trojan-activity; sid:100005452; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=806bac90dc071edf&resid=806bac90dc071edf!105&authkey=!ao7jyz6-licb8hq",nocase; classtype:trojan-activity; sid:100005453; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=81c2d8b116274e17&resid=81c2d8b116274e17%21107&authkey=aaqw-t4dx2sbvda",nocase; classtype:trojan-activity; sid:100005454; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=82977114b1af209d&resid=82977114b1af209d!220&authkey=abuin5vdedjughm",nocase; classtype:trojan-activity; sid:100005455; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=860a0980486c93fa&resid=860a0980486c93fa!303&authkey=!agcmlab4r6syfvk",nocase; classtype:trojan-activity; sid:100005456; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21164&authkey=agbeiinncf8ok_4",nocase; classtype:trojan-activity; sid:100005457; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21165&authkey=aiof8rdvxglnm-c",nocase; classtype:trojan-activity; sid:100005458; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4!2402&authkey=amigiam45mt6jia",nocase; classtype:trojan-activity; sid:100005459; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4%212402&authkey=amigiam45mt6jia",nocase; classtype:trojan-activity; sid:100005460; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=890837b4e4ca07c6&resid=890837b4e4ca07c6%21289&authkey=abujc0akmtbsxf4",nocase; classtype:trojan-activity; sid:100005461; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8983011c6ecfb1d8&resid=8983011c6ecfb1d8%21132&authkey=ah0vja7wpyfjj84",nocase; classtype:trojan-activity; sid:100005462; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8a1574ed0cecd68a&resid=8a1574ed0cecd68a%21395&authkey=ane01evt0sz-1wk",nocase; classtype:trojan-activity; sid:100005463; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8c77cee60e33a6b1&resid=8c77cee60e33a6b1%21106&authkey=af8h8jn801bjnbk",nocase; classtype:trojan-activity; sid:100005464; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8ca507baa15fdb5c&resid=8ca507baa15fdb5c!213&authkey=acyrjlhflcrypae",nocase; classtype:trojan-activity; sid:100005465; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8ffd8cbd6540c065&resid=8ffd8cbd6540c065!822&authkey=acfj7bbrmktj1i0",nocase; classtype:trojan-activity; sid:100005466; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!243&authkey=aeiqd4ihuqopwm8",nocase; classtype:trojan-activity; sid:100005467; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21276&authkey=afig5wsljtdc33s",nocase; classtype:trojan-activity; sid:100005468; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my",nocase; classtype:trojan-activity; sid:100005469; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25!130&authkey=ais_g9dqoddonsc",nocase; classtype:trojan-activity; sid:100005470; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby",nocase; classtype:trojan-activity; sid:100005471; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21109&authkey=akr1n3qxtmnttuo",nocase; classtype:trojan-activity; sid:100005472; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21113&authkey=ajpvf1h89sqstti",nocase; classtype:trojan-activity; sid:100005473; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!289&authkey=aoiy68zx8ddnjhe",nocase; classtype:trojan-activity; sid:100005474; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!290&authkey=afn1bhvmpaicari",nocase; classtype:trojan-activity; sid:100005475; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!291&authkey=aknqfhnxttsrvz4",nocase; classtype:trojan-activity; sid:100005476; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!297&authkey=agy0f-5almc6_ia",nocase; classtype:trojan-activity; sid:100005477; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!298&authkey=ajiut2kebcaycok",nocase; classtype:trojan-activity; sid:100005478; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21288&authkey=ag9wi9pub-q4jly",nocase; classtype:trojan-activity; sid:100005479; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21289&authkey=aoiy68zx8ddnjhe",nocase; classtype:trojan-activity; sid:100005480; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21290&authkey=afn1bhvmpaicari",nocase; classtype:trojan-activity; sid:100005481; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21291&authkey=aknqfhnxttsrvz4",nocase; classtype:trojan-activity; sid:100005482; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21295&authkey=afvy6r0mspzeb6m",nocase; classtype:trojan-activity; sid:100005483; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21297&authkey=agy0f-5almc6_ia",nocase; classtype:trojan-activity; sid:100005484; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21298&authkey=ajiut2kebcaycok",nocase; classtype:trojan-activity; sid:100005485; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21299&authkey=agmfs3scdvngolm",nocase; classtype:trojan-activity; sid:100005486; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21105&authkey=ah9x7rn0p03kd_m",nocase; classtype:trojan-activity; sid:100005487; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21110&authkey=ammswulpdsjeu4w",nocase; classtype:trojan-activity; sid:100005488; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3!107&authkey=ac-m9dlvo5l7wfk",nocase; classtype:trojan-activity; sid:100005489; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3%21107&authkey=ac-m9dlvo5l7wfk",nocase; classtype:trojan-activity; sid:100005490; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=96a54b19ff5f6bab&resid=96a54b19ff5f6bab%21107&authkey=anxv07ez7s5sh_k",nocase; classtype:trojan-activity; sid:100005491; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21410&authkey=acwug6bewxk0pli",nocase; classtype:trojan-activity; sid:100005492; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21411&authkey=aj8o1fcvfhibmlm",nocase; classtype:trojan-activity; sid:100005493; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=96fd249b957988a2&resid=96fd249b957988a2%211303&authkey=ah_etf1fqofknue",nocase; classtype:trojan-activity; sid:100005494; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935!778&authkey=aaezyk4ypt-elma",nocase; classtype:trojan-activity; sid:100005495; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21772&authkey=akeozmv0aafqlbg",nocase; classtype:trojan-activity; sid:100005496; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21774&authkey=aly_m3fnrvh6dfq",nocase; classtype:trojan-activity; sid:100005497; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21775&authkey=abblpjxi4mwomgs",nocase; classtype:trojan-activity; sid:100005498; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21777&authkey=ahmuwqi4jg8rvho",nocase; classtype:trojan-activity; sid:100005499; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=98103c88c2d68867&resid=98103c88c2d68867!773&authkey=akptbml43mi4ufc",nocase; classtype:trojan-activity; sid:100005500; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211925&authkey=amhhfhcsigeue9w",nocase; classtype:trojan-activity; sid:100005501; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211927&authkey=an_3paqpemptbvm",nocase; classtype:trojan-activity; sid:100005502; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211953&authkey=abdfqiyruwplpo0",nocase; classtype:trojan-activity; sid:100005503; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211954&authkey=aok-srkhxjazccy",nocase; classtype:trojan-activity; sid:100005504; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21172&authkey=ahharhcv0fmn5fm",nocase; classtype:trojan-activity; sid:100005505; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21173&authkey=aecb3qcquacvzhi",nocase; classtype:trojan-activity; sid:100005506; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21174&authkey=afv7cprqwxezgsi",nocase; classtype:trojan-activity; sid:100005507; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8",nocase; classtype:trojan-activity; sid:100005508; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq",nocase; classtype:trojan-activity; sid:100005509; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq",nocase; classtype:trojan-activity; sid:100005510; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9fb622acb27482ef&resid=9fb622acb27482ef%211197&authkey=aeacibxy2zlyxro",nocase; classtype:trojan-activity; sid:100005511; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o",nocase; classtype:trojan-activity; sid:100005512; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4",nocase; classtype:trojan-activity; sid:100005513; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi",nocase; classtype:trojan-activity; sid:100005514; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340!997&authkey=akw6btyej2zht08",nocase; classtype:trojan-activity; sid:100005515; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340%21997&authkey=akw6btyej2zht08",nocase; classtype:trojan-activity; sid:100005516; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a1c8c8055848b889&resid=a1c8c8055848b889!111&authkey=agzlftsgr4lspvo",nocase; classtype:trojan-activity; sid:100005517; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a2cd2cdb93584d7e&resid=a2cd2cdb93584d7e%21106&authkey=aeifpqbwo1s3dyq",nocase; classtype:trojan-activity; sid:100005518; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211064&authkey=apebndb6tstxywi",nocase; classtype:trojan-activity; sid:100005519; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211065&authkey=aca4_dggi5gbbfs",nocase; classtype:trojan-activity; sid:100005520; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211067&authkey=ae-3ej9zzj4ibhw",nocase; classtype:trojan-activity; sid:100005521; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211069&authkey=agx6b8qjt_clm-o",nocase; classtype:trojan-activity; sid:100005522; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4acaf66051e469e&resid=a4acaf66051e469e!189&authkey=alnhzcg0wzhusdc",nocase; classtype:trojan-activity; sid:100005523; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a502994ea313f5c7&resid=a502994ea313f5c7%21215&authkey=aiydvejv0l8stbs",nocase; classtype:trojan-activity; sid:100005524; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21!6053&authkey=agfh0ahstj7rrki",nocase; classtype:trojan-activity; sid:100005525; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21%216053&authkey=agfh0ahstj7rrki",nocase; classtype:trojan-activity; sid:100005526; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fi",nocase; classtype:trojan-activity; sid:100005527; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a76c2c9b2bbef5ec&resid=a76c2c9b2bbef5ec%21141&authkey=akcfuxzfafd_c9c",nocase; classtype:trojan-activity; sid:100005528; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21414&authkey=akf9uwwkitvhrvc",nocase; classtype:trojan-activity; sid:100005529; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21415&authkey=ag_5kthuezprnoy",nocase; classtype:trojan-activity; sid:100005530; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21416&authkey=airlma-pycgfkyc",nocase; classtype:trojan-activity; sid:100005531; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21419&authkey=ab1-sgyv2gibyey",nocase; classtype:trojan-activity; sid:100005532; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21422&authkey=acphsmdy415izjg",nocase; classtype:trojan-activity; sid:100005533; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21424&authkey=afvfwz5uvde1pui",nocase; classtype:trojan-activity; sid:100005534; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a819c72315838312&resid=a819c72315838312%21112&authkey=abl1vflnfw3nrgi",nocase; classtype:trojan-activity; sid:100005535; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=aa4e252db942faec&resid=aa4e252db942faec%21168&authkey=anlnjo7xnwtswuk",nocase; classtype:trojan-activity; sid:100005536; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ae28961c75435487&resid=ae28961c75435487%21106&authkey=alph5awcis8r9iw",nocase; classtype:trojan-activity; sid:100005537; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992!113&authkey=agh9q_zzyjjcspc",nocase; classtype:trojan-activity; sid:100005538; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992%21113&authkey=agh9q_zzyjjcspc",nocase; classtype:trojan-activity; sid:100005539; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=af84ebf13dd5499c&resid=af84ebf13dd5499c!167&authkey=anqr_yvn_hdh2_e",nocase; classtype:trojan-activity; sid:100005540; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308!2152&authkey=abutaac83l5utks",nocase; classtype:trojan-activity; sid:100005541; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308%212152&authkey=abutaac83l5utks",nocase; classtype:trojan-activity; sid:100005542; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b0fddd36b3843d3b&resid=b0fddd36b3843d3b!561&authkey=abhena0pdghcveu",nocase; classtype:trojan-activity; sid:100005543; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b0fddd36b3843d3b&resid=b0fddd36b3843d3b%21561&authkey=abhena0pdghcveu",nocase; classtype:trojan-activity; sid:100005544; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21650&authkey=aht-wbxsofyx33u",nocase; classtype:trojan-activity; sid:100005545; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21651&authkey=aebbyk6sevdmzgm",nocase; classtype:trojan-activity; sid:100005546; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21652&authkey=afsw5wahxo5kwjy",nocase; classtype:trojan-activity; sid:100005547; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1c3a5ef115e135c&resid=b1c3a5ef115e135c%216219&authkey=ahr7bklirbub0pc",nocase; classtype:trojan-activity; sid:100005548; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b2289382b9cf7ba8&resid=b2289382b9cf7ba8%21106&authkey=ajwobaztcbbpxmy",nocase; classtype:trojan-activity; sid:100005549; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21120&authkey=aozmspl2dqkgkgy",nocase; classtype:trojan-activity; sid:100005550; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21123&authkey=aj18p0rtfbtwa84",nocase; classtype:trojan-activity; sid:100005551; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21139&authkey=ahwfjvw4zmjukeo",nocase; classtype:trojan-activity; sid:100005552; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21140&authkey=aksvfpmrfqrrggw",nocase; classtype:trojan-activity; sid:100005553; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21141&authkey=acznh6clby0qyww",nocase; classtype:trojan-activity; sid:100005554; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21142&authkey=ajf7j1rr3d7jcxy",nocase; classtype:trojan-activity; sid:100005555; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21143&authkey=ahs21wnsqb_vu9w",nocase; classtype:trojan-activity; sid:100005556; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b50c4248502103d0&resid=b50c4248502103d0%21107&authkey=alf1nley7ja4dbq",nocase; classtype:trojan-activity; sid:100005557; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6!164&authkey=adfsfcdaw3biboy",nocase; classtype:trojan-activity; sid:100005558; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6%21164&authkey=adfsfcdaw3biboy",nocase; classtype:trojan-activity; sid:100005559; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b7cb31db66675eb4&resid=b7cb31db66675eb4%21922&authkey=aghayyucvwey7lg",nocase; classtype:trojan-activity; sid:100005560; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b86046e8cbd4254b&resid=b86046e8cbd4254b%21115&authkey=agwstptwpaquleg",nocase; classtype:trojan-activity; sid:100005561; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b!7521&authkey=ablt9zdyq2d4rb0",nocase; classtype:trojan-activity; sid:100005562; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b%217521&authkey=ablt9zdyq2d4rb0",nocase; classtype:trojan-activity; sid:100005563; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b90c1aa3b6cd0326&resid=b90c1aa3b6cd0326%21471&authkey=aoil8ra4oc4s_2m",nocase; classtype:trojan-activity; sid:100005564; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b9690a1860a591d0&resid=b9690a1860a591d0%21161&authkey=aehawjpwf6tqtm8",nocase; classtype:trojan-activity; sid:100005565; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b!246&authkey=afyrchdutalpu90",nocase; classtype:trojan-activity; sid:100005566; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b%21246&authkey=afyrchdutalpu90",nocase; classtype:trojan-activity; sid:100005567; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=bf83d9247c2329e0&resid=bf83d9247c2329e0%211108&authkey=absaw-bpqrc6mpq",nocase; classtype:trojan-activity; sid:100005568; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214199&authkey=adgqe8qiyu92bqm",nocase; classtype:trojan-activity; sid:100005569; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214200&authkey=adqtju8i3nmlgai",nocase; classtype:trojan-activity; sid:100005570; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214201&authkey=ahqber27s7gg8kk",nocase; classtype:trojan-activity; sid:100005571; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019!1251&authkey=act34eizpzjugfa",nocase; classtype:trojan-activity; sid:100005572; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019%211251&authkey=act34eizpzjugfa",nocase; classtype:trojan-activity; sid:100005573; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1337&authkey=afnvu1fsuczht5e",nocase; classtype:trojan-activity; sid:100005574; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1338&authkey=ajngambosws75_c",nocase; classtype:trojan-activity; sid:100005575; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1340&authkey=al1ay3fbtude6d8",nocase; classtype:trojan-activity; sid:100005576; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1342&authkey=acpr_htn2jtaxfu",nocase; classtype:trojan-activity; sid:100005577; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1343&authkey=abodysrxu9l2xxu",nocase; classtype:trojan-activity; sid:100005578; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1344&authkey=aozerppd6mnokwy",nocase; classtype:trojan-activity; sid:100005579; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1345&authkey=aevvyhonxhtcdh0",nocase; classtype:trojan-activity; sid:100005580; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1346&authkey=achrnf5vlov1gf4",nocase; classtype:trojan-activity; sid:100005581; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1347&authkey=al-zge-ttvr921s",nocase; classtype:trojan-activity; sid:100005582; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211337&authkey=afnvu1fsuczht5e",nocase; classtype:trojan-activity; sid:100005583; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211338&authkey=ajngambosws75_c",nocase; classtype:trojan-activity; sid:100005584; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211340&authkey=al1ay3fbtude6d8",nocase; classtype:trojan-activity; sid:100005585; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211342&authkey=acpr_htn2jtaxfu",nocase; classtype:trojan-activity; sid:100005586; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211343&authkey=abodysrxu9l2xxu",nocase; classtype:trojan-activity; sid:100005587; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211344&authkey=aozerppd6mnokwy",nocase; classtype:trojan-activity; sid:100005588; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211345&authkey=aevvyhonxhtcdh0",nocase; classtype:trojan-activity; sid:100005589; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211346&authkey=achrnf5vlov1gf4",nocase; classtype:trojan-activity; sid:100005590; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211347&authkey=al-zge-ttvr921s",nocase; classtype:trojan-activity; sid:100005591; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c701663053a57d59&resid=c701663053a57d59%211009&authkey=ahowgkak7j0p2q8",nocase; classtype:trojan-activity; sid:100005592; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21486&authkey=amy4euf_rrlcykc",nocase; classtype:trojan-activity; sid:100005593; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21489&authkey=ako3anwfnqfohnc",nocase; classtype:trojan-activity; sid:100005594; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c7c32628aba70e70&resid=c7c32628aba70e70%21114&authkey=agdy8xpuh32sluw",nocase; classtype:trojan-activity; sid:100005595; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c80630c4d385fb9d&resid=c80630c4d385fb9d%21286&authkey=amgaucv8bld_5qs",nocase; classtype:trojan-activity; sid:100005596; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c8b0c7dc2b2570c5&resid=c8b0c7dc2b2570c5!122&authkey=aa4yfqt4cckzxhe",nocase; classtype:trojan-activity; sid:100005597; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c8b0c7dc2b2570c5&resid=c8b0c7dc2b2570c5%21122&authkey=aa4yfqt4cckzxhe",nocase; classtype:trojan-activity; sid:100005598; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21546&authkey=aa6q-ryiifnet5m",nocase; classtype:trojan-activity; sid:100005599; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21547&authkey=aipm8qnwbgo4yga",nocase; classtype:trojan-activity; sid:100005600; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!355&authkey=aajjwf_sm4xdqdk",nocase; classtype:trojan-activity; sid:100005601; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!357&authkey=alw3vqqxz6myrle",nocase; classtype:trojan-activity; sid:100005602; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21354&authkey=aa_ukeour7rex1s",nocase; classtype:trojan-activity; sid:100005603; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21355&authkey=aajjwf_sm4xdqdk",nocase; classtype:trojan-activity; sid:100005604; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21357&authkey=alw3vqqxz6myrle",nocase; classtype:trojan-activity; sid:100005605; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca897bdd16fc7940&resid=ca897bdd16fc7940%21106&authkey=aniklpt8vtlahbg",nocase; classtype:trojan-activity; sid:100005606; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2!109&authkey=ac4gxwjoopafr9a",nocase; classtype:trojan-activity; sid:100005607; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2%21109&authkey=ac4gxwjoopafr9a",nocase; classtype:trojan-activity; sid:100005608; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cbb66cac420484bc&resid=cbb66cac420484bc!10968&authkey=aj9bjkobu-rlnaw",nocase; classtype:trojan-activity; sid:100005609; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!742&authkey=akbxju17f8g0r2s",nocase; classtype:trojan-activity; sid:100005610; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!744&authkey=adak4zftd0yhhhs",nocase; classtype:trojan-activity; sid:100005611; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21742&authkey=akbxju17f8g0r2s",nocase; classtype:trojan-activity; sid:100005612; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21744&authkey=adak4zftd0yhhhs",nocase; classtype:trojan-activity; sid:100005613; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!872&authkey=ap9hchztywo8zuo",nocase; classtype:trojan-activity; sid:100005614; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!874&authkey=alkzcbxz-dscgum",nocase; classtype:trojan-activity; sid:100005615; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!875&authkey=aka55ybdhqnoc6c",nocase; classtype:trojan-activity; sid:100005616; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21872&authkey=ap9hchztywo8zuo",nocase; classtype:trojan-activity; sid:100005617; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21874&authkey=alkzcbxz-dscgum",nocase; classtype:trojan-activity; sid:100005618; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21875&authkey=aka55ybdhqnoc6c",nocase; classtype:trojan-activity; sid:100005619; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d2f3748954f6f8a8&resid=d2f3748954f6f8a8%21119&authkey=aex5s9uoun2zps0",nocase; classtype:trojan-activity; sid:100005620; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1029&authkey=ann3uz8huqi7ogw",nocase; classtype:trojan-activity; sid:100005621; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1030&authkey=aeqnasuksxccax4",nocase; classtype:trojan-activity; sid:100005622; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1031&authkey=acxtarrhbwrqt20",nocase; classtype:trojan-activity; sid:100005623; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1032&authkey=aemitbkn-vma9yk",nocase; classtype:trojan-activity; sid:100005624; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1033&authkey=abiydifgst6musa",nocase; classtype:trojan-activity; sid:100005625; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1035&authkey=ahd_ichsrf8ok_u",nocase; classtype:trojan-activity; sid:100005626; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1038&authkey=anxf-kuw1jn9-8y",nocase; classtype:trojan-activity; sid:100005627; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211029&authkey=ann3uz8huqi7ogw",nocase; classtype:trojan-activity; sid:100005628; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211030&authkey=aeqnasuksxccax4",nocase; classtype:trojan-activity; sid:100005629; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211031&authkey=acxtarrhbwrqt20",nocase; classtype:trojan-activity; sid:100005630; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211032&authkey=aemitbkn-vma9yk",nocase; classtype:trojan-activity; sid:100005631; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211035&authkey=ahd_ichsrf8ok_u",nocase; classtype:trojan-activity; sid:100005632; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!191&authkey=ajl2uegqunsgc3q",nocase; classtype:trojan-activity; sid:100005633; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!192&authkey=acd_hx4bka3z0nw",nocase; classtype:trojan-activity; sid:100005634; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21191&authkey=ajl2uegqunsgc3q",nocase; classtype:trojan-activity; sid:100005635; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21192&authkey=acd_hx4bka3z0nw",nocase; classtype:trojan-activity; sid:100005636; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy",nocase; classtype:trojan-activity; sid:100005637; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21109&authkey=adnbm6mekgzvvh8",nocase; classtype:trojan-activity; sid:100005638; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!141&authkey=alya4infudqs53o",nocase; classtype:trojan-activity; sid:100005639; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!142&authkey=aiemnxi-s-5vrz0",nocase; classtype:trojan-activity; sid:100005640; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21141&authkey=alya4infudqs53o",nocase; classtype:trojan-activity; sid:100005641; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21142&authkey=aiemnxi-s-5vrz0",nocase; classtype:trojan-activity; sid:100005642; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21142&authkey=aiemnxi-s-5vrz0&c=3ii9gcd&r=5onulz3wldybwlmup37su3&k=7s1&s=kzymn52eroemh1tamvmlsfsn9jtvwguukky5hlxcfgw",nocase; classtype:trojan-activity; sid:100005643; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=db0fc77df51690e1&resid=db0fc77df51690e1%21802&authkey=apefr8w_rdk--pe",nocase; classtype:trojan-activity; sid:100005644; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=db5548cd728f142b&resid=db5548cd728f142b%21187&authkey=aansxudby0o7uwq",nocase; classtype:trojan-activity; sid:100005645; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=db62f747c6d887d0&resid=db62f747c6d887d0%21111&authkey=ai2guftczvfehs4",nocase; classtype:trojan-activity; sid:100005646; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dcd65237fcd1a1a9&resid=dcd65237fcd1a1a9%21162&authkey=aprqs0hugnfo6uq",nocase; classtype:trojan-activity; sid:100005647; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7527&authkey=aipybipwht56um8",nocase; classtype:trojan-activity; sid:100005648; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7530&authkey=am9p2ic6zdkgfmy",nocase; classtype:trojan-activity; sid:100005649; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7532&authkey=aonjnubquvon_uk",nocase; classtype:trojan-activity; sid:100005650; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217527&authkey=aipybipwht56um8",nocase; classtype:trojan-activity; sid:100005651; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217530&authkey=am9p2ic6zdkgfmy",nocase; classtype:trojan-activity; sid:100005652; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217532&authkey=aonjnubquvon_uk",nocase; classtype:trojan-activity; sid:100005653; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21107&authkey=akrabrcroiddkxw",nocase; classtype:trojan-activity; sid:100005654; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21115&authkey=ad1ncwtj_zcjsh0",nocase; classtype:trojan-activity; sid:100005655; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21132&authkey=akpbxohbtjebyn4",nocase; classtype:trojan-activity; sid:100005656; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21150&authkey=aevazjbqnu7cmjs",nocase; classtype:trojan-activity; sid:100005657; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21160&authkey=aiendf-9lyln0x0",nocase; classtype:trojan-activity; sid:100005658; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e1065ab3e86a5fc2&resid=e1065ab3e86a5fc2%211443&authkey=apybkcvf4iwxp_q",nocase; classtype:trojan-activity; sid:100005659; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e3ddc3980f743711&resid=e3ddc3980f743711%21795&authkey=aptivsvyk2we5xc",nocase; classtype:trojan-activity; sid:100005660; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21745&authkey=ah1i_jo73zgdxpc",nocase; classtype:trojan-activity; sid:100005661; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21746&authkey=ag1mhwlznwdxpw0",nocase; classtype:trojan-activity; sid:100005662; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e43694f4bd6f68d1&resid=e43694f4bd6f68d1!563&authkey=aj8ovsob9ll6r-c",nocase; classtype:trojan-activity; sid:100005663; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!509&authkey=akmdyqkzcsuf_gg",nocase; classtype:trojan-activity; sid:100005664; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!511&authkey=agfs0q7dz7os1lu",nocase; classtype:trojan-activity; sid:100005665; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c%21511&authkey=agfs0q7dz7os1lu",nocase; classtype:trojan-activity; sid:100005666; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e54ea4e0368d023b&resid=e54ea4e0368d023b%21106&authkey=aozas6g9pm0fzvq",nocase; classtype:trojan-activity; sid:100005667; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21349&authkey=ae9ea8jdsa7vmom",nocase; classtype:trojan-activity; sid:100005668; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21350&authkey=ao-vuexoihzj7da",nocase; classtype:trojan-activity; sid:100005669; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2!142&authkey=ais88uad5aom6qu",nocase; classtype:trojan-activity; sid:100005670; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2%21142&authkey=ais88uad5aom6qu",nocase; classtype:trojan-activity; sid:100005671; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e86539a3497e46a2&resid=e86539a3497e46a2!120&authkey=amd6o5flalahjsy",nocase; classtype:trojan-activity; sid:100005672; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e86539a3497e46a2&resid=e86539a3497e46a2%21120&authkey=amd6o5flalahjsy",nocase; classtype:trojan-activity; sid:100005673; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e97110434470423e&resid=e97110434470423e%21113&authkey=afowclex54if0g0",nocase; classtype:trojan-activity; sid:100005674; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw",nocase; classtype:trojan-activity; sid:100005675; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw",nocase; classtype:trojan-activity; sid:100005676; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211215&authkey=ac1jr_bieufz0ai",nocase; classtype:trojan-activity; sid:100005677; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211219&authkey=akgo75rmvr4khlc",nocase; classtype:trojan-activity; sid:100005678; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ebacca5dec27fd20&resid=ebacca5dec27fd20%2118735&authkey=ajfyl1mzidnylc8",nocase; classtype:trojan-activity; sid:100005679; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21113&authkey=aovavpmokd2jrns",nocase; classtype:trojan-activity; sid:100005680; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21116&authkey=aadnj5xyfasugu8",nocase; classtype:trojan-activity; sid:100005681; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ef04dd7f0a6a5f7c&resid=ef04dd7f0a6a5f7c%21142&authkey=aad-nuysvlhc-i4",nocase; classtype:trojan-activity; sid:100005682; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!202&authkey=ah1gjq8j29darw4",nocase; classtype:trojan-activity; sid:100005683; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!203&authkey=af8xr99mrqp8um8",nocase; classtype:trojan-activity; sid:100005684; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!204&authkey=ad0nbzlscbg-0sa",nocase; classtype:trojan-activity; sid:100005685; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21202&authkey=ah1gjq8j29darw4",nocase; classtype:trojan-activity; sid:100005686; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21203&authkey=af8xr99mrqp8um8",nocase; classtype:trojan-activity; sid:100005687; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21204&authkey=ad0nbzlscbg-0sa",nocase; classtype:trojan-activity; sid:100005688; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21489&authkey=ads_gff3tjkd0w0",nocase; classtype:trojan-activity; sid:100005689; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21490&authkey=aj_rld7xooge6aw",nocase; classtype:trojan-activity; sid:100005690; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21492&authkey=ahdb75ptd1_uc8e",nocase; classtype:trojan-activity; sid:100005691; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f06038a5f7dbd6d6&resid=f06038a5f7dbd6d6%215498&authkey=aiozi3z5qzdysmu",nocase; classtype:trojan-activity; sid:100005692; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f293cebb54e5ea71&resid=f293cebb54e5ea71%21293&authkey=aha74rsqiuewnpq",nocase; classtype:trojan-activity; sid:100005693; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21566&authkey=aevafh7rydhi19k",nocase; classtype:trojan-activity; sid:100005694; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21581&authkey=agx0b8ho87w4uie",nocase; classtype:trojan-activity; sid:100005695; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21582&authkey=af-9_xwysl1o7-c",nocase; classtype:trojan-activity; sid:100005696; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21598&authkey=ah-gkc-b7fa8h-g",nocase; classtype:trojan-activity; sid:100005697; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21599&authkey=aajunhe1ex_-zta",nocase; classtype:trojan-activity; sid:100005698; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!216&authkey=alslscyemd7hr_o",nocase; classtype:trojan-activity; sid:100005699; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!223&authkey=ajbtso2laio00ao",nocase; classtype:trojan-activity; sid:100005700; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21216&authkey=alslscyemd7hr_o",nocase; classtype:trojan-activity; sid:100005701; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f50a3aff00683adc&resid=f50a3aff00683adc%21108&authkey=ac44gtgp13l9xpw",nocase; classtype:trojan-activity; sid:100005702; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f50a3aff00683adc&resid=f50a3aff00683adc%21139&authkey=aovmqh4ookdlkty",nocase; classtype:trojan-activity; sid:100005703; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f79e41c0e32d3314&resid=f79e41c0e32d3314%211182&authkey=aiqtptberyvlgqk&em=2%22",nocase; classtype:trojan-activity; sid:100005704; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806!1368&authkey=anphh1fijhvzv6c",nocase; classtype:trojan-activity; sid:100005705; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806%211368&authkey=anphh1fijhvzv6c",nocase; classtype:trojan-activity; sid:100005706; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382!159&authkey=ai4_8srrzf48hw0",nocase; classtype:trojan-activity; sid:100005707; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382%21159&authkey=ai4_8srrzf48hw0",nocase; classtype:trojan-activity; sid:100005708; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fb2177c192eed796&resid=fb2177c192eed796%21124&authkey=abotnmdhu_tg7bc",nocase; classtype:trojan-activity; sid:100005709; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fd50774e5ce0e314&resid=fd50774e5ce0e314%21778&authkey=aoxb2vhhz3qodiu",nocase; classtype:trojan-activity; sid:100005710; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fe85161c3947f2c1&resid=fe85161c3947f2c1%211441&authkey=agb6c1ecr91svrw",nocase; classtype:trojan-activity; sid:100005711; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e!192&authkey=ab_lrrmyxmcfrjc",nocase; classtype:trojan-activity; sid:100005712; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e%21192&authkey=ab_lrrmyxmcfrjc",nocase; classtype:trojan-activity; sid:100005713; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!693&authkey=agcpkhnewfte_yc",nocase; classtype:trojan-activity; sid:100005714; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!694&authkey=aa5jqzjsp0esr1s",nocase; classtype:trojan-activity; sid:100005715; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21693&authkey=agcpkhnewfte_yc",nocase; classtype:trojan-activity; sid:100005716; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21694&authkey=aa5jqzjsp0esr1s",nocase; classtype:trojan-activity; sid:100005717; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!330&authkey=adxnzkb0a09pizw",nocase; classtype:trojan-activity; sid:100005718; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!334&authkey=agsvox_t7qim4ta",nocase; classtype:trojan-activity; sid:100005719; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!335&authkey=ach14e6omcghwgg",nocase; classtype:trojan-activity; sid:100005720; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21330&authkey=adxnzkb0a09pizw",nocase; classtype:trojan-activity; sid:100005721; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21333&authkey=aielwtaiuvcttlm",nocase; classtype:trojan-activity; sid:100005722; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta",nocase; classtype:trojan-activity; sid:100005723; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pastebin.com",nocase; http_uri; content:"/raw/yqvsvlvq",nocase; classtype:trojan-activity; sid:100005724; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pierreconsulting.info",nocase; http_uri; content:"/wp-admin/llc/mwcacs65xienqdp/",nocase; classtype:trojan-activity; sid:100005725; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pioneiraagronegocio.com.br",nocase; http_uri; content:"/bayesian-forecasting-amj5e/s5hqmf6/",nocase; classtype:trojan-activity; sid:100005726; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"procrossover.ru",nocase; http_uri; content:"/wp-content/uploads/2020/10/skoda22.jpg",nocase; classtype:trojan-activity; sid:100005727; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"procrossover.ru",nocase; http_uri; content:"/wp-content/uploads/2020/10/skodaqq.jpg",nocase; classtype:trojan-activity; sid:100005728; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qjbutterflyevents.co.za",nocase; http_uri; content:"/wp-admin/zzcoiatsr5wujrwagsgbnm2wkjxldvgu/",nocase; classtype:trojan-activity; sid:100005729; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"quen.s3.us-east-2.amazonaws.com",nocase; http_uri; content:"/order+acknowledgement+bc202374++stock++20021+dem+p4.ace",nocase; classtype:trojan-activity; sid:100005730; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"quen.s3.us-east-2.amazonaws.com",nocase; http_uri; content:"/purchasing+ordersigned+contractinv-30067121.ace",nocase; classtype:trojan-activity; sid:100005731; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/arntsonl/calc_security_poc/master/dll/calc.dll",nocase; classtype:trojan-activity; sid:100005732; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/bero1985/berotinypascal/e34bd4164f4b7c27e7cf667dffd9274d33d6dfbe/bin/btpc.exe",nocase; classtype:trojan-activity; sid:100005733; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/evil-coder66/defendercontrol/main/defendercontrol.exe",nocase; classtype:trojan-activity; sid:100005734; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/fuzzbunch/fuzzbunch/master/payloads/doublepulsar-1.3.1.exe",nocase; classtype:trojan-activity; sid:100005735; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe",nocase; classtype:trojan-activity; sid:100005736; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/malwares/webshell/master/ajax_php%20command%20shell.rar",nocase; classtype:trojan-activity; sid:100005737; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/myqseeaccount/one/main/one.htm",nocase; classtype:trojan-activity; sid:100005738; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/realtek25556/rhti2/gh-pages/90hfnvo69vk2ot.bmp",nocase; classtype:trojan-activity; sid:100005739; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/secwiki/windows-kernel-exploits/master/ms15-076/binary/trebuchet.exe",nocase; classtype:trojan-activity; sid:100005740; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/secwiki/windows-kernel-exploits/master/ms16-098/bfill.exe",nocase; classtype:trojan-activity; sid:100005741; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/tennc/webshell/master/other/small_shell.txt",nocase; classtype:trojan-activity; sid:100005742; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"res.yeshen.com",nocase; http_uri; content:"/player/launch/2017/09/12/da5f9a1c23034353852750488feeaf36.exe",nocase; classtype:trojan-activity; sid:100005743; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sendspace.com",nocase; http_uri; content:"/pro/dl/q05z91",nocase; classtype:trojan-activity; sid:100005744; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shribharatvatika.com",nocase; http_uri; content:"/ey4lpx8rx.zip",nocase; classtype:trojan-activity; sid:100005745; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sites.google.com",nocase; http_uri; content:"/site/stormqk/dn/stormagent.apk?attredirects=0",nocase; classtype:trojan-activity; sid:100005746; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6ca94027662tilxa4p/base.txt",nocase; classtype:trojan-activity; sid:100005747; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt",nocase; classtype:trojan-activity; sid:100005748; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6cd19c87f44r9fomit/base64jef.txt",nocase; classtype:trojan-activity; sid:100005749; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6e2cbda22efxk3t7x2/base64.txt",nocase; classtype:trojan-activity; sid:100005750; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6e2f6c8c5adup2yiwx/basejefin.txt",nocase; classtype:trojan-activity; sid:100005751; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6eab37b8dadmy1gx7c/base3.5.txt",nocase; classtype:trojan-activity; sid:100005752; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6eb2aa215a8cvwcf6s/fudjs.txt",nocase; classtype:trojan-activity; sid:100005753; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aamus8/go.jpeg",nocase; classtype:trojan-activity; sid:100005754; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c7921a2cf26cunjcgvm/nanocoregomes.txt",nocase; classtype:trojan-activity; sid:100005755; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt",nocase; classtype:trojan-activity; sid:100005756; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"technologydistilled.com",nocase; http_uri; content:"/a-nurse-ss8d9/z/",nocase; classtype:trojan-activity; sid:100005757; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"truemerit.io",nocase; http_uri; content:"/databases/merit.php",nocase; classtype:trojan-activity; sid:100005758; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tsrv4.ws",nocase; http_uri; content:"/23.exe",nocase; classtype:trojan-activity; sid:100005759; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"users.skynet.be",nocase; http_uri; content:"/crisanar/defis/jek_crackme1.7.zip",nocase; classtype:trojan-activity; sid:100005760; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vniel.co.kr",nocase; http_uri; content:"/gnuboard/data/scan/amowvegfrt9ja/",nocase; classtype:trojan-activity; sid:100005761; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vniel.co.kr",nocase; http_uri; content:"/gnuboard/data/scan/fu6jvxzzs46uqlp7l/",nocase; classtype:trojan-activity; sid:100005762; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.mit.edu",nocase; http_uri; content:"/kolya/.f/root/net.mit.edu/net/user/chris/winnt/mit_agenda2a.doc",nocase; classtype:trojan-activity; sid:100005763; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.mit.edu",nocase; http_uri; content:"/kolya/.f/root/net.mit.edu/sipb/user/kolya/afs/root.afs/net/user/chris/winnt/mit_agenda2a.doc",nocase; classtype:trojan-activity; sid:100005764; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/136_140/flt_shovemydiscoupyourarse.exe",nocase; classtype:trojan-activity; sid:100005765; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/136_140/kb%5efr_ouverture.exe",nocase; classtype:trojan-activity; sid:100005766; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/136_140/kb^fr_ouverture.exe",nocase; classtype:trojan-activity; sid:100005767; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/146_150/bc_memories_from_the_mcp.exe",nocase; classtype:trojan-activity; sid:100005768; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/151_155/tidex_-_short_stuff.exe",nocase; classtype:trojan-activity; sid:100005769; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wikileaks.org",nocase; http_uri; content:"/syria-files/attach/222/222051_instruction.zip",nocase; classtype:trojan-activity; sid:100005770; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yp.hnggzyjy.cn",nocase; http_uri; content:"/common/yz.vbs",nocase; classtype:trojan-activity; sid:100005771; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.225.24",nocase; classtype:trojan-activity; sid:100000185; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.233.147",nocase; classtype:trojan-activity; sid:100000186; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.235.57",nocase; classtype:trojan-activity; sid:100000187; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.249.21",nocase; classtype:trojan-activity; sid:100000188; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110.35.4.2",nocase; classtype:trojan-activity; sid:100000189; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"110fss.net",nocase; classtype:trojan-activity; sid:100000190; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.118.111.207",nocase; classtype:trojan-activity; sid:100000191; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.118.41.173",nocase; classtype:trojan-activity; sid:100000192; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.118.88.61",nocase; classtype:trojan-activity; sid:100000193; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.119.245.114",nocase; classtype:trojan-activity; sid:100000194; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.125.67.125",nocase; classtype:trojan-activity; sid:100000195; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.160.112.142",nocase; classtype:trojan-activity; sid:100000196; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.162.224.14",nocase; classtype:trojan-activity; sid:100000197; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.163.50.120",nocase; classtype:trojan-activity; sid:100000198; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.165.21.195",nocase; classtype:trojan-activity; sid:100000199; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.165.28.234",nocase; classtype:trojan-activity; sid:100000200; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.17.186.194",nocase; classtype:trojan-activity; sid:100000201; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.170.84.182",nocase; classtype:trojan-activity; sid:100000202; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.170.86.133",nocase; classtype:trojan-activity; sid:100000203; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.172.164.104",nocase; classtype:trojan-activity; sid:100000204; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.176.182.149",nocase; classtype:trojan-activity; sid:100000205; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.179.153.69",nocase; classtype:trojan-activity; sid:100000206; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.179.243.126",nocase; classtype:trojan-activity; sid:100000207; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.182.232.18",nocase; classtype:trojan-activity; sid:100000208; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.177.85",nocase; classtype:trojan-activity; sid:100000209; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.23.84",nocase; classtype:trojan-activity; sid:100000210; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.230.136",nocase; classtype:trojan-activity; sid:100000211; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.27.9",nocase; classtype:trojan-activity; sid:100000212; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.185.48.248",nocase; classtype:trojan-activity; sid:100000213; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.103.114",nocase; classtype:trojan-activity; sid:100000214; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.103.122",nocase; classtype:trojan-activity; sid:100000215; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.103.13",nocase; classtype:trojan-activity; sid:100000216; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.103.66",nocase; classtype:trojan-activity; sid:100000217; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.104.141",nocase; classtype:trojan-activity; sid:100000218; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.104.165",nocase; classtype:trojan-activity; sid:100000219; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.106.128",nocase; classtype:trojan-activity; sid:100000220; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.106.19",nocase; classtype:trojan-activity; sid:100000221; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.106.48",nocase; classtype:trojan-activity; sid:100000222; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.121.222",nocase; classtype:trojan-activity; sid:100000223; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.121.223",nocase; classtype:trojan-activity; sid:100000224; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.121.228",nocase; classtype:trojan-activity; sid:100000225; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.123.18",nocase; classtype:trojan-activity; sid:100000226; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.123.184",nocase; classtype:trojan-activity; sid:100000227; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.123.197",nocase; classtype:trojan-activity; sid:100000228; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.123.200",nocase; classtype:trojan-activity; sid:100000229; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.123.23",nocase; classtype:trojan-activity; sid:100000230; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.26.173",nocase; classtype:trojan-activity; sid:100000231; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.26.243",nocase; classtype:trojan-activity; sid:100000232; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.38.8.81",nocase; classtype:trojan-activity; sid:100000233; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.61.52.53",nocase; classtype:trojan-activity; sid:100000234; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.73.99.162",nocase; classtype:trojan-activity; sid:100000235; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.91.185.131",nocase; classtype:trojan-activity; sid:100000236; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.92.63.24",nocase; classtype:trojan-activity; sid:100000237; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"111.93.169.90",nocase; classtype:trojan-activity; sid:100000238; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.105.117.227",nocase; classtype:trojan-activity; sid:100000239; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.111.100.236",nocase; classtype:trojan-activity; sid:100000240; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.111.108.184",nocase; classtype:trojan-activity; sid:100000241; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.111.31.175",nocase; classtype:trojan-activity; sid:100000242; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.122.36.108",nocase; classtype:trojan-activity; sid:100000243; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.123.200.47",nocase; classtype:trojan-activity; sid:100000244; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.132.134.106",nocase; classtype:trojan-activity; sid:100000245; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.159.108.96",nocase; classtype:trojan-activity; sid:100000246; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.170.124.75",nocase; classtype:trojan-activity; sid:100000247; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.170.233.9",nocase; classtype:trojan-activity; sid:100000248; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.186.210.211",nocase; classtype:trojan-activity; sid:100000249; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.186.96.252",nocase; classtype:trojan-activity; sid:100000250; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.187.91.117",nocase; classtype:trojan-activity; sid:100000251; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.214.127.42",nocase; classtype:trojan-activity; sid:100000252; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.187.19",nocase; classtype:trojan-activity; sid:100000253; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.236.77",nocase; classtype:trojan-activity; sid:100000254; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.43.27",nocase; classtype:trojan-activity; sid:100000255; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.52.145",nocase; classtype:trojan-activity; sid:100000256; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.225.82.4",nocase; classtype:trojan-activity; sid:100000257; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.118.229",nocase; classtype:trojan-activity; sid:100000258; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.176.167",nocase; classtype:trojan-activity; sid:100000259; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.195.104",nocase; classtype:trojan-activity; sid:100000260; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.202.111",nocase; classtype:trojan-activity; sid:100000261; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.205.96",nocase; classtype:trojan-activity; sid:100000262; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.47.235",nocase; classtype:trojan-activity; sid:100000263; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.67.193",nocase; classtype:trojan-activity; sid:100000264; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.226.92.34",nocase; classtype:trojan-activity; sid:100000265; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.228.100.15",nocase; classtype:trojan-activity; sid:100000266; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.228.180.95",nocase; classtype:trojan-activity; sid:100000267; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.228.79.114",nocase; classtype:trojan-activity; sid:100000268; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.228.79.137",nocase; classtype:trojan-activity; sid:100000269; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.229.178.109",nocase; classtype:trojan-activity; sid:100000270; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.229.188.28",nocase; classtype:trojan-activity; sid:100000271; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.229.199.19",nocase; classtype:trojan-activity; sid:100000272; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.234.134.244",nocase; classtype:trojan-activity; sid:100000273; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.234.16.252",nocase; classtype:trojan-activity; sid:100000274; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.234.194.178",nocase; classtype:trojan-activity; sid:100000275; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.234.216.151",nocase; classtype:trojan-activity; sid:100000276; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.234.218.202",nocase; classtype:trojan-activity; sid:100000277; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.235.149.73",nocase; classtype:trojan-activity; sid:100000278; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.235.188.86",nocase; classtype:trojan-activity; sid:100000279; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.236.126.177",nocase; classtype:trojan-activity; sid:100000280; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.236.171.69",nocase; classtype:trojan-activity; sid:100000281; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.236.228.21",nocase; classtype:trojan-activity; sid:100000282; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.141.241",nocase; classtype:trojan-activity; sid:100000283; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.144.226",nocase; classtype:trojan-activity; sid:100000284; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.197.144",nocase; classtype:trojan-activity; sid:100000285; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.230.192",nocase; classtype:trojan-activity; sid:100000286; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.75.157",nocase; classtype:trojan-activity; sid:100000287; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.237.89.82",nocase; classtype:trojan-activity; sid:100000288; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.143.135",nocase; classtype:trojan-activity; sid:100000289; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.17.120",nocase; classtype:trojan-activity; sid:100000290; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.190.207",nocase; classtype:trojan-activity; sid:100000291; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.194.18",nocase; classtype:trojan-activity; sid:100000292; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.227.228",nocase; classtype:trojan-activity; sid:100000293; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.238.73.181",nocase; classtype:trojan-activity; sid:100000294; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.240.184.162",nocase; classtype:trojan-activity; sid:100000295; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.240.216.17",nocase; classtype:trojan-activity; sid:100000296; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.242.106.228",nocase; classtype:trojan-activity; sid:100000297; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.242.18.128",nocase; classtype:trojan-activity; sid:100000298; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.242.2.247",nocase; classtype:trojan-activity; sid:100000299; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.243.115.183",nocase; classtype:trojan-activity; sid:100000300; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.245.12.89",nocase; classtype:trojan-activity; sid:100000301; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.245.5.141",nocase; classtype:trojan-activity; sid:100000302; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.245.8.24",nocase; classtype:trojan-activity; sid:100000303; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.246.162.50",nocase; classtype:trojan-activity; sid:100000304; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.246.180.49",nocase; classtype:trojan-activity; sid:100000305; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.100.14",nocase; classtype:trojan-activity; sid:100000306; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.121.39",nocase; classtype:trojan-activity; sid:100000307; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.14.135",nocase; classtype:trojan-activity; sid:100000308; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.161.45",nocase; classtype:trojan-activity; sid:100000309; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.191.118",nocase; classtype:trojan-activity; sid:100000310; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.214.146",nocase; classtype:trojan-activity; sid:100000311; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.240.226",nocase; classtype:trojan-activity; sid:100000312; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.248.76",nocase; classtype:trojan-activity; sid:100000313; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.81.173",nocase; classtype:trojan-activity; sid:100000314; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.82.122",nocase; classtype:trojan-activity; sid:100000315; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.247.89.81",nocase; classtype:trojan-activity; sid:100000316; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.248.148.90",nocase; classtype:trojan-activity; sid:100000317; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.248.197.164",nocase; classtype:trojan-activity; sid:100000318; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.248.44.153",nocase; classtype:trojan-activity; sid:100000319; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.109.217",nocase; classtype:trojan-activity; sid:100000320; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.118.157",nocase; classtype:trojan-activity; sid:100000321; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.206.69",nocase; classtype:trojan-activity; sid:100000322; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.26.129",nocase; classtype:trojan-activity; sid:100000323; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.41.142",nocase; classtype:trojan-activity; sid:100000324; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.249.79.98",nocase; classtype:trojan-activity; sid:100000325; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.250.102.173",nocase; classtype:trojan-activity; sid:100000326; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.250.57.99",nocase; classtype:trojan-activity; sid:100000327; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.251.17.5",nocase; classtype:trojan-activity; sid:100000328; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.251.218.210",nocase; classtype:trojan-activity; sid:100000329; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.251.23.55",nocase; classtype:trojan-activity; sid:100000330; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.136.84",nocase; classtype:trojan-activity; sid:100000331; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.199.150",nocase; classtype:trojan-activity; sid:100000332; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.221.244",nocase; classtype:trojan-activity; sid:100000333; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.236.40",nocase; classtype:trojan-activity; sid:100000334; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.237.109",nocase; classtype:trojan-activity; sid:100000335; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.239.103",nocase; classtype:trojan-activity; sid:100000336; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.245.249",nocase; classtype:trojan-activity; sid:100000337; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.252.46.212",nocase; classtype:trojan-activity; sid:100000338; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.254.208.123",nocase; classtype:trojan-activity; sid:100000339; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.255.38.10",nocase; classtype:trojan-activity; sid:100000340; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.255.52.179",nocase; classtype:trojan-activity; sid:100000341; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.255.8.235",nocase; classtype:trojan-activity; sid:100000342; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.121.163",nocase; classtype:trojan-activity; sid:100000343; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.123.174",nocase; classtype:trojan-activity; sid:100000344; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.109",nocase; classtype:trojan-activity; sid:100000345; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.110",nocase; classtype:trojan-activity; sid:100000346; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.111",nocase; classtype:trojan-activity; sid:100000347; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.112",nocase; classtype:trojan-activity; sid:100000348; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.117",nocase; classtype:trojan-activity; sid:100000349; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.119",nocase; classtype:trojan-activity; sid:100000350; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.120",nocase; classtype:trojan-activity; sid:100000351; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.122",nocase; classtype:trojan-activity; sid:100000352; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.124",nocase; classtype:trojan-activity; sid:100000353; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.127",nocase; classtype:trojan-activity; sid:100000354; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.128",nocase; classtype:trojan-activity; sid:100000355; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.130",nocase; classtype:trojan-activity; sid:100000356; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.131",nocase; classtype:trojan-activity; sid:100000357; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.132",nocase; classtype:trojan-activity; sid:100000358; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.133",nocase; classtype:trojan-activity; sid:100000359; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.136",nocase; classtype:trojan-activity; sid:100000360; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.139",nocase; classtype:trojan-activity; sid:100000361; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.140",nocase; classtype:trojan-activity; sid:100000362; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.142",nocase; classtype:trojan-activity; sid:100000363; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.143",nocase; classtype:trojan-activity; sid:100000364; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.144",nocase; classtype:trojan-activity; sid:100000365; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.146",nocase; classtype:trojan-activity; sid:100000366; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.149",nocase; classtype:trojan-activity; sid:100000367; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.150",nocase; classtype:trojan-activity; sid:100000368; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.155",nocase; classtype:trojan-activity; sid:100000369; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.158",nocase; classtype:trojan-activity; sid:100000370; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.160",nocase; classtype:trojan-activity; sid:100000371; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.162",nocase; classtype:trojan-activity; sid:100000372; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.163",nocase; classtype:trojan-activity; sid:100000373; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.165",nocase; classtype:trojan-activity; sid:100000374; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.168",nocase; classtype:trojan-activity; sid:100000375; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.171",nocase; classtype:trojan-activity; sid:100000376; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.172",nocase; classtype:trojan-activity; sid:100000377; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.175",nocase; classtype:trojan-activity; sid:100000378; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.176",nocase; classtype:trojan-activity; sid:100000379; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.178",nocase; classtype:trojan-activity; sid:100000380; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.179",nocase; classtype:trojan-activity; sid:100000381; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.124.71",nocase; classtype:trojan-activity; sid:100000382; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.126.243",nocase; classtype:trojan-activity; sid:100000383; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.127.155",nocase; classtype:trojan-activity; sid:100000384; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.80.120",nocase; classtype:trojan-activity; sid:100000385; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.80.121",nocase; classtype:trojan-activity; sid:100000386; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.80.98",nocase; classtype:trojan-activity; sid:100000387; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.82.29",nocase; classtype:trojan-activity; sid:100000388; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.83.182",nocase; classtype:trojan-activity; sid:100000389; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.83.23",nocase; classtype:trojan-activity; sid:100000390; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.87.213",nocase; classtype:trojan-activity; sid:100000391; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.88.116",nocase; classtype:trojan-activity; sid:100000392; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.91.212",nocase; classtype:trojan-activity; sid:100000393; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.27.91.247",nocase; classtype:trojan-activity; sid:100000394; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.150",nocase; classtype:trojan-activity; sid:100000395; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.158",nocase; classtype:trojan-activity; sid:100000396; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.159",nocase; classtype:trojan-activity; sid:100000397; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.168",nocase; classtype:trojan-activity; sid:100000398; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.177",nocase; classtype:trojan-activity; sid:100000399; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.178",nocase; classtype:trojan-activity; sid:100000400; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.181",nocase; classtype:trojan-activity; sid:100000401; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.188",nocase; classtype:trojan-activity; sid:100000402; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.194",nocase; classtype:trojan-activity; sid:100000403; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.197",nocase; classtype:trojan-activity; sid:100000404; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.200",nocase; classtype:trojan-activity; sid:100000405; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.211",nocase; classtype:trojan-activity; sid:100000406; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.219",nocase; classtype:trojan-activity; sid:100000407; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.229",nocase; classtype:trojan-activity; sid:100000408; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.230",nocase; classtype:trojan-activity; sid:100000409; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.245",nocase; classtype:trojan-activity; sid:100000410; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.247",nocase; classtype:trojan-activity; sid:100000411; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.54",nocase; classtype:trojan-activity; sid:100000412; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.55",nocase; classtype:trojan-activity; sid:100000413; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.57",nocase; classtype:trojan-activity; sid:100000414; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.60",nocase; classtype:trojan-activity; sid:100000415; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.90",nocase; classtype:trojan-activity; sid:100000416; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.1.91",nocase; classtype:trojan-activity; sid:100000417; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.100.228",nocase; classtype:trojan-activity; sid:100000418; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.27",nocase; classtype:trojan-activity; sid:100000419; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.30",nocase; classtype:trojan-activity; sid:100000420; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.31",nocase; classtype:trojan-activity; sid:100000421; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.32",nocase; classtype:trojan-activity; sid:100000422; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.33",nocase; classtype:trojan-activity; sid:100000423; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.37",nocase; classtype:trojan-activity; sid:100000424; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.38",nocase; classtype:trojan-activity; sid:100000425; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.41",nocase; classtype:trojan-activity; sid:100000426; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.42",nocase; classtype:trojan-activity; sid:100000427; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.43",nocase; classtype:trojan-activity; sid:100000428; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.52",nocase; classtype:trojan-activity; sid:100000429; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.55",nocase; classtype:trojan-activity; sid:100000430; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.57",nocase; classtype:trojan-activity; sid:100000431; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.58",nocase; classtype:trojan-activity; sid:100000432; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.60",nocase; classtype:trojan-activity; sid:100000433; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.62",nocase; classtype:trojan-activity; sid:100000434; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.110.64",nocase; classtype:trojan-activity; sid:100000435; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.35.237",nocase; classtype:trojan-activity; sid:100000436; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.38.100",nocase; classtype:trojan-activity; sid:100000437; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.38.19",nocase; classtype:trojan-activity; sid:100000438; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.118",nocase; classtype:trojan-activity; sid:100000439; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.119",nocase; classtype:trojan-activity; sid:100000440; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.121",nocase; classtype:trojan-activity; sid:100000441; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.136",nocase; classtype:trojan-activity; sid:100000442; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.37",nocase; classtype:trojan-activity; sid:100000443; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.52",nocase; classtype:trojan-activity; sid:100000444; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.53",nocase; classtype:trojan-activity; sid:100000445; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.73",nocase; classtype:trojan-activity; sid:100000446; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.77",nocase; classtype:trojan-activity; sid:100000447; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.30.4.90",nocase; classtype:trojan-activity; sid:100000448; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.31.211.135",nocase; classtype:trojan-activity; sid:100000449; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.53.224.79",nocase; classtype:trojan-activity; sid:100000450; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.53.227.57",nocase; classtype:trojan-activity; sid:100000451; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.53.227.66",nocase; classtype:trojan-activity; sid:100000452; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.65.53.175",nocase; classtype:trojan-activity; sid:100000453; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.153.37",nocase; classtype:trojan-activity; sid:100000454; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.162.159",nocase; classtype:trojan-activity; sid:100000455; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.162.49",nocase; classtype:trojan-activity; sid:100000456; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.175.147",nocase; classtype:trojan-activity; sid:100000457; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.176.112",nocase; classtype:trojan-activity; sid:100000458; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.176.84",nocase; classtype:trojan-activity; sid:100000459; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.72.226.202",nocase; classtype:trojan-activity; sid:100000460; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.78.45.158",nocase; classtype:trojan-activity; sid:100000461; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.80.118.16",nocase; classtype:trojan-activity; sid:100000462; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.80.127.91",nocase; classtype:trojan-activity; sid:100000463; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.80.215.101",nocase; classtype:trojan-activity; sid:100000464; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.81.161.10",nocase; classtype:trojan-activity; sid:100000465; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.81.199.218",nocase; classtype:trojan-activity; sid:100000466; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.81.49.200",nocase; classtype:trojan-activity; sid:100000467; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.131.124",nocase; classtype:trojan-activity; sid:100000468; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.141.200",nocase; classtype:trojan-activity; sid:100000469; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.146.253",nocase; classtype:trojan-activity; sid:100000470; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.148.146",nocase; classtype:trojan-activity; sid:100000471; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.18.255",nocase; classtype:trojan-activity; sid:100000472; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.224.139",nocase; classtype:trojan-activity; sid:100000473; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.227.41",nocase; classtype:trojan-activity; sid:100000474; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.82.228.175",nocase; classtype:trojan-activity; sid:100000475; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.86.133.125",nocase; classtype:trojan-activity; sid:100000476; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.86.253.238",nocase; classtype:trojan-activity; sid:100000477; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.9.140.247",nocase; classtype:trojan-activity; sid:100000478; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.93.29.211",nocase; classtype:trojan-activity; sid:100000479; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.95.22.17",nocase; classtype:trojan-activity; sid:100000480; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"112.95.23.121",nocase; classtype:trojan-activity; sid:100000481; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.103.10.209",nocase; classtype:trojan-activity; sid:100000482; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.104.237.52",nocase; classtype:trojan-activity; sid:100000483; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.105.71.239",nocase; classtype:trojan-activity; sid:100000484; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.116.121.167",nocase; classtype:trojan-activity; sid:100000485; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.116.149.83",nocase; classtype:trojan-activity; sid:100000486; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.116.150.147",nocase; classtype:trojan-activity; sid:100000487; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.116.246.109",nocase; classtype:trojan-activity; sid:100000488; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.116.48.217",nocase; classtype:trojan-activity; sid:100000489; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.118.195.247",nocase; classtype:trojan-activity; sid:100000490; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.122.238.68",nocase; classtype:trojan-activity; sid:100000491; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.122.59.84",nocase; classtype:trojan-activity; sid:100000492; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.161.58.249",nocase; classtype:trojan-activity; sid:100000493; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.172.250.35",nocase; classtype:trojan-activity; sid:100000494; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.179.129.99",nocase; classtype:trojan-activity; sid:100000495; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.194.133.9",nocase; classtype:trojan-activity; sid:100000496; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.194.135.154",nocase; classtype:trojan-activity; sid:100000497; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.195.163.26",nocase; classtype:trojan-activity; sid:100000498; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.195.166.46",nocase; classtype:trojan-activity; sid:100000499; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.201.24.26",nocase; classtype:trojan-activity; sid:100000500; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.224.225.172",nocase; classtype:trojan-activity; sid:100000501; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.226.42.250",nocase; classtype:trojan-activity; sid:100000502; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.227.128.9",nocase; classtype:trojan-activity; sid:100000503; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.227.169.170",nocase; classtype:trojan-activity; sid:100000504; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.227.35.229",nocase; classtype:trojan-activity; sid:100000505; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.231.211.131",nocase; classtype:trojan-activity; sid:100000506; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.231.93.142",nocase; classtype:trojan-activity; sid:100000507; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.232.141.23",nocase; classtype:trojan-activity; sid:100000508; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.232.211.182",nocase; classtype:trojan-activity; sid:100000509; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.234.224.130",nocase; classtype:trojan-activity; sid:100000510; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.235.116.209",nocase; classtype:trojan-activity; sid:100000511; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.237.129.7",nocase; classtype:trojan-activity; sid:100000512; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.253.144.141",nocase; classtype:trojan-activity; sid:100000513; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.254.169.251",nocase; classtype:trojan-activity; sid:100000514; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.3.153.57",nocase; classtype:trojan-activity; sid:100000515; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.3.155.199",nocase; classtype:trojan-activity; sid:100000516; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.133.16",nocase; classtype:trojan-activity; sid:100000517; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.59.154.21",nocase; classtype:trojan-activity; sid:100000518; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.61.204.205",nocase; classtype:trojan-activity; sid:100000519; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.81.112.35",nocase; classtype:trojan-activity; sid:100000520; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.86.204.13",nocase; classtype:trojan-activity; sid:100000521; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.87.175.112",nocase; classtype:trojan-activity; sid:100000522; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.87.248.177",nocase; classtype:trojan-activity; sid:100000523; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.88.100.120",nocase; classtype:trojan-activity; sid:100000524; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.88.208.189",nocase; classtype:trojan-activity; sid:100000525; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.88.232.36",nocase; classtype:trojan-activity; sid:100000526; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.88.242.0",nocase; classtype:trojan-activity; sid:100000527; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.88.38.232",nocase; classtype:trojan-activity; sid:100000528; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.89.245.13",nocase; classtype:trojan-activity; sid:100000529; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"113.89.41.51",nocase; classtype:trojan-activity; sid:100000530; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.199.204.37",nocase; classtype:trojan-activity; sid:100000531; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.226.100.56",nocase; classtype:trojan-activity; sid:100000532; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.227.156.119",nocase; classtype:trojan-activity; sid:100000533; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.228.205.101",nocase; classtype:trojan-activity; sid:100000534; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.228.242.109",nocase; classtype:trojan-activity; sid:100000535; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.229.165.194",nocase; classtype:trojan-activity; sid:100000536; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.229.52.14",nocase; classtype:trojan-activity; sid:100000537; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.235.115.236",nocase; classtype:trojan-activity; sid:100000538; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.235.42.152",nocase; classtype:trojan-activity; sid:100000539; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.79.161.94",nocase; classtype:trojan-activity; sid:100000540; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"114.79.172.42",nocase; classtype:trojan-activity; sid:100000541; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.165.216.112",nocase; classtype:trojan-activity; sid:100000542; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.171.239.28",nocase; classtype:trojan-activity; sid:100000543; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.193.130.126",nocase; classtype:trojan-activity; sid:100000544; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.201.38.185",nocase; classtype:trojan-activity; sid:100000545; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.208.101.195",nocase; classtype:trojan-activity; sid:100000546; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.213.187.251",nocase; classtype:trojan-activity; sid:100000547; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.223.159.80",nocase; classtype:trojan-activity; sid:100000548; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.23.88.135",nocase; classtype:trojan-activity; sid:100000549; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.42.47.36",nocase; classtype:trojan-activity; sid:100000550; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.45.178.12",nocase; classtype:trojan-activity; sid:100000551; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.48.130.181",nocase; classtype:trojan-activity; sid:100000552; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.48.130.187",nocase; classtype:trojan-activity; sid:100000553; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.48.135.151",nocase; classtype:trojan-activity; sid:100000554; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.48.141.239",nocase; classtype:trojan-activity; sid:100000555; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.48.198.142",nocase; classtype:trojan-activity; sid:100000556; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.48.200.115",nocase; classtype:trojan-activity; sid:100000557; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.48.22.130",nocase; classtype:trojan-activity; sid:100000558; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.48.228.176",nocase; classtype:trojan-activity; sid:100000559; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.48.9.246",nocase; classtype:trojan-activity; sid:100000560; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.49.100.124",nocase; classtype:trojan-activity; sid:100000561; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.49.152.10",nocase; classtype:trojan-activity; sid:100000562; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.49.242.100",nocase; classtype:trojan-activity; sid:100000563; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.49.60.231",nocase; classtype:trojan-activity; sid:100000564; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.49.80.117",nocase; classtype:trojan-activity; sid:100000565; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.49.96.88",nocase; classtype:trojan-activity; sid:100000566; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.1.143",nocase; classtype:trojan-activity; sid:100000567; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.158.223",nocase; classtype:trojan-activity; sid:100000568; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.2.251",nocase; classtype:trojan-activity; sid:100000569; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.202.11",nocase; classtype:trojan-activity; sid:100000570; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.220.156",nocase; classtype:trojan-activity; sid:100000571; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.239.222",nocase; classtype:trojan-activity; sid:100000572; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.240.230",nocase; classtype:trojan-activity; sid:100000573; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.61.247",nocase; classtype:trojan-activity; sid:100000574; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.64.182",nocase; classtype:trojan-activity; sid:100000575; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.50.81.194",nocase; classtype:trojan-activity; sid:100000576; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.51.104.85",nocase; classtype:trojan-activity; sid:100000577; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.51.107.18",nocase; classtype:trojan-activity; sid:100000578; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.51.123.216",nocase; classtype:trojan-activity; sid:100000579; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.51.93.76",nocase; classtype:trojan-activity; sid:100000580; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.52.112.200",nocase; classtype:trojan-activity; sid:100000581; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.52.17.196",nocase; classtype:trojan-activity; sid:100000582; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.52.19.250",nocase; classtype:trojan-activity; sid:100000583; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.52.200.245",nocase; classtype:trojan-activity; sid:100000584; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.52.201.231",nocase; classtype:trojan-activity; sid:100000585; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.52.21.5",nocase; classtype:trojan-activity; sid:100000586; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.52.22.162",nocase; classtype:trojan-activity; sid:100000587; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.54.160.25",nocase; classtype:trojan-activity; sid:100000588; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.54.212.227",nocase; classtype:trojan-activity; sid:100000589; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.54.236.22",nocase; classtype:trojan-activity; sid:100000590; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.54.240.173",nocase; classtype:trojan-activity; sid:100000591; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.54.241.122",nocase; classtype:trojan-activity; sid:100000592; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.54.70.108",nocase; classtype:trojan-activity; sid:100000593; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.54.73.162",nocase; classtype:trojan-activity; sid:100000594; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.54.73.50",nocase; classtype:trojan-activity; sid:100000595; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.144.146",nocase; classtype:trojan-activity; sid:100000596; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.144.222",nocase; classtype:trojan-activity; sid:100000597; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.144.42",nocase; classtype:trojan-activity; sid:100000598; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.145.147",nocase; classtype:trojan-activity; sid:100000599; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.149.30",nocase; classtype:trojan-activity; sid:100000600; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.178.67",nocase; classtype:trojan-activity; sid:100000601; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.198.209",nocase; classtype:trojan-activity; sid:100000602; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.211.41",nocase; classtype:trojan-activity; sid:100000603; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.211.86",nocase; classtype:trojan-activity; sid:100000604; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.3.36",nocase; classtype:trojan-activity; sid:100000605; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.42.200",nocase; classtype:trojan-activity; sid:100000606; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.55.53.51",nocase; classtype:trojan-activity; sid:100000607; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.134.116",nocase; classtype:trojan-activity; sid:100000608; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.134.220",nocase; classtype:trojan-activity; sid:100000609; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.136.144",nocase; classtype:trojan-activity; sid:100000610; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.139.122",nocase; classtype:trojan-activity; sid:100000611; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.142.251",nocase; classtype:trojan-activity; sid:100000612; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.143.241",nocase; classtype:trojan-activity; sid:100000613; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.148.22",nocase; classtype:trojan-activity; sid:100000614; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.154.147",nocase; classtype:trojan-activity; sid:100000615; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.155.72",nocase; classtype:trojan-activity; sid:100000616; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.156.185",nocase; classtype:trojan-activity; sid:100000617; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.156.54",nocase; classtype:trojan-activity; sid:100000618; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.162.173",nocase; classtype:trojan-activity; sid:100000619; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.177.202",nocase; classtype:trojan-activity; sid:100000620; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.188.24",nocase; classtype:trojan-activity; sid:100000621; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.31.54",nocase; classtype:trojan-activity; sid:100000622; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.86.251",nocase; classtype:trojan-activity; sid:100000623; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.87.42",nocase; classtype:trojan-activity; sid:100000624; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.56.98.205",nocase; classtype:trojan-activity; sid:100000625; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.111.222",nocase; classtype:trojan-activity; sid:100000626; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.119.171",nocase; classtype:trojan-activity; sid:100000627; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.132.199",nocase; classtype:trojan-activity; sid:100000628; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.134.143",nocase; classtype:trojan-activity; sid:100000629; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.141.177",nocase; classtype:trojan-activity; sid:100000630; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.167.90",nocase; classtype:trojan-activity; sid:100000631; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.20.186",nocase; classtype:trojan-activity; sid:100000632; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.83.233",nocase; classtype:trojan-activity; sid:100000633; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.88.163",nocase; classtype:trojan-activity; sid:100000634; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.58.93.151",nocase; classtype:trojan-activity; sid:100000635; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.197.123",nocase; classtype:trojan-activity; sid:100000636; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.198.165",nocase; classtype:trojan-activity; sid:100000637; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.198.200",nocase; classtype:trojan-activity; sid:100000638; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.210.228",nocase; classtype:trojan-activity; sid:100000639; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.215.96",nocase; classtype:trojan-activity; sid:100000640; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.235.229",nocase; classtype:trojan-activity; sid:100000641; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.253.202",nocase; classtype:trojan-activity; sid:100000642; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.63.220",nocase; classtype:trojan-activity; sid:100000643; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.59.95.247",nocase; classtype:trojan-activity; sid:100000644; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.60.201.176",nocase; classtype:trojan-activity; sid:100000645; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.107.203",nocase; classtype:trojan-activity; sid:100000646; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.118.201",nocase; classtype:trojan-activity; sid:100000647; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.119.187",nocase; classtype:trojan-activity; sid:100000648; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.119.198",nocase; classtype:trojan-activity; sid:100000649; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.119.77",nocase; classtype:trojan-activity; sid:100000650; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.125.184",nocase; classtype:trojan-activity; sid:100000651; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.180.193",nocase; classtype:trojan-activity; sid:100000652; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.182.138",nocase; classtype:trojan-activity; sid:100000653; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.185.246",nocase; classtype:trojan-activity; sid:100000654; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.97.190",nocase; classtype:trojan-activity; sid:100000655; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.61.97.55",nocase; classtype:trojan-activity; sid:100000656; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.62.152.207",nocase; classtype:trojan-activity; sid:100000657; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.62.26.39",nocase; classtype:trojan-activity; sid:100000658; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.63.135.206",nocase; classtype:trojan-activity; sid:100000659; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.63.140.242",nocase; classtype:trojan-activity; sid:100000660; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.63.4.244",nocase; classtype:trojan-activity; sid:100000661; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.63.56.176",nocase; classtype:trojan-activity; sid:100000662; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.73.3.11",nocase; classtype:trojan-activity; sid:100000663; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.74.217.2",nocase; classtype:trojan-activity; sid:100000664; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.75.217.79",nocase; classtype:trojan-activity; sid:100000665; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.78.133.146",nocase; classtype:trojan-activity; sid:100000666; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"115.92.174.231",nocase; classtype:trojan-activity; sid:100000667; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.124.219.2",nocase; classtype:trojan-activity; sid:100000668; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.127.207.224",nocase; classtype:trojan-activity; sid:100000669; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.149.119.185",nocase; classtype:trojan-activity; sid:100000670; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.2.100.221",nocase; classtype:trojan-activity; sid:100000671; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.2.66.3",nocase; classtype:trojan-activity; sid:100000672; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.206.164.46",nocase; classtype:trojan-activity; sid:100000673; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.211.100.26",nocase; classtype:trojan-activity; sid:100000674; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.212.142.215",nocase; classtype:trojan-activity; sid:100000675; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.24.153.40",nocase; classtype:trojan-activity; sid:100000676; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.72.202.126",nocase; classtype:trojan-activity; sid:100000677; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.72.202.87",nocase; classtype:trojan-activity; sid:100000678; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.72.203.143",nocase; classtype:trojan-activity; sid:100000679; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.74.84.65",nocase; classtype:trojan-activity; sid:100000680; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.75.194.14",nocase; classtype:trojan-activity; sid:100000681; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.76.114.71",nocase; classtype:trojan-activity; sid:100000682; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"116.88.65.131",nocase; classtype:trojan-activity; sid:100000683; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.11.234.35",nocase; classtype:trojan-activity; sid:100000684; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.15.201.1",nocase; classtype:trojan-activity; sid:100000685; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.156.69.22",nocase; classtype:trojan-activity; sid:100000686; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.194.160.84",nocase; classtype:trojan-activity; sid:100000687; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.194.161.143",nocase; classtype:trojan-activity; sid:100000688; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.194.162.121",nocase; classtype:trojan-activity; sid:100000689; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.196.48.216",nocase; classtype:trojan-activity; sid:100000690; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.204.138",nocase; classtype:trojan-activity; sid:100000691; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.204.5",nocase; classtype:trojan-activity; sid:100000692; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.210.52",nocase; classtype:trojan-activity; sid:100000693; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.220.126",nocase; classtype:trojan-activity; sid:100000694; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.236.14",nocase; classtype:trojan-activity; sid:100000695; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.20.243.40",nocase; classtype:trojan-activity; sid:100000696; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.200.76.54",nocase; classtype:trojan-activity; sid:100000697; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.200.76.60",nocase; classtype:trojan-activity; sid:100000698; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.201.128.152",nocase; classtype:trojan-activity; sid:100000699; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.202.66.177",nocase; classtype:trojan-activity; sid:100000700; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.202.68.94",nocase; classtype:trojan-activity; sid:100000701; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.208.133.121",nocase; classtype:trojan-activity; sid:100000702; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.222.161.68",nocase; classtype:trojan-activity; sid:100000703; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.222.162.144",nocase; classtype:trojan-activity; sid:100000704; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.222.163.150",nocase; classtype:trojan-activity; sid:100000705; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.222.165.31",nocase; classtype:trojan-activity; sid:100000706; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.222.170.189",nocase; classtype:trojan-activity; sid:100000707; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.222.171.68",nocase; classtype:trojan-activity; sid:100000708; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.222.172.97",nocase; classtype:trojan-activity; sid:100000709; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.241.66.200",nocase; classtype:trojan-activity; sid:100000710; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.241.67.68",nocase; classtype:trojan-activity; sid:100000711; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.242.210.69",nocase; classtype:trojan-activity; sid:100000712; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.242.211.111",nocase; classtype:trojan-activity; sid:100000713; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.242.211.98",nocase; classtype:trojan-activity; sid:100000714; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.251.56.135",nocase; classtype:trojan-activity; sid:100000715; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.251.59.242",nocase; classtype:trojan-activity; sid:100000716; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.251.60.161",nocase; classtype:trojan-activity; sid:100000717; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.251.60.69",nocase; classtype:trojan-activity; sid:100000718; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.26.110.17",nocase; classtype:trojan-activity; sid:100000719; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.26.235.164",nocase; classtype:trojan-activity; sid:100000720; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.27.10.73",nocase; classtype:trojan-activity; sid:100000721; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.63.113.146",nocase; classtype:trojan-activity; sid:100000722; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.63.195.140",nocase; classtype:trojan-activity; sid:100000723; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.63.252.82",nocase; classtype:trojan-activity; sid:100000724; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.63.53.15",nocase; classtype:trojan-activity; sid:100000725; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.63.56.81",nocase; classtype:trojan-activity; sid:100000726; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.86.105.110",nocase; classtype:trojan-activity; sid:100000727; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.87.170.32",nocase; classtype:trojan-activity; sid:100000728; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.90.78.120",nocase; classtype:trojan-activity; sid:100000729; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.91.240.50",nocase; classtype:trojan-activity; sid:100000730; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.93.115.242",nocase; classtype:trojan-activity; sid:100000731; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"117.93.79.40",nocase; classtype:trojan-activity; sid:100000732; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.176.104.35",nocase; classtype:trojan-activity; sid:100000733; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.176.157.64",nocase; classtype:trojan-activity; sid:100000734; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.176.7.132",nocase; classtype:trojan-activity; sid:100000735; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.211.38.112",nocase; classtype:trojan-activity; sid:100000736; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.223.32.74",nocase; classtype:trojan-activity; sid:100000737; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.223.5.149",nocase; classtype:trojan-activity; sid:100000738; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.223.72.141",nocase; classtype:trojan-activity; sid:100000739; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.128.147",nocase; classtype:trojan-activity; sid:100000740; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.208.215",nocase; classtype:trojan-activity; sid:100000741; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.209.108",nocase; classtype:trojan-activity; sid:100000742; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.214.72",nocase; classtype:trojan-activity; sid:100000743; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.88.146",nocase; classtype:trojan-activity; sid:100000744; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.96.150",nocase; classtype:trojan-activity; sid:100000745; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.232.96.6",nocase; classtype:trojan-activity; sid:100000746; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.233.221.162",nocase; classtype:trojan-activity; sid:100000747; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.233.63.194",nocase; classtype:trojan-activity; sid:100000748; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.233.65.93",nocase; classtype:trojan-activity; sid:100000749; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.249.136.112",nocase; classtype:trojan-activity; sid:100000750; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.250.51.192",nocase; classtype:trojan-activity; sid:100000751; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.42.125.246",nocase; classtype:trojan-activity; sid:100000752; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.43.180.33",nocase; classtype:trojan-activity; sid:100000753; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.68.245.69",nocase; classtype:trojan-activity; sid:100000754; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.75.120.136",nocase; classtype:trojan-activity; sid:100000755; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.75.240.239",nocase; classtype:trojan-activity; sid:100000756; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.75.50.253",nocase; classtype:trojan-activity; sid:100000757; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.75.70.70",nocase; classtype:trojan-activity; sid:100000758; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.125.92",nocase; classtype:trojan-activity; sid:100000759; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.164.102",nocase; classtype:trojan-activity; sid:100000760; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.218.157",nocase; classtype:trojan-activity; sid:100000761; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.50.203",nocase; classtype:trojan-activity; sid:100000762; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.58.82",nocase; classtype:trojan-activity; sid:100000763; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.79.73.123",nocase; classtype:trojan-activity; sid:100000764; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.83.79.43",nocase; classtype:trojan-activity; sid:100000765; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.99.179.164",nocase; classtype:trojan-activity; sid:100000766; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.99.183.235",nocase; classtype:trojan-activity; sid:100000767; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"118.99.239.217",nocase; classtype:trojan-activity; sid:100000768; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.100.40.250",nocase; classtype:trojan-activity; sid:100000769; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.108.188.238",nocase; classtype:trojan-activity; sid:100000770; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.108.252.237",nocase; classtype:trojan-activity; sid:100000771; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.109.34.245",nocase; classtype:trojan-activity; sid:100000772; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.112.22.58",nocase; classtype:trojan-activity; sid:100000773; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.118.251.73",nocase; classtype:trojan-activity; sid:100000774; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.119.52.202",nocase; classtype:trojan-activity; sid:100000775; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.123.175.133",nocase; classtype:trojan-activity; sid:100000776; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.14.143.145",nocase; classtype:trojan-activity; sid:100000777; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.147.213.57",nocase; classtype:trojan-activity; sid:100000778; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.162.109.111",nocase; classtype:trojan-activity; sid:100000779; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.163.144.208",nocase; classtype:trojan-activity; sid:100000780; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.163.93.191",nocase; classtype:trojan-activity; sid:100000781; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.164.18.235",nocase; classtype:trojan-activity; sid:100000782; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.164.31.76",nocase; classtype:trojan-activity; sid:100000783; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.164.74.153",nocase; classtype:trojan-activity; sid:100000784; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.107.93",nocase; classtype:trojan-activity; sid:100000785; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.163.220",nocase; classtype:trojan-activity; sid:100000786; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.174.63",nocase; classtype:trojan-activity; sid:100000787; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.208.73",nocase; classtype:trojan-activity; sid:100000788; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.241.222",nocase; classtype:trojan-activity; sid:100000789; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.27.77",nocase; classtype:trojan-activity; sid:100000790; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.165.68.145",nocase; classtype:trojan-activity; sid:100000791; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.166.170.241",nocase; classtype:trojan-activity; sid:100000792; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.166.19.254",nocase; classtype:trojan-activity; sid:100000793; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.166.97.6",nocase; classtype:trojan-activity; sid:100000794; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.167.1.13",nocase; classtype:trojan-activity; sid:100000795; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.167.2.214",nocase; classtype:trojan-activity; sid:100000796; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.167.26.33",nocase; classtype:trojan-activity; sid:100000797; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.167.63.195",nocase; classtype:trojan-activity; sid:100000798; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.176.231.217",nocase; classtype:trojan-activity; sid:100000799; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.178.201.188",nocase; classtype:trojan-activity; sid:100000800; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.178.248.123",nocase; classtype:trojan-activity; sid:100000801; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.178.249.140",nocase; classtype:trojan-activity; sid:100000802; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.157.219",nocase; classtype:trojan-activity; sid:100000803; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.16.149",nocase; classtype:trojan-activity; sid:100000804; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.170.212",nocase; classtype:trojan-activity; sid:100000805; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.27.213",nocase; classtype:trojan-activity; sid:100000806; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.43.1",nocase; classtype:trojan-activity; sid:100000807; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.44.141",nocase; classtype:trojan-activity; sid:100000808; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.179.75.8",nocase; classtype:trojan-activity; sid:100000809; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.18.38.144",nocase; classtype:trojan-activity; sid:100000810; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.101.151",nocase; classtype:trojan-activity; sid:100000811; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.106.217",nocase; classtype:trojan-activity; sid:100000812; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.108.227",nocase; classtype:trojan-activity; sid:100000813; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.108.79",nocase; classtype:trojan-activity; sid:100000814; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.11.29",nocase; classtype:trojan-activity; sid:100000815; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.231.79",nocase; classtype:trojan-activity; sid:100000816; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.33.161",nocase; classtype:trojan-activity; sid:100000817; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.80.69",nocase; classtype:trojan-activity; sid:100000818; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.9.35",nocase; classtype:trojan-activity; sid:100000819; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.180.94.80",nocase; classtype:trojan-activity; sid:100000820; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.181.124.203",nocase; classtype:trojan-activity; sid:100000821; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.181.43.18",nocase; classtype:trojan-activity; sid:100000822; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.183.109.21",nocase; classtype:trojan-activity; sid:100000823; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.183.115.103",nocase; classtype:trojan-activity; sid:100000824; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.183.9.82",nocase; classtype:trojan-activity; sid:100000825; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.184.14.112",nocase; classtype:trojan-activity; sid:100000826; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.184.172.199",nocase; classtype:trojan-activity; sid:100000827; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.184.172.53",nocase; classtype:trojan-activity; sid:100000828; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.185.102.182",nocase; classtype:trojan-activity; sid:100000829; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.185.237.89",nocase; classtype:trojan-activity; sid:100000830; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.185.39.240",nocase; classtype:trojan-activity; sid:100000831; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.185.43.193",nocase; classtype:trojan-activity; sid:100000832; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.186.22.245",nocase; classtype:trojan-activity; sid:100000833; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.187.195.161",nocase; classtype:trojan-activity; sid:100000834; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.187.220.115",nocase; classtype:trojan-activity; sid:100000835; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.187.62.80",nocase; classtype:trojan-activity; sid:100000836; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.189.137.195",nocase; classtype:trojan-activity; sid:100000837; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.189.227.244",nocase; classtype:trojan-activity; sid:100000838; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.190.211.99",nocase; classtype:trojan-activity; sid:100000839; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.190.240.238",nocase; classtype:trojan-activity; sid:100000840; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.150.85",nocase; classtype:trojan-activity; sid:100000841; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.187.206",nocase; classtype:trojan-activity; sid:100000842; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.215.221",nocase; classtype:trojan-activity; sid:100000843; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.191.253.206",nocase; classtype:trojan-activity; sid:100000844; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.204.30.144",nocase; classtype:trojan-activity; sid:100000845; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.250.129.231",nocase; classtype:trojan-activity; sid:100000846; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.250.218.177",nocase; classtype:trojan-activity; sid:100000847; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.251.105.221",nocase; classtype:trojan-activity; sid:100000848; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.251.12.85",nocase; classtype:trojan-activity; sid:100000849; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.251.14.251",nocase; classtype:trojan-activity; sid:100000850; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.131.155",nocase; classtype:trojan-activity; sid:100000851; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.143.46",nocase; classtype:trojan-activity; sid:100000852; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.143.71",nocase; classtype:trojan-activity; sid:100000853; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.144.75",nocase; classtype:trojan-activity; sid:100000854; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.148.115",nocase; classtype:trojan-activity; sid:100000855; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.155.57",nocase; classtype:trojan-activity; sid:100000856; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.166.36",nocase; classtype:trojan-activity; sid:100000857; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.172.28",nocase; classtype:trojan-activity; sid:100000858; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.56.206.43",nocase; classtype:trojan-activity; sid:100000859; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.96.37.55",nocase; classtype:trojan-activity; sid:100000860; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.96.70.116",nocase; classtype:trojan-activity; sid:100000861; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.99.188.187",nocase; classtype:trojan-activity; sid:100000862; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.99.190.152",nocase; classtype:trojan-activity; sid:100000863; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"119.99.232.62",nocase; classtype:trojan-activity; sid:100000864; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.132.113.2",nocase; classtype:trojan-activity; sid:100000865; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.15.69.83",nocase; classtype:trojan-activity; sid:100000866; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.6",nocase; classtype:trojan-activity; sid:100000867; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.7",nocase; classtype:trojan-activity; sid:100000868; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.8",nocase; classtype:trojan-activity; sid:100000869; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.178.187.9",nocase; classtype:trojan-activity; sid:100000870; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"12.207.39.227",nocase; classtype:trojan-activity; sid:100000871; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.12.144.232",nocase; classtype:trojan-activity; sid:100000872; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.12.153.54",nocase; classtype:trojan-activity; sid:100000873; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.12.212.5",nocase; classtype:trojan-activity; sid:100000874; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.142.222.22",nocase; classtype:trojan-activity; sid:100000875; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.150.213.110",nocase; classtype:trojan-activity; sid:100000876; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.151.248.134",nocase; classtype:trojan-activity; sid:100000877; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.177",nocase; classtype:trojan-activity; sid:100000878; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.178",nocase; classtype:trojan-activity; sid:100000879; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.180",nocase; classtype:trojan-activity; sid:100000880; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.181",nocase; classtype:trojan-activity; sid:100000881; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.183",nocase; classtype:trojan-activity; sid:100000882; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.184",nocase; classtype:trojan-activity; sid:100000883; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.185",nocase; classtype:trojan-activity; sid:100000884; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.186",nocase; classtype:trojan-activity; sid:100000885; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.188",nocase; classtype:trojan-activity; sid:100000886; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.191",nocase; classtype:trojan-activity; sid:100000887; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.193",nocase; classtype:trojan-activity; sid:100000888; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.196",nocase; classtype:trojan-activity; sid:100000889; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.197",nocase; classtype:trojan-activity; sid:100000890; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.198",nocase; classtype:trojan-activity; sid:100000891; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.199",nocase; classtype:trojan-activity; sid:100000892; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.200",nocase; classtype:trojan-activity; sid:100000893; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.201",nocase; classtype:trojan-activity; sid:100000894; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.202",nocase; classtype:trojan-activity; sid:100000895; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.203",nocase; classtype:trojan-activity; sid:100000896; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.204",nocase; classtype:trojan-activity; sid:100000897; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.207",nocase; classtype:trojan-activity; sid:100000898; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.208",nocase; classtype:trojan-activity; sid:100000899; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.209",nocase; classtype:trojan-activity; sid:100000900; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.212",nocase; classtype:trojan-activity; sid:100000901; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.213",nocase; classtype:trojan-activity; sid:100000902; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.215",nocase; classtype:trojan-activity; sid:100000903; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.91.233",nocase; classtype:trojan-activity; sid:100000904; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.193.93.227",nocase; classtype:trojan-activity; sid:100000905; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.121.243",nocase; classtype:trojan-activity; sid:100000906; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.206",nocase; classtype:trojan-activity; sid:100000907; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.214",nocase; classtype:trojan-activity; sid:100000908; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.240",nocase; classtype:trojan-activity; sid:100000909; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.243",nocase; classtype:trojan-activity; sid:100000910; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.25",nocase; classtype:trojan-activity; sid:100000911; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.126.60",nocase; classtype:trojan-activity; sid:100000912; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.127.187",nocase; classtype:trojan-activity; sid:100000913; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.209.99.127",nocase; classtype:trojan-activity; sid:100000914; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.210.89.79",nocase; classtype:trojan-activity; sid:100000915; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.43.54.218",nocase; classtype:trojan-activity; sid:100000916; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.50.66.60",nocase; classtype:trojan-activity; sid:100000917; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.50.93.115",nocase; classtype:trojan-activity; sid:100000918; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.6.141.142",nocase; classtype:trojan-activity; sid:100000919; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.6.8.11",nocase; classtype:trojan-activity; sid:100000920; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.69.113.208",nocase; classtype:trojan-activity; sid:100000921; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.69.131.51",nocase; classtype:trojan-activity; sid:100000922; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.7.90.104",nocase; classtype:trojan-activity; sid:100000923; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.165.141",nocase; classtype:trojan-activity; sid:100000924; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.173.137",nocase; classtype:trojan-activity; sid:100000925; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.174.165",nocase; classtype:trojan-activity; sid:100000926; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.174.175",nocase; classtype:trojan-activity; sid:100000927; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.174.39",nocase; classtype:trojan-activity; sid:100000928; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.199.222",nocase; classtype:trojan-activity; sid:100000929; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.212.45",nocase; classtype:trojan-activity; sid:100000930; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.85.237.129",nocase; classtype:trojan-activity; sid:100000931; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"120.9.32.51",nocase; classtype:trojan-activity; sid:100000932; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.100.114.164",nocase; classtype:trojan-activity; sid:100000933; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.100.96.8",nocase; classtype:trojan-activity; sid:100000934; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.121.44.222",nocase; classtype:trojan-activity; sid:100000935; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.123.53.25",nocase; classtype:trojan-activity; sid:100000936; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.127.155.220",nocase; classtype:trojan-activity; sid:100000937; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.141.11.56",nocase; classtype:trojan-activity; sid:100000938; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.15.142.137",nocase; classtype:trojan-activity; sid:100000939; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.151.78.190",nocase; classtype:trojan-activity; sid:100000940; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.159.22.144",nocase; classtype:trojan-activity; sid:100000941; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.16.155.206",nocase; classtype:trojan-activity; sid:100000942; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.17.103.176",nocase; classtype:trojan-activity; sid:100000943; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.170.234.142",nocase; classtype:trojan-activity; sid:100000944; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.185.31.2",nocase; classtype:trojan-activity; sid:100000945; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.190.36.8",nocase; classtype:trojan-activity; sid:100000946; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.205.229.200",nocase; classtype:trojan-activity; sid:100000947; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.225.11.163",nocase; classtype:trojan-activity; sid:100000948; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.226.82.202",nocase; classtype:trojan-activity; sid:100000949; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.23.18.18",nocase; classtype:trojan-activity; sid:100000950; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.230.171.198",nocase; classtype:trojan-activity; sid:100000951; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.231.103.95",nocase; classtype:trojan-activity; sid:100000952; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.237.225.91",nocase; classtype:trojan-activity; sid:100000953; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.238.175.87",nocase; classtype:trojan-activity; sid:100000954; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.239.15.74",nocase; classtype:trojan-activity; sid:100000955; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.24.116.173",nocase; classtype:trojan-activity; sid:100000956; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.25.101.86",nocase; classtype:trojan-activity; sid:100000957; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.254.43.215",nocase; classtype:trojan-activity; sid:100000958; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.34.150.32",nocase; classtype:trojan-activity; sid:100000959; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.61.101.93",nocase; classtype:trojan-activity; sid:100000960; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.61.102.1",nocase; classtype:trojan-activity; sid:100000961; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.61.107.189",nocase; classtype:trojan-activity; sid:100000962; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.61.97.195",nocase; classtype:trojan-activity; sid:100000963; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.61.98.151",nocase; classtype:trojan-activity; sid:100000964; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"121.88.99.236",nocase; classtype:trojan-activity; sid:100000965; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.100.150.204",nocase; classtype:trojan-activity; sid:100000966; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.137.52.122",nocase; classtype:trojan-activity; sid:100000967; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.160.147.53",nocase; classtype:trojan-activity; sid:100000968; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.188.86.225",nocase; classtype:trojan-activity; sid:100000969; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.190.19.204",nocase; classtype:trojan-activity; sid:100000970; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.192.190.203",nocase; classtype:trojan-activity; sid:100000971; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.194.191.57",nocase; classtype:trojan-activity; sid:100000972; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.199.72.23",nocase; classtype:trojan-activity; sid:100000973; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.199.79.27",nocase; classtype:trojan-activity; sid:100000974; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.199.83.86",nocase; classtype:trojan-activity; sid:100000975; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.202.37.85",nocase; classtype:trojan-activity; sid:100000976; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.202.41.23",nocase; classtype:trojan-activity; sid:100000977; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.252.250.22",nocase; classtype:trojan-activity; sid:100000978; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.254.183.207",nocase; classtype:trojan-activity; sid:100000979; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.254.29.37",nocase; classtype:trojan-activity; sid:100000980; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"122.254.33.214",nocase; classtype:trojan-activity; sid:100000981; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.0.240.58",nocase; classtype:trojan-activity; sid:100000982; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.10.128.46",nocase; classtype:trojan-activity; sid:100000983; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.10.131.225",nocase; classtype:trojan-activity; sid:100000984; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.10.140.225",nocase; classtype:trojan-activity; sid:100000985; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.10.209.95",nocase; classtype:trojan-activity; sid:100000986; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.10.36.124",nocase; classtype:trojan-activity; sid:100000987; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.10.41.32",nocase; classtype:trojan-activity; sid:100000988; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.10.83.136",nocase; classtype:trojan-activity; sid:100000989; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.124.238",nocase; classtype:trojan-activity; sid:100000990; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.124.244",nocase; classtype:trojan-activity; sid:100000991; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.170.237",nocase; classtype:trojan-activity; sid:100000992; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.182.187",nocase; classtype:trojan-activity; sid:100000993; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.19.248",nocase; classtype:trojan-activity; sid:100000994; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.200.98",nocase; classtype:trojan-activity; sid:100000995; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.110.238.188",nocase; classtype:trojan-activity; sid:100000996; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.12.229.243",nocase; classtype:trojan-activity; sid:100000997; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.12.3.58",nocase; classtype:trojan-activity; sid:100000998; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.12.36.185",nocase; classtype:trojan-activity; sid:100000999; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.128.128.205",nocase; classtype:trojan-activity; sid:100001000; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.128.133.91",nocase; classtype:trojan-activity; sid:100001001; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.129.84.36",nocase; classtype:trojan-activity; sid:100001002; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.129.88.123",nocase; classtype:trojan-activity; sid:100001003; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.13.101.56",nocase; classtype:trojan-activity; sid:100001004; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.13.30.75",nocase; classtype:trojan-activity; sid:100001005; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.208.52",nocase; classtype:trojan-activity; sid:100001006; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.23.110",nocase; classtype:trojan-activity; sid:100001007; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.37.182",nocase; classtype:trojan-activity; sid:100001008; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.130.61.210",nocase; classtype:trojan-activity; sid:100001009; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.131.186.250",nocase; classtype:trojan-activity; sid:100001010; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.132.219.147",nocase; classtype:trojan-activity; sid:100001011; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.133.125.77",nocase; classtype:trojan-activity; sid:100001012; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.133.144.138",nocase; classtype:trojan-activity; sid:100001013; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.133.98.135",nocase; classtype:trojan-activity; sid:100001014; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.134.14.130",nocase; classtype:trojan-activity; sid:100001015; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.134.50.186",nocase; classtype:trojan-activity; sid:100001016; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.135.157.193",nocase; classtype:trojan-activity; sid:100001017; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.135.39.36",nocase; classtype:trojan-activity; sid:100001018; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.135.71.150",nocase; classtype:trojan-activity; sid:100001019; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.101.111",nocase; classtype:trojan-activity; sid:100001020; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.150.79",nocase; classtype:trojan-activity; sid:100001021; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.205.23",nocase; classtype:trojan-activity; sid:100001022; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.217.22",nocase; classtype:trojan-activity; sid:100001023; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.235.65",nocase; classtype:trojan-activity; sid:100001024; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.76.38",nocase; classtype:trojan-activity; sid:100001025; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.14.88.195",nocase; classtype:trojan-activity; sid:100001026; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.152.42.4",nocase; classtype:trojan-activity; sid:100001027; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.152.43.21",nocase; classtype:trojan-activity; sid:100001028; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.154.94.1",nocase; classtype:trojan-activity; sid:100001029; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.155.118.36",nocase; classtype:trojan-activity; sid:100001030; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.156.136.21",nocase; classtype:trojan-activity; sid:100001031; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.159.137.101",nocase; classtype:trojan-activity; sid:100001032; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.159.31.110",nocase; classtype:trojan-activity; sid:100001033; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.159.8.100",nocase; classtype:trojan-activity; sid:100001034; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.183.123.41",nocase; classtype:trojan-activity; sid:100001035; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.191.173.88",nocase; classtype:trojan-activity; sid:100001036; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.192.101.163",nocase; classtype:trojan-activity; sid:100001037; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.192.194.233",nocase; classtype:trojan-activity; sid:100001038; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.193.149.235",nocase; classtype:trojan-activity; sid:100001039; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.193.53.237",nocase; classtype:trojan-activity; sid:100001040; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.235.37",nocase; classtype:trojan-activity; sid:100001041; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.35.146",nocase; classtype:trojan-activity; sid:100001042; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.52.79",nocase; classtype:trojan-activity; sid:100001043; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.194.60.238",nocase; classtype:trojan-activity; sid:100001044; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.195.112.240",nocase; classtype:trojan-activity; sid:100001045; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.195.184.191",nocase; classtype:trojan-activity; sid:100001046; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.195.98.141",nocase; classtype:trojan-activity; sid:100001047; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.212.29.154",nocase; classtype:trojan-activity; sid:100001048; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.213.225.130",nocase; classtype:trojan-activity; sid:100001049; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.233.130.162",nocase; classtype:trojan-activity; sid:100001050; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.233.152.249",nocase; classtype:trojan-activity; sid:100001051; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.234.100.219",nocase; classtype:trojan-activity; sid:100001052; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.234.116.110",nocase; classtype:trojan-activity; sid:100001053; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.234.184.57",nocase; classtype:trojan-activity; sid:100001054; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.234.246.103",nocase; classtype:trojan-activity; sid:100001055; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.240.103.89",nocase; classtype:trojan-activity; sid:100001056; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.240.181.57",nocase; classtype:trojan-activity; sid:100001057; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.240.79.61",nocase; classtype:trojan-activity; sid:100001058; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.241.148.58",nocase; classtype:trojan-activity; sid:100001059; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.241.184.124",nocase; classtype:trojan-activity; sid:100001060; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.27.44.219",nocase; classtype:trojan-activity; sid:100001061; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.28.217.23",nocase; classtype:trojan-activity; sid:100001062; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.180.137",nocase; classtype:trojan-activity; sid:100001063; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.185.137",nocase; classtype:trojan-activity; sid:100001064; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.193.171",nocase; classtype:trojan-activity; sid:100001065; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.44.217",nocase; classtype:trojan-activity; sid:100001066; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.85.76",nocase; classtype:trojan-activity; sid:100001067; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.4.92.3",nocase; classtype:trojan-activity; sid:100001068; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.5.123.162",nocase; classtype:trojan-activity; sid:100001069; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.5.178.213",nocase; classtype:trojan-activity; sid:100001070; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.5.188.181",nocase; classtype:trojan-activity; sid:100001071; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.5.22.220",nocase; classtype:trojan-activity; sid:100001072; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.5.27.66",nocase; classtype:trojan-activity; sid:100001073; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.8.183.194",nocase; classtype:trojan-activity; sid:100001074; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.8.254.172",nocase; classtype:trojan-activity; sid:100001075; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.8.40.20",nocase; classtype:trojan-activity; sid:100001076; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.8.41.63",nocase; classtype:trojan-activity; sid:100001077; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.8.62.165",nocase; classtype:trojan-activity; sid:100001078; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"123.9.243.93",nocase; classtype:trojan-activity; sid:100001079; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.105.105.222",nocase; classtype:trojan-activity; sid:100001080; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.129.162.169",nocase; classtype:trojan-activity; sid:100001081; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.129.221.150",nocase; classtype:trojan-activity; sid:100001082; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.129.76.230",nocase; classtype:trojan-activity; sid:100001083; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.130.167.20",nocase; classtype:trojan-activity; sid:100001084; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.130.40.31",nocase; classtype:trojan-activity; sid:100001085; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.104.82",nocase; classtype:trojan-activity; sid:100001086; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.130.95",nocase; classtype:trojan-activity; sid:100001087; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.136.75",nocase; classtype:trojan-activity; sid:100001088; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.151.135",nocase; classtype:trojan-activity; sid:100001089; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.21.39",nocase; classtype:trojan-activity; sid:100001090; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.26.243",nocase; classtype:trojan-activity; sid:100001091; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.26.78",nocase; classtype:trojan-activity; sid:100001092; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.54.33",nocase; classtype:trojan-activity; sid:100001093; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.70.49",nocase; classtype:trojan-activity; sid:100001094; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.131.72.208",nocase; classtype:trojan-activity; sid:100001095; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.132.110.150",nocase; classtype:trojan-activity; sid:100001096; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.135.34.49",nocase; classtype:trojan-activity; sid:100001097; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.153.136.175",nocase; classtype:trojan-activity; sid:100001098; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.153.236.6",nocase; classtype:trojan-activity; sid:100001099; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.160.126.238",nocase; classtype:trojan-activity; sid:100001100; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.138.104",nocase; classtype:trojan-activity; sid:100001101; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.167.54",nocase; classtype:trojan-activity; sid:100001102; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.65.64",nocase; classtype:trojan-activity; sid:100001103; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.72.102",nocase; classtype:trojan-activity; sid:100001104; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.77.191",nocase; classtype:trojan-activity; sid:100001105; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.163.90.243",nocase; classtype:trojan-activity; sid:100001106; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.165.123.7",nocase; classtype:trojan-activity; sid:100001107; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.167.186.211",nocase; classtype:trojan-activity; sid:100001108; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.187.111.160",nocase; classtype:trojan-activity; sid:100001109; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.199.56.198",nocase; classtype:trojan-activity; sid:100001110; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.226.24.117",nocase; classtype:trojan-activity; sid:100001111; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.230.174.233",nocase; classtype:trojan-activity; sid:100001112; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.234.6.130",nocase; classtype:trojan-activity; sid:100001113; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.5.92.20",nocase; classtype:trojan-activity; sid:100001114; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.6.0.4",nocase; classtype:trojan-activity; sid:100001115; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.7.254.85",nocase; classtype:trojan-activity; sid:100001116; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.80.46.73",nocase; classtype:trojan-activity; sid:100001117; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.92.148.218",nocase; classtype:trojan-activity; sid:100001118; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"124.95.17.41",nocase; classtype:trojan-activity; sid:100001119; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.106.125.119",nocase; classtype:trojan-activity; sid:100001120; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.106.252.96",nocase; classtype:trojan-activity; sid:100001121; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.126.69.95",nocase; classtype:trojan-activity; sid:100001122; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.128.28.161",nocase; classtype:trojan-activity; sid:100001123; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.142.93.34",nocase; classtype:trojan-activity; sid:100001124; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.168.10.234",nocase; classtype:trojan-activity; sid:100001125; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.191.113.212",nocase; classtype:trojan-activity; sid:100001126; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.1.127",nocase; classtype:trojan-activity; sid:100001127; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.107.252",nocase; classtype:trojan-activity; sid:100001128; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.113.66",nocase; classtype:trojan-activity; sid:100001129; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.136.25",nocase; classtype:trojan-activity; sid:100001130; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.150.131",nocase; classtype:trojan-activity; sid:100001131; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.16.231",nocase; classtype:trojan-activity; sid:100001132; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.163.112",nocase; classtype:trojan-activity; sid:100001133; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.237.130",nocase; classtype:trojan-activity; sid:100001134; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.65.120",nocase; classtype:trojan-activity; sid:100001135; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.73.6",nocase; classtype:trojan-activity; sid:100001136; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.74.153",nocase; classtype:trojan-activity; sid:100001137; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.40.75.22",nocase; classtype:trojan-activity; sid:100001138; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.106.180",nocase; classtype:trojan-activity; sid:100001139; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.138.208",nocase; classtype:trojan-activity; sid:100001140; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.189.235",nocase; classtype:trojan-activity; sid:100001141; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.191.183",nocase; classtype:trojan-activity; sid:100001142; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.196.151",nocase; classtype:trojan-activity; sid:100001143; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.200.189",nocase; classtype:trojan-activity; sid:100001144; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.204.126",nocase; classtype:trojan-activity; sid:100001145; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.205.197",nocase; classtype:trojan-activity; sid:100001146; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.6.192",nocase; classtype:trojan-activity; sid:100001147; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.7.204",nocase; classtype:trojan-activity; sid:100001148; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.80.153",nocase; classtype:trojan-activity; sid:100001149; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.86.72",nocase; classtype:trojan-activity; sid:100001150; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.41.96.53",nocase; classtype:trojan-activity; sid:100001151; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.42.124.114",nocase; classtype:trojan-activity; sid:100001152; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.42.125.103",nocase; classtype:trojan-activity; sid:100001153; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.42.234.197",nocase; classtype:trojan-activity; sid:100001154; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.42.96.17",nocase; classtype:trojan-activity; sid:100001155; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.42.98.24",nocase; classtype:trojan-activity; sid:100001156; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.105.157",nocase; classtype:trojan-activity; sid:100001157; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.106.162",nocase; classtype:trojan-activity; sid:100001158; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.112.123",nocase; classtype:trojan-activity; sid:100001159; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.126.184",nocase; classtype:trojan-activity; sid:100001160; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.130.232",nocase; classtype:trojan-activity; sid:100001161; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.136.23",nocase; classtype:trojan-activity; sid:100001162; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.177.48",nocase; classtype:trojan-activity; sid:100001163; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.21.157",nocase; classtype:trojan-activity; sid:100001164; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.26.36",nocase; classtype:trojan-activity; sid:100001165; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.34.132",nocase; classtype:trojan-activity; sid:100001166; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.53.9",nocase; classtype:trojan-activity; sid:100001167; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.43.73.19",nocase; classtype:trojan-activity; sid:100001168; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.168.169",nocase; classtype:trojan-activity; sid:100001169; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.212.107",nocase; classtype:trojan-activity; sid:100001170; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.213.216",nocase; classtype:trojan-activity; sid:100001171; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.230.191",nocase; classtype:trojan-activity; sid:100001172; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.30.143",nocase; classtype:trojan-activity; sid:100001173; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.31.79",nocase; classtype:trojan-activity; sid:100001174; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.44.8.227",nocase; classtype:trojan-activity; sid:100001175; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.45.57.249",nocase; classtype:trojan-activity; sid:100001176; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.45.65.166",nocase; classtype:trojan-activity; sid:100001177; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.45.90.158",nocase; classtype:trojan-activity; sid:100001178; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.46.138.117",nocase; classtype:trojan-activity; sid:100001179; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.46.184.28",nocase; classtype:trojan-activity; sid:100001180; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.46.206.206",nocase; classtype:trojan-activity; sid:100001181; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.193.134",nocase; classtype:trojan-activity; sid:100001182; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.200.11",nocase; classtype:trojan-activity; sid:100001183; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.209.166",nocase; classtype:trojan-activity; sid:100001184; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.244.201",nocase; classtype:trojan-activity; sid:100001185; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.252.106",nocase; classtype:trojan-activity; sid:100001186; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.254.44",nocase; classtype:trojan-activity; sid:100001187; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.28.217",nocase; classtype:trojan-activity; sid:100001188; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.36.171",nocase; classtype:trojan-activity; sid:100001189; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.45.218",nocase; classtype:trojan-activity; sid:100001190; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.71.30",nocase; classtype:trojan-activity; sid:100001191; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.90.82",nocase; classtype:trojan-activity; sid:100001192; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.47.91.51",nocase; classtype:trojan-activity; sid:100001193; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"125.99.220.202",nocase; classtype:trojan-activity; sid:100001194; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"128.116.133.92",nocase; classtype:trojan-activity; sid:100001195; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"130.255.159.133",nocase; classtype:trojan-activity; sid:100001196; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"134.195.139.4",nocase; classtype:trojan-activity; sid:100001197; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"138.99.204.224",nocase; classtype:trojan-activity; sid:100001198; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.159.226.180",nocase; classtype:trojan-activity; sid:100001199; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.170.173.198",nocase; classtype:trojan-activity; sid:100001200; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.170.174.162",nocase; classtype:trojan-activity; sid:100001201; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.170.228.166",nocase; classtype:trojan-activity; sid:100001202; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.216.102.151",nocase; classtype:trojan-activity; sid:100001203; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"139.227.46.137",nocase; classtype:trojan-activity; sid:100001204; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.102.17.222",nocase; classtype:trojan-activity; sid:100001205; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.136.80.242",nocase; classtype:trojan-activity; sid:100001206; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.138.109.129",nocase; classtype:trojan-activity; sid:100001207; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.138.109.26",nocase; classtype:trojan-activity; sid:100001208; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.138.8.215",nocase; classtype:trojan-activity; sid:100001209; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.138.8.51",nocase; classtype:trojan-activity; sid:100001210; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.155.220.240",nocase; classtype:trojan-activity; sid:100001211; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.155.223.79",nocase; classtype:trojan-activity; sid:100001212; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.169.164.77",nocase; classtype:trojan-activity; sid:100001213; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.189.247.118",nocase; classtype:trojan-activity; sid:100001214; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.205.201.192",nocase; classtype:trojan-activity; sid:100001215; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.37.222.190",nocase; classtype:trojan-activity; sid:100001216; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.45.127.110",nocase; classtype:trojan-activity; sid:100001217; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.46.25.17",nocase; classtype:trojan-activity; sid:100001218; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.46.98.241",nocase; classtype:trojan-activity; sid:100001219; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"14.55.29.2",nocase; classtype:trojan-activity; sid:100001220; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"140.237.30.113",nocase; classtype:trojan-activity; sid:100001221; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"140.237.5.43",nocase; classtype:trojan-activity; sid:100001222; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"142.11.216.5",nocase; classtype:trojan-activity; sid:100001223; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"142.177.56.127",nocase; classtype:trojan-activity; sid:100001224; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"146.71.79.230",nocase; classtype:trojan-activity; sid:100001225; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"148.69.108.177",nocase; classtype:trojan-activity; sid:100001226; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.20.176.179",nocase; classtype:trojan-activity; sid:100001227; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.180",nocase; classtype:trojan-activity; sid:100001228; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.182",nocase; classtype:trojan-activity; sid:100001229; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.191",nocase; classtype:trojan-activity; sid:100001230; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.235",nocase; classtype:trojan-activity; sid:100001231; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.255.15.87",nocase; classtype:trojan-activity; sid:100001232; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"149.3.85.55",nocase; classtype:trojan-activity; sid:100001233; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"150.116.207.99",nocase; classtype:trojan-activity; sid:100001234; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"150.129.105.61",nocase; classtype:trojan-activity; sid:100001235; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"151.177.163.87",nocase; classtype:trojan-activity; sid:100001236; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"151.33.230.191",nocase; classtype:trojan-activity; sid:100001237; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"151.51.158.195",nocase; classtype:trojan-activity; sid:100001238; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"151.73.124.231",nocase; classtype:trojan-activity; sid:100001239; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.101.225.96",nocase; classtype:trojan-activity; sid:100001240; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.101.234.167",nocase; classtype:trojan-activity; sid:100001241; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.3.123.47",nocase; classtype:trojan-activity; sid:100001242; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.3.43.136",nocase; classtype:trojan-activity; sid:100001243; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.3.44.44",nocase; classtype:trojan-activity; sid:100001244; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.34.135.92",nocase; classtype:trojan-activity; sid:100001245; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.34.23.76",nocase; classtype:trojan-activity; sid:100001246; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.34.29.28",nocase; classtype:trojan-activity; sid:100001247; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.35.111.46",nocase; classtype:trojan-activity; sid:100001248; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.35.27.49",nocase; classtype:trojan-activity; sid:100001249; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"153.36.126.35",nocase; classtype:trojan-activity; sid:100001250; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"154.126.178.16",nocase; classtype:trojan-activity; sid:100001251; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"154.91.1.27",nocase; classtype:trojan-activity; sid:100001252; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"157.122.105.142",nocase; classtype:trojan-activity; sid:100001253; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"158.101.165.14",nocase; classtype:trojan-activity; sid:100001254; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"158.174.213.128",nocase; classtype:trojan-activity; sid:100001255; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"158.51.125.115",nocase; classtype:trojan-activity; sid:100001256; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"159.224.74.112",nocase; classtype:trojan-activity; sid:100001257; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.191.165.238",nocase; classtype:trojan-activity; sid:100001258; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.191.205.175",nocase; classtype:trojan-activity; sid:100001259; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.191.249.195",nocase; classtype:trojan-activity; sid:100001260; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.194.28.60",nocase; classtype:trojan-activity; sid:100001261; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"162.209.98.174",nocase; classtype:trojan-activity; sid:100001262; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.183.111",nocase; classtype:trojan-activity; sid:100001263; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.195.108",nocase; classtype:trojan-activity; sid:100001264; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.200.72",nocase; classtype:trojan-activity; sid:100001265; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.200.73",nocase; classtype:trojan-activity; sid:100001266; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.202.174",nocase; classtype:trojan-activity; sid:100001267; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.202.74",nocase; classtype:trojan-activity; sid:100001268; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.203.179",nocase; classtype:trojan-activity; sid:100001269; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.207.125",nocase; classtype:trojan-activity; sid:100001270; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.250.202",nocase; classtype:trojan-activity; sid:100001271; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.125.68.29",nocase; classtype:trojan-activity; sid:100001272; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"163.53.206.228",nocase; classtype:trojan-activity; sid:100001273; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"165.90.16.5",nocase; classtype:trojan-activity; sid:100001274; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"170.78.39.3",nocase; classtype:trojan-activity; sid:100001275; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"170.81.238.178",nocase; classtype:trojan-activity; sid:100001276; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.118.18.184",nocase; classtype:trojan-activity; sid:100001277; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.118.210.67",nocase; classtype:trojan-activity; sid:100001278; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.119.217.149",nocase; classtype:trojan-activity; sid:100001279; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.119.218.208",nocase; classtype:trojan-activity; sid:100001280; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.119.219.150",nocase; classtype:trojan-activity; sid:100001281; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.119.255.96",nocase; classtype:trojan-activity; sid:100001282; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.120.125.147",nocase; classtype:trojan-activity; sid:100001283; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.121.6.162",nocase; classtype:trojan-activity; sid:100001284; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.123.189.154",nocase; classtype:trojan-activity; sid:100001285; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.125.30.233",nocase; classtype:trojan-activity; sid:100001286; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.125.30.93",nocase; classtype:trojan-activity; sid:100001287; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.125.64.223",nocase; classtype:trojan-activity; sid:100001288; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.125.65.22",nocase; classtype:trojan-activity; sid:100001289; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.126.109.145",nocase; classtype:trojan-activity; sid:100001290; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.34.112.42",nocase; classtype:trojan-activity; sid:100001291; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.34.114.181",nocase; classtype:trojan-activity; sid:100001292; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.34.179.178",nocase; classtype:trojan-activity; sid:100001293; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.35.161.234",nocase; classtype:trojan-activity; sid:100001294; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.35.162.156",nocase; classtype:trojan-activity; sid:100001295; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.35.173.151",nocase; classtype:trojan-activity; sid:100001296; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.35.174.198",nocase; classtype:trojan-activity; sid:100001297; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.36.42.154",nocase; classtype:trojan-activity; sid:100001298; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.38.219.189",nocase; classtype:trojan-activity; sid:100001299; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"171.44.254.4",nocase; classtype:trojan-activity; sid:100001300; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.105.36.168",nocase; classtype:trojan-activity; sid:100001301; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.114.244.127",nocase; classtype:trojan-activity; sid:100001302; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.245.5.185",nocase; classtype:trojan-activity; sid:100001303; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"172.245.5.190",nocase; classtype:trojan-activity; sid:100001304; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.167.85.89",nocase; classtype:trojan-activity; sid:100001305; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.169.46.85",nocase; classtype:trojan-activity; sid:100001306; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.19.58.108",nocase; classtype:trojan-activity; sid:100001307; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.220.222.227",nocase; classtype:trojan-activity; sid:100001308; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.233.85.171",nocase; classtype:trojan-activity; sid:100001309; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.235.209.70",nocase; classtype:trojan-activity; sid:100001310; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.25.113.8",nocase; classtype:trojan-activity; sid:100001311; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.52.95.134",nocase; classtype:trojan-activity; sid:100001312; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.52.97.25",nocase; classtype:trojan-activity; sid:100001313; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.56.119.108",nocase; classtype:trojan-activity; sid:100001314; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"173.56.92.166",nocase; classtype:trojan-activity; sid:100001315; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.106.33.85",nocase; classtype:trojan-activity; sid:100001316; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.48.181.23",nocase; classtype:trojan-activity; sid:100001317; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.73.246.193",nocase; classtype:trojan-activity; sid:100001318; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.81.78.7",nocase; classtype:trojan-activity; sid:100001319; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.84.148.29",nocase; classtype:trojan-activity; sid:100001320; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"174.96.30.156",nocase; classtype:trojan-activity; sid:100001321; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.10.147.167",nocase; classtype:trojan-activity; sid:100001322; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.11.193.66",nocase; classtype:trojan-activity; sid:100001323; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.115.241.87",nocase; classtype:trojan-activity; sid:100001324; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.117.66.74",nocase; classtype:trojan-activity; sid:100001325; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.145.200.216",nocase; classtype:trojan-activity; sid:100001326; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.146.17.227",nocase; classtype:trojan-activity; sid:100001327; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.153.144.2",nocase; classtype:trojan-activity; sid:100001328; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.162.69.13",nocase; classtype:trojan-activity; sid:100001329; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.169.172.216",nocase; classtype:trojan-activity; sid:100001330; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.173.196.162",nocase; classtype:trojan-activity; sid:100001331; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.174.93.57",nocase; classtype:trojan-activity; sid:100001332; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.199.33.139",nocase; classtype:trojan-activity; sid:100001333; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.201.104.192",nocase; classtype:trojan-activity; sid:100001334; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.208.230.8",nocase; classtype:trojan-activity; sid:100001335; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.212.6.169",nocase; classtype:trojan-activity; sid:100001336; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.42.46.118",nocase; classtype:trojan-activity; sid:100001337; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"175.9.24.110",nocase; classtype:trojan-activity; sid:100001338; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.14",nocase; classtype:trojan-activity; sid:100001339; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.35",nocase; classtype:trojan-activity; sid:100001340; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.63",nocase; classtype:trojan-activity; sid:100001341; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.66",nocase; classtype:trojan-activity; sid:100001342; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.111.174.67",nocase; classtype:trojan-activity; sid:100001343; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.101",nocase; classtype:trojan-activity; sid:100001344; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.104",nocase; classtype:trojan-activity; sid:100001345; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.113",nocase; classtype:trojan-activity; sid:100001346; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.120",nocase; classtype:trojan-activity; sid:100001347; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.128",nocase; classtype:trojan-activity; sid:100001348; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.138",nocase; classtype:trojan-activity; sid:100001349; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.59",nocase; classtype:trojan-activity; sid:100001350; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.60",nocase; classtype:trojan-activity; sid:100001351; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.65",nocase; classtype:trojan-activity; sid:100001352; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.66",nocase; classtype:trojan-activity; sid:100001353; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.84",nocase; classtype:trojan-activity; sid:100001354; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.88",nocase; classtype:trojan-activity; sid:100001355; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.91",nocase; classtype:trojan-activity; sid:100001356; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.161.93",nocase; classtype:trojan-activity; sid:100001357; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.113.174.139",nocase; classtype:trojan-activity; sid:100001358; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.12.117.70",nocase; classtype:trojan-activity; sid:100001359; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.123.4.115",nocase; classtype:trojan-activity; sid:100001360; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.123.7.115",nocase; classtype:trojan-activity; sid:100001361; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.123.7.127",nocase; classtype:trojan-activity; sid:100001362; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.123.9.243",nocase; classtype:trojan-activity; sid:100001363; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.124.7.225",nocase; classtype:trojan-activity; sid:100001364; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.221.251.147",nocase; classtype:trojan-activity; sid:100001365; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.240.40.142",nocase; classtype:trojan-activity; sid:100001366; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.240.84.106",nocase; classtype:trojan-activity; sid:100001367; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"176.32.151.180",nocase; classtype:trojan-activity; sid:100001368; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.229.64.218",nocase; classtype:trojan-activity; sid:100001369; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.44.61.243",nocase; classtype:trojan-activity; sid:100001370; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.54.82.154",nocase; classtype:trojan-activity; sid:100001371; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"177.86.235.143",nocase; classtype:trojan-activity; sid:100001372; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.124.182.187",nocase; classtype:trojan-activity; sid:100001373; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.134.185.112",nocase; classtype:trojan-activity; sid:100001374; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.141.161.129",nocase; classtype:trojan-activity; sid:100001375; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.141.25.82",nocase; classtype:trojan-activity; sid:100001376; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.141.57.166",nocase; classtype:trojan-activity; sid:100001377; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.150.174.65",nocase; classtype:trojan-activity; sid:100001378; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.165.122.141",nocase; classtype:trojan-activity; sid:100001379; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.0.140",nocase; classtype:trojan-activity; sid:100001380; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.0.232",nocase; classtype:trojan-activity; sid:100001381; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.247",nocase; classtype:trojan-activity; sid:100001382; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.250",nocase; classtype:trojan-activity; sid:100001383; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.252",nocase; classtype:trojan-activity; sid:100001384; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.1.80",nocase; classtype:trojan-activity; sid:100001385; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.10.108",nocase; classtype:trojan-activity; sid:100001386; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.10.156",nocase; classtype:trojan-activity; sid:100001387; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.10.26",nocase; classtype:trojan-activity; sid:100001388; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.10.34",nocase; classtype:trojan-activity; sid:100001389; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.10.42",nocase; classtype:trojan-activity; sid:100001390; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.129",nocase; classtype:trojan-activity; sid:100001391; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.180",nocase; classtype:trojan-activity; sid:100001392; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.190",nocase; classtype:trojan-activity; sid:100001393; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.223",nocase; classtype:trojan-activity; sid:100001394; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.4",nocase; classtype:trojan-activity; sid:100001395; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.100.87",nocase; classtype:trojan-activity; sid:100001396; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.101.110",nocase; classtype:trojan-activity; sid:100001397; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.101.207",nocase; classtype:trojan-activity; sid:100001398; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.134",nocase; classtype:trojan-activity; sid:100001399; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.136",nocase; classtype:trojan-activity; sid:100001400; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.152",nocase; classtype:trojan-activity; sid:100001401; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.221",nocase; classtype:trojan-activity; sid:100001402; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.228",nocase; classtype:trojan-activity; sid:100001403; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.102.245",nocase; classtype:trojan-activity; sid:100001404; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.103.172",nocase; classtype:trojan-activity; sid:100001405; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.103.195",nocase; classtype:trojan-activity; sid:100001406; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.103.91",nocase; classtype:trojan-activity; sid:100001407; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.106",nocase; classtype:trojan-activity; sid:100001408; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.110",nocase; classtype:trojan-activity; sid:100001409; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.120",nocase; classtype:trojan-activity; sid:100001410; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.128",nocase; classtype:trojan-activity; sid:100001411; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.153",nocase; classtype:trojan-activity; sid:100001412; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.155",nocase; classtype:trojan-activity; sid:100001413; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.16",nocase; classtype:trojan-activity; sid:100001414; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.169",nocase; classtype:trojan-activity; sid:100001415; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.183",nocase; classtype:trojan-activity; sid:100001416; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.206",nocase; classtype:trojan-activity; sid:100001417; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.49",nocase; classtype:trojan-activity; sid:100001418; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.64",nocase; classtype:trojan-activity; sid:100001419; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.104.80",nocase; classtype:trojan-activity; sid:100001420; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.111",nocase; classtype:trojan-activity; sid:100001421; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.125",nocase; classtype:trojan-activity; sid:100001422; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.146",nocase; classtype:trojan-activity; sid:100001423; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.177",nocase; classtype:trojan-activity; sid:100001424; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.217",nocase; classtype:trojan-activity; sid:100001425; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.245",nocase; classtype:trojan-activity; sid:100001426; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.247",nocase; classtype:trojan-activity; sid:100001427; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.27",nocase; classtype:trojan-activity; sid:100001428; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.28",nocase; classtype:trojan-activity; sid:100001429; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.49",nocase; classtype:trojan-activity; sid:100001430; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.105.94",nocase; classtype:trojan-activity; sid:100001431; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.118",nocase; classtype:trojan-activity; sid:100001432; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.18",nocase; classtype:trojan-activity; sid:100001433; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.193",nocase; classtype:trojan-activity; sid:100001434; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.219",nocase; classtype:trojan-activity; sid:100001435; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.253",nocase; classtype:trojan-activity; sid:100001436; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.37",nocase; classtype:trojan-activity; sid:100001437; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.77",nocase; classtype:trojan-activity; sid:100001438; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.106.87",nocase; classtype:trojan-activity; sid:100001439; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.0",nocase; classtype:trojan-activity; sid:100001440; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.133",nocase; classtype:trojan-activity; sid:100001441; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.245",nocase; classtype:trojan-activity; sid:100001442; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.83",nocase; classtype:trojan-activity; sid:100001443; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.107.86",nocase; classtype:trojan-activity; sid:100001444; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.116",nocase; classtype:trojan-activity; sid:100001445; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.145",nocase; classtype:trojan-activity; sid:100001446; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.148",nocase; classtype:trojan-activity; sid:100001447; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.179",nocase; classtype:trojan-activity; sid:100001448; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.232",nocase; classtype:trojan-activity; sid:100001449; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.67",nocase; classtype:trojan-activity; sid:100001450; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.87",nocase; classtype:trojan-activity; sid:100001451; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.108.94",nocase; classtype:trojan-activity; sid:100001452; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.109.1",nocase; classtype:trojan-activity; sid:100001453; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.109.127",nocase; classtype:trojan-activity; sid:100001454; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.109.193",nocase; classtype:trojan-activity; sid:100001455; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.109.37",nocase; classtype:trojan-activity; sid:100001456; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.109.77",nocase; classtype:trojan-activity; sid:100001457; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.109.78",nocase; classtype:trojan-activity; sid:100001458; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.176",nocase; classtype:trojan-activity; sid:100001459; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.184",nocase; classtype:trojan-activity; sid:100001460; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.204",nocase; classtype:trojan-activity; sid:100001461; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.11.57",nocase; classtype:trojan-activity; sid:100001462; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.150",nocase; classtype:trojan-activity; sid:100001463; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.155",nocase; classtype:trojan-activity; sid:100001464; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.214",nocase; classtype:trojan-activity; sid:100001465; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.221",nocase; classtype:trojan-activity; sid:100001466; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.90",nocase; classtype:trojan-activity; sid:100001467; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.110.97",nocase; classtype:trojan-activity; sid:100001468; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.105",nocase; classtype:trojan-activity; sid:100001469; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.157",nocase; classtype:trojan-activity; sid:100001470; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.190",nocase; classtype:trojan-activity; sid:100001471; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.206",nocase; classtype:trojan-activity; sid:100001472; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.36",nocase; classtype:trojan-activity; sid:100001473; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.111.84",nocase; classtype:trojan-activity; sid:100001474; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.159",nocase; classtype:trojan-activity; sid:100001475; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.26",nocase; classtype:trojan-activity; sid:100001476; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.4",nocase; classtype:trojan-activity; sid:100001477; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.112.79",nocase; classtype:trojan-activity; sid:100001478; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.113.0",nocase; classtype:trojan-activity; sid:100001479; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.113.171",nocase; classtype:trojan-activity; sid:100001480; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.113.174",nocase; classtype:trojan-activity; sid:100001481; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.113.35",nocase; classtype:trojan-activity; sid:100001482; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.113.64",nocase; classtype:trojan-activity; sid:100001483; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.113.85",nocase; classtype:trojan-activity; sid:100001484; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.107",nocase; classtype:trojan-activity; sid:100001485; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.215",nocase; classtype:trojan-activity; sid:100001486; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.234",nocase; classtype:trojan-activity; sid:100001487; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.238",nocase; classtype:trojan-activity; sid:100001488; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.241",nocase; classtype:trojan-activity; sid:100001489; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.247",nocase; classtype:trojan-activity; sid:100001490; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.254",nocase; classtype:trojan-activity; sid:100001491; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.5",nocase; classtype:trojan-activity; sid:100001492; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.55",nocase; classtype:trojan-activity; sid:100001493; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.63",nocase; classtype:trojan-activity; sid:100001494; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.82",nocase; classtype:trojan-activity; sid:100001495; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.90",nocase; classtype:trojan-activity; sid:100001496; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.114.99",nocase; classtype:trojan-activity; sid:100001497; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.1",nocase; classtype:trojan-activity; sid:100001498; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.12",nocase; classtype:trojan-activity; sid:100001499; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.13",nocase; classtype:trojan-activity; sid:100001500; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.142",nocase; classtype:trojan-activity; sid:100001501; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.143",nocase; classtype:trojan-activity; sid:100001502; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.19",nocase; classtype:trojan-activity; sid:100001503; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.206",nocase; classtype:trojan-activity; sid:100001504; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.208",nocase; classtype:trojan-activity; sid:100001505; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.221",nocase; classtype:trojan-activity; sid:100001506; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.242",nocase; classtype:trojan-activity; sid:100001507; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.35",nocase; classtype:trojan-activity; sid:100001508; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.115.40",nocase; classtype:trojan-activity; sid:100001509; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.116.15",nocase; classtype:trojan-activity; sid:100001510; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.116.236",nocase; classtype:trojan-activity; sid:100001511; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.116.48",nocase; classtype:trojan-activity; sid:100001512; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.116.64",nocase; classtype:trojan-activity; sid:100001513; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.116.87",nocase; classtype:trojan-activity; sid:100001514; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.117.215",nocase; classtype:trojan-activity; sid:100001515; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.117.32",nocase; classtype:trojan-activity; sid:100001516; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.117.51",nocase; classtype:trojan-activity; sid:100001517; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.117.63",nocase; classtype:trojan-activity; sid:100001518; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.117.84",nocase; classtype:trojan-activity; sid:100001519; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.112",nocase; classtype:trojan-activity; sid:100001520; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.139",nocase; classtype:trojan-activity; sid:100001521; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.192",nocase; classtype:trojan-activity; sid:100001522; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.225",nocase; classtype:trojan-activity; sid:100001523; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.118.60",nocase; classtype:trojan-activity; sid:100001524; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.205",nocase; classtype:trojan-activity; sid:100001525; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.209",nocase; classtype:trojan-activity; sid:100001526; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.26",nocase; classtype:trojan-activity; sid:100001527; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.86",nocase; classtype:trojan-activity; sid:100001528; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.119.88",nocase; classtype:trojan-activity; sid:100001529; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.114",nocase; classtype:trojan-activity; sid:100001530; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.252",nocase; classtype:trojan-activity; sid:100001531; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.53",nocase; classtype:trojan-activity; sid:100001532; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.12.97",nocase; classtype:trojan-activity; sid:100001533; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.120.133",nocase; classtype:trojan-activity; sid:100001534; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.120.184",nocase; classtype:trojan-activity; sid:100001535; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.120.196",nocase; classtype:trojan-activity; sid:100001536; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.120.203",nocase; classtype:trojan-activity; sid:100001537; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.120.251",nocase; classtype:trojan-activity; sid:100001538; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.123",nocase; classtype:trojan-activity; sid:100001539; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.155",nocase; classtype:trojan-activity; sid:100001540; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.55",nocase; classtype:trojan-activity; sid:100001541; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.62",nocase; classtype:trojan-activity; sid:100001542; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.63",nocase; classtype:trojan-activity; sid:100001543; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.68",nocase; classtype:trojan-activity; sid:100001544; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.121.99",nocase; classtype:trojan-activity; sid:100001545; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.172",nocase; classtype:trojan-activity; sid:100001546; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.245",nocase; classtype:trojan-activity; sid:100001547; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.26",nocase; classtype:trojan-activity; sid:100001548; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.122.28",nocase; classtype:trojan-activity; sid:100001549; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.113",nocase; classtype:trojan-activity; sid:100001550; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.2",nocase; classtype:trojan-activity; sid:100001551; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.20",nocase; classtype:trojan-activity; sid:100001552; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.30",nocase; classtype:trojan-activity; sid:100001553; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.56",nocase; classtype:trojan-activity; sid:100001554; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.123.60",nocase; classtype:trojan-activity; sid:100001555; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.109",nocase; classtype:trojan-activity; sid:100001556; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.122",nocase; classtype:trojan-activity; sid:100001557; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.131",nocase; classtype:trojan-activity; sid:100001558; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.141",nocase; classtype:trojan-activity; sid:100001559; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.211",nocase; classtype:trojan-activity; sid:100001560; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.4",nocase; classtype:trojan-activity; sid:100001561; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.79",nocase; classtype:trojan-activity; sid:100001562; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.124.89",nocase; classtype:trojan-activity; sid:100001563; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.118",nocase; classtype:trojan-activity; sid:100001564; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.14",nocase; classtype:trojan-activity; sid:100001565; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.153",nocase; classtype:trojan-activity; sid:100001566; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.156",nocase; classtype:trojan-activity; sid:100001567; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.174",nocase; classtype:trojan-activity; sid:100001568; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.219",nocase; classtype:trojan-activity; sid:100001569; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.125.39",nocase; classtype:trojan-activity; sid:100001570; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.124",nocase; classtype:trojan-activity; sid:100001571; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.131",nocase; classtype:trojan-activity; sid:100001572; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.141",nocase; classtype:trojan-activity; sid:100001573; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.167",nocase; classtype:trojan-activity; sid:100001574; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.220",nocase; classtype:trojan-activity; sid:100001575; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.222",nocase; classtype:trojan-activity; sid:100001576; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.237",nocase; classtype:trojan-activity; sid:100001577; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.126.83",nocase; classtype:trojan-activity; sid:100001578; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.10",nocase; classtype:trojan-activity; sid:100001579; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.109",nocase; classtype:trojan-activity; sid:100001580; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.116",nocase; classtype:trojan-activity; sid:100001581; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.129",nocase; classtype:trojan-activity; sid:100001582; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.142",nocase; classtype:trojan-activity; sid:100001583; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.15",nocase; classtype:trojan-activity; sid:100001584; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.182",nocase; classtype:trojan-activity; sid:100001585; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.230",nocase; classtype:trojan-activity; sid:100001586; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.231",nocase; classtype:trojan-activity; sid:100001587; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.236",nocase; classtype:trojan-activity; sid:100001588; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.238",nocase; classtype:trojan-activity; sid:100001589; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.63",nocase; classtype:trojan-activity; sid:100001590; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.127.75",nocase; classtype:trojan-activity; sid:100001591; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.13.237",nocase; classtype:trojan-activity; sid:100001592; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.14.106",nocase; classtype:trojan-activity; sid:100001593; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.14.185",nocase; classtype:trojan-activity; sid:100001594; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.14.246",nocase; classtype:trojan-activity; sid:100001595; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.14.60",nocase; classtype:trojan-activity; sid:100001596; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.17",nocase; classtype:trojan-activity; sid:100001597; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.217",nocase; classtype:trojan-activity; sid:100001598; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.232",nocase; classtype:trojan-activity; sid:100001599; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.246",nocase; classtype:trojan-activity; sid:100001600; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.252",nocase; classtype:trojan-activity; sid:100001601; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.35",nocase; classtype:trojan-activity; sid:100001602; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.44",nocase; classtype:trojan-activity; sid:100001603; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.45",nocase; classtype:trojan-activity; sid:100001604; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.15.85",nocase; classtype:trojan-activity; sid:100001605; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.1",nocase; classtype:trojan-activity; sid:100001606; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.108",nocase; classtype:trojan-activity; sid:100001607; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.114",nocase; classtype:trojan-activity; sid:100001608; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.17",nocase; classtype:trojan-activity; sid:100001609; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.179",nocase; classtype:trojan-activity; sid:100001610; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.193",nocase; classtype:trojan-activity; sid:100001611; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.208",nocase; classtype:trojan-activity; sid:100001612; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.73",nocase; classtype:trojan-activity; sid:100001613; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.16.97",nocase; classtype:trojan-activity; sid:100001614; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.17.176",nocase; classtype:trojan-activity; sid:100001615; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.17.245",nocase; classtype:trojan-activity; sid:100001616; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.18.238",nocase; classtype:trojan-activity; sid:100001617; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.18.27",nocase; classtype:trojan-activity; sid:100001618; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.18.93",nocase; classtype:trojan-activity; sid:100001619; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.144",nocase; classtype:trojan-activity; sid:100001620; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.150",nocase; classtype:trojan-activity; sid:100001621; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.163",nocase; classtype:trojan-activity; sid:100001622; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.174",nocase; classtype:trojan-activity; sid:100001623; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.229",nocase; classtype:trojan-activity; sid:100001624; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.242",nocase; classtype:trojan-activity; sid:100001625; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.44",nocase; classtype:trojan-activity; sid:100001626; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.19.47",nocase; classtype:trojan-activity; sid:100001627; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.110",nocase; classtype:trojan-activity; sid:100001628; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.237",nocase; classtype:trojan-activity; sid:100001629; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.41",nocase; classtype:trojan-activity; sid:100001630; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.2.5",nocase; classtype:trojan-activity; sid:100001631; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.117",nocase; classtype:trojan-activity; sid:100001632; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.145",nocase; classtype:trojan-activity; sid:100001633; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.170",nocase; classtype:trojan-activity; sid:100001634; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.21",nocase; classtype:trojan-activity; sid:100001635; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.225",nocase; classtype:trojan-activity; sid:100001636; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.237",nocase; classtype:trojan-activity; sid:100001637; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.238",nocase; classtype:trojan-activity; sid:100001638; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.24",nocase; classtype:trojan-activity; sid:100001639; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.38",nocase; classtype:trojan-activity; sid:100001640; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.20.70",nocase; classtype:trojan-activity; sid:100001641; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.149",nocase; classtype:trojan-activity; sid:100001642; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.184",nocase; classtype:trojan-activity; sid:100001643; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.238",nocase; classtype:trojan-activity; sid:100001644; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.21.76",nocase; classtype:trojan-activity; sid:100001645; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.22.207",nocase; classtype:trojan-activity; sid:100001646; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.22.248",nocase; classtype:trojan-activity; sid:100001647; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.23.102",nocase; classtype:trojan-activity; sid:100001648; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.23.156",nocase; classtype:trojan-activity; sid:100001649; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.23.250",nocase; classtype:trojan-activity; sid:100001650; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.23.6",nocase; classtype:trojan-activity; sid:100001651; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.13",nocase; classtype:trojan-activity; sid:100001652; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.138",nocase; classtype:trojan-activity; sid:100001653; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.15",nocase; classtype:trojan-activity; sid:100001654; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.171",nocase; classtype:trojan-activity; sid:100001655; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.227",nocase; classtype:trojan-activity; sid:100001656; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.24.230",nocase; classtype:trojan-activity; sid:100001657; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.117",nocase; classtype:trojan-activity; sid:100001658; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.169",nocase; classtype:trojan-activity; sid:100001659; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.244",nocase; classtype:trojan-activity; sid:100001660; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.28",nocase; classtype:trojan-activity; sid:100001661; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.56",nocase; classtype:trojan-activity; sid:100001662; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.64",nocase; classtype:trojan-activity; sid:100001663; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.25.77",nocase; classtype:trojan-activity; sid:100001664; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.134",nocase; classtype:trojan-activity; sid:100001665; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.164",nocase; classtype:trojan-activity; sid:100001666; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.165",nocase; classtype:trojan-activity; sid:100001667; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.215",nocase; classtype:trojan-activity; sid:100001668; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.219",nocase; classtype:trojan-activity; sid:100001669; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.224",nocase; classtype:trojan-activity; sid:100001670; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.246",nocase; classtype:trojan-activity; sid:100001671; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.26.34",nocase; classtype:trojan-activity; sid:100001672; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.122",nocase; classtype:trojan-activity; sid:100001673; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.138",nocase; classtype:trojan-activity; sid:100001674; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.14",nocase; classtype:trojan-activity; sid:100001675; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.167",nocase; classtype:trojan-activity; sid:100001676; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.179",nocase; classtype:trojan-activity; sid:100001677; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.199",nocase; classtype:trojan-activity; sid:100001678; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.202",nocase; classtype:trojan-activity; sid:100001679; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.215",nocase; classtype:trojan-activity; sid:100001680; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.225",nocase; classtype:trojan-activity; sid:100001681; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.233",nocase; classtype:trojan-activity; sid:100001682; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.239",nocase; classtype:trojan-activity; sid:100001683; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.32",nocase; classtype:trojan-activity; sid:100001684; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.48",nocase; classtype:trojan-activity; sid:100001685; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.68",nocase; classtype:trojan-activity; sid:100001686; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.69",nocase; classtype:trojan-activity; sid:100001687; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.27.84",nocase; classtype:trojan-activity; sid:100001688; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.28.124",nocase; classtype:trojan-activity; sid:100001689; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.28.168",nocase; classtype:trojan-activity; sid:100001690; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.28.75",nocase; classtype:trojan-activity; sid:100001691; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.28.8",nocase; classtype:trojan-activity; sid:100001692; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.12",nocase; classtype:trojan-activity; sid:100001693; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.16",nocase; classtype:trojan-activity; sid:100001694; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.173",nocase; classtype:trojan-activity; sid:100001695; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.174",nocase; classtype:trojan-activity; sid:100001696; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.29.207",nocase; classtype:trojan-activity; sid:100001697; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.116",nocase; classtype:trojan-activity; sid:100001698; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.123",nocase; classtype:trojan-activity; sid:100001699; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.130",nocase; classtype:trojan-activity; sid:100001700; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.172",nocase; classtype:trojan-activity; sid:100001701; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.190",nocase; classtype:trojan-activity; sid:100001702; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.194",nocase; classtype:trojan-activity; sid:100001703; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.196",nocase; classtype:trojan-activity; sid:100001704; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.214",nocase; classtype:trojan-activity; sid:100001705; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.56",nocase; classtype:trojan-activity; sid:100001706; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.3.81",nocase; classtype:trojan-activity; sid:100001707; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.0",nocase; classtype:trojan-activity; sid:100001708; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.30.77",nocase; classtype:trojan-activity; sid:100001709; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.31.211",nocase; classtype:trojan-activity; sid:100001710; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.31.232",nocase; classtype:trojan-activity; sid:100001711; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.31.249",nocase; classtype:trojan-activity; sid:100001712; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.31.251",nocase; classtype:trojan-activity; sid:100001713; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.0",nocase; classtype:trojan-activity; sid:100001714; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.172",nocase; classtype:trojan-activity; sid:100001715; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.198",nocase; classtype:trojan-activity; sid:100001716; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.208",nocase; classtype:trojan-activity; sid:100001717; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.211",nocase; classtype:trojan-activity; sid:100001718; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.229",nocase; classtype:trojan-activity; sid:100001719; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.243",nocase; classtype:trojan-activity; sid:100001720; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.255",nocase; classtype:trojan-activity; sid:100001721; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.42",nocase; classtype:trojan-activity; sid:100001722; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.32.89",nocase; classtype:trojan-activity; sid:100001723; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.112",nocase; classtype:trojan-activity; sid:100001724; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.155",nocase; classtype:trojan-activity; sid:100001725; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.161",nocase; classtype:trojan-activity; sid:100001726; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.162",nocase; classtype:trojan-activity; sid:100001727; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.170",nocase; classtype:trojan-activity; sid:100001728; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.173",nocase; classtype:trojan-activity; sid:100001729; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.174",nocase; classtype:trojan-activity; sid:100001730; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.181",nocase; classtype:trojan-activity; sid:100001731; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.2",nocase; classtype:trojan-activity; sid:100001732; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.205",nocase; classtype:trojan-activity; sid:100001733; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.216",nocase; classtype:trojan-activity; sid:100001734; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.234",nocase; classtype:trojan-activity; sid:100001735; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.236",nocase; classtype:trojan-activity; sid:100001736; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.33.26",nocase; classtype:trojan-activity; sid:100001737; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.34.219",nocase; classtype:trojan-activity; sid:100001738; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.34.5",nocase; classtype:trojan-activity; sid:100001739; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.34.56",nocase; classtype:trojan-activity; sid:100001740; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.34.96",nocase; classtype:trojan-activity; sid:100001741; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.35.21",nocase; classtype:trojan-activity; sid:100001742; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.35.215",nocase; classtype:trojan-activity; sid:100001743; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.35.38",nocase; classtype:trojan-activity; sid:100001744; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.35.83",nocase; classtype:trojan-activity; sid:100001745; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.35.89",nocase; classtype:trojan-activity; sid:100001746; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.0",nocase; classtype:trojan-activity; sid:100001747; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.1",nocase; classtype:trojan-activity; sid:100001748; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.102",nocase; classtype:trojan-activity; sid:100001749; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.112",nocase; classtype:trojan-activity; sid:100001750; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.12",nocase; classtype:trojan-activity; sid:100001751; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.127",nocase; classtype:trojan-activity; sid:100001752; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.176",nocase; classtype:trojan-activity; sid:100001753; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.19",nocase; classtype:trojan-activity; sid:100001754; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.199",nocase; classtype:trojan-activity; sid:100001755; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.218",nocase; classtype:trojan-activity; sid:100001756; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.22",nocase; classtype:trojan-activity; sid:100001757; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.223",nocase; classtype:trojan-activity; sid:100001758; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.33",nocase; classtype:trojan-activity; sid:100001759; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.36.78",nocase; classtype:trojan-activity; sid:100001760; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.121",nocase; classtype:trojan-activity; sid:100001761; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.135",nocase; classtype:trojan-activity; sid:100001762; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.159",nocase; classtype:trojan-activity; sid:100001763; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.37.6",nocase; classtype:trojan-activity; sid:100001764; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.1",nocase; classtype:trojan-activity; sid:100001765; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.132",nocase; classtype:trojan-activity; sid:100001766; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.162",nocase; classtype:trojan-activity; sid:100001767; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.165",nocase; classtype:trojan-activity; sid:100001768; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.191",nocase; classtype:trojan-activity; sid:100001769; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.200",nocase; classtype:trojan-activity; sid:100001770; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.53",nocase; classtype:trojan-activity; sid:100001771; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.38.98",nocase; classtype:trojan-activity; sid:100001772; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.39.167",nocase; classtype:trojan-activity; sid:100001773; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.39.176",nocase; classtype:trojan-activity; sid:100001774; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.39.245",nocase; classtype:trojan-activity; sid:100001775; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.39.61",nocase; classtype:trojan-activity; sid:100001776; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.219",nocase; classtype:trojan-activity; sid:100001777; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.222",nocase; classtype:trojan-activity; sid:100001778; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.42",nocase; classtype:trojan-activity; sid:100001779; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.4.95",nocase; classtype:trojan-activity; sid:100001780; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.1",nocase; classtype:trojan-activity; sid:100001781; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.145",nocase; classtype:trojan-activity; sid:100001782; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.151",nocase; classtype:trojan-activity; sid:100001783; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.166",nocase; classtype:trojan-activity; sid:100001784; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.199",nocase; classtype:trojan-activity; sid:100001785; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.226",nocase; classtype:trojan-activity; sid:100001786; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.41",nocase; classtype:trojan-activity; sid:100001787; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.5",nocase; classtype:trojan-activity; sid:100001788; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.67",nocase; classtype:trojan-activity; sid:100001789; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.70",nocase; classtype:trojan-activity; sid:100001790; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.71",nocase; classtype:trojan-activity; sid:100001791; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.40.82",nocase; classtype:trojan-activity; sid:100001792; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.165",nocase; classtype:trojan-activity; sid:100001793; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.178",nocase; classtype:trojan-activity; sid:100001794; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.200",nocase; classtype:trojan-activity; sid:100001795; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.203",nocase; classtype:trojan-activity; sid:100001796; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.210",nocase; classtype:trojan-activity; sid:100001797; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.216",nocase; classtype:trojan-activity; sid:100001798; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.246",nocase; classtype:trojan-activity; sid:100001799; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.41.34",nocase; classtype:trojan-activity; sid:100001800; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.162",nocase; classtype:trojan-activity; sid:100001801; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.166",nocase; classtype:trojan-activity; sid:100001802; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.200",nocase; classtype:trojan-activity; sid:100001803; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.211",nocase; classtype:trojan-activity; sid:100001804; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.221",nocase; classtype:trojan-activity; sid:100001805; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.27",nocase; classtype:trojan-activity; sid:100001806; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.42.31",nocase; classtype:trojan-activity; sid:100001807; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.1",nocase; classtype:trojan-activity; sid:100001808; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.121",nocase; classtype:trojan-activity; sid:100001809; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.125",nocase; classtype:trojan-activity; sid:100001810; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.147",nocase; classtype:trojan-activity; sid:100001811; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.16",nocase; classtype:trojan-activity; sid:100001812; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.33",nocase; classtype:trojan-activity; sid:100001813; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.43.34",nocase; classtype:trojan-activity; sid:100001814; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.0",nocase; classtype:trojan-activity; sid:100001815; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.134",nocase; classtype:trojan-activity; sid:100001816; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.143",nocase; classtype:trojan-activity; sid:100001817; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.155",nocase; classtype:trojan-activity; sid:100001818; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.197",nocase; classtype:trojan-activity; sid:100001819; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.209",nocase; classtype:trojan-activity; sid:100001820; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.218",nocase; classtype:trojan-activity; sid:100001821; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.219",nocase; classtype:trojan-activity; sid:100001822; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.22",nocase; classtype:trojan-activity; sid:100001823; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.241",nocase; classtype:trojan-activity; sid:100001824; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.70",nocase; classtype:trojan-activity; sid:100001825; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.89",nocase; classtype:trojan-activity; sid:100001826; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.90",nocase; classtype:trojan-activity; sid:100001827; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.44.95",nocase; classtype:trojan-activity; sid:100001828; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.45.205",nocase; classtype:trojan-activity; sid:100001829; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.45.221",nocase; classtype:trojan-activity; sid:100001830; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.45.224",nocase; classtype:trojan-activity; sid:100001831; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.45.230",nocase; classtype:trojan-activity; sid:100001832; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.119",nocase; classtype:trojan-activity; sid:100001833; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.132",nocase; classtype:trojan-activity; sid:100001834; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.151",nocase; classtype:trojan-activity; sid:100001835; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.46.187",nocase; classtype:trojan-activity; sid:100001836; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.141",nocase; classtype:trojan-activity; sid:100001837; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.47.151",nocase; classtype:trojan-activity; sid:100001838; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.48.121",nocase; classtype:trojan-activity; sid:100001839; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.48.195",nocase; classtype:trojan-activity; sid:100001840; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.48.243",nocase; classtype:trojan-activity; sid:100001841; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.48.76",nocase; classtype:trojan-activity; sid:100001842; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.100",nocase; classtype:trojan-activity; sid:100001843; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.107",nocase; classtype:trojan-activity; sid:100001844; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.129",nocase; classtype:trojan-activity; sid:100001845; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.138",nocase; classtype:trojan-activity; sid:100001846; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.188",nocase; classtype:trojan-activity; sid:100001847; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.247",nocase; classtype:trojan-activity; sid:100001848; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.49.3",nocase; classtype:trojan-activity; sid:100001849; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.5.247",nocase; classtype:trojan-activity; sid:100001850; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.5.251",nocase; classtype:trojan-activity; sid:100001851; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.5.70",nocase; classtype:trojan-activity; sid:100001852; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.131",nocase; classtype:trojan-activity; sid:100001853; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.177",nocase; classtype:trojan-activity; sid:100001854; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.196",nocase; classtype:trojan-activity; sid:100001855; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.201",nocase; classtype:trojan-activity; sid:100001856; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.218",nocase; classtype:trojan-activity; sid:100001857; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.236",nocase; classtype:trojan-activity; sid:100001858; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.50.237",nocase; classtype:trojan-activity; sid:100001859; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.51.197",nocase; classtype:trojan-activity; sid:100001860; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.51.202",nocase; classtype:trojan-activity; sid:100001861; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.51.223",nocase; classtype:trojan-activity; sid:100001862; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.51.66",nocase; classtype:trojan-activity; sid:100001863; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.149",nocase; classtype:trojan-activity; sid:100001864; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.52.161",nocase; classtype:trojan-activity; sid:100001865; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.103",nocase; classtype:trojan-activity; sid:100001866; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.186",nocase; classtype:trojan-activity; sid:100001867; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.20",nocase; classtype:trojan-activity; sid:100001868; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.228",nocase; classtype:trojan-activity; sid:100001869; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.4",nocase; classtype:trojan-activity; sid:100001870; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.5",nocase; classtype:trojan-activity; sid:100001871; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.53.79",nocase; classtype:trojan-activity; sid:100001872; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.105",nocase; classtype:trojan-activity; sid:100001873; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.205",nocase; classtype:trojan-activity; sid:100001874; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.214",nocase; classtype:trojan-activity; sid:100001875; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.35",nocase; classtype:trojan-activity; sid:100001876; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.54.72",nocase; classtype:trojan-activity; sid:100001877; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.101",nocase; classtype:trojan-activity; sid:100001878; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.163",nocase; classtype:trojan-activity; sid:100001879; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.170",nocase; classtype:trojan-activity; sid:100001880; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.216",nocase; classtype:trojan-activity; sid:100001881; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.248",nocase; classtype:trojan-activity; sid:100001882; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.29",nocase; classtype:trojan-activity; sid:100001883; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.41",nocase; classtype:trojan-activity; sid:100001884; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.77",nocase; classtype:trojan-activity; sid:100001885; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.55.85",nocase; classtype:trojan-activity; sid:100001886; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.103",nocase; classtype:trojan-activity; sid:100001887; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.196",nocase; classtype:trojan-activity; sid:100001888; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.33",nocase; classtype:trojan-activity; sid:100001889; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.75",nocase; classtype:trojan-activity; sid:100001890; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.56.94",nocase; classtype:trojan-activity; sid:100001891; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.57.141",nocase; classtype:trojan-activity; sid:100001892; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.57.178",nocase; classtype:trojan-activity; sid:100001893; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.57.192",nocase; classtype:trojan-activity; sid:100001894; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.58.141",nocase; classtype:trojan-activity; sid:100001895; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.58.42",nocase; classtype:trojan-activity; sid:100001896; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.142",nocase; classtype:trojan-activity; sid:100001897; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.161",nocase; classtype:trojan-activity; sid:100001898; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.229",nocase; classtype:trojan-activity; sid:100001899; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.33",nocase; classtype:trojan-activity; sid:100001900; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.46",nocase; classtype:trojan-activity; sid:100001901; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.54",nocase; classtype:trojan-activity; sid:100001902; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.59.91",nocase; classtype:trojan-activity; sid:100001903; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.134",nocase; classtype:trojan-activity; sid:100001904; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.151",nocase; classtype:trojan-activity; sid:100001905; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.162",nocase; classtype:trojan-activity; sid:100001906; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.6.72",nocase; classtype:trojan-activity; sid:100001907; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.60.181",nocase; classtype:trojan-activity; sid:100001908; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.60.209",nocase; classtype:trojan-activity; sid:100001909; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.117",nocase; classtype:trojan-activity; sid:100001910; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.156",nocase; classtype:trojan-activity; sid:100001911; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.219",nocase; classtype:trojan-activity; sid:100001912; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.229",nocase; classtype:trojan-activity; sid:100001913; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.234",nocase; classtype:trojan-activity; sid:100001914; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.253",nocase; classtype:trojan-activity; sid:100001915; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.40",nocase; classtype:trojan-activity; sid:100001916; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.42",nocase; classtype:trojan-activity; sid:100001917; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.61.82",nocase; classtype:trojan-activity; sid:100001918; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.110",nocase; classtype:trojan-activity; sid:100001919; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.115",nocase; classtype:trojan-activity; sid:100001920; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.168",nocase; classtype:trojan-activity; sid:100001921; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.216",nocase; classtype:trojan-activity; sid:100001922; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.43",nocase; classtype:trojan-activity; sid:100001923; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.44",nocase; classtype:trojan-activity; sid:100001924; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.62.70",nocase; classtype:trojan-activity; sid:100001925; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.63.194",nocase; classtype:trojan-activity; sid:100001926; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.63.21",nocase; classtype:trojan-activity; sid:100001927; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.63.218",nocase; classtype:trojan-activity; sid:100001928; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.116",nocase; classtype:trojan-activity; sid:100001929; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.12",nocase; classtype:trojan-activity; sid:100001930; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.142",nocase; classtype:trojan-activity; sid:100001931; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.158",nocase; classtype:trojan-activity; sid:100001932; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.219",nocase; classtype:trojan-activity; sid:100001933; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.30",nocase; classtype:trojan-activity; sid:100001934; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.64.66",nocase; classtype:trojan-activity; sid:100001935; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.65.115",nocase; classtype:trojan-activity; sid:100001936; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.65.171",nocase; classtype:trojan-activity; sid:100001937; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.65.223",nocase; classtype:trojan-activity; sid:100001938; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.65.44",nocase; classtype:trojan-activity; sid:100001939; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.65.70",nocase; classtype:trojan-activity; sid:100001940; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.65.95",nocase; classtype:trojan-activity; sid:100001941; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.65.96",nocase; classtype:trojan-activity; sid:100001942; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.105",nocase; classtype:trojan-activity; sid:100001943; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.170",nocase; classtype:trojan-activity; sid:100001944; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.177",nocase; classtype:trojan-activity; sid:100001945; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.186",nocase; classtype:trojan-activity; sid:100001946; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.199",nocase; classtype:trojan-activity; sid:100001947; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.211",nocase; classtype:trojan-activity; sid:100001948; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.228",nocase; classtype:trojan-activity; sid:100001949; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.66.93",nocase; classtype:trojan-activity; sid:100001950; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.0",nocase; classtype:trojan-activity; sid:100001951; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.184",nocase; classtype:trojan-activity; sid:100001952; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.201",nocase; classtype:trojan-activity; sid:100001953; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.254",nocase; classtype:trojan-activity; sid:100001954; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.67.83",nocase; classtype:trojan-activity; sid:100001955; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.1",nocase; classtype:trojan-activity; sid:100001956; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.109",nocase; classtype:trojan-activity; sid:100001957; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.126",nocase; classtype:trojan-activity; sid:100001958; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.170",nocase; classtype:trojan-activity; sid:100001959; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.227",nocase; classtype:trojan-activity; sid:100001960; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.232",nocase; classtype:trojan-activity; sid:100001961; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.29",nocase; classtype:trojan-activity; sid:100001962; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.44",nocase; classtype:trojan-activity; sid:100001963; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.66",nocase; classtype:trojan-activity; sid:100001964; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.68.83",nocase; classtype:trojan-activity; sid:100001965; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.111",nocase; classtype:trojan-activity; sid:100001966; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.112",nocase; classtype:trojan-activity; sid:100001967; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.119",nocase; classtype:trojan-activity; sid:100001968; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.128",nocase; classtype:trojan-activity; sid:100001969; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.138",nocase; classtype:trojan-activity; sid:100001970; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.148",nocase; classtype:trojan-activity; sid:100001971; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.149",nocase; classtype:trojan-activity; sid:100001972; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.173",nocase; classtype:trojan-activity; sid:100001973; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.188",nocase; classtype:trojan-activity; sid:100001974; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.69.77",nocase; classtype:trojan-activity; sid:100001975; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.7.163",nocase; classtype:trojan-activity; sid:100001976; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.119",nocase; classtype:trojan-activity; sid:100001977; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.12",nocase; classtype:trojan-activity; sid:100001978; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.147",nocase; classtype:trojan-activity; sid:100001979; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.18",nocase; classtype:trojan-activity; sid:100001980; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.200",nocase; classtype:trojan-activity; sid:100001981; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.38",nocase; classtype:trojan-activity; sid:100001982; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.53",nocase; classtype:trojan-activity; sid:100001983; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.70.54",nocase; classtype:trojan-activity; sid:100001984; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.148",nocase; classtype:trojan-activity; sid:100001985; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.153",nocase; classtype:trojan-activity; sid:100001986; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.185",nocase; classtype:trojan-activity; sid:100001987; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.22",nocase; classtype:trojan-activity; sid:100001988; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.240",nocase; classtype:trojan-activity; sid:100001989; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.55",nocase; classtype:trojan-activity; sid:100001990; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.63",nocase; classtype:trojan-activity; sid:100001991; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.64",nocase; classtype:trojan-activity; sid:100001992; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.71.84",nocase; classtype:trojan-activity; sid:100001993; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.13",nocase; classtype:trojan-activity; sid:100001994; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.164",nocase; classtype:trojan-activity; sid:100001995; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.196",nocase; classtype:trojan-activity; sid:100001996; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.72.222",nocase; classtype:trojan-activity; sid:100001997; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.73.211",nocase; classtype:trojan-activity; sid:100001998; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.73.71",nocase; classtype:trojan-activity; sid:100001999; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.74.182",nocase; classtype:trojan-activity; sid:100002000; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.74.48",nocase; classtype:trojan-activity; sid:100002001; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.74.77",nocase; classtype:trojan-activity; sid:100002002; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.75.181",nocase; classtype:trojan-activity; sid:100002003; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.75.19",nocase; classtype:trojan-activity; sid:100002004; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.75.209",nocase; classtype:trojan-activity; sid:100002005; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.75.84",nocase; classtype:trojan-activity; sid:100002006; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.75.87",nocase; classtype:trojan-activity; sid:100002007; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.109",nocase; classtype:trojan-activity; sid:100002008; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.121",nocase; classtype:trojan-activity; sid:100002009; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.167",nocase; classtype:trojan-activity; sid:100002010; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.187",nocase; classtype:trojan-activity; sid:100002011; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.214",nocase; classtype:trojan-activity; sid:100002012; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.215",nocase; classtype:trojan-activity; sid:100002013; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.217",nocase; classtype:trojan-activity; sid:100002014; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.76.24",nocase; classtype:trojan-activity; sid:100002015; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.77.46",nocase; classtype:trojan-activity; sid:100002016; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.77.47",nocase; classtype:trojan-activity; sid:100002017; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.77.95",nocase; classtype:trojan-activity; sid:100002018; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.106",nocase; classtype:trojan-activity; sid:100002019; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.118",nocase; classtype:trojan-activity; sid:100002020; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.233",nocase; classtype:trojan-activity; sid:100002021; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.46",nocase; classtype:trojan-activity; sid:100002022; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.76",nocase; classtype:trojan-activity; sid:100002023; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.78.97",nocase; classtype:trojan-activity; sid:100002024; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.79.156",nocase; classtype:trojan-activity; sid:100002025; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.79.227",nocase; classtype:trojan-activity; sid:100002026; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.79.247",nocase; classtype:trojan-activity; sid:100002027; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.79.45",nocase; classtype:trojan-activity; sid:100002028; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.79.77",nocase; classtype:trojan-activity; sid:100002029; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.8.100",nocase; classtype:trojan-activity; sid:100002030; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.8.199",nocase; classtype:trojan-activity; sid:100002031; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.8.217",nocase; classtype:trojan-activity; sid:100002032; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.8.254",nocase; classtype:trojan-activity; sid:100002033; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.8.97",nocase; classtype:trojan-activity; sid:100002034; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.100",nocase; classtype:trojan-activity; sid:100002035; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.136",nocase; classtype:trojan-activity; sid:100002036; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.237",nocase; classtype:trojan-activity; sid:100002037; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.41",nocase; classtype:trojan-activity; sid:100002038; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.79",nocase; classtype:trojan-activity; sid:100002039; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.80.86",nocase; classtype:trojan-activity; sid:100002040; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.1",nocase; classtype:trojan-activity; sid:100002041; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.141",nocase; classtype:trojan-activity; sid:100002042; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.15",nocase; classtype:trojan-activity; sid:100002043; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.152",nocase; classtype:trojan-activity; sid:100002044; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.17",nocase; classtype:trojan-activity; sid:100002045; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.194",nocase; classtype:trojan-activity; sid:100002046; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.226",nocase; classtype:trojan-activity; sid:100002047; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.244",nocase; classtype:trojan-activity; sid:100002048; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.32",nocase; classtype:trojan-activity; sid:100002049; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.50",nocase; classtype:trojan-activity; sid:100002050; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.81.8",nocase; classtype:trojan-activity; sid:100002051; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.82.120",nocase; classtype:trojan-activity; sid:100002052; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.82.61",nocase; classtype:trojan-activity; sid:100002053; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.83.147",nocase; classtype:trojan-activity; sid:100002054; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.83.196",nocase; classtype:trojan-activity; sid:100002055; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.83.247",nocase; classtype:trojan-activity; sid:100002056; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.102",nocase; classtype:trojan-activity; sid:100002057; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.109",nocase; classtype:trojan-activity; sid:100002058; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.148",nocase; classtype:trojan-activity; sid:100002059; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.158",nocase; classtype:trojan-activity; sid:100002060; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.159",nocase; classtype:trojan-activity; sid:100002061; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.215",nocase; classtype:trojan-activity; sid:100002062; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.84.42",nocase; classtype:trojan-activity; sid:100002063; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.153",nocase; classtype:trojan-activity; sid:100002064; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.183",nocase; classtype:trojan-activity; sid:100002065; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.190",nocase; classtype:trojan-activity; sid:100002066; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.23",nocase; classtype:trojan-activity; sid:100002067; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.81",nocase; classtype:trojan-activity; sid:100002068; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.85.87",nocase; classtype:trojan-activity; sid:100002069; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.86.119",nocase; classtype:trojan-activity; sid:100002070; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.86.159",nocase; classtype:trojan-activity; sid:100002071; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.86.166",nocase; classtype:trojan-activity; sid:100002072; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.108",nocase; classtype:trojan-activity; sid:100002073; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.123",nocase; classtype:trojan-activity; sid:100002074; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.162",nocase; classtype:trojan-activity; sid:100002075; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.87.253",nocase; classtype:trojan-activity; sid:100002076; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.180",nocase; classtype:trojan-activity; sid:100002077; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.88.181",nocase; classtype:trojan-activity; sid:100002078; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.89.130",nocase; classtype:trojan-activity; sid:100002079; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.89.157",nocase; classtype:trojan-activity; sid:100002080; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.89.160",nocase; classtype:trojan-activity; sid:100002081; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.89.169",nocase; classtype:trojan-activity; sid:100002082; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.89.37",nocase; classtype:trojan-activity; sid:100002083; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.106",nocase; classtype:trojan-activity; sid:100002084; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.139",nocase; classtype:trojan-activity; sid:100002085; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.183",nocase; classtype:trojan-activity; sid:100002086; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.210",nocase; classtype:trojan-activity; sid:100002087; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.215",nocase; classtype:trojan-activity; sid:100002088; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.217",nocase; classtype:trojan-activity; sid:100002089; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.245",nocase; classtype:trojan-activity; sid:100002090; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.45",nocase; classtype:trojan-activity; sid:100002091; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.80",nocase; classtype:trojan-activity; sid:100002092; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.84",nocase; classtype:trojan-activity; sid:100002093; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.9.95",nocase; classtype:trojan-activity; sid:100002094; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.104",nocase; classtype:trojan-activity; sid:100002095; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.122",nocase; classtype:trojan-activity; sid:100002096; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.178",nocase; classtype:trojan-activity; sid:100002097; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.187",nocase; classtype:trojan-activity; sid:100002098; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.21",nocase; classtype:trojan-activity; sid:100002099; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.212",nocase; classtype:trojan-activity; sid:100002100; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.4",nocase; classtype:trojan-activity; sid:100002101; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.90.8",nocase; classtype:trojan-activity; sid:100002102; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.15",nocase; classtype:trojan-activity; sid:100002103; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.165",nocase; classtype:trojan-activity; sid:100002104; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.172",nocase; classtype:trojan-activity; sid:100002105; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.191",nocase; classtype:trojan-activity; sid:100002106; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.223",nocase; classtype:trojan-activity; sid:100002107; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.230",nocase; classtype:trojan-activity; sid:100002108; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.253",nocase; classtype:trojan-activity; sid:100002109; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.58",nocase; classtype:trojan-activity; sid:100002110; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.91.96",nocase; classtype:trojan-activity; sid:100002111; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.132",nocase; classtype:trojan-activity; sid:100002112; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.186",nocase; classtype:trojan-activity; sid:100002113; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.201",nocase; classtype:trojan-activity; sid:100002114; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.208",nocase; classtype:trojan-activity; sid:100002115; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.215",nocase; classtype:trojan-activity; sid:100002116; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.231",nocase; classtype:trojan-activity; sid:100002117; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.248",nocase; classtype:trojan-activity; sid:100002118; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.92.45",nocase; classtype:trojan-activity; sid:100002119; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.143",nocase; classtype:trojan-activity; sid:100002120; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.148",nocase; classtype:trojan-activity; sid:100002121; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.150",nocase; classtype:trojan-activity; sid:100002122; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.155",nocase; classtype:trojan-activity; sid:100002123; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.171",nocase; classtype:trojan-activity; sid:100002124; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.198",nocase; classtype:trojan-activity; sid:100002125; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.224",nocase; classtype:trojan-activity; sid:100002126; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.225",nocase; classtype:trojan-activity; sid:100002127; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.31",nocase; classtype:trojan-activity; sid:100002128; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.34",nocase; classtype:trojan-activity; sid:100002129; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.4",nocase; classtype:trojan-activity; sid:100002130; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.45",nocase; classtype:trojan-activity; sid:100002131; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.6",nocase; classtype:trojan-activity; sid:100002132; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.93.90",nocase; classtype:trojan-activity; sid:100002133; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.116",nocase; classtype:trojan-activity; sid:100002134; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.195",nocase; classtype:trojan-activity; sid:100002135; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.238",nocase; classtype:trojan-activity; sid:100002136; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.248",nocase; classtype:trojan-activity; sid:100002137; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.94.40",nocase; classtype:trojan-activity; sid:100002138; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.111",nocase; classtype:trojan-activity; sid:100002139; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.132",nocase; classtype:trojan-activity; sid:100002140; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.147",nocase; classtype:trojan-activity; sid:100002141; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.227",nocase; classtype:trojan-activity; sid:100002142; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.237",nocase; classtype:trojan-activity; sid:100002143; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.244",nocase; classtype:trojan-activity; sid:100002144; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.4",nocase; classtype:trojan-activity; sid:100002145; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.7",nocase; classtype:trojan-activity; sid:100002146; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.95.89",nocase; classtype:trojan-activity; sid:100002147; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.96.13",nocase; classtype:trojan-activity; sid:100002148; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.96.195",nocase; classtype:trojan-activity; sid:100002149; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.96.6",nocase; classtype:trojan-activity; sid:100002150; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.97.1",nocase; classtype:trojan-activity; sid:100002151; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.97.128",nocase; classtype:trojan-activity; sid:100002152; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.97.135",nocase; classtype:trojan-activity; sid:100002153; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.97.162",nocase; classtype:trojan-activity; sid:100002154; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.97.17",nocase; classtype:trojan-activity; sid:100002155; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.97.208",nocase; classtype:trojan-activity; sid:100002156; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.98.228",nocase; classtype:trojan-activity; sid:100002157; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.98.254",nocase; classtype:trojan-activity; sid:100002158; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.98.50",nocase; classtype:trojan-activity; sid:100002159; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.98.68",nocase; classtype:trojan-activity; sid:100002160; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.123",nocase; classtype:trojan-activity; sid:100002161; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.130",nocase; classtype:trojan-activity; sid:100002162; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.22",nocase; classtype:trojan-activity; sid:100002163; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.45",nocase; classtype:trojan-activity; sid:100002164; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.8",nocase; classtype:trojan-activity; sid:100002165; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.175.99.91",nocase; classtype:trojan-activity; sid:100002166; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.19.183.14",nocase; classtype:trojan-activity; sid:100002167; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.21.164.68",nocase; classtype:trojan-activity; sid:100002168; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.217.8.194",nocase; classtype:trojan-activity; sid:100002169; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.22.117.102",nocase; classtype:trojan-activity; sid:100002170; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.222.252.130",nocase; classtype:trojan-activity; sid:100002171; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.34.183.30",nocase; classtype:trojan-activity; sid:100002172; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.92.246.246",nocase; classtype:trojan-activity; sid:100002173; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"178.95.115.33",nocase; classtype:trojan-activity; sid:100002174; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.159.58.134",nocase; classtype:trojan-activity; sid:100002175; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.4.187.39",nocase; classtype:trojan-activity; sid:100002176; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.48.156.252",nocase; classtype:trojan-activity; sid:100002177; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.60.84.7",nocase; classtype:trojan-activity; sid:100002178; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"179.99.210.161",nocase; classtype:trojan-activity; sid:100002179; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.109.36.244",nocase; classtype:trojan-activity; sid:100002180; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.111.101.141",nocase; classtype:trojan-activity; sid:100002181; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.114.111.153",nocase; classtype:trojan-activity; sid:100002182; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.116.203.220",nocase; classtype:trojan-activity; sid:100002183; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.120.149.106",nocase; classtype:trojan-activity; sid:100002184; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.122.13.227",nocase; classtype:trojan-activity; sid:100002185; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.125.44.194",nocase; classtype:trojan-activity; sid:100002186; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.157.66.204",nocase; classtype:trojan-activity; sid:100002187; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.175.93.52",nocase; classtype:trojan-activity; sid:100002188; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.105.41",nocase; classtype:trojan-activity; sid:100002189; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.110.243",nocase; classtype:trojan-activity; sid:100002190; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.165.230",nocase; classtype:trojan-activity; sid:100002191; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.214.171",nocase; classtype:trojan-activity; sid:100002192; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.34.51",nocase; classtype:trojan-activity; sid:100002193; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.176.96.248",nocase; classtype:trojan-activity; sid:100002194; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.177.104.65",nocase; classtype:trojan-activity; sid:100002195; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.177.242.73",nocase; classtype:trojan-activity; sid:100002196; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.218.5.171",nocase; classtype:trojan-activity; sid:100002197; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.248.80.38",nocase; classtype:trojan-activity; sid:100002198; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.66.111.36",nocase; classtype:trojan-activity; sid:100002199; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.66.53.93",nocase; classtype:trojan-activity; sid:100002200; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"180.94.170.166",nocase; classtype:trojan-activity; sid:100002201; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.112.138.154",nocase; classtype:trojan-activity; sid:100002202; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.112.218.238",nocase; classtype:trojan-activity; sid:100002203; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.112.218.6",nocase; classtype:trojan-activity; sid:100002204; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.143.60.163",nocase; classtype:trojan-activity; sid:100002205; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.193.107.10",nocase; classtype:trojan-activity; sid:100002206; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.199.170.210",nocase; classtype:trojan-activity; sid:100002207; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.199.170.222",nocase; classtype:trojan-activity; sid:100002208; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.199.170.230",nocase; classtype:trojan-activity; sid:100002209; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.199.170.240",nocase; classtype:trojan-activity; sid:100002210; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.210.45.42",nocase; classtype:trojan-activity; sid:100002211; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.215.47.82",nocase; classtype:trojan-activity; sid:100002212; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.224.242.131",nocase; classtype:trojan-activity; sid:100002213; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.49.236.4",nocase; classtype:trojan-activity; sid:100002214; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"181.49.59.162",nocase; classtype:trojan-activity; sid:100002215; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.112.0.33",nocase; classtype:trojan-activity; sid:100002216; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.112.15.49",nocase; classtype:trojan-activity; sid:100002217; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.112.39.201",nocase; classtype:trojan-activity; sid:100002218; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.112.52.131",nocase; classtype:trojan-activity; sid:100002219; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.113.0.79",nocase; classtype:trojan-activity; sid:100002220; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.113.222.154",nocase; classtype:trojan-activity; sid:100002221; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.113.233.129",nocase; classtype:trojan-activity; sid:100002222; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.113.24.21",nocase; classtype:trojan-activity; sid:100002223; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.106.207",nocase; classtype:trojan-activity; sid:100002224; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.202.186",nocase; classtype:trojan-activity; sid:100002225; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.114.64.27",nocase; classtype:trojan-activity; sid:100002226; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.101.82",nocase; classtype:trojan-activity; sid:100002227; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.103.81",nocase; classtype:trojan-activity; sid:100002228; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.108.180",nocase; classtype:trojan-activity; sid:100002229; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.108.244",nocase; classtype:trojan-activity; sid:100002230; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.110.31",nocase; classtype:trojan-activity; sid:100002231; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.119.129",nocase; classtype:trojan-activity; sid:100002232; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.60.73",nocase; classtype:trojan-activity; sid:100002233; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.61.252",nocase; classtype:trojan-activity; sid:100002234; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.65.157",nocase; classtype:trojan-activity; sid:100002235; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.65.245",nocase; classtype:trojan-activity; sid:100002236; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.68.40",nocase; classtype:trojan-activity; sid:100002237; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.69.37",nocase; classtype:trojan-activity; sid:100002238; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.94.196",nocase; classtype:trojan-activity; sid:100002239; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.99.150",nocase; classtype:trojan-activity; sid:100002240; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.116.99.17",nocase; classtype:trojan-activity; sid:100002241; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.155.204",nocase; classtype:trojan-activity; sid:100002242; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.25.120",nocase; classtype:trojan-activity; sid:100002243; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.26.235",nocase; classtype:trojan-activity; sid:100002244; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.29.220",nocase; classtype:trojan-activity; sid:100002245; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.29.74",nocase; classtype:trojan-activity; sid:100002246; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.117.43.27",nocase; classtype:trojan-activity; sid:100002247; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.118.140.117",nocase; classtype:trojan-activity; sid:100002248; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.100.228",nocase; classtype:trojan-activity; sid:100002249; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.13.141",nocase; classtype:trojan-activity; sid:100002250; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.14.252",nocase; classtype:trojan-activity; sid:100002251; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.166.208",nocase; classtype:trojan-activity; sid:100002252; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.196.182",nocase; classtype:trojan-activity; sid:100002253; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.211.69",nocase; classtype:trojan-activity; sid:100002254; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.220.48",nocase; classtype:trojan-activity; sid:100002255; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.236.21",nocase; classtype:trojan-activity; sid:100002256; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.49.17",nocase; classtype:trojan-activity; sid:100002257; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.50.155",nocase; classtype:trojan-activity; sid:100002258; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.7.54",nocase; classtype:trojan-activity; sid:100002259; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.119.81.33",nocase; classtype:trojan-activity; sid:100002260; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.10.21",nocase; classtype:trojan-activity; sid:100002261; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.16.22",nocase; classtype:trojan-activity; sid:100002262; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.16.46",nocase; classtype:trojan-activity; sid:100002263; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.37.251",nocase; classtype:trojan-activity; sid:100002264; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.43.0",nocase; classtype:trojan-activity; sid:100002265; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.120.86.248",nocase; classtype:trojan-activity; sid:100002266; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.101.100",nocase; classtype:trojan-activity; sid:100002267; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.109.190",nocase; classtype:trojan-activity; sid:100002268; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.12.128",nocase; classtype:trojan-activity; sid:100002269; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.125.170",nocase; classtype:trojan-activity; sid:100002270; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.129.232",nocase; classtype:trojan-activity; sid:100002271; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.133.200",nocase; classtype:trojan-activity; sid:100002272; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.133.46",nocase; classtype:trojan-activity; sid:100002273; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.134.73",nocase; classtype:trojan-activity; sid:100002274; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.148.236",nocase; classtype:trojan-activity; sid:100002275; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.157.221",nocase; classtype:trojan-activity; sid:100002276; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.165.217",nocase; classtype:trojan-activity; sid:100002277; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.205.118",nocase; classtype:trojan-activity; sid:100002278; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.206.132",nocase; classtype:trojan-activity; sid:100002279; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.219.239",nocase; classtype:trojan-activity; sid:100002280; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.233.191",nocase; classtype:trojan-activity; sid:100002281; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.249.26",nocase; classtype:trojan-activity; sid:100002282; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.50.111",nocase; classtype:trojan-activity; sid:100002283; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.78.29",nocase; classtype:trojan-activity; sid:100002284; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.81.241",nocase; classtype:trojan-activity; sid:100002285; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.92.113",nocase; classtype:trojan-activity; sid:100002286; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.93.174",nocase; classtype:trojan-activity; sid:100002287; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.121.98.21",nocase; classtype:trojan-activity; sid:100002288; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.122.170.19",nocase; classtype:trojan-activity; sid:100002289; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.122.202.37",nocase; classtype:trojan-activity; sid:100002290; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.122.220.203",nocase; classtype:trojan-activity; sid:100002291; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.122.229.102",nocase; classtype:trojan-activity; sid:100002292; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.122.245.2",nocase; classtype:trojan-activity; sid:100002293; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.122.246.187",nocase; classtype:trojan-activity; sid:100002294; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.122.249.24",nocase; classtype:trojan-activity; sid:100002295; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.122.251.141",nocase; classtype:trojan-activity; sid:100002296; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.124.134.80",nocase; classtype:trojan-activity; sid:100002297; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.124.15.108",nocase; classtype:trojan-activity; sid:100002298; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.124.166.57",nocase; classtype:trojan-activity; sid:100002299; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.124.188.23",nocase; classtype:trojan-activity; sid:100002300; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.124.95.139",nocase; classtype:trojan-activity; sid:100002301; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.113.127",nocase; classtype:trojan-activity; sid:100002302; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.117.41",nocase; classtype:trojan-activity; sid:100002303; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.124.47",nocase; classtype:trojan-activity; sid:100002304; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.126.203",nocase; classtype:trojan-activity; sid:100002305; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.127.40",nocase; classtype:trojan-activity; sid:100002306; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.139.193",nocase; classtype:trojan-activity; sid:100002307; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.139.66",nocase; classtype:trojan-activity; sid:100002308; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.140.30",nocase; classtype:trojan-activity; sid:100002309; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.178.187",nocase; classtype:trojan-activity; sid:100002310; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.181.121",nocase; classtype:trojan-activity; sid:100002311; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.241.7",nocase; classtype:trojan-activity; sid:100002312; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.52.233",nocase; classtype:trojan-activity; sid:100002313; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.82.29",nocase; classtype:trojan-activity; sid:100002314; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.83.79",nocase; classtype:trojan-activity; sid:100002315; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.87.207",nocase; classtype:trojan-activity; sid:100002316; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.126.95.209",nocase; classtype:trojan-activity; sid:100002317; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.155.157",nocase; classtype:trojan-activity; sid:100002318; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.166.232",nocase; classtype:trojan-activity; sid:100002319; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.210.107",nocase; classtype:trojan-activity; sid:100002320; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.6.12",nocase; classtype:trojan-activity; sid:100002321; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.70.195",nocase; classtype:trojan-activity; sid:100002322; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.78.61",nocase; classtype:trojan-activity; sid:100002323; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.91.161",nocase; classtype:trojan-activity; sid:100002324; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.127.96.120",nocase; classtype:trojan-activity; sid:100002325; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.172.36.164",nocase; classtype:trojan-activity; sid:100002326; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.233.0.252",nocase; classtype:trojan-activity; sid:100002327; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.235.252.31",nocase; classtype:trojan-activity; sid:100002328; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.53.197.62",nocase; classtype:trojan-activity; sid:100002329; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.58.160.0",nocase; classtype:trojan-activity; sid:100002330; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.59.227.125",nocase; classtype:trojan-activity; sid:100002331; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"182.88.235.221",nocase; classtype:trojan-activity; sid:100002332; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.105.104.83",nocase; classtype:trojan-activity; sid:100002333; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.105.225.154",nocase; classtype:trojan-activity; sid:100002334; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.109.169.45",nocase; classtype:trojan-activity; sid:100002335; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.11.238.228",nocase; classtype:trojan-activity; sid:100002336; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.136.252.233",nocase; classtype:trojan-activity; sid:100002337; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.150.138.131",nocase; classtype:trojan-activity; sid:100002338; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.16.208.172",nocase; classtype:trojan-activity; sid:100002339; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.187.163.176",nocase; classtype:trojan-activity; sid:100002340; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.188.151.225",nocase; classtype:trojan-activity; sid:100002341; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.188.180.116",nocase; classtype:trojan-activity; sid:100002342; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.188.180.68",nocase; classtype:trojan-activity; sid:100002343; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.188.188.186",nocase; classtype:trojan-activity; sid:100002344; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.191.162.120",nocase; classtype:trojan-activity; sid:100002345; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.83.105.21",nocase; classtype:trojan-activity; sid:100002346; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.83.14.35",nocase; classtype:trojan-activity; sid:100002347; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.83.15.116",nocase; classtype:trojan-activity; sid:100002348; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.83.23.138",nocase; classtype:trojan-activity; sid:100002349; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.83.99.36",nocase; classtype:trojan-activity; sid:100002350; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.92.195.140",nocase; classtype:trojan-activity; sid:100002351; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.95.147.102",nocase; classtype:trojan-activity; sid:100002352; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"183.97.22.14",nocase; classtype:trojan-activity; sid:100002353; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"184.164.185.41",nocase; classtype:trojan-activity; sid:100002354; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"184.175.115.10",nocase; classtype:trojan-activity; sid:100002355; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"184.74.149.230",nocase; classtype:trojan-activity; sid:100002356; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.106.209.68",nocase; classtype:trojan-activity; sid:100002357; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.107.3.8",nocase; classtype:trojan-activity; sid:100002358; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.172.110.235",nocase; classtype:trojan-activity; sid:100002359; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.181.10.234",nocase; classtype:trojan-activity; sid:100002360; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.200.241.196",nocase; classtype:trojan-activity; sid:100002361; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.112",nocase; classtype:trojan-activity; sid:100002362; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.54",nocase; classtype:trojan-activity; sid:100002363; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.77",nocase; classtype:trojan-activity; sid:100002364; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.215.113.93",nocase; classtype:trojan-activity; sid:100002365; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.219.133.122",nocase; classtype:trojan-activity; sid:100002366; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.221.3.244",nocase; classtype:trojan-activity; sid:100002367; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.228.141.74",nocase; classtype:trojan-activity; sid:100002368; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.239.243.77",nocase; classtype:trojan-activity; sid:100002369; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.26.113.95",nocase; classtype:trojan-activity; sid:100002370; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.43.19.151",nocase; classtype:trojan-activity; sid:100002371; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.55.1.182",nocase; classtype:trojan-activity; sid:100002372; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.68.230.207",nocase; classtype:trojan-activity; sid:100002373; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.81.157.186",nocase; classtype:trojan-activity; sid:100002374; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.217.185",nocase; classtype:trojan-activity; sid:100002375; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.160",nocase; classtype:trojan-activity; sid:100002376; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.161",nocase; classtype:trojan-activity; sid:100002377; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.82.219.219",nocase; classtype:trojan-activity; sid:100002378; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"185.90.166.56",nocase; classtype:trojan-activity; sid:100002379; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.151.144.85",nocase; classtype:trojan-activity; sid:100002380; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.219.164",nocase; classtype:trojan-activity; sid:100002381; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.243.112",nocase; classtype:trojan-activity; sid:100002382; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.243.77",nocase; classtype:trojan-activity; sid:100002383; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.243.91",nocase; classtype:trojan-activity; sid:100002384; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.179.253.150",nocase; classtype:trojan-activity; sid:100002385; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.225.120.173",nocase; classtype:trojan-activity; sid:100002386; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.227.148.107",nocase; classtype:trojan-activity; sid:100002387; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.232.44.86",nocase; classtype:trojan-activity; sid:100002388; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.28.60.184",nocase; classtype:trojan-activity; sid:100002389; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.33.112.28",nocase; classtype:trojan-activity; sid:100002390; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"186.73.188.132",nocase; classtype:trojan-activity; sid:100002391; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.12.10.98",nocase; classtype:trojan-activity; sid:100002392; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.188.124.229",nocase; classtype:trojan-activity; sid:100002393; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"187.212.200.162",nocase; classtype:trojan-activity; sid:100002394; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.10.21.14",nocase; classtype:trojan-activity; sid:100002395; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.10.231.246",nocase; classtype:trojan-activity; sid:100002396; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.113.102.18",nocase; classtype:trojan-activity; sid:100002397; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.113.81.17",nocase; classtype:trojan-activity; sid:100002398; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.127.224.61",nocase; classtype:trojan-activity; sid:100002399; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.127.227.173",nocase; classtype:trojan-activity; sid:100002400; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.127.227.99",nocase; classtype:trojan-activity; sid:100002401; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.127.231.226",nocase; classtype:trojan-activity; sid:100002402; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.127.231.55",nocase; classtype:trojan-activity; sid:100002403; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.127.235.232",nocase; classtype:trojan-activity; sid:100002404; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.127.235.244",nocase; classtype:trojan-activity; sid:100002405; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.127.235.71",nocase; classtype:trojan-activity; sid:100002406; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.127.237.152",nocase; classtype:trojan-activity; sid:100002407; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.127.254.114",nocase; classtype:trojan-activity; sid:100002408; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.13.179.87",nocase; classtype:trojan-activity; sid:100002409; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.138.200.32",nocase; classtype:trojan-activity; sid:100002410; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.152.41.141",nocase; classtype:trojan-activity; sid:100002411; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.169.178.50",nocase; classtype:trojan-activity; sid:100002412; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.169.30.30",nocase; classtype:trojan-activity; sid:100002413; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.169.36.163",nocase; classtype:trojan-activity; sid:100002414; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.242.167.159",nocase; classtype:trojan-activity; sid:100002415; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.242.242.144",nocase; classtype:trojan-activity; sid:100002416; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.83.202.25",nocase; classtype:trojan-activity; sid:100002417; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"188.93.233.223",nocase; classtype:trojan-activity; sid:100002418; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"189.222.157.241",nocase; classtype:trojan-activity; sid:100002419; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"19.dbstrony.pl",nocase; classtype:trojan-activity; sid:100002420; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.0.42.106",nocase; classtype:trojan-activity; sid:100002421; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.110.161.252",nocase; classtype:trojan-activity; sid:100002422; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.111.151.164",nocase; classtype:trojan-activity; sid:100002423; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.119.207.58",nocase; classtype:trojan-activity; sid:100002424; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.12.99.194",nocase; classtype:trojan-activity; sid:100002425; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.121.194.18",nocase; classtype:trojan-activity; sid:100002426; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.160",nocase; classtype:trojan-activity; sid:100002427; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.3",nocase; classtype:trojan-activity; sid:100002428; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.37",nocase; classtype:trojan-activity; sid:100002429; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.41",nocase; classtype:trojan-activity; sid:100002430; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.122.112.42",nocase; classtype:trojan-activity; sid:100002431; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.130.15.212",nocase; classtype:trojan-activity; sid:100002432; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.130.20.14",nocase; classtype:trojan-activity; sid:100002433; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.141.117.41",nocase; classtype:trojan-activity; sid:100002434; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.159.240.9",nocase; classtype:trojan-activity; sid:100002435; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.187.55.150",nocase; classtype:trojan-activity; sid:100002436; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.210.214.130",nocase; classtype:trojan-activity; sid:100002437; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.213.177.39",nocase; classtype:trojan-activity; sid:100002438; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.213.226.63",nocase; classtype:trojan-activity; sid:100002439; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.213.49.207",nocase; classtype:trojan-activity; sid:100002440; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.216.140.123",nocase; classtype:trojan-activity; sid:100002441; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.35.225.36",nocase; classtype:trojan-activity; sid:100002442; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.65.206.162",nocase; classtype:trojan-activity; sid:100002443; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.92.4.231",nocase; classtype:trojan-activity; sid:100002444; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.98.37.135",nocase; classtype:trojan-activity; sid:100002445; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.98.37.200",nocase; classtype:trojan-activity; sid:100002446; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"190.98.41.33",nocase; classtype:trojan-activity; sid:100002447; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"191.255.248.220",nocase; classtype:trojan-activity; sid:100002448; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.210.175.130",nocase; classtype:trojan-activity; sid:100002449; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.210.241.200",nocase; classtype:trojan-activity; sid:100002450; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.185.106",nocase; classtype:trojan-activity; sid:100002451; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.209.27",nocase; classtype:trojan-activity; sid:100002452; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.227.228.67",nocase; classtype:trojan-activity; sid:100002453; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.3.152.166",nocase; classtype:trojan-activity; sid:100002454; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.3.73.205",nocase; classtype:trojan-activity; sid:100002455; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"192.99.240.77",nocase; classtype:trojan-activity; sid:100002456; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"193.142.146.25",nocase; classtype:trojan-activity; sid:100002457; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"193.228.135.144",nocase; classtype:trojan-activity; sid:100002458; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"193.91.131.237",nocase; classtype:trojan-activity; sid:100002459; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.15.36.167",nocase; classtype:trojan-activity; sid:100002460; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.15.36.202",nocase; classtype:trojan-activity; sid:100002461; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.152.35.139",nocase; classtype:trojan-activity; sid:100002462; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.38.20.199",nocase; classtype:trojan-activity; sid:100002463; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"194.87.139.10",nocase; classtype:trojan-activity; sid:100002464; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.123.213.154",nocase; classtype:trojan-activity; sid:100002465; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.139.126.51",nocase; classtype:trojan-activity; sid:100002466; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.228.231.218",nocase; classtype:trojan-activity; sid:100002467; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.24.94.187",nocase; classtype:trojan-activity; sid:100002468; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"195.64.163.103",nocase; classtype:trojan-activity; sid:100002469; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.202.26.182",nocase; classtype:trojan-activity; sid:100002470; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.218.48.82",nocase; classtype:trojan-activity; sid:100002471; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.221.148.90",nocase; classtype:trojan-activity; sid:100002472; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"196.221.166.203",nocase; classtype:trojan-activity; sid:100002473; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"197.159.2.106",nocase; classtype:trojan-activity; sid:100002474; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"197.50.27.115",nocase; classtype:trojan-activity; sid:100002475; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.133.218",nocase; classtype:trojan-activity; sid:100002476; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.207.121",nocase; classtype:trojan-activity; sid:100002477; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.213.57",nocase; classtype:trojan-activity; sid:100002478; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.23.251.105",nocase; classtype:trojan-activity; sid:100002479; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.46.201.76",nocase; classtype:trojan-activity; sid:100002480; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"198.46.202.7",nocase; classtype:trojan-activity; sid:100002481; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"1am.co.nz",nocase; classtype:trojan-activity; sid:100002482; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.229.89.119",nocase; classtype:trojan-activity; sid:100002483; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.249.161.188",nocase; classtype:trojan-activity; sid:100002484; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.45.111.158",nocase; classtype:trojan-activity; sid:100002485; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.45.4.24",nocase; classtype:trojan-activity; sid:100002486; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.55.125.182",nocase; classtype:trojan-activity; sid:100002487; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.55.92.184",nocase; classtype:trojan-activity; sid:100002488; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.83.152.16",nocase; classtype:trojan-activity; sid:100002489; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"20.dbstrony.pl",nocase; classtype:trojan-activity; sid:100002490; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.105.167.98",nocase; classtype:trojan-activity; sid:100002491; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.111.189.70",nocase; classtype:trojan-activity; sid:100002492; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.194.4.24",nocase; classtype:trojan-activity; sid:100002493; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.2.161.171",nocase; classtype:trojan-activity; sid:100002494; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"200.30.132.50",nocase; classtype:trojan-activity; sid:100002495; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.142.147.89",nocase; classtype:trojan-activity; sid:100002496; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.184.163.170",nocase; classtype:trojan-activity; sid:100002497; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.184.248.190",nocase; classtype:trojan-activity; sid:100002498; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.187.102.73",nocase; classtype:trojan-activity; sid:100002499; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.200.254.86",nocase; classtype:trojan-activity; sid:100002500; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.203.221.20",nocase; classtype:trojan-activity; sid:100002501; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.208.139.84",nocase; classtype:trojan-activity; sid:100002502; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.215.84.97",nocase; classtype:trojan-activity; sid:100002503; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"201.218.97.142",nocase; classtype:trojan-activity; sid:100002504; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.107.233.41",nocase; classtype:trojan-activity; sid:100002505; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.111.131.91",nocase; classtype:trojan-activity; sid:100002506; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.164.150.115",nocase; classtype:trojan-activity; sid:100002507; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.166.217.54",nocase; classtype:trojan-activity; sid:100002508; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.169.234.22",nocase; classtype:trojan-activity; sid:100002509; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.169.234.47",nocase; classtype:trojan-activity; sid:100002510; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.169.234.52",nocase; classtype:trojan-activity; sid:100002511; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.169.234.56",nocase; classtype:trojan-activity; sid:100002512; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.169.234.9",nocase; classtype:trojan-activity; sid:100002513; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.29.95.12",nocase; classtype:trojan-activity; sid:100002514; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.4.124.58",nocase; classtype:trojan-activity; sid:100002515; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.51.176.114",nocase; classtype:trojan-activity; sid:100002516; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.51.191.174",nocase; classtype:trojan-activity; sid:100002517; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"202.74.236.9",nocase; classtype:trojan-activity; sid:100002518; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.109.201.243",nocase; classtype:trojan-activity; sid:100002519; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.170.115.82",nocase; classtype:trojan-activity; sid:100002520; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.189.156.107",nocase; classtype:trojan-activity; sid:100002521; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.202.248.237",nocase; classtype:trojan-activity; sid:100002522; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.204.232.18",nocase; classtype:trojan-activity; sid:100002523; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.229.21.56",nocase; classtype:trojan-activity; sid:100002524; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.236.190.28",nocase; classtype:trojan-activity; sid:100002525; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.238.86.202",nocase; classtype:trojan-activity; sid:100002526; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.70.166.107",nocase; classtype:trojan-activity; sid:100002527; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.77.80.159",nocase; classtype:trojan-activity; sid:100002528; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.80.119.166",nocase; classtype:trojan-activity; sid:100002529; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.80.171.138",nocase; classtype:trojan-activity; sid:100002530; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.82.36.34",nocase; classtype:trojan-activity; sid:100002531; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"203.93.6.28",nocase; classtype:trojan-activity; sid:100002532; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"204.195.116.171",nocase; classtype:trojan-activity; sid:100002533; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"205.185.123.217",nocase; classtype:trojan-activity; sid:100002534; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"206.248.137.132",nocase; classtype:trojan-activity; sid:100002535; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"206.47.41.166",nocase; classtype:trojan-activity; sid:100002536; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"207.200.247.187",nocase; classtype:trojan-activity; sid:100002537; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"207.44.28.234",nocase; classtype:trojan-activity; sid:100002538; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"207.5.32.6",nocase; classtype:trojan-activity; sid:100002539; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"208.163.58.18",nocase; classtype:trojan-activity; sid:100002540; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.141.39.50",nocase; classtype:trojan-activity; sid:100002541; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.141.40.190",nocase; classtype:trojan-activity; sid:100002542; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"209.145.60.38",nocase; classtype:trojan-activity; sid:100002543; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.102.196.200",nocase; classtype:trojan-activity; sid:100002544; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.124.149.19",nocase; classtype:trojan-activity; sid:100002545; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.216.152.122",nocase; classtype:trojan-activity; sid:100002546; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.216.153.142",nocase; classtype:trojan-activity; sid:100002547; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.57.237.70",nocase; classtype:trojan-activity; sid:100002548; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.57.245.109",nocase; classtype:trojan-activity; sid:100002549; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.68.242.114",nocase; classtype:trojan-activity; sid:100002550; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"210.96.116.236",nocase; classtype:trojan-activity; sid:100002551; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.172.11.169",nocase; classtype:trojan-activity; sid:100002552; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.187.132.204",nocase; classtype:trojan-activity; sid:100002553; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.187.75.220",nocase; classtype:trojan-activity; sid:100002554; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.204.215.157",nocase; classtype:trojan-activity; sid:100002555; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.210.66.179",nocase; classtype:trojan-activity; sid:100002556; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.210.93.93",nocase; classtype:trojan-activity; sid:100002557; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.216.66.105",nocase; classtype:trojan-activity; sid:100002558; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.237.114.96",nocase; classtype:trojan-activity; sid:100002559; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.237.120.13",nocase; classtype:trojan-activity; sid:100002560; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.238.83.238",nocase; classtype:trojan-activity; sid:100002561; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.247.113.49",nocase; classtype:trojan-activity; sid:100002562; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.247.5.96",nocase; classtype:trojan-activity; sid:100002563; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.36.174.137",nocase; classtype:trojan-activity; sid:100002564; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.41.197.30",nocase; classtype:trojan-activity; sid:100002565; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.47.102.51",nocase; classtype:trojan-activity; sid:100002566; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"211.51.174.149",nocase; classtype:trojan-activity; sid:100002567; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.122.86.105",nocase; classtype:trojan-activity; sid:100002568; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.143.227.22",nocase; classtype:trojan-activity; sid:100002569; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.156.215.178",nocase; classtype:trojan-activity; sid:100002570; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.46.197.114",nocase; classtype:trojan-activity; sid:100002571; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"212.56.197.230",nocase; classtype:trojan-activity; sid:100002572; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.119.74.202",nocase; classtype:trojan-activity; sid:100002573; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.123.206.197",nocase; classtype:trojan-activity; sid:100002574; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.135.178.253",nocase; classtype:trojan-activity; sid:100002575; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.14.173.117",nocase; classtype:trojan-activity; sid:100002576; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.149.182.113",nocase; classtype:trojan-activity; sid:100002577; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.149.190.193",nocase; classtype:trojan-activity; sid:100002578; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.104.10",nocase; classtype:trojan-activity; sid:100002579; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.104.12",nocase; classtype:trojan-activity; sid:100002580; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.104.20",nocase; classtype:trojan-activity; sid:100002581; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.104.99",nocase; classtype:trojan-activity; sid:100002582; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.100",nocase; classtype:trojan-activity; sid:100002583; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.199",nocase; classtype:trojan-activity; sid:100002584; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.225",nocase; classtype:trojan-activity; sid:100002585; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.51",nocase; classtype:trojan-activity; sid:100002586; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.113.79",nocase; classtype:trojan-activity; sid:100002587; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.114.80",nocase; classtype:trojan-activity; sid:100002588; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.11",nocase; classtype:trojan-activity; sid:100002589; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.15",nocase; classtype:trojan-activity; sid:100002590; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.26",nocase; classtype:trojan-activity; sid:100002591; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.33",nocase; classtype:trojan-activity; sid:100002592; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.115.71",nocase; classtype:trojan-activity; sid:100002593; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.116.132",nocase; classtype:trojan-activity; sid:100002594; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.116.164",nocase; classtype:trojan-activity; sid:100002595; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.116.203",nocase; classtype:trojan-activity; sid:100002596; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.116.249",nocase; classtype:trojan-activity; sid:100002597; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.116.33",nocase; classtype:trojan-activity; sid:100002598; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.116.85",nocase; classtype:trojan-activity; sid:100002599; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.117.97",nocase; classtype:trojan-activity; sid:100002600; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.118.10",nocase; classtype:trojan-activity; sid:100002601; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.118.144",nocase; classtype:trojan-activity; sid:100002602; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.118.238",nocase; classtype:trojan-activity; sid:100002603; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.119.24",nocase; classtype:trojan-activity; sid:100002604; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.131",nocase; classtype:trojan-activity; sid:100002605; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.243",nocase; classtype:trojan-activity; sid:100002606; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.60",nocase; classtype:trojan-activity; sid:100002607; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.7",nocase; classtype:trojan-activity; sid:100002608; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.126.71",nocase; classtype:trojan-activity; sid:100002609; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.127.217",nocase; classtype:trojan-activity; sid:100002610; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.163.127.46",nocase; classtype:trojan-activity; sid:100002611; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.189.178.163",nocase; classtype:trojan-activity; sid:100002612; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.240.218.15",nocase; classtype:trojan-activity; sid:100002613; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.249.156.189",nocase; classtype:trojan-activity; sid:100002614; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.27.8.6",nocase; classtype:trojan-activity; sid:100002615; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.80.44.17",nocase; classtype:trojan-activity; sid:100002616; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.92.254.52",nocase; classtype:trojan-activity; sid:100002617; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.92.255.36",nocase; classtype:trojan-activity; sid:100002618; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"213.92.255.84",nocase; classtype:trojan-activity; sid:100002619; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.12.93.132",nocase; classtype:trojan-activity; sid:100002620; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.127.185.150",nocase; classtype:trojan-activity; sid:100002621; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.170.240.98",nocase; classtype:trojan-activity; sid:100002622; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.183.54.169",nocase; classtype:trojan-activity; sid:100002623; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.24.72.12",nocase; classtype:trojan-activity; sid:100002624; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"216.36.12.98",nocase; classtype:trojan-activity; sid:100002625; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"217.11.75.162",nocase; classtype:trojan-activity; sid:100002626; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"217.127.133.214",nocase; classtype:trojan-activity; sid:100002627; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.103.180.199",nocase; classtype:trojan-activity; sid:100002628; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.215.243.65",nocase; classtype:trojan-activity; sid:100002629; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.238.246.3",nocase; classtype:trojan-activity; sid:100002630; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.28.160.174",nocase; classtype:trojan-activity; sid:100002631; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.207.119",nocase; classtype:trojan-activity; sid:100002632; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.227.133",nocase; classtype:trojan-activity; sid:100002633; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.68.35",nocase; classtype:trojan-activity; sid:100002634; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.35.81.81",nocase; classtype:trojan-activity; sid:100002635; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.48.135.50",nocase; classtype:trojan-activity; sid:100002636; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.56.93.129",nocase; classtype:trojan-activity; sid:100002637; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.57.53.55",nocase; classtype:trojan-activity; sid:100002638; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.59.116.203",nocase; classtype:trojan-activity; sid:100002639; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.72.198.15",nocase; classtype:trojan-activity; sid:100002640; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"218.79.103.159",nocase; classtype:trojan-activity; sid:100002641; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.104.209",nocase; classtype:trojan-activity; sid:100002642; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.119.145",nocase; classtype:trojan-activity; sid:100002643; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.141.222",nocase; classtype:trojan-activity; sid:100002644; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.154.182.197",nocase; classtype:trojan-activity; sid:100002645; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.102.14",nocase; classtype:trojan-activity; sid:100002646; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.12.221",nocase; classtype:trojan-activity; sid:100002647; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.14.17",nocase; classtype:trojan-activity; sid:100002648; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.170.22",nocase; classtype:trojan-activity; sid:100002649; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.208.188",nocase; classtype:trojan-activity; sid:100002650; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.24.246",nocase; classtype:trojan-activity; sid:100002651; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.241.135",nocase; classtype:trojan-activity; sid:100002652; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.26.37",nocase; classtype:trojan-activity; sid:100002653; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.31.15",nocase; classtype:trojan-activity; sid:100002654; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.31.67",nocase; classtype:trojan-activity; sid:100002655; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.37.97",nocase; classtype:trojan-activity; sid:100002656; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.155.9.202",nocase; classtype:trojan-activity; sid:100002657; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.156.103.248",nocase; classtype:trojan-activity; sid:100002658; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.156.21.73",nocase; classtype:trojan-activity; sid:100002659; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.156.23.29",nocase; classtype:trojan-activity; sid:100002660; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.156.60.224",nocase; classtype:trojan-activity; sid:100002661; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.156.9.32",nocase; classtype:trojan-activity; sid:100002662; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.146.200",nocase; classtype:trojan-activity; sid:100002663; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.150.91",nocase; classtype:trojan-activity; sid:100002664; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.162.205",nocase; classtype:trojan-activity; sid:100002665; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.17.8",nocase; classtype:trojan-activity; sid:100002666; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.178.201",nocase; classtype:trojan-activity; sid:100002667; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.183.29",nocase; classtype:trojan-activity; sid:100002668; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.202.66",nocase; classtype:trojan-activity; sid:100002669; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.220.170",nocase; classtype:trojan-activity; sid:100002670; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.221.133",nocase; classtype:trojan-activity; sid:100002671; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.223.245",nocase; classtype:trojan-activity; sid:100002672; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.244.33",nocase; classtype:trojan-activity; sid:100002673; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.32.244",nocase; classtype:trojan-activity; sid:100002674; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.50.211",nocase; classtype:trojan-activity; sid:100002675; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.54.158",nocase; classtype:trojan-activity; sid:100002676; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.157.56.46",nocase; classtype:trojan-activity; sid:100002677; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.241.6.180",nocase; classtype:trojan-activity; sid:100002678; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.1.148",nocase; classtype:trojan-activity; sid:100002679; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.1.84",nocase; classtype:trojan-activity; sid:100002680; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.163.7",nocase; classtype:trojan-activity; sid:100002681; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.171.144",nocase; classtype:trojan-activity; sid:100002682; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.245.63",nocase; classtype:trojan-activity; sid:100002683; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.251.32",nocase; classtype:trojan-activity; sid:100002684; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.68.5.140",nocase; classtype:trojan-activity; sid:100002685; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.69.71.186",nocase; classtype:trojan-activity; sid:100002686; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.80.217.209",nocase; classtype:trojan-activity; sid:100002687; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"219.85.145.194",nocase; classtype:trojan-activity; sid:100002688; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"21robo.com",nocase; classtype:trojan-activity; sid:100002689; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.118.168.155",nocase; classtype:trojan-activity; sid:100002690; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.126.237.74",nocase; classtype:trojan-activity; sid:100002691; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.173.160.53",nocase; classtype:trojan-activity; sid:100002692; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.200.22.163",nocase; classtype:trojan-activity; sid:100002693; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.71.239.115",nocase; classtype:trojan-activity; sid:100002694; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"220.90.159.188",nocase; classtype:trojan-activity; sid:100002695; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.0.16.221",nocase; classtype:trojan-activity; sid:100002696; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.1.162.82",nocase; classtype:trojan-activity; sid:100002697; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.124.78.15",nocase; classtype:trojan-activity; sid:100002698; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.14.122.127",nocase; classtype:trojan-activity; sid:100002699; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.14.182.157",nocase; classtype:trojan-activity; sid:100002700; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.14.46.33",nocase; classtype:trojan-activity; sid:100002701; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.14.58.5",nocase; classtype:trojan-activity; sid:100002702; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.14.58.84",nocase; classtype:trojan-activity; sid:100002703; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.147.220",nocase; classtype:trojan-activity; sid:100002704; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.153.17",nocase; classtype:trojan-activity; sid:100002705; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.218.173",nocase; classtype:trojan-activity; sid:100002706; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.234.159",nocase; classtype:trojan-activity; sid:100002707; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.234.175",nocase; classtype:trojan-activity; sid:100002708; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.237.107",nocase; classtype:trojan-activity; sid:100002709; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.54.237",nocase; classtype:trojan-activity; sid:100002710; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.15.7.202",nocase; classtype:trojan-activity; sid:100002711; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.157.191.178",nocase; classtype:trojan-activity; sid:100002712; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.160.136.213",nocase; classtype:trojan-activity; sid:100002713; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.160.177.104",nocase; classtype:trojan-activity; sid:100002714; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.160.177.107",nocase; classtype:trojan-activity; sid:100002715; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.160.177.224",nocase; classtype:trojan-activity; sid:100002716; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.196.12.96",nocase; classtype:trojan-activity; sid:100002717; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.214.130.147",nocase; classtype:trojan-activity; sid:100002718; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.214.162.109",nocase; classtype:trojan-activity; sid:100002719; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.214.224.184",nocase; classtype:trojan-activity; sid:100002720; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.116.167",nocase; classtype:trojan-activity; sid:100002721; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.172.207",nocase; classtype:trojan-activity; sid:100002722; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.184.31",nocase; classtype:trojan-activity; sid:100002723; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.237.220",nocase; classtype:trojan-activity; sid:100002724; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.239.162",nocase; classtype:trojan-activity; sid:100002725; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.252.64",nocase; classtype:trojan-activity; sid:100002726; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.215.8.64",nocase; classtype:trojan-activity; sid:100002727; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.232.1.82",nocase; classtype:trojan-activity; sid:100002728; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.232.179.70",nocase; classtype:trojan-activity; sid:100002729; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.235.137.36",nocase; classtype:trojan-activity; sid:100002730; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.235.142.206",nocase; classtype:trojan-activity; sid:100002731; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.112.125",nocase; classtype:trojan-activity; sid:100002732; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.32.88",nocase; classtype:trojan-activity; sid:100002733; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.34.43",nocase; classtype:trojan-activity; sid:100002734; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.43.223",nocase; classtype:trojan-activity; sid:100002735; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.3.68.16",nocase; classtype:trojan-activity; sid:100002736; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"221.5.30.118",nocase; classtype:trojan-activity; sid:100002737; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.108.17.64",nocase; classtype:trojan-activity; sid:100002738; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.119.65.145",nocase; classtype:trojan-activity; sid:100002739; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.132.125.138",nocase; classtype:trojan-activity; sid:100002740; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.133.102.202",nocase; classtype:trojan-activity; sid:100002741; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.133.103.120",nocase; classtype:trojan-activity; sid:100002742; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.133.105.87",nocase; classtype:trojan-activity; sid:100002743; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.135.113.41",nocase; classtype:trojan-activity; sid:100002744; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.135.219.29",nocase; classtype:trojan-activity; sid:100002745; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.135.26.161",nocase; classtype:trojan-activity; sid:100002746; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.136.231.197",nocase; classtype:trojan-activity; sid:100002747; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.136.49.252",nocase; classtype:trojan-activity; sid:100002748; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.101.251",nocase; classtype:trojan-activity; sid:100002749; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.113.184",nocase; classtype:trojan-activity; sid:100002750; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.121.127",nocase; classtype:trojan-activity; sid:100002751; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.136.241",nocase; classtype:trojan-activity; sid:100002752; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.137.5",nocase; classtype:trojan-activity; sid:100002753; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.137.94",nocase; classtype:trojan-activity; sid:100002754; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.138.252",nocase; classtype:trojan-activity; sid:100002755; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.139.170",nocase; classtype:trojan-activity; sid:100002756; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.148.192",nocase; classtype:trojan-activity; sid:100002757; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.152.35",nocase; classtype:trojan-activity; sid:100002758; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.172.250",nocase; classtype:trojan-activity; sid:100002759; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.175.242",nocase; classtype:trojan-activity; sid:100002760; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.186.150",nocase; classtype:trojan-activity; sid:100002761; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.22.79",nocase; classtype:trojan-activity; sid:100002762; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.220.94",nocase; classtype:trojan-activity; sid:100002763; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.221.128",nocase; classtype:trojan-activity; sid:100002764; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.49.4",nocase; classtype:trojan-activity; sid:100002765; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.5.150",nocase; classtype:trojan-activity; sid:100002766; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.72.146",nocase; classtype:trojan-activity; sid:100002767; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.81.67",nocase; classtype:trojan-activity; sid:100002768; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.137.83.53",nocase; classtype:trojan-activity; sid:100002769; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.137.188",nocase; classtype:trojan-activity; sid:100002770; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.143.84",nocase; classtype:trojan-activity; sid:100002771; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.189.88",nocase; classtype:trojan-activity; sid:100002772; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.203.22",nocase; classtype:trojan-activity; sid:100002773; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.215.161",nocase; classtype:trojan-activity; sid:100002774; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.232.159",nocase; classtype:trojan-activity; sid:100002775; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.232.84",nocase; classtype:trojan-activity; sid:100002776; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.49.93",nocase; classtype:trojan-activity; sid:100002777; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.138.96.79",nocase; classtype:trojan-activity; sid:100002778; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.139.16.229",nocase; classtype:trojan-activity; sid:100002779; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.139.59.63",nocase; classtype:trojan-activity; sid:100002780; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.112.150",nocase; classtype:trojan-activity; sid:100002781; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.117.221",nocase; classtype:trojan-activity; sid:100002782; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.161.11",nocase; classtype:trojan-activity; sid:100002783; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.163.112",nocase; classtype:trojan-activity; sid:100002784; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.17.245",nocase; classtype:trojan-activity; sid:100002785; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.209.222",nocase; classtype:trojan-activity; sid:100002786; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.219.212",nocase; classtype:trojan-activity; sid:100002787; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.140.39.66",nocase; classtype:trojan-activity; sid:100002788; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.150.38",nocase; classtype:trojan-activity; sid:100002789; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.165.180",nocase; classtype:trojan-activity; sid:100002790; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.244.231",nocase; classtype:trojan-activity; sid:100002791; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.40.136",nocase; classtype:trojan-activity; sid:100002792; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.41.155",nocase; classtype:trojan-activity; sid:100002793; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.44.36",nocase; classtype:trojan-activity; sid:100002794; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.45.153",nocase; classtype:trojan-activity; sid:100002795; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.60.251",nocase; classtype:trojan-activity; sid:100002796; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.73.249",nocase; classtype:trojan-activity; sid:100002797; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.141.85.128",nocase; classtype:trojan-activity; sid:100002798; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.142.162.164",nocase; classtype:trojan-activity; sid:100002799; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.142.192.66",nocase; classtype:trojan-activity; sid:100002800; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.142.209.7",nocase; classtype:trojan-activity; sid:100002801; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.142.65.30",nocase; classtype:trojan-activity; sid:100002802; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.179.215.189",nocase; classtype:trojan-activity; sid:100002803; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.185.116.233",nocase; classtype:trojan-activity; sid:100002804; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.187.9.178",nocase; classtype:trojan-activity; sid:100002805; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.211.72.66",nocase; classtype:trojan-activity; sid:100002806; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.214.54.208",nocase; classtype:trojan-activity; sid:100002807; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.218.220.219",nocase; classtype:trojan-activity; sid:100002808; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.238.230.7",nocase; classtype:trojan-activity; sid:100002809; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.239.83.232",nocase; classtype:trojan-activity; sid:100002810; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.248.64.253",nocase; classtype:trojan-activity; sid:100002811; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.64.16.239",nocase; classtype:trojan-activity; sid:100002812; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.83.150.240",nocase; classtype:trojan-activity; sid:100002813; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.92.9.126",nocase; classtype:trojan-activity; sid:100002814; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"222.99.171.192",nocase; classtype:trojan-activity; sid:100002815; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.166.117.210",nocase; classtype:trojan-activity; sid:100002816; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.167.118.17",nocase; classtype:trojan-activity; sid:100002817; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.212.225.68",nocase; classtype:trojan-activity; sid:100002818; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.212.234.84",nocase; classtype:trojan-activity; sid:100002819; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.212.252.180",nocase; classtype:trojan-activity; sid:100002820; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.212.5.29",nocase; classtype:trojan-activity; sid:100002821; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"223.212.73.175",nocase; classtype:trojan-activity; sid:100002822; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.125.186.135",nocase; classtype:trojan-activity; sid:100002823; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.126.120.25",nocase; classtype:trojan-activity; sid:100002824; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.228.143.58",nocase; classtype:trojan-activity; sid:100002825; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.24.213.121",nocase; classtype:trojan-activity; sid:100002826; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.243.149.13",nocase; classtype:trojan-activity; sid:100002827; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.243.21.167",nocase; classtype:trojan-activity; sid:100002828; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"23.95.89.21",nocase; classtype:trojan-activity; sid:100002829; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.103.74.180",nocase; classtype:trojan-activity; sid:100002830; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.11.141.134",nocase; classtype:trojan-activity; sid:100002831; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.119.158.74",nocase; classtype:trojan-activity; sid:100002832; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.137.147.95",nocase; classtype:trojan-activity; sid:100002833; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.152.235.88",nocase; classtype:trojan-activity; sid:100002834; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.158.25.98",nocase; classtype:trojan-activity; sid:100002835; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.176.206.12",nocase; classtype:trojan-activity; sid:100002836; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.184.1.41",nocase; classtype:trojan-activity; sid:100002837; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.192.191.109",nocase; classtype:trojan-activity; sid:100002838; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.225.114.161",nocase; classtype:trojan-activity; sid:100002839; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.227.190.78",nocase; classtype:trojan-activity; sid:100002840; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.35.245.52",nocase; classtype:trojan-activity; sid:100002841; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.39.181.18",nocase; classtype:trojan-activity; sid:100002842; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.39.34.242",nocase; classtype:trojan-activity; sid:100002843; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.42.229.143",nocase; classtype:trojan-activity; sid:100002844; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.45.4.1",nocase; classtype:trojan-activity; sid:100002845; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.51.91.113",nocase; classtype:trojan-activity; sid:100002846; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.53.163.10",nocase; classtype:trojan-activity; sid:100002847; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.53.163.9",nocase; classtype:trojan-activity; sid:100002848; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"24.dbstrony.pl",nocase; classtype:trojan-activity; sid:100002849; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.1.245.16",nocase; classtype:trojan-activity; sid:100002850; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.1.245.7",nocase; classtype:trojan-activity; sid:100002851; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.105.106.201",nocase; classtype:trojan-activity; sid:100002852; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.105.152.107",nocase; classtype:trojan-activity; sid:100002853; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.116.84.57",nocase; classtype:trojan-activity; sid:100002854; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.12.234.4",nocase; classtype:trojan-activity; sid:100002855; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.12.245.238",nocase; classtype:trojan-activity; sid:100002856; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.13.83.77",nocase; classtype:trojan-activity; sid:100002857; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.14.211.219",nocase; classtype:trojan-activity; sid:100002858; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.141.218.17",nocase; classtype:trojan-activity; sid:100002859; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.147.29.52",nocase; classtype:trojan-activity; sid:100002860; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.147.40.128",nocase; classtype:trojan-activity; sid:100002861; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.153.132.82",nocase; classtype:trojan-activity; sid:100002862; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.153.207.1",nocase; classtype:trojan-activity; sid:100002863; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.184.244.14",nocase; classtype:trojan-activity; sid:100002864; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.184.54.199",nocase; classtype:trojan-activity; sid:100002865; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.187.248.22",nocase; classtype:trojan-activity; sid:100002866; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.193.196.190",nocase; classtype:trojan-activity; sid:100002867; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.193.217.210",nocase; classtype:trojan-activity; sid:100002868; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.194.149.142",nocase; classtype:trojan-activity; sid:100002869; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.194.158.229",nocase; classtype:trojan-activity; sid:100002870; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.194.192.66",nocase; classtype:trojan-activity; sid:100002871; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.194.210.20",nocase; classtype:trojan-activity; sid:100002872; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.194.224.96",nocase; classtype:trojan-activity; sid:100002873; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.197.17.88",nocase; classtype:trojan-activity; sid:100002874; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.197.22.217",nocase; classtype:trojan-activity; sid:100002875; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.197.23.215",nocase; classtype:trojan-activity; sid:100002876; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.197.24.175",nocase; classtype:trojan-activity; sid:100002877; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.199.232.65",nocase; classtype:trojan-activity; sid:100002878; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.199.3.194",nocase; classtype:trojan-activity; sid:100002879; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.199.34.48",nocase; classtype:trojan-activity; sid:100002880; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.200.140.229",nocase; classtype:trojan-activity; sid:100002881; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.200.23.62",nocase; classtype:trojan-activity; sid:100002882; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.200.32.146",nocase; classtype:trojan-activity; sid:100002883; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.202.182.201",nocase; classtype:trojan-activity; sid:100002884; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.202.21.57",nocase; classtype:trojan-activity; sid:100002885; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.202.66.46",nocase; classtype:trojan-activity; sid:100002886; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.102.12",nocase; classtype:trojan-activity; sid:100002887; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.126.194",nocase; classtype:trojan-activity; sid:100002888; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.154.105",nocase; classtype:trojan-activity; sid:100002889; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.165.138",nocase; classtype:trojan-activity; sid:100002890; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.185.42",nocase; classtype:trojan-activity; sid:100002891; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.185.48",nocase; classtype:trojan-activity; sid:100002892; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.213.79",nocase; classtype:trojan-activity; sid:100002893; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.234.76",nocase; classtype:trojan-activity; sid:100002894; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.246.96",nocase; classtype:trojan-activity; sid:100002895; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.255.42",nocase; classtype:trojan-activity; sid:100002896; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.28.115",nocase; classtype:trojan-activity; sid:100002897; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.4.188",nocase; classtype:trojan-activity; sid:100002898; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.54.217",nocase; classtype:trojan-activity; sid:100002899; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.87.75",nocase; classtype:trojan-activity; sid:100002900; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.203.94.134",nocase; classtype:trojan-activity; sid:100002901; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.204.253.74",nocase; classtype:trojan-activity; sid:100002902; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.205.178.110",nocase; classtype:trojan-activity; sid:100002903; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.136.101",nocase; classtype:trojan-activity; sid:100002904; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.14.137",nocase; classtype:trojan-activity; sid:100002905; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.148.106",nocase; classtype:trojan-activity; sid:100002906; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.154.122",nocase; classtype:trojan-activity; sid:100002907; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.185.118",nocase; classtype:trojan-activity; sid:100002908; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.26.218",nocase; classtype:trojan-activity; sid:100002909; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.81.66",nocase; classtype:trojan-activity; sid:100002910; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.83.48",nocase; classtype:trojan-activity; sid:100002911; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.206.97.81",nocase; classtype:trojan-activity; sid:100002912; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.207.155.31",nocase; classtype:trojan-activity; sid:100002913; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.207.194.254",nocase; classtype:trojan-activity; sid:100002914; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.207.199.162",nocase; classtype:trojan-activity; sid:100002915; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.152.10",nocase; classtype:trojan-activity; sid:100002916; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.160.177",nocase; classtype:trojan-activity; sid:100002917; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.164.18",nocase; classtype:trojan-activity; sid:100002918; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.166.13",nocase; classtype:trojan-activity; sid:100002919; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.201.212",nocase; classtype:trojan-activity; sid:100002920; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.247.130",nocase; classtype:trojan-activity; sid:100002921; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.25.59",nocase; classtype:trojan-activity; sid:100002922; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.34.2",nocase; classtype:trojan-activity; sid:100002923; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.208.92.64",nocase; classtype:trojan-activity; sid:100002924; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.209.160.222",nocase; classtype:trojan-activity; sid:100002925; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.209.231.15",nocase; classtype:trojan-activity; sid:100002926; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.209.60.21",nocase; classtype:trojan-activity; sid:100002927; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.107.125",nocase; classtype:trojan-activity; sid:100002928; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.127.11",nocase; classtype:trojan-activity; sid:100002929; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.146.61",nocase; classtype:trojan-activity; sid:100002930; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.172.245",nocase; classtype:trojan-activity; sid:100002931; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.234.28",nocase; classtype:trojan-activity; sid:100002932; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.236.134",nocase; classtype:trojan-activity; sid:100002933; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.210.63.243",nocase; classtype:trojan-activity; sid:100002934; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.211.251.162",nocase; classtype:trojan-activity; sid:100002935; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.104.201",nocase; classtype:trojan-activity; sid:100002936; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.109.105",nocase; classtype:trojan-activity; sid:100002937; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.109.58",nocase; classtype:trojan-activity; sid:100002938; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.145.221",nocase; classtype:trojan-activity; sid:100002939; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.167.175",nocase; classtype:trojan-activity; sid:100002940; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.175.208",nocase; classtype:trojan-activity; sid:100002941; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.220.5",nocase; classtype:trojan-activity; sid:100002942; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.255.202",nocase; classtype:trojan-activity; sid:100002943; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.255.6",nocase; classtype:trojan-activity; sid:100002944; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.213.84.74",nocase; classtype:trojan-activity; sid:100002945; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.214.37.129",nocase; classtype:trojan-activity; sid:100002946; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.139.242",nocase; classtype:trojan-activity; sid:100002947; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.190.172",nocase; classtype:trojan-activity; sid:100002948; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.212.209",nocase; classtype:trojan-activity; sid:100002949; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.253.149",nocase; classtype:trojan-activity; sid:100002950; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.34.242",nocase; classtype:trojan-activity; sid:100002951; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.38.166",nocase; classtype:trojan-activity; sid:100002952; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.71.243",nocase; classtype:trojan-activity; sid:100002953; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.215.98.242",nocase; classtype:trojan-activity; sid:100002954; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.131.66",nocase; classtype:trojan-activity; sid:100002955; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.144.66",nocase; classtype:trojan-activity; sid:100002956; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.193.217",nocase; classtype:trojan-activity; sid:100002957; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.197.193",nocase; classtype:trojan-activity; sid:100002958; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.225.28",nocase; classtype:trojan-activity; sid:100002959; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.234.98",nocase; classtype:trojan-activity; sid:100002960; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.46.85",nocase; classtype:trojan-activity; sid:100002961; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.58.120",nocase; classtype:trojan-activity; sid:100002962; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.216.95.56",nocase; classtype:trojan-activity; sid:100002963; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.217.120.226",nocase; classtype:trojan-activity; sid:100002964; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.217.133.53",nocase; classtype:trojan-activity; sid:100002965; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.217.155.141",nocase; classtype:trojan-activity; sid:100002966; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.217.191.58",nocase; classtype:trojan-activity; sid:100002967; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.217.31.245",nocase; classtype:trojan-activity; sid:100002968; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.217.76.48",nocase; classtype:trojan-activity; sid:100002969; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.218.180.172",nocase; classtype:trojan-activity; sid:100002970; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.218.219.228",nocase; classtype:trojan-activity; sid:100002971; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.218.248.121",nocase; classtype:trojan-activity; sid:100002972; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.132.71",nocase; classtype:trojan-activity; sid:100002973; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.151.83",nocase; classtype:trojan-activity; sid:100002974; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.160.112",nocase; classtype:trojan-activity; sid:100002975; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.172.175",nocase; classtype:trojan-activity; sid:100002976; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.173.180",nocase; classtype:trojan-activity; sid:100002977; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.176.72",nocase; classtype:trojan-activity; sid:100002978; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.184.94",nocase; classtype:trojan-activity; sid:100002979; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.192.223",nocase; classtype:trojan-activity; sid:100002980; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.219.83.244",nocase; classtype:trojan-activity; sid:100002981; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.220.40.189",nocase; classtype:trojan-activity; sid:100002982; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.220.85.168",nocase; classtype:trojan-activity; sid:100002983; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.221.239.223",nocase; classtype:trojan-activity; sid:100002984; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.222.241.223",nocase; classtype:trojan-activity; sid:100002985; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.222.249.105",nocase; classtype:trojan-activity; sid:100002986; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.222.249.210",nocase; classtype:trojan-activity; sid:100002987; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.222.42.189",nocase; classtype:trojan-activity; sid:100002988; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.222.50.170",nocase; classtype:trojan-activity; sid:100002989; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.223.242.164",nocase; classtype:trojan-activity; sid:100002990; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.223.44.106",nocase; classtype:trojan-activity; sid:100002991; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.24.28.134",nocase; classtype:trojan-activity; sid:100002992; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.129.198",nocase; classtype:trojan-activity; sid:100002993; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.154.13",nocase; classtype:trojan-activity; sid:100002994; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.16.145",nocase; classtype:trojan-activity; sid:100002995; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.2.30",nocase; classtype:trojan-activity; sid:100002996; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.212.124",nocase; classtype:trojan-activity; sid:100002997; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.35.58.5",nocase; classtype:trojan-activity; sid:100002998; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.41.153.66",nocase; classtype:trojan-activity; sid:100002999; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.41.154.31",nocase; classtype:trojan-activity; sid:100003000; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.43.82.210",nocase; classtype:trojan-activity; sid:100003001; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.46.45.248",nocase; classtype:trojan-activity; sid:100003002; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.46.47.74",nocase; classtype:trojan-activity; sid:100003003; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.5.16.243",nocase; classtype:trojan-activity; sid:100003004; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.5.26.105",nocase; classtype:trojan-activity; sid:100003005; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.5.26.4",nocase; classtype:trojan-activity; sid:100003006; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.5.27.1",nocase; classtype:trojan-activity; sid:100003007; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"27.5.35.127",nocase; classtype:trojan-activity; sid:100003008; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.0.98.131",nocase; classtype:trojan-activity; sid:100003009; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.11.51.57",nocase; classtype:trojan-activity; sid:100003010; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.13.23.180",nocase; classtype:trojan-activity; sid:100003011; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.154.234.3",nocase; classtype:trojan-activity; sid:100003012; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.163.191.11",nocase; classtype:trojan-activity; sid:100003013; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.124.130",nocase; classtype:trojan-activity; sid:100003014; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.179.83",nocase; classtype:trojan-activity; sid:100003015; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.184.59",nocase; classtype:trojan-activity; sid:100003016; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.191.243",nocase; classtype:trojan-activity; sid:100003017; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.194.67",nocase; classtype:trojan-activity; sid:100003018; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.216.132",nocase; classtype:trojan-activity; sid:100003019; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.219.28",nocase; classtype:trojan-activity; sid:100003020; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.24.115",nocase; classtype:trojan-activity; sid:100003021; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.30.65",nocase; classtype:trojan-activity; sid:100003022; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.60.234",nocase; classtype:trojan-activity; sid:100003023; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.63.203",nocase; classtype:trojan-activity; sid:100003024; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.65.233",nocase; classtype:trojan-activity; sid:100003025; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.168.94.16",nocase; classtype:trojan-activity; sid:100003026; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.179.201.26",nocase; classtype:trojan-activity; sid:100003027; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.195.84.250",nocase; classtype:trojan-activity; sid:100003028; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.204.174.180",nocase; classtype:trojan-activity; sid:100003029; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.210.20.138",nocase; classtype:trojan-activity; sid:100003030; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.210.20.177",nocase; classtype:trojan-activity; sid:100003031; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.210.20.227",nocase; classtype:trojan-activity; sid:100003032; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.28.7.159",nocase; classtype:trojan-activity; sid:100003033; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.30.119.23",nocase; classtype:trojan-activity; sid:100003034; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"31.62.255.3",nocase; classtype:trojan-activity; sid:100003035; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"32.208.157.193",nocase; classtype:trojan-activity; sid:100003036; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"32792.prolocksmithwinterpark.com",nocase; classtype:trojan-activity; sid:100003037; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"35.184.169.169",nocase; classtype:trojan-activity; sid:100003038; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.108.231.218",nocase; classtype:trojan-activity; sid:100003039; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.109.132.50",nocase; classtype:trojan-activity; sid:100003040; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.250.203.246",nocase; classtype:trojan-activity; sid:100003041; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.157.225",nocase; classtype:trojan-activity; sid:100003042; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.18.18",nocase; classtype:trojan-activity; sid:100003043; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.19.88",nocase; classtype:trojan-activity; sid:100003044; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.251.51.244",nocase; classtype:trojan-activity; sid:100003045; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.255.90.219",nocase; classtype:trojan-activity; sid:100003046; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.33.128.60",nocase; classtype:trojan-activity; sid:100003047; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.33.160.167",nocase; classtype:trojan-activity; sid:100003048; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.36.243.67",nocase; classtype:trojan-activity; sid:100003049; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.66.105.159",nocase; classtype:trojan-activity; sid:100003050; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.66.111.203",nocase; classtype:trojan-activity; sid:100003051; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.66.133.125",nocase; classtype:trojan-activity; sid:100003052; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.66.139.36",nocase; classtype:trojan-activity; sid:100003053; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.67.152.161",nocase; classtype:trojan-activity; sid:100003054; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.89.18.133",nocase; classtype:trojan-activity; sid:100003055; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"36.96.187.93",nocase; classtype:trojan-activity; sid:100003056; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"360.lcy2zzx.pw",nocase; classtype:trojan-activity; sid:100003057; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"360down7.miiyun.cn",nocase; classtype:trojan-activity; sid:100003058; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.222.98.51",nocase; classtype:trojan-activity; sid:100003059; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.233.60.68",nocase; classtype:trojan-activity; sid:100003060; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.34.179.221",nocase; classtype:trojan-activity; sid:100003061; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.34.180.172",nocase; classtype:trojan-activity; sid:100003062; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.44.238.35",nocase; classtype:trojan-activity; sid:100003063; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.49.229.154",nocase; classtype:trojan-activity; sid:100003064; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.49.230.152",nocase; classtype:trojan-activity; sid:100003065; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.52.117.132",nocase; classtype:trojan-activity; sid:100003066; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"37.54.14.36",nocase; classtype:trojan-activity; sid:100003067; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"38.77.14.237",nocase; classtype:trojan-activity; sid:100003068; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"38.81.149.108",nocase; classtype:trojan-activity; sid:100003069; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.113.245.254",nocase; classtype:trojan-activity; sid:100003070; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.113.98.136",nocase; classtype:trojan-activity; sid:100003071; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.114.137.102",nocase; classtype:trojan-activity; sid:100003072; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.117.31.162",nocase; classtype:trojan-activity; sid:100003073; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.162.104.119",nocase; classtype:trojan-activity; sid:100003074; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.64.28.214",nocase; classtype:trojan-activity; sid:100003075; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.65.171.29",nocase; classtype:trojan-activity; sid:100003076; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.65.196.34",nocase; classtype:trojan-activity; sid:100003077; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.65.59.160",nocase; classtype:trojan-activity; sid:100003078; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.66.129.163",nocase; classtype:trojan-activity; sid:100003079; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.66.85.187",nocase; classtype:trojan-activity; sid:100003080; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.104.83",nocase; classtype:trojan-activity; sid:100003081; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.125.186",nocase; classtype:trojan-activity; sid:100003082; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.146.60",nocase; classtype:trojan-activity; sid:100003083; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.148.163",nocase; classtype:trojan-activity; sid:100003084; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.67.92.131",nocase; classtype:trojan-activity; sid:100003085; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.68.124.76",nocase; classtype:trojan-activity; sid:100003086; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.68.249.255",nocase; classtype:trojan-activity; sid:100003087; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.72.130.114",nocase; classtype:trojan-activity; sid:100003088; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.72.167.202",nocase; classtype:trojan-activity; sid:100003089; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.72.67.64",nocase; classtype:trojan-activity; sid:100003090; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.10.198",nocase; classtype:trojan-activity; sid:100003091; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.163.231",nocase; classtype:trojan-activity; sid:100003092; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.203.225",nocase; classtype:trojan-activity; sid:100003093; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.73.44.17",nocase; classtype:trojan-activity; sid:100003094; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.74.104.228",nocase; classtype:trojan-activity; sid:100003095; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.74.21.201",nocase; classtype:trojan-activity; sid:100003096; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.74.28.89",nocase; classtype:trojan-activity; sid:100003097; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.74.31.192",nocase; classtype:trojan-activity; sid:100003098; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.74.68.182",nocase; classtype:trojan-activity; sid:100003099; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.76.194.65",nocase; classtype:trojan-activity; sid:100003100; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.76.79.43",nocase; classtype:trojan-activity; sid:100003101; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.76.97.16",nocase; classtype:trojan-activity; sid:100003102; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.113.201",nocase; classtype:trojan-activity; sid:100003103; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.114.45",nocase; classtype:trojan-activity; sid:100003104; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.136.47",nocase; classtype:trojan-activity; sid:100003105; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.14.27",nocase; classtype:trojan-activity; sid:100003106; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.150.203",nocase; classtype:trojan-activity; sid:100003107; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.197.81",nocase; classtype:trojan-activity; sid:100003108; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.209.209",nocase; classtype:trojan-activity; sid:100003109; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.94.189",nocase; classtype:trojan-activity; sid:100003110; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.77.95.50",nocase; classtype:trojan-activity; sid:100003111; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.107.66",nocase; classtype:trojan-activity; sid:100003112; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.166.31",nocase; classtype:trojan-activity; sid:100003113; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.218.46",nocase; classtype:trojan-activity; sid:100003114; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.62.43",nocase; classtype:trojan-activity; sid:100003115; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.90.92",nocase; classtype:trojan-activity; sid:100003116; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.91.244",nocase; classtype:trojan-activity; sid:100003117; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.79.93.171",nocase; classtype:trojan-activity; sid:100003118; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.127.214",nocase; classtype:trojan-activity; sid:100003119; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.191.137",nocase; classtype:trojan-activity; sid:100003120; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.205.255",nocase; classtype:trojan-activity; sid:100003121; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.24.54",nocase; classtype:trojan-activity; sid:100003122; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.34.26",nocase; classtype:trojan-activity; sid:100003123; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.80.36.151",nocase; classtype:trojan-activity; sid:100003124; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.124.33",nocase; classtype:trojan-activity; sid:100003125; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.130.19",nocase; classtype:trojan-activity; sid:100003126; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.251.0",nocase; classtype:trojan-activity; sid:100003127; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.27.15",nocase; classtype:trojan-activity; sid:100003128; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.81.29.231",nocase; classtype:trojan-activity; sid:100003129; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.82.86.105",nocase; classtype:trojan-activity; sid:100003130; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.83.94.11",nocase; classtype:trojan-activity; sid:100003131; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.84.157.52",nocase; classtype:trojan-activity; sid:100003132; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.84.34.217",nocase; classtype:trojan-activity; sid:100003133; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.84.95.200",nocase; classtype:trojan-activity; sid:100003134; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.85.54.191",nocase; classtype:trojan-activity; sid:100003135; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.85.54.4",nocase; classtype:trojan-activity; sid:100003136; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.129.233",nocase; classtype:trojan-activity; sid:100003137; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.13.0",nocase; classtype:trojan-activity; sid:100003138; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.151.49",nocase; classtype:trojan-activity; sid:100003139; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.170.209",nocase; classtype:trojan-activity; sid:100003140; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.184.164",nocase; classtype:trojan-activity; sid:100003141; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.211.20",nocase; classtype:trojan-activity; sid:100003142; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.234.187",nocase; classtype:trojan-activity; sid:100003143; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.248.91",nocase; classtype:trojan-activity; sid:100003144; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.60.98",nocase; classtype:trojan-activity; sid:100003145; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.66.24",nocase; classtype:trojan-activity; sid:100003146; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.76.9",nocase; classtype:trojan-activity; sid:100003147; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.86.78.228",nocase; classtype:trojan-activity; sid:100003148; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.87.63.58",nocase; classtype:trojan-activity; sid:100003149; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.87.90.210",nocase; classtype:trojan-activity; sid:100003150; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.87.93.109",nocase; classtype:trojan-activity; sid:100003151; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.141.172",nocase; classtype:trojan-activity; sid:100003152; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.155.96",nocase; classtype:trojan-activity; sid:100003153; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.233.131",nocase; classtype:trojan-activity; sid:100003154; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.39.222",nocase; classtype:trojan-activity; sid:100003155; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.41.73",nocase; classtype:trojan-activity; sid:100003156; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.67.238",nocase; classtype:trojan-activity; sid:100003157; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.88.72.9",nocase; classtype:trojan-activity; sid:100003158; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.146.198",nocase; classtype:trojan-activity; sid:100003159; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.146.36",nocase; classtype:trojan-activity; sid:100003160; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.157.140",nocase; classtype:trojan-activity; sid:100003161; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.89.63.23",nocase; classtype:trojan-activity; sid:100003162; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"39.90.86.212",nocase; classtype:trojan-activity; sid:100003163; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.139.209.46",nocase; classtype:trojan-activity; sid:100003164; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.165.130.43",nocase; classtype:trojan-activity; sid:100003165; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.190.63.174",nocase; classtype:trojan-activity; sid:100003166; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.193.192.100",nocase; classtype:trojan-activity; sid:100003167; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.219.185.171",nocase; classtype:trojan-activity; sid:100003168; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.230.31.58",nocase; classtype:trojan-activity; sid:100003169; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.72.203.82",nocase; classtype:trojan-activity; sid:100003170; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.18.133",nocase; classtype:trojan-activity; sid:100003171; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.18.147",nocase; classtype:trojan-activity; sid:100003172; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.18.148",nocase; classtype:trojan-activity; sid:100003173; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.18.165",nocase; classtype:trojan-activity; sid:100003174; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.18.200",nocase; classtype:trojan-activity; sid:100003175; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.18.71",nocase; classtype:trojan-activity; sid:100003176; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.21.28",nocase; classtype:trojan-activity; sid:100003177; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.21.5",nocase; classtype:trojan-activity; sid:100003178; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.21.62",nocase; classtype:trojan-activity; sid:100003179; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"41.86.5.103",nocase; classtype:trojan-activity; sid:100003180; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.176.112.72",nocase; classtype:trojan-activity; sid:100003181; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.202.101.147",nocase; classtype:trojan-activity; sid:100003182; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.122.39",nocase; classtype:trojan-activity; sid:100003183; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.128.210",nocase; classtype:trojan-activity; sid:100003184; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.168.142",nocase; classtype:trojan-activity; sid:100003185; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.168.97",nocase; classtype:trojan-activity; sid:100003186; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.176.214",nocase; classtype:trojan-activity; sid:100003187; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.179.49",nocase; classtype:trojan-activity; sid:100003188; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.209.156",nocase; classtype:trojan-activity; sid:100003189; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.212.124",nocase; classtype:trojan-activity; sid:100003190; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.218.16",nocase; classtype:trojan-activity; sid:100003191; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.233.247",nocase; classtype:trojan-activity; sid:100003192; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.235.4",nocase; classtype:trojan-activity; sid:100003193; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.249.8",nocase; classtype:trojan-activity; sid:100003194; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.37.186",nocase; classtype:trojan-activity; sid:100003195; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.37.44",nocase; classtype:trojan-activity; sid:100003196; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.43.25",nocase; classtype:trojan-activity; sid:100003197; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.64.34",nocase; classtype:trojan-activity; sid:100003198; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.70.213",nocase; classtype:trojan-activity; sid:100003199; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.76.168",nocase; classtype:trojan-activity; sid:100003200; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.76.198",nocase; classtype:trojan-activity; sid:100003201; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.8.136",nocase; classtype:trojan-activity; sid:100003202; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.90.17",nocase; classtype:trojan-activity; sid:100003203; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.224.91.8",nocase; classtype:trojan-activity; sid:100003204; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.225.240.244",nocase; classtype:trojan-activity; sid:100003205; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.225.250.39",nocase; classtype:trojan-activity; sid:100003206; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.225.33.31",nocase; classtype:trojan-activity; sid:100003207; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.226.89.25",nocase; classtype:trojan-activity; sid:100003208; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.227.179.209",nocase; classtype:trojan-activity; sid:100003209; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.227.66.88",nocase; classtype:trojan-activity; sid:100003210; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.198.102",nocase; classtype:trojan-activity; sid:100003211; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.60.114",nocase; classtype:trojan-activity; sid:100003212; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.65.201",nocase; classtype:trojan-activity; sid:100003213; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.70.126",nocase; classtype:trojan-activity; sid:100003214; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.70.231",nocase; classtype:trojan-activity; sid:100003215; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.75.7",nocase; classtype:trojan-activity; sid:100003216; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.228.76.135",nocase; classtype:trojan-activity; sid:100003217; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.230.100.114",nocase; classtype:trojan-activity; sid:100003218; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.230.174.125",nocase; classtype:trojan-activity; sid:100003219; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.230.219.243",nocase; classtype:trojan-activity; sid:100003220; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.230.228.78",nocase; classtype:trojan-activity; sid:100003221; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.230.66.255",nocase; classtype:trojan-activity; sid:100003222; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.230.82.44",nocase; classtype:trojan-activity; sid:100003223; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.230.88.107",nocase; classtype:trojan-activity; sid:100003224; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.230.93.169",nocase; classtype:trojan-activity; sid:100003225; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.231.223.215",nocase; classtype:trojan-activity; sid:100003226; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.231.244.80",nocase; classtype:trojan-activity; sid:100003227; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.231.66.174",nocase; classtype:trojan-activity; sid:100003228; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.231.95.195",nocase; classtype:trojan-activity; sid:100003229; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.232.102.163",nocase; classtype:trojan-activity; sid:100003230; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.232.170.117",nocase; classtype:trojan-activity; sid:100003231; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.232.226.16",nocase; classtype:trojan-activity; sid:100003232; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.233.90.183",nocase; classtype:trojan-activity; sid:100003233; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.234.105.6",nocase; classtype:trojan-activity; sid:100003234; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.234.162.44",nocase; classtype:trojan-activity; sid:100003235; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.234.166.242",nocase; classtype:trojan-activity; sid:100003236; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.234.255.20",nocase; classtype:trojan-activity; sid:100003237; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.235.124.55",nocase; classtype:trojan-activity; sid:100003238; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.235.169.85",nocase; classtype:trojan-activity; sid:100003239; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.235.23.163",nocase; classtype:trojan-activity; sid:100003240; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.235.66.249",nocase; classtype:trojan-activity; sid:100003241; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.235.90.32",nocase; classtype:trojan-activity; sid:100003242; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.235.92.111",nocase; classtype:trojan-activity; sid:100003243; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.236.148.201",nocase; classtype:trojan-activity; sid:100003244; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.236.212.174",nocase; classtype:trojan-activity; sid:100003245; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.236.212.83",nocase; classtype:trojan-activity; sid:100003246; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.236.215.63",nocase; classtype:trojan-activity; sid:100003247; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.236.236.179",nocase; classtype:trojan-activity; sid:100003248; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.237.45.223",nocase; classtype:trojan-activity; sid:100003249; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.237.54.162",nocase; classtype:trojan-activity; sid:100003250; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.238.175.32",nocase; classtype:trojan-activity; sid:100003251; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.238.191.210",nocase; classtype:trojan-activity; sid:100003252; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.238.241.239",nocase; classtype:trojan-activity; sid:100003253; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.238.59.222",nocase; classtype:trojan-activity; sid:100003254; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.239.192.128",nocase; classtype:trojan-activity; sid:100003255; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.242.200.90",nocase; classtype:trojan-activity; sid:100003256; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.52.180.36",nocase; classtype:trojan-activity; sid:100003257; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.56.15.227",nocase; classtype:trojan-activity; sid:100003258; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.61.99.155",nocase; classtype:trojan-activity; sid:100003259; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.82.217.241",nocase; classtype:trojan-activity; sid:100003260; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"42.84.14.5",nocase; classtype:trojan-activity; sid:100003261; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"43.230.156.44",nocase; classtype:trojan-activity; sid:100003262; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"43.241.106.183",nocase; classtype:trojan-activity; sid:100003263; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"43.241.106.234",nocase; classtype:trojan-activity; sid:100003264; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"43.252.8.94",nocase; classtype:trojan-activity; sid:100003265; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.112.203.218",nocase; classtype:trojan-activity; sid:100003266; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.130.138.66",nocase; classtype:trojan-activity; sid:100003267; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.133.1.137",nocase; classtype:trojan-activity; sid:100003268; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.133.1.242",nocase; classtype:trojan-activity; sid:100003269; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.133.203.192",nocase; classtype:trojan-activity; sid:100003270; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.135.134.228",nocase; classtype:trojan-activity; sid:100003271; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.14.149.182",nocase; classtype:trojan-activity; sid:100003272; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.14.149.204",nocase; classtype:trojan-activity; sid:100003273; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.14.149.244",nocase; classtype:trojan-activity; sid:100003274; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.14.149.66",nocase; classtype:trojan-activity; sid:100003275; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.141.84.184",nocase; classtype:trojan-activity; sid:100003276; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.142",nocase; classtype:trojan-activity; sid:100003277; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.213",nocase; classtype:trojan-activity; sid:100003278; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.144.225.65",nocase; classtype:trojan-activity; sid:100003279; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.148.10.47",nocase; classtype:trojan-activity; sid:100003280; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.15.143.158",nocase; classtype:trojan-activity; sid:100003281; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.164.140.133",nocase; classtype:trojan-activity; sid:100003282; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.108.116",nocase; classtype:trojan-activity; sid:100003283; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.108.248",nocase; classtype:trojan-activity; sid:100003284; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.110.99",nocase; classtype:trojan-activity; sid:100003285; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.111.154",nocase; classtype:trojan-activity; sid:100003286; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.111.16",nocase; classtype:trojan-activity; sid:100003287; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.111.202",nocase; classtype:trojan-activity; sid:100003288; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.176.111.84",nocase; classtype:trojan-activity; sid:100003289; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.178.101.22",nocase; classtype:trojan-activity; sid:100003290; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.201.165.164",nocase; classtype:trojan-activity; sid:100003291; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.22.209.58",nocase; classtype:trojan-activity; sid:100003292; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.23.22.186",nocase; classtype:trojan-activity; sid:100003293; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.27.253.137",nocase; classtype:trojan-activity; sid:100003294; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.33.112.19",nocase; classtype:trojan-activity; sid:100003295; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.51.104.59",nocase; classtype:trojan-activity; sid:100003296; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.81.235.31",nocase; classtype:trojan-activity; sid:100003297; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"45.9.148.37",nocase; classtype:trojan-activity; sid:100003298; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.151.155.218",nocase; classtype:trojan-activity; sid:100003299; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.172.75.231",nocase; classtype:trojan-activity; sid:100003300; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.175.184.121",nocase; classtype:trojan-activity; sid:100003301; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.182.173.246",nocase; classtype:trojan-activity; sid:100003302; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.20.63.218",nocase; classtype:trojan-activity; sid:100003303; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.201.214.64",nocase; classtype:trojan-activity; sid:100003304; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.21.153.231",nocase; classtype:trojan-activity; sid:100003305; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.214.27.4",nocase; classtype:trojan-activity; sid:100003306; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.24.130.254",nocase; classtype:trojan-activity; sid:100003307; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.243.179.115",nocase; classtype:trojan-activity; sid:100003308; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.249.33.79",nocase; classtype:trojan-activity; sid:100003309; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.25.242.211",nocase; classtype:trojan-activity; sid:100003310; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.42.118.86",nocase; classtype:trojan-activity; sid:100003311; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.42.86.128",nocase; classtype:trojan-activity; sid:100003312; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"46.97.76.242",nocase; classtype:trojan-activity; sid:100003313; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.145.152.26",nocase; classtype:trojan-activity; sid:100003314; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.151.23.172",nocase; classtype:trojan-activity; sid:100003315; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.157.97.71",nocase; classtype:trojan-activity; sid:100003316; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.16.131.51",nocase; classtype:trojan-activity; sid:100003317; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.197.0.119",nocase; classtype:trojan-activity; sid:100003318; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.21.202.98",nocase; classtype:trojan-activity; sid:100003319; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.223.167.153",nocase; classtype:trojan-activity; sid:100003320; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"47.46.231.38",nocase; classtype:trojan-activity; sid:100003321; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.142.162.113",nocase; classtype:trojan-activity; sid:100003322; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.142.87.36",nocase; classtype:trojan-activity; sid:100003323; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.143.43.93",nocase; classtype:trojan-activity; sid:100003324; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.156.35.166",nocase; classtype:trojan-activity; sid:100003325; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.158.201.200",nocase; classtype:trojan-activity; sid:100003326; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.159.20.121",nocase; classtype:trojan-activity; sid:100003327; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.159.21.3",nocase; classtype:trojan-activity; sid:100003328; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.174.182.99",nocase; classtype:trojan-activity; sid:100003329; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.213.170.49",nocase; classtype:trojan-activity; sid:100003330; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.213.178.183",nocase; classtype:trojan-activity; sid:100003331; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.213.179.129",nocase; classtype:trojan-activity; sid:100003332; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.68.221.252",nocase; classtype:trojan-activity; sid:100003333; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.68.249.121",nocase; classtype:trojan-activity; sid:100003334; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"49.70.15.16",nocase; classtype:trojan-activity; sid:100003335; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.181.135.114",nocase; classtype:trojan-activity; sid:100003336; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.2.70.50",nocase; classtype:trojan-activity; sid:100003337; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.53.146.179",nocase; classtype:trojan-activity; sid:100003338; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"5.8.10.62",nocase; classtype:trojan-activity; sid:100003339; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.115.174.102",nocase; classtype:trojan-activity; sid:100003340; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.121.91.255",nocase; classtype:trojan-activity; sid:100003341; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"50.252.47.29",nocase; classtype:trojan-activity; sid:100003342; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"51.171.146.13",nocase; classtype:trojan-activity; sid:100003343; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"51.222.56.159",nocase; classtype:trojan-activity; sid:100003344; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"54.180.158.181",nocase; classtype:trojan-activity; sid:100003345; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"54.253.194.14",nocase; classtype:trojan-activity; sid:100003346; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"54.36.114.136",nocase; classtype:trojan-activity; sid:100003347; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"54.36.180.122",nocase; classtype:trojan-activity; sid:100003348; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"54.37.93.29",nocase; classtype:trojan-activity; sid:100003349; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.114.246.26",nocase; classtype:trojan-activity; sid:100003350; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.115.162.92",nocase; classtype:trojan-activity; sid:100003351; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.115.174.4",nocase; classtype:trojan-activity; sid:100003352; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.125.191.4",nocase; classtype:trojan-activity; sid:100003353; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.126.247.118",nocase; classtype:trojan-activity; sid:100003354; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.142.166.120",nocase; classtype:trojan-activity; sid:100003355; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.142.200.124",nocase; classtype:trojan-activity; sid:100003356; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.143.142.142",nocase; classtype:trojan-activity; sid:100003357; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.143.189.75",nocase; classtype:trojan-activity; sid:100003358; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.18.103.109",nocase; classtype:trojan-activity; sid:100003359; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.19.249.50",nocase; classtype:trojan-activity; sid:100003360; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.217.171.157",nocase; classtype:trojan-activity; sid:100003361; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.22.212.107",nocase; classtype:trojan-activity; sid:100003362; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.226.129.29",nocase; classtype:trojan-activity; sid:100003363; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.229.194.122",nocase; classtype:trojan-activity; sid:100003364; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.23.245.24",nocase; classtype:trojan-activity; sid:100003365; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.230.89.42",nocase; classtype:trojan-activity; sid:100003366; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.232.155.37",nocase; classtype:trojan-activity; sid:100003367; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.238.42.192",nocase; classtype:trojan-activity; sid:100003368; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.240.147.97",nocase; classtype:trojan-activity; sid:100003369; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.241.57.237",nocase; classtype:trojan-activity; sid:100003370; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.241.78.55",nocase; classtype:trojan-activity; sid:100003371; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.117.188",nocase; classtype:trojan-activity; sid:100003372; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.143.173",nocase; classtype:trojan-activity; sid:100003373; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.144.97",nocase; classtype:trojan-activity; sid:100003374; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.149.117",nocase; classtype:trojan-activity; sid:100003375; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.149.226",nocase; classtype:trojan-activity; sid:100003376; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.154.55",nocase; classtype:trojan-activity; sid:100003377; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.154.66",nocase; classtype:trojan-activity; sid:100003378; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.76.206",nocase; classtype:trojan-activity; sid:100003379; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.248.79.25",nocase; classtype:trojan-activity; sid:100003380; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.18.244",nocase; classtype:trojan-activity; sid:100003381; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.74.104",nocase; classtype:trojan-activity; sid:100003382; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.74.124",nocase; classtype:trojan-activity; sid:100003383; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.74.248",nocase; classtype:trojan-activity; sid:100003384; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.77.227",nocase; classtype:trojan-activity; sid:100003385; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.78.155",nocase; classtype:trojan-activity; sid:100003386; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.80.23",nocase; classtype:trojan-activity; sid:100003387; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.80.46",nocase; classtype:trojan-activity; sid:100003388; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.86.85",nocase; classtype:trojan-activity; sid:100003389; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.87.248",nocase; classtype:trojan-activity; sid:100003390; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.89.210",nocase; classtype:trojan-activity; sid:100003391; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.90.206",nocase; classtype:trojan-activity; sid:100003392; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.249.90.86",nocase; classtype:trojan-activity; sid:100003393; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.252.176.107",nocase; classtype:trojan-activity; sid:100003394; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.252.177.66",nocase; classtype:trojan-activity; sid:100003395; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.255.43.163",nocase; classtype:trojan-activity; sid:100003396; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.48.154.143",nocase; classtype:trojan-activity; sid:100003397; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.50.178.137",nocase; classtype:trojan-activity; sid:100003398; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.50.221.148",nocase; classtype:trojan-activity; sid:100003399; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.72.165.153",nocase; classtype:trojan-activity; sid:100003400; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.72.165.39",nocase; classtype:trojan-activity; sid:100003401; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.97.201.45",nocase; classtype:trojan-activity; sid:100003402; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"58.97.206.33",nocase; classtype:trojan-activity; sid:100003403; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.0.211.161",nocase; classtype:trojan-activity; sid:100003404; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.102.168.189",nocase; classtype:trojan-activity; sid:100003405; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.151.202.3",nocase; classtype:trojan-activity; sid:100003406; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.151.214.4",nocase; classtype:trojan-activity; sid:100003407; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.151.237.51",nocase; classtype:trojan-activity; sid:100003408; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.29.133.229",nocase; classtype:trojan-activity; sid:100003409; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.30.12.254",nocase; classtype:trojan-activity; sid:100003410; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.32.97.190",nocase; classtype:trojan-activity; sid:100003411; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.58.104.244",nocase; classtype:trojan-activity; sid:100003412; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.58.117.226",nocase; classtype:trojan-activity; sid:100003413; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.7.124.148",nocase; classtype:trojan-activity; sid:100003414; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.8.35.22",nocase; classtype:trojan-activity; sid:100003415; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.92.182.72",nocase; classtype:trojan-activity; sid:100003416; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.92.218.77",nocase; classtype:trojan-activity; sid:100003417; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.92.219.28",nocase; classtype:trojan-activity; sid:100003418; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.97.174.85",nocase; classtype:trojan-activity; sid:100003419; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"59.99.47.93",nocase; classtype:trojan-activity; sid:100003420; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.13.61.12",nocase; classtype:trojan-activity; sid:100003421; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.14.48.221",nocase; classtype:trojan-activity; sid:100003422; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.162.122.36",nocase; classtype:trojan-activity; sid:100003423; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.162.160.200",nocase; classtype:trojan-activity; sid:100003424; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.164.130.220",nocase; classtype:trojan-activity; sid:100003425; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.17.12.143",nocase; classtype:trojan-activity; sid:100003426; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.176.249.56",nocase; classtype:trojan-activity; sid:100003427; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.20.217.142",nocase; classtype:trojan-activity; sid:100003428; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.208.135.42",nocase; classtype:trojan-activity; sid:100003429; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.122.57",nocase; classtype:trojan-activity; sid:100003430; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.186.185",nocase; classtype:trojan-activity; sid:100003431; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.216.23",nocase; classtype:trojan-activity; sid:100003432; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.209.33.5",nocase; classtype:trojan-activity; sid:100003433; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.211.19.63",nocase; classtype:trojan-activity; sid:100003434; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.211.6.112",nocase; classtype:trojan-activity; sid:100003435; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.211.7.166",nocase; classtype:trojan-activity; sid:100003436; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.100.83",nocase; classtype:trojan-activity; sid:100003437; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.162.152",nocase; classtype:trojan-activity; sid:100003438; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.206.246",nocase; classtype:trojan-activity; sid:100003439; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.218.31",nocase; classtype:trojan-activity; sid:100003440; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.220.167",nocase; classtype:trojan-activity; sid:100003441; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.23.84",nocase; classtype:trojan-activity; sid:100003442; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.212.254.178",nocase; classtype:trojan-activity; sid:100003443; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.213.162.59",nocase; classtype:trojan-activity; sid:100003444; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.213.58.188",nocase; classtype:trojan-activity; sid:100003445; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.213.83.55",nocase; classtype:trojan-activity; sid:100003446; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.214.93.166",nocase; classtype:trojan-activity; sid:100003447; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.215.165.64",nocase; classtype:trojan-activity; sid:100003448; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.215.195.111",nocase; classtype:trojan-activity; sid:100003449; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.215.207.11",nocase; classtype:trojan-activity; sid:100003450; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.215.219.108",nocase; classtype:trojan-activity; sid:100003451; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.215.4.239",nocase; classtype:trojan-activity; sid:100003452; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.216.95.211",nocase; classtype:trojan-activity; sid:100003453; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.217.177.196",nocase; classtype:trojan-activity; sid:100003454; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.217.86.208",nocase; classtype:trojan-activity; sid:100003455; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.220.22.89",nocase; classtype:trojan-activity; sid:100003456; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.25.115.48",nocase; classtype:trojan-activity; sid:100003457; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.25.76.224",nocase; classtype:trojan-activity; sid:100003458; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.4.72",nocase; classtype:trojan-activity; sid:100003459; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.42.72",nocase; classtype:trojan-activity; sid:100003460; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.51.127",nocase; classtype:trojan-activity; sid:100003461; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.60.174",nocase; classtype:trojan-activity; sid:100003462; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.8.36",nocase; classtype:trojan-activity; sid:100003463; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.253.8.81",nocase; classtype:trojan-activity; sid:100003464; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.254.49.59",nocase; classtype:trojan-activity; sid:100003465; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.7.10.121",nocase; classtype:trojan-activity; sid:100003466; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.7.136.8",nocase; classtype:trojan-activity; sid:100003467; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.7.202.153",nocase; classtype:trojan-activity; sid:100003468; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.7.8.43",nocase; classtype:trojan-activity; sid:100003469; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"60.7.99.254",nocase; classtype:trojan-activity; sid:100003470; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.102.243.124",nocase; classtype:trojan-activity; sid:100003471; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.109.164.140",nocase; classtype:trojan-activity; sid:100003472; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.141.124.123",nocase; classtype:trojan-activity; sid:100003473; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.162.169.210",nocase; classtype:trojan-activity; sid:100003474; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.162.55.42",nocase; classtype:trojan-activity; sid:100003475; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.164.96.98",nocase; classtype:trojan-activity; sid:100003476; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.179.171.60",nocase; classtype:trojan-activity; sid:100003477; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.179.91.194",nocase; classtype:trojan-activity; sid:100003478; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.179.91.230",nocase; classtype:trojan-activity; sid:100003479; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.179.93.79",nocase; classtype:trojan-activity; sid:100003480; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.18.112.48",nocase; classtype:trojan-activity; sid:100003481; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.192.73.253",nocase; classtype:trojan-activity; sid:100003482; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.213.118.28",nocase; classtype:trojan-activity; sid:100003483; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.247.224.66",nocase; classtype:trojan-activity; sid:100003484; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.253.94.230",nocase; classtype:trojan-activity; sid:100003485; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.3.124.3",nocase; classtype:trojan-activity; sid:100003486; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.3.124.51",nocase; classtype:trojan-activity; sid:100003487; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.47.220.169",nocase; classtype:trojan-activity; sid:100003488; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.102.61",nocase; classtype:trojan-activity; sid:100003489; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.103.144",nocase; classtype:trojan-activity; sid:100003490; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.11.87",nocase; classtype:trojan-activity; sid:100003491; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.135.192",nocase; classtype:trojan-activity; sid:100003492; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.157.4",nocase; classtype:trojan-activity; sid:100003493; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.159.231",nocase; classtype:trojan-activity; sid:100003494; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.195.226",nocase; classtype:trojan-activity; sid:100003495; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.212.191",nocase; classtype:trojan-activity; sid:100003496; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.212.250",nocase; classtype:trojan-activity; sid:100003497; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.243.169",nocase; classtype:trojan-activity; sid:100003498; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.247.208",nocase; classtype:trojan-activity; sid:100003499; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.35.86",nocase; classtype:trojan-activity; sid:100003500; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.39.119",nocase; classtype:trojan-activity; sid:100003501; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.43.174",nocase; classtype:trojan-activity; sid:100003502; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.48.112",nocase; classtype:trojan-activity; sid:100003503; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.5.217",nocase; classtype:trojan-activity; sid:100003504; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.63.119",nocase; classtype:trojan-activity; sid:100003505; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.76.72",nocase; classtype:trojan-activity; sid:100003506; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.9.166",nocase; classtype:trojan-activity; sid:100003507; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.52.99.183",nocase; classtype:trojan-activity; sid:100003508; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.100.87",nocase; classtype:trojan-activity; sid:100003509; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.123.162",nocase; classtype:trojan-activity; sid:100003510; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.125.182",nocase; classtype:trojan-activity; sid:100003511; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.251.243",nocase; classtype:trojan-activity; sid:100003512; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.62.169",nocase; classtype:trojan-activity; sid:100003513; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.73.171",nocase; classtype:trojan-activity; sid:100003514; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.81.18",nocase; classtype:trojan-activity; sid:100003515; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.53.83.14",nocase; classtype:trojan-activity; sid:100003516; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.172.248",nocase; classtype:trojan-activity; sid:100003517; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.240.20",nocase; classtype:trojan-activity; sid:100003518; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.58.190",nocase; classtype:trojan-activity; sid:100003519; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.58.20",nocase; classtype:trojan-activity; sid:100003520; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.61.18",nocase; classtype:trojan-activity; sid:100003521; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.64.104",nocase; classtype:trojan-activity; sid:100003522; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.54.77.175",nocase; classtype:trojan-activity; sid:100003523; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.56.180.67",nocase; classtype:trojan-activity; sid:100003524; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.56.181.7",nocase; classtype:trojan-activity; sid:100003525; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.57.96.116",nocase; classtype:trojan-activity; sid:100003526; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.58.170.60",nocase; classtype:trojan-activity; sid:100003527; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.58.73.220",nocase; classtype:trojan-activity; sid:100003528; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.61.218.23",nocase; classtype:trojan-activity; sid:100003529; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.65.172.121",nocase; classtype:trojan-activity; sid:100003530; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.0.22",nocase; classtype:trojan-activity; sid:100003531; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.104.46",nocase; classtype:trojan-activity; sid:100003532; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.110.59",nocase; classtype:trojan-activity; sid:100003533; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.132.195",nocase; classtype:trojan-activity; sid:100003534; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.132.86",nocase; classtype:trojan-activity; sid:100003535; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.255.60",nocase; classtype:trojan-activity; sid:100003536; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.70.45.130",nocase; classtype:trojan-activity; sid:100003537; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"61.98.144.75",nocase; classtype:trojan-activity; sid:100003538; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.1.98.131",nocase; classtype:trojan-activity; sid:100003539; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.117.124.114",nocase; classtype:trojan-activity; sid:100003540; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.141.73.58",nocase; classtype:trojan-activity; sid:100003541; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.219.131.205",nocase; classtype:trojan-activity; sid:100003542; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.219.143.46",nocase; classtype:trojan-activity; sid:100003543; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.219.155.61",nocase; classtype:trojan-activity; sid:100003544; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.219.227.31",nocase; classtype:trojan-activity; sid:100003545; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.31.126.33",nocase; classtype:trojan-activity; sid:100003546; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.38.149.66",nocase; classtype:trojan-activity; sid:100003547; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.38.222.98",nocase; classtype:trojan-activity; sid:100003548; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.43.207.148",nocase; classtype:trojan-activity; sid:100003549; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"62.90.165.236",nocase; classtype:trojan-activity; sid:100003550; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"63.245.122.93",nocase; classtype:trojan-activity; sid:100003551; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"64.233.154.99",nocase; classtype:trojan-activity; sid:100003552; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.125.128.196",nocase; classtype:trojan-activity; sid:100003553; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.21.58.252",nocase; classtype:trojan-activity; sid:100003554; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"65.26.155.131",nocase; classtype:trojan-activity; sid:100003555; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.153.233.87",nocase; classtype:trojan-activity; sid:100003556; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.229.214.115",nocase; classtype:trojan-activity; sid:100003557; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.57.55.210",nocase; classtype:trojan-activity; sid:100003558; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.74.7.197",nocase; classtype:trojan-activity; sid:100003559; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.91.21.31",nocase; classtype:trojan-activity; sid:100003560; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.97.181.196",nocase; classtype:trojan-activity; sid:100003561; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"66.97.181.213",nocase; classtype:trojan-activity; sid:100003562; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.245.151.203",nocase; classtype:trojan-activity; sid:100003563; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.3.169.223",nocase; classtype:trojan-activity; sid:100003564; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.8.138.101",nocase; classtype:trojan-activity; sid:100003565; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.81.98.111",nocase; classtype:trojan-activity; sid:100003566; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.82.242.243",nocase; classtype:trojan-activity; sid:100003567; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.83.49.234",nocase; classtype:trojan-activity; sid:100003568; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"67.84.138.165",nocase; classtype:trojan-activity; sid:100003569; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.148.103.248",nocase; classtype:trojan-activity; sid:100003570; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.151.244.128",nocase; classtype:trojan-activity; sid:100003571; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.174.182.226",nocase; classtype:trojan-activity; sid:100003572; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.175.107.153",nocase; classtype:trojan-activity; sid:100003573; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.188.144.143",nocase; classtype:trojan-activity; sid:100003574; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.204.88.29",nocase; classtype:trojan-activity; sid:100003575; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.205.106.84",nocase; classtype:trojan-activity; sid:100003576; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.205.119.241",nocase; classtype:trojan-activity; sid:100003577; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"68.78.33.33",nocase; classtype:trojan-activity; sid:100003578; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.115.37.205",nocase; classtype:trojan-activity; sid:100003579; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.120.237.255",nocase; classtype:trojan-activity; sid:100003580; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.123.245.151",nocase; classtype:trojan-activity; sid:100003581; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.124.231.110",nocase; classtype:trojan-activity; sid:100003582; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.127.214.47",nocase; classtype:trojan-activity; sid:100003583; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.146.232.34",nocase; classtype:trojan-activity; sid:100003584; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.165.173.49",nocase; classtype:trojan-activity; sid:100003585; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.196.158.227",nocase; classtype:trojan-activity; sid:100003586; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.222.157.166",nocase; classtype:trojan-activity; sid:100003587; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.229.0.133",nocase; classtype:trojan-activity; sid:100003588; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.63.73.234",nocase; classtype:trojan-activity; sid:100003589; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.75.115.194",nocase; classtype:trojan-activity; sid:100003590; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.75.227.186",nocase; classtype:trojan-activity; sid:100003591; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"69.76.240.206",nocase; classtype:trojan-activity; sid:100003592; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.115.31.30",nocase; classtype:trojan-activity; sid:100003593; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.118.240.88",nocase; classtype:trojan-activity; sid:100003594; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.167.10.180",nocase; classtype:trojan-activity; sid:100003595; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.236.190.250",nocase; classtype:trojan-activity; sid:100003596; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.25.5.105",nocase; classtype:trojan-activity; sid:100003597; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.33.144.248",nocase; classtype:trojan-activity; sid:100003598; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"70.93.129.118",nocase; classtype:trojan-activity; sid:100003599; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.127.148.69",nocase; classtype:trojan-activity; sid:100003600; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.19.150.93",nocase; classtype:trojan-activity; sid:100003601; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.204.63.239",nocase; classtype:trojan-activity; sid:100003602; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.29.48.164",nocase; classtype:trojan-activity; sid:100003603; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.34.191.213",nocase; classtype:trojan-activity; sid:100003604; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.40.234.166",nocase; classtype:trojan-activity; sid:100003605; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.43.2.122",nocase; classtype:trojan-activity; sid:100003606; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.43.235.106",nocase; classtype:trojan-activity; sid:100003607; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.47.133.58",nocase; classtype:trojan-activity; sid:100003608; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.71.60.69",nocase; classtype:trojan-activity; sid:100003609; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"71.85.106.211",nocase; classtype:trojan-activity; sid:100003610; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.17.22.30",nocase; classtype:trojan-activity; sid:100003611; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.186.139.38",nocase; classtype:trojan-activity; sid:100003612; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.189.180.98",nocase; classtype:trojan-activity; sid:100003613; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.214.69.226",nocase; classtype:trojan-activity; sid:100003614; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.229.230.118",nocase; classtype:trojan-activity; sid:100003615; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.229.35.40",nocase; classtype:trojan-activity; sid:100003616; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"72.31.40.122",nocase; classtype:trojan-activity; sid:100003617; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"73.204.216.103",nocase; classtype:trojan-activity; sid:100003618; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.101.1.159",nocase; classtype:trojan-activity; sid:100003619; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.108.224.112",nocase; classtype:trojan-activity; sid:100003620; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.194.117.165",nocase; classtype:trojan-activity; sid:100003621; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.195.115.176",nocase; classtype:trojan-activity; sid:100003622; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.199.84.77",nocase; classtype:trojan-activity; sid:100003623; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"74.75.165.81",nocase; classtype:trojan-activity; sid:100003624; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"75.127.141.52",nocase; classtype:trojan-activity; sid:100003625; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"75.82.36.220",nocase; classtype:trojan-activity; sid:100003626; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"75.83.102.27",nocase; classtype:trojan-activity; sid:100003627; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"75.99.213.61",nocase; classtype:trojan-activity; sid:100003628; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.108.199.153",nocase; classtype:trojan-activity; sid:100003629; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.170.11.82",nocase; classtype:trojan-activity; sid:100003630; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.178.22.145",nocase; classtype:trojan-activity; sid:100003631; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.250.199.133",nocase; classtype:trojan-activity; sid:100003632; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.254.129.227",nocase; classtype:trojan-activity; sid:100003633; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.84.134.33",nocase; classtype:trojan-activity; sid:100003634; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"76.95.12.137",nocase; classtype:trojan-activity; sid:100003635; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.237.25.210",nocase; classtype:trojan-activity; sid:100003636; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.45.183.39",nocase; classtype:trojan-activity; sid:100003637; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.71.50.153",nocase; classtype:trojan-activity; sid:100003638; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.71.52.220",nocase; classtype:trojan-activity; sid:100003639; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.79.191.32",nocase; classtype:trojan-activity; sid:100003640; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"77.89.203.238",nocase; classtype:trojan-activity; sid:100003641; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.179.225.254",nocase; classtype:trojan-activity; sid:100003642; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.186.155.18",nocase; classtype:trojan-activity; sid:100003643; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.187.141.144",nocase; classtype:trojan-activity; sid:100003644; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.187.240.125",nocase; classtype:trojan-activity; sid:100003645; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.187.41.200",nocase; classtype:trojan-activity; sid:100003646; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.188.168.64",nocase; classtype:trojan-activity; sid:100003647; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.188.188.141",nocase; classtype:trojan-activity; sid:100003648; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.189.104.157",nocase; classtype:trojan-activity; sid:100003649; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.189.176.163",nocase; classtype:trojan-activity; sid:100003650; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.23.172.81",nocase; classtype:trojan-activity; sid:100003651; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.72.231.120",nocase; classtype:trojan-activity; sid:100003652; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"78.8.225.77",nocase; classtype:trojan-activity; sid:100003653; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.11.195.121",nocase; classtype:trojan-activity; sid:100003654; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.13.49.221",nocase; classtype:trojan-activity; sid:100003655; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.130.253.13",nocase; classtype:trojan-activity; sid:100003656; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.147.123.48",nocase; classtype:trojan-activity; sid:100003657; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.170.31.56",nocase; classtype:trojan-activity; sid:100003658; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.175.42.244",nocase; classtype:trojan-activity; sid:100003659; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.21.84.63",nocase; classtype:trojan-activity; sid:100003660; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.7.170.58",nocase; classtype:trojan-activity; sid:100003661; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.79.58.94",nocase; classtype:trojan-activity; sid:100003662; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.8.70.162",nocase; classtype:trojan-activity; sid:100003663; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"79.9.88.185",nocase; classtype:trojan-activity; sid:100003664; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.107.89.207",nocase; classtype:trojan-activity; sid:100003665; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.19.101.218",nocase; classtype:trojan-activity; sid:100003666; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.211.181.77",nocase; classtype:trojan-activity; sid:100003667; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.217.12.7",nocase; classtype:trojan-activity; sid:100003668; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"80.99.128.61",nocase; classtype:trojan-activity; sid:100003669; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.136.146.213",nocase; classtype:trojan-activity; sid:100003670; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.165.44.109",nocase; classtype:trojan-activity; sid:100003671; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.191.40.58",nocase; classtype:trojan-activity; sid:100003672; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.198.7.22",nocase; classtype:trojan-activity; sid:100003673; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.213.111.60",nocase; classtype:trojan-activity; sid:100003674; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.213.141.184",nocase; classtype:trojan-activity; sid:100003675; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.215.199.29",nocase; classtype:trojan-activity; sid:100003676; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.218.187.113",nocase; classtype:trojan-activity; sid:100003677; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.218.195.216",nocase; classtype:trojan-activity; sid:100003678; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.237.128.200",nocase; classtype:trojan-activity; sid:100003679; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.246.225.203",nocase; classtype:trojan-activity; sid:100003680; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"81.92.36.96",nocase; classtype:trojan-activity; sid:100003681; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.103.108.72",nocase; classtype:trojan-activity; sid:100003682; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.135.196.130",nocase; classtype:trojan-activity; sid:100003683; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.166.212.178",nocase; classtype:trojan-activity; sid:100003684; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.166.85.112",nocase; classtype:trojan-activity; sid:100003685; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.207.61.194",nocase; classtype:trojan-activity; sid:100003686; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.209.250.155",nocase; classtype:trojan-activity; sid:100003687; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.211.156.38",nocase; classtype:trojan-activity; sid:100003688; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.62.110.252",nocase; classtype:trojan-activity; sid:100003689; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.62.53.77",nocase; classtype:trojan-activity; sid:100003690; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.138.72",nocase; classtype:trojan-activity; sid:100003691; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.139.92",nocase; classtype:trojan-activity; sid:100003692; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.154.214",nocase; classtype:trojan-activity; sid:100003693; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.80.187.109",nocase; classtype:trojan-activity; sid:100003694; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.100.54",nocase; classtype:trojan-activity; sid:100003695; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.106.65",nocase; classtype:trojan-activity; sid:100003696; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.108.172",nocase; classtype:trojan-activity; sid:100003697; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.131.158",nocase; classtype:trojan-activity; sid:100003698; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.19.42",nocase; classtype:trojan-activity; sid:100003699; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.197.254",nocase; classtype:trojan-activity; sid:100003700; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.215.149",nocase; classtype:trojan-activity; sid:100003701; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.232.68",nocase; classtype:trojan-activity; sid:100003702; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.234.195",nocase; classtype:trojan-activity; sid:100003703; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.246.96",nocase; classtype:trojan-activity; sid:100003704; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.28.57",nocase; classtype:trojan-activity; sid:100003705; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.4.57",nocase; classtype:trojan-activity; sid:100003706; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.55.84",nocase; classtype:trojan-activity; sid:100003707; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.73.245",nocase; classtype:trojan-activity; sid:100003708; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.9.62",nocase; classtype:trojan-activity; sid:100003709; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"82.81.98.51",nocase; classtype:trojan-activity; sid:100003710; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.165.237.163",nocase; classtype:trojan-activity; sid:100003711; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.234.147.99",nocase; classtype:trojan-activity; sid:100003712; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.234.218.42",nocase; classtype:trojan-activity; sid:100003713; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.242.253.154",nocase; classtype:trojan-activity; sid:100003714; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"83.252.9.37",nocase; classtype:trojan-activity; sid:100003715; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.210.219.208",nocase; classtype:trojan-activity; sid:100003716; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.210.219.213",nocase; classtype:trojan-activity; sid:100003717; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.212.219.127",nocase; classtype:trojan-activity; sid:100003718; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.224.162.170",nocase; classtype:trojan-activity; sid:100003719; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.228.50.118",nocase; classtype:trojan-activity; sid:100003720; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.228.95.204",nocase; classtype:trojan-activity; sid:100003721; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.238.24.35",nocase; classtype:trojan-activity; sid:100003722; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.247.83.74",nocase; classtype:trojan-activity; sid:100003723; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.254.39.129",nocase; classtype:trojan-activity; sid:100003724; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.33.111.227",nocase; classtype:trojan-activity; sid:100003725; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.38.152.148",nocase; classtype:trojan-activity; sid:100003726; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.40.127.242",nocase; classtype:trojan-activity; sid:100003727; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"84.42.20.217",nocase; classtype:trojan-activity; sid:100003728; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com",nocase; classtype:trojan-activity; sid:100003729; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.11.216",nocase; classtype:trojan-activity; sid:100003730; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.123.251",nocase; classtype:trojan-activity; sid:100003731; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.135.187",nocase; classtype:trojan-activity; sid:100003732; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.208.25",nocase; classtype:trojan-activity; sid:100003733; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.224.141",nocase; classtype:trojan-activity; sid:100003734; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.241.2",nocase; classtype:trojan-activity; sid:100003735; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.105.9.152",nocase; classtype:trojan-activity; sid:100003736; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.214.149.236",nocase; classtype:trojan-activity; sid:100003737; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.64.181.50",nocase; classtype:trojan-activity; sid:100003738; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.74.215.180",nocase; classtype:trojan-activity; sid:100003739; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.97.130.227",nocase; classtype:trojan-activity; sid:100003740; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"85.97.195.129",nocase; classtype:trojan-activity; sid:100003741; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"86.35.43.220",nocase; classtype:trojan-activity; sid:100003742; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"87.121.98.51",nocase; classtype:trojan-activity; sid:100003743; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"87.61.89.40",nocase; classtype:trojan-activity; sid:100003744; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.119.171.253",nocase; classtype:trojan-activity; sid:100003745; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.2.208.71",nocase; classtype:trojan-activity; sid:100003746; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.2.219.179",nocase; classtype:trojan-activity; sid:100003747; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.225.222.128",nocase; classtype:trojan-activity; sid:100003748; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.247.96.19",nocase; classtype:trojan-activity; sid:100003749; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.248.136.231",nocase; classtype:trojan-activity; sid:100003750; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.248.51.139",nocase; classtype:trojan-activity; sid:100003751; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.249.244.180",nocase; classtype:trojan-activity; sid:100003752; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.250.204.12",nocase; classtype:trojan-activity; sid:100003753; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.250.226.26",nocase; classtype:trojan-activity; sid:100003754; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"88.250.254.90",nocase; classtype:trojan-activity; sid:100003755; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.122.183.130",nocase; classtype:trojan-activity; sid:100003756; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.136.197.170",nocase; classtype:trojan-activity; sid:100003757; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.29.213.33",nocase; classtype:trojan-activity; sid:100003758; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.35.62.96",nocase; classtype:trojan-activity; sid:100003759; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.40.85.166",nocase; classtype:trojan-activity; sid:100003760; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"89.40.87.5",nocase; classtype:trojan-activity; sid:100003761; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"8poieq.bn.files.1drv.com",nocase; classtype:trojan-activity; sid:100003762; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"90.152.144.139",nocase; classtype:trojan-activity; sid:100003763; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.177.139.132",nocase; classtype:trojan-activity; sid:100003764; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.187.103.32",nocase; classtype:trojan-activity; sid:100003765; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.212.150.241",nocase; classtype:trojan-activity; sid:100003766; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.212.150.243",nocase; classtype:trojan-activity; sid:100003767; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.217.104.185",nocase; classtype:trojan-activity; sid:100003768; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.233.112.188",nocase; classtype:trojan-activity; sid:100003769; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.234.60.94",nocase; classtype:trojan-activity; sid:100003770; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.239.168.83",nocase; classtype:trojan-activity; sid:100003771; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.244.114.198",nocase; classtype:trojan-activity; sid:100003772; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.244.169.139",nocase; classtype:trojan-activity; sid:100003773; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.92.16.244",nocase; classtype:trojan-activity; sid:100003774; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"91.98.4.181",nocase; classtype:trojan-activity; sid:100003775; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.114.191.82",nocase; classtype:trojan-activity; sid:100003776; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.241.78.114",nocase; classtype:trojan-activity; sid:100003777; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.27.246.202",nocase; classtype:trojan-activity; sid:100003778; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.54.237.237",nocase; classtype:trojan-activity; sid:100003779; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"92.85.18.138",nocase; classtype:trojan-activity; sid:100003780; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.171.157.73",nocase; classtype:trojan-activity; sid:100003781; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.21.224.154",nocase; classtype:trojan-activity; sid:100003782; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.39.115.176",nocase; classtype:trojan-activity; sid:100003783; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.41.137.16",nocase; classtype:trojan-activity; sid:100003784; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.41.182.249",nocase; classtype:trojan-activity; sid:100003785; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.41.206.56",nocase; classtype:trojan-activity; sid:100003786; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.57.43.233",nocase; classtype:trojan-activity; sid:100003787; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"93.73.99.102",nocase; classtype:trojan-activity; sid:100003788; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.136.69.199",nocase; classtype:trojan-activity; sid:100003789; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.143.53.34",nocase; classtype:trojan-activity; sid:100003790; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.154.17.170",nocase; classtype:trojan-activity; sid:100003791; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.154.82.190",nocase; classtype:trojan-activity; sid:100003792; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.200.16.22",nocase; classtype:trojan-activity; sid:100003793; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.224.83.208",nocase; classtype:trojan-activity; sid:100003794; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.43.139.153",nocase; classtype:trojan-activity; sid:100003795; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"94.53.120.109",nocase; classtype:trojan-activity; sid:100003796; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.132.129.250",nocase; classtype:trojan-activity; sid:100003797; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.154.20.231",nocase; classtype:trojan-activity; sid:100003798; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.158.19.130",nocase; classtype:trojan-activity; sid:100003799; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.170.113.52",nocase; classtype:trojan-activity; sid:100003800; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.170.201.34",nocase; classtype:trojan-activity; sid:100003801; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.181.155.112",nocase; classtype:trojan-activity; sid:100003802; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.214.52.64",nocase; classtype:trojan-activity; sid:100003803; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.54.11.179",nocase; classtype:trojan-activity; sid:100003804; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.60.146.134",nocase; classtype:trojan-activity; sid:100003805; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.60.6.114",nocase; classtype:trojan-activity; sid:100003806; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.66.196.63",nocase; classtype:trojan-activity; sid:100003807; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"95.9.120.40",nocase; classtype:trojan-activity; sid:100003808; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"96.239.73.246",nocase; classtype:trojan-activity; sid:100003809; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"96.47.147.169",nocase; classtype:trojan-activity; sid:100003810; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"97.68.140.254",nocase; classtype:trojan-activity; sid:100003811; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"97.96.199.75",nocase; classtype:trojan-activity; sid:100003812; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.0.210.218",nocase; classtype:trojan-activity; sid:100003813; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.0.239.142",nocase; classtype:trojan-activity; sid:100003814; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.113.239.207",nocase; classtype:trojan-activity; sid:100003815; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.116.72.119",nocase; classtype:trojan-activity; sid:100003816; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.128.147.115",nocase; classtype:trojan-activity; sid:100003817; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.178.242.44",nocase; classtype:trojan-activity; sid:100003818; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.249.236.11",nocase; classtype:trojan-activity; sid:100003819; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.28.200.139",nocase; classtype:trojan-activity; sid:100003820; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"98.30.24.54",nocase; classtype:trojan-activity; sid:100003821; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"99.150.245.203",nocase; classtype:trojan-activity; sid:100003822; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"99.33.195.164",nocase; classtype:trojan-activity; sid:100003823; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abcd.bg",nocase; classtype:trojan-activity; sid:100003824; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abclicks.in",nocase; classtype:trojan-activity; sid:100003825; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abissnet.net",nocase; classtype:trojan-activity; sid:100003826; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aboveandbelow.com.au",nocase; classtype:trojan-activity; sid:100003827; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"absoftechworld.com",nocase; classtype:trojan-activity; sid:100003828; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"absupplies.co.uk",nocase; classtype:trojan-activity; sid:100003829; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"abyssos.eu",nocase; classtype:trojan-activity; sid:100003830; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"academyshademani.com",nocase; classtype:trojan-activity; sid:100003831; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"acbick.com",nocase; classtype:trojan-activity; sid:100003832; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"accounts.thesmarttechhub.com",nocase; classtype:trojan-activity; sid:100003833; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aceeprc.com.aceeprc.com",nocase; classtype:trojan-activity; sid:100003834; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"acellr.co.uk",nocase; classtype:trojan-activity; sid:100003835; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aciabogados.com",nocase; classtype:trojan-activity; sid:100003836; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"acteon.com.ar",nocase; classtype:trojan-activity; sid:100003837; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"activateyourdiscount.com",nocase; classtype:trojan-activity; sid:100003838; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"activecost.com.au",nocase; classtype:trojan-activity; sid:100003839; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"adamorinmusic.com",nocase; classtype:trojan-activity; sid:100003840; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"addahealingmusic.com",nocase; classtype:trojan-activity; sid:100003841; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"adithimedia.com",nocase; classtype:trojan-activity; sid:100003842; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"adithimedia.memengers.com",nocase; classtype:trojan-activity; sid:100003843; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"admin.erapor.smk-alasror.net",nocase; classtype:trojan-activity; sid:100003844; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"admin.gentbcn.org",nocase; classtype:trojan-activity; sid:100003845; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"admin.grandoceanvilla.com",nocase; classtype:trojan-activity; sid:100003846; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"adventureexplorer.in",nocase; classtype:trojan-activity; sid:100003847; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aeropilates.cl",nocase; classtype:trojan-activity; sid:100003848; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"afrimedspecialist.com",nocase; classtype:trojan-activity; sid:100003849; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agemn.co.za",nocase; classtype:trojan-activity; sid:100003850; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agenciadigitalwdys.com",nocase; classtype:trojan-activity; sid:100003851; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agenciatabletshouse.com.br",nocase; classtype:trojan-activity; sid:100003852; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agenda.gmelloinformatica.com.br",nocase; classtype:trojan-activity; sid:100003853; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agenmovie.xyz",nocase; classtype:trojan-activity; sid:100003854; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agentt.ac.ug",nocase; classtype:trojan-activity; sid:100003855; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agile8studio.com",nocase; classtype:trojan-activity; sid:100003856; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"agmcarpetcare.co.uk",nocase; classtype:trojan-activity; sid:100003857; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aiqtest.com",nocase; classtype:trojan-activity; sid:100003858; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ajpharmaholding.com",nocase; classtype:trojan-activity; sid:100003859; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ajstudiollc.com",nocase; classtype:trojan-activity; sid:100003860; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aktyd05.top",nocase; classtype:trojan-activity; sid:100003861; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"al-wahd.com",nocase; classtype:trojan-activity; sid:100003862; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alasdemariposas.org",nocase; classtype:trojan-activity; sid:100003863; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alemelektronik.com",nocase; classtype:trojan-activity; sid:100003864; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alena1971.es",nocase; classtype:trojan-activity; sid:100003865; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alexdubai.com.aldiabsteel.com",nocase; classtype:trojan-activity; sid:100003866; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alka.institute",nocase; classtype:trojan-activity; sid:100003867; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"allforcreative.com.au",nocase; classtype:trojan-activity; sid:100003868; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alltheway.travel",nocase; classtype:trojan-activity; sid:100003869; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"alpaylar.com.tr",nocase; classtype:trojan-activity; sid:100003870; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"am-concepts.ca",nocase; classtype:trojan-activity; sid:100003871; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amamontajes.com",nocase; classtype:trojan-activity; sid:100003872; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amarresdeamorymaestroshechiceros.com",nocase; classtype:trojan-activity; sid:100003873; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amarteargentina.com.ar",nocase; classtype:trojan-activity; sid:100003874; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amenyan.zouri.jp",nocase; classtype:trojan-activity; sid:100003875; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amos524.org",nocase; classtype:trojan-activity; sid:100003876; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ams.alvinasschools.org.ng",nocase; classtype:trojan-activity; sid:100003877; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anantam.net.in",nocase; classtype:trojan-activity; sid:100003878; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andreelapeyre.com",nocase; classtype:trojan-activity; sid:100003879; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andremaraisbeleggings.co.za",nocase; classtype:trojan-activity; sid:100003880; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andres.ac.ug",nocase; classtype:trojan-activity; sid:100003881; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andres.ug",nocase; classtype:trojan-activity; sid:100003882; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"andreshconcejal.solucioneslink.com",nocase; classtype:trojan-activity; sid:100003883; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"angelazgheibld.com",nocase; classtype:trojan-activity; sid:100003884; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"angelsdetour.com",nocase; classtype:trojan-activity; sid:100003885; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"angloteste.bigprime.com.br",nocase; classtype:trojan-activity; sid:100003886; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anhung1102.vn",nocase; classtype:trojan-activity; sid:100003887; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"anysbergbiltong.co.za",nocase; classtype:trojan-activity; sid:100003888; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"apartamentoscitta.com",nocase; classtype:trojan-activity; sid:100003889; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"api-ms.cobainaja.id",nocase; classtype:trojan-activity; sid:100003890; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"api.cstdevs.com",nocase; classtype:trojan-activity; sid:100003891; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"api.quocbao.biz",nocase; classtype:trojan-activity; sid:100003892; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"api.sampy.io",nocase; classtype:trojan-activity; sid:100003893; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aplicativoparasindicato.com.br",nocase; classtype:trojan-activity; sid:100003894; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"apoolcondo.com",nocase; classtype:trojan-activity; sid:100003895; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"app.adsensearticle.com",nocase; classtype:trojan-activity; sid:100003896; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"app.prerana.info",nocase; classtype:trojan-activity; sid:100003897; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"apps.saintsoporte.com",nocase; classtype:trojan-activity; sid:100003898; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aqv.news",nocase; classtype:trojan-activity; sid:100003899; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"areyoulivingwell.com",nocase; classtype:trojan-activity; sid:100003900; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"arsapetrolab.com",nocase; classtype:trojan-activity; sid:100003901; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"artedibujoyarquitectura.com",nocase; classtype:trojan-activity; sid:100003902; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ask-regard.call-save.biz",nocase; classtype:trojan-activity; sid:100003903; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"atfile.com",nocase; classtype:trojan-activity; sid:100003904; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"athenacapsg.com",nocase; classtype:trojan-activity; sid:100003905; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"atlasconcreteworks.com",nocase; classtype:trojan-activity; sid:100003906; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"attach.66rpg.com",nocase; classtype:trojan-activity; sid:100003907; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"atteuqpotentialunlimited.com",nocase; classtype:trojan-activity; sid:100003908; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"augustair.com",nocase; classtype:trojan-activity; sid:100003909; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"aulist.com",nocase; classtype:trojan-activity; sid:100003910; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"australiafashions.com",nocase; classtype:trojan-activity; sid:100003911; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"automaticrefreshments.com",nocase; classtype:trojan-activity; sid:100003912; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"avadhanagames.com",nocase; classtype:trojan-activity; sid:100003913; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"avissrilanka.com",nocase; classtype:trojan-activity; sid:100003914; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ayamallah.com",nocase; classtype:trojan-activity; sid:100003915; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"azmeasurement.com",nocase; classtype:trojan-activity; sid:100003916; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"azraktours.com",nocase; classtype:trojan-activity; sid:100003917; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"backgrounds.pk",nocase; classtype:trojan-activity; sid:100003918; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"backup.agewsage.com",nocase; classtype:trojan-activity; sid:100003919; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"badeggdesign.com",nocase; classtype:trojan-activity; sid:100003920; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"balealgodon.mx",nocase; classtype:trojan-activity; sid:100003921; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bangkok-orchids.com",nocase; classtype:trojan-activity; sid:100003922; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"barcionstw.eastus.cloudapp.azure.com",nocase; classtype:trojan-activity; sid:100003923; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bary.sz4h.com",nocase; classtype:trojan-activity; sid:100003924; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"basma.com.kw",nocase; classtype:trojan-activity; sid:100003925; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bausch.kr-atlas.monaxikoslykos@zytrox.tk",nocase; classtype:trojan-activity; sid:100003926; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bavhome.com",nocase; classtype:trojan-activity; sid:100003927; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bbia.co.uk",nocase; classtype:trojan-activity; sid:100003928; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bcmt.elin.co.za",nocase; classtype:trojan-activity; sid:100003929; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bcrg.co.za",nocase; classtype:trojan-activity; sid:100003930; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bearcatpumps.com.cn",nocase; classtype:trojan-activity; sid:100003931; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"beautincollagen.rs",nocase; classtype:trojan-activity; sid:100003932; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bekape.co.id",nocase; classtype:trojan-activity; sid:100003933; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bespokeweddings.ie",nocase; classtype:trojan-activity; sid:100003934; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bestcarenepal.com",nocase; classtype:trojan-activity; sid:100003935; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"betone.co.kr",nocase; classtype:trojan-activity; sid:100003936; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"betycopaints.com",nocase; classtype:trojan-activity; sid:100003937; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"beveragesmiami.solucioneslink.com",nocase; classtype:trojan-activity; sid:100003938; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bhavaniengineering.com",nocase; classtype:trojan-activity; sid:100003939; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bigbag.wootraining.certificacion.cl",nocase; classtype:trojan-activity; sid:100003940; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bilbosaquet.ug",nocase; classtype:trojan-activity; sid:100003941; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bilhen.co.za",nocase; classtype:trojan-activity; sid:100003942; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"billing.rahitechnosoft.com",nocase; classtype:trojan-activity; sid:100003943; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"birdi.elin.co.za",nocase; classtype:trojan-activity; sid:100003944; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"birminghamlink.org",nocase; classtype:trojan-activity; sid:100003945; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.callensaxen.com",nocase; classtype:trojan-activity; sid:100003946; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"blog.oyinblogs.com",nocase; classtype:trojan-activity; sid:100003947; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bmlifestyle.co.uk",nocase; classtype:trojan-activity; sid:100003948; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bnrbook.com",nocase; classtype:trojan-activity; sid:100003949; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bnrnews.id",nocase; classtype:trojan-activity; sid:100003950; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bodenstein.co.za",nocase; classtype:trojan-activity; sid:100003951; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"booksearch.com",nocase; classtype:trojan-activity; sid:100003952; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bounces.mi-fs.com",nocase; classtype:trojan-activity; sid:100003953; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bpo.correct.go.th",nocase; classtype:trojan-activity; sid:100003954; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bradleyinstitute.co.za",nocase; classtype:trojan-activity; sid:100003955; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brandtrust.com.pk",nocase; classtype:trojan-activity; sid:100003956; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brendanquine.com",nocase; classtype:trojan-activity; sid:100003957; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brideofmessiah.com",nocase; classtype:trojan-activity; sid:100003958; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bridesofmaldives.com",nocase; classtype:trojan-activity; sid:100003959; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brightmega.com",nocase; classtype:trojan-activity; sid:100003960; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brightonrooms.co.uk",nocase; classtype:trojan-activity; sid:100003961; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"brightstarshop.com",nocase; classtype:trojan-activity; sid:100003962; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"browardinsurancemiami.solucioneslink.com",nocase; classtype:trojan-activity; sid:100003963; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bt2.elin.co.za",nocase; classtype:trojan-activity; sid:100003964; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bucrinsuranlceonlines.com",nocase; classtype:trojan-activity; sid:100003965; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"buenavista.co",nocase; classtype:trojan-activity; sid:100003966; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bullseyemedia.in",nocase; classtype:trojan-activity; sid:100003967; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"busandvanrentalmalaysia.com",nocase; classtype:trojan-activity; sid:100003968; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"buscascolegios.diit.cl",nocase; classtype:trojan-activity; sid:100003969; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"business.softberg.ro",nocase; classtype:trojan-activity; sid:100003970; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"buyingmusiconline.com",nocase; classtype:trojan-activity; sid:100003971; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bwsr.eu",nocase; classtype:trojan-activity; sid:100003972; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"c.oooooooooo.ga",nocase; classtype:trojan-activity; sid:100003973; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"c0140529.ferozo.com",nocase; classtype:trojan-activity; sid:100003974; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"caballo.com.au",nocase; classtype:trojan-activity; sid:100003975; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cacapavaonline.sdserver144.com.br",nocase; classtype:trojan-activity; sid:100003976; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"calgaryautorepairservice.com",nocase; classtype:trojan-activity; sid:100003977; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"callbury.in",nocase; classtype:trojan-activity; sid:100003978; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"camminachetipassa.it",nocase; classtype:trojan-activity; sid:100003979; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cancer.educandome.co",nocase; classtype:trojan-activity; sid:100003980; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"capitalgroup-kw.com",nocase; classtype:trojan-activity; sid:100003981; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"capitalnewsagency.com",nocase; classtype:trojan-activity; sid:100003982; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"capoeiraventrelivre.com",nocase; classtype:trojan-activity; sid:100003983; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cashyinvestment.org",nocase; classtype:trojan-activity; sid:100003984; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"casoauditores.com",nocase; classtype:trojan-activity; sid:100003985; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"catchperch.com",nocase; classtype:trojan-activity; sid:100003986; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"catchpoolshetlands.co.uk",nocase; classtype:trojan-activity; sid:100003987; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cazyacustomfurniture.com",nocase; classtype:trojan-activity; sid:100003988; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ccauthority.net",nocase; classtype:trojan-activity; sid:100003989; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdaonline.com.ar",nocase; classtype:trojan-activity; sid:100003990; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cec.asso.ac-amiens.fr",nocase; classtype:trojan-activity; sid:100003991; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cendekiabinaaksara.com",nocase; classtype:trojan-activity; sid:100003992; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cespol-bote.com.mx",nocase; classtype:trojan-activity; sid:100003993; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cfs5.tistory.com",nocase; classtype:trojan-activity; sid:100003994; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ch.rmu.ac.th",nocase; classtype:trojan-activity; sid:100003995; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chardhamdodham.com",nocase; classtype:trojan-activity; sid:100003996; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cheacrilnsurances.com",nocase; classtype:trojan-activity; sid:100003997; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chealablilitycarinsurances.com",nocase; classtype:trojan-activity; sid:100003998; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chezalice.co.za",nocase; classtype:trojan-activity; sid:100003999; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"childselect.com",nocase; classtype:trojan-activity; sid:100004000; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chinhdropfile.myvnc.com",nocase; classtype:trojan-activity; sid:100004001; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chinhdropfile80.myvnc.com",nocase; classtype:trojan-activity; sid:100004002; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cible-energy.com",nocase; classtype:trojan-activity; sid:100004003; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cifeer.net",nocase; classtype:trojan-activity; sid:100004004; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"citycapproperty.ru",nocase; classtype:trojan-activity; sid:100004005; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cityglobalgospel.com",nocase; classtype:trojan-activity; sid:100004006; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"civi.istmejia.com",nocase; classtype:trojan-activity; sid:100004007; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cleanbydesignllc.com",nocase; classtype:trojan-activity; sid:100004008; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cloud.fc.co.mz",nocase; classtype:trojan-activity; sid:100004009; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"clurbgolf.com",nocase; classtype:trojan-activity; sid:100004010; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"codsambal.com",nocase; classtype:trojan-activity; sid:100004011; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"colinde.pricesne.com",nocase; classtype:trojan-activity; sid:100004012; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"colorpak.pl",nocase; classtype:trojan-activity; sid:100004013; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"competancy.indigoconsult.net",nocase; classtype:trojan-activity; sid:100004014; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"conceptimagine.ro",nocase; classtype:trojan-activity; sid:100004015; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"config.cqhbkjzx.com",nocase; classtype:trojan-activity; sid:100004016; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"constructoralyon.com",nocase; classtype:trojan-activity; sid:100004017; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"consulateins.solucioneslink.com",nocase; classtype:trojan-activity; sid:100004018; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"contributeindustry.com",nocase; classtype:trojan-activity; sid:100004019; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"controladoradeplagasmm.com",nocase; classtype:trojan-activity; sid:100004020; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"copelandscapes.com",nocase; classtype:trojan-activity; sid:100004021; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"corporativos.com.co",nocase; classtype:trojan-activity; sid:100004022; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"coulsongraphics.com",nocase; classtype:trojan-activity; sid:100004023; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"coutler.newreadermedia.net",nocase; classtype:trojan-activity; sid:100004024; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"covid19.cyberschool.or.id",nocase; classtype:trojan-activity; sid:100004025; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cr-sq.com",nocase; classtype:trojan-activity; sid:100004026; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crearechile.cl",nocase; classtype:trojan-activity; sid:100004027; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"creationskateboards.com",nocase; classtype:trojan-activity; sid:100004028; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crecerco.com",nocase; classtype:trojan-activity; sid:100004029; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crittersbythebay.com",nocase; classtype:trojan-activity; sid:100004030; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crm.notariavieitoyvelamazan.com",nocase; classtype:trojan-activity; sid:100004031; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"crscorretordeimoveis.com.br",nocase; classtype:trojan-activity; sid:100004032; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cse-engineer.com",nocase; classtype:trojan-activity; sid:100004033; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"csnserver.com",nocase; classtype:trojan-activity; sid:100004034; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cubescargoexpress.com",nocase; classtype:trojan-activity; sid:100004035; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cubrebocasenpuebla.com.mx",nocase; classtype:trojan-activity; sid:100004036; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"curasoles.co.za",nocase; classtype:trojan-activity; sid:100004037; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"currantmedia.com",nocase; classtype:trojan-activity; sid:100004038; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cwa.mx",nocase; classtype:trojan-activity; sid:100004039; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cyber.searchkero.com",nocase; classtype:trojan-activity; sid:100004040; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cyclomove.com",nocase; classtype:trojan-activity; sid:100004041; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cynkon.kairoscs.net",nocase; classtype:trojan-activity; sid:100004042; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"czas.dbstrony.pl",nocase; classtype:trojan-activity; sid:100004043; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"czsl.91756.cn",nocase; classtype:trojan-activity; sid:100004044; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"d.powerofwish.com",nocase; classtype:trojan-activity; sid:100004045; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"d9.99ddd.com",nocase; classtype:trojan-activity; sid:100004046; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"da.alibuf.com",nocase; classtype:trojan-activity; sid:100004047; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"damagedessentialtelecommunications.testmail4.repl.co",nocase; classtype:trojan-activity; sid:100004048; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dandyair.com",nocase; classtype:trojan-activity; sid:100004049; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dannexgh.com",nocase; classtype:trojan-activity; sid:100004050; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dartoonpictures.com",nocase; classtype:trojan-activity; sid:100004051; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"data.cdevelop.org",nocase; classtype:trojan-activity; sid:100004052; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"data.over-blog-kiwi.com",nocase; classtype:trojan-activity; sid:100004053; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"datapolish.com",nocase; classtype:trojan-activity; sid:100004054; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dating.khokhas.co.za",nocase; classtype:trojan-activity; sid:100004055; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"datsom.vn",nocase; classtype:trojan-activity; sid:100004056; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"daunhotq10.com",nocase; classtype:trojan-activity; sid:100004057; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"davethompson.me.uk",nocase; classtype:trojan-activity; sid:100004058; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"davidmcguinness.info",nocase; classtype:trojan-activity; sid:100004059; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dayspringdaisies.com",nocase; classtype:trojan-activity; sid:100004060; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dd.qiyuea.cn",nocase; classtype:trojan-activity; sid:100004061; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"de.gsearch.com.de",nocase; classtype:trojan-activity; sid:100004062; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"decifrar.com.br",nocase; classtype:trojan-activity; sid:100004063; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"deigratia2.elin.co.za",nocase; classtype:trojan-activity; sid:100004064; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dekovizyon.com",nocase; classtype:trojan-activity; sid:100004065; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"demo-cliente.mindcreative.com.br",nocase; classtype:trojan-activity; sid:100004066; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"demo6.hiites.com",nocase; classtype:trojan-activity; sid:100004067; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dent-estet.com",nocase; classtype:trojan-activity; sid:100004068; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dental.xiaoxiao.media",nocase; classtype:trojan-activity; sid:100004069; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dentalalliance.se",nocase; classtype:trojan-activity; sid:100004070; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"designerliving.co.za",nocase; classtype:trojan-activity; sid:100004071; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"desiringhands.com",nocase; classtype:trojan-activity; sid:100004072; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"despertaresi.com.br",nocase; classtype:trojan-activity; sid:100004073; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"destinymc.co.za",nocase; classtype:trojan-activity; sid:100004074; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"detorre.es",nocase; classtype:trojan-activity; sid:100004075; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dev-interestingtech.pantheonsite.io",nocase; classtype:trojan-activity; sid:100004076; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dev.sebpo.net",nocase; classtype:trojan-activity; sid:100004077; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dfcf.91756.cn",nocase; classtype:trojan-activity; sid:100004078; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dfsfcsfcdsfsdvcfsvcscv.com",nocase; classtype:trojan-activity; sid:100004079; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"diamantenegro.mi-fs.com",nocase; classtype:trojan-activity; sid:100004080; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dienmayminhhung.com",nocase; classtype:trojan-activity; sid:100004081; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"digilib.dianhusada.ac.id",nocase; classtype:trojan-activity; sid:100004082; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"djking.f3322.net",nocase; classtype:trojan-activity; sid:100004083; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.1003b.56a.com",nocase; classtype:trojan-activity; sid:100004084; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.198424.com",nocase; classtype:trojan-activity; sid:100004085; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.installcdn-aws.com",nocase; classtype:trojan-activity; sid:100004086; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.packetstormsecurity.net",nocase; classtype:trojan-activity; sid:100004087; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.rina-roleplay.com",nocase; classtype:trojan-activity; sid:100004088; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dl.zkytech.com",nocase; classtype:trojan-activity; sid:100004089; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dns.cyberium.cc",nocase; classtype:trojan-activity; sid:100004090; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dockerupdate.anondns.net",nocase; classtype:trojan-activity; sid:100004091; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"docman.orientalservices.in",nocase; classtype:trojan-activity; sid:100004092; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dodsonimaging.com",nocase; classtype:trojan-activity; sid:100004093; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dokan.blueberrytec.com",nocase; classtype:trojan-activity; sid:100004094; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dom-chel74.ru",nocase; classtype:trojan-activity; sid:100004095; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dom.daf.free.fr",nocase; classtype:trojan-activity; sid:100004096; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"doncedyhall.com",nocase; classtype:trojan-activity; sid:100004097; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"donghobinhminh.com",nocase; classtype:trojan-activity; sid:100004098; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dongphuctop.com",nocase; classtype:trojan-activity; sid:100004099; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dosame.com",nocase; classtype:trojan-activity; sid:100004100; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dosman.pl",nocase; classtype:trojan-activity; sid:100004101; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dovberger.com",nocase; classtype:trojan-activity; sid:100004102; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.flash-plays.com",nocase; classtype:trojan-activity; sid:100004103; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.pcclear.com",nocase; classtype:trojan-activity; sid:100004104; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.posti-fi-fsa.top",nocase; classtype:trojan-activity; sid:100004105; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.posti-fi-fwa.top",nocase; classtype:trojan-activity; sid:100004106; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.posti-fi-ij.top",nocase; classtype:trojan-activity; sid:100004107; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.posti-fi-in.top",nocase; classtype:trojan-activity; sid:100004108; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.posti-fi-iz.top",nocase; classtype:trojan-activity; sid:100004109; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.udashi.com",nocase; classtype:trojan-activity; sid:100004110; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down.webbora.com",nocase; classtype:trojan-activity; sid:100004111; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"down1.arpun.com",nocase; classtype:trojan-activity; sid:100004112; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.caihong.com",nocase; classtype:trojan-activity; sid:100004113; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.doumaibiji.cn",nocase; classtype:trojan-activity; sid:100004114; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.exrnybuf.cn",nocase; classtype:trojan-activity; sid:100004115; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.kaobeitu.com",nocase; classtype:trojan-activity; sid:100004116; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.pdf00.cn",nocase; classtype:trojan-activity; sid:100004117; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.rising.com.cn",nocase; classtype:trojan-activity; sid:100004118; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.skycn.com",nocase; classtype:trojan-activity; sid:100004119; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"download.zjsyawqj.cn",nocase; classtype:trojan-activity; sid:100004120; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"downloads.jxtsteel.cn",nocase; classtype:trojan-activity; sid:100004121; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dragonsknot.com",nocase; classtype:trojan-activity; sid:100004122; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drbaby.com.sa",nocase; classtype:trojan-activity; sid:100004123; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drohnen.ensenanzainteligente.com",nocase; classtype:trojan-activity; sid:100004124; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drools-moved.46999.n3.nabble.com",nocase; classtype:trojan-activity; sid:100004125; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drsha.innovativesolutions.mobi",nocase; classtype:trojan-activity; sid:100004126; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dsenterprize.co.za",nocase; classtype:trojan-activity; sid:100004127; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dsspainting.com",nocase; classtype:trojan-activity; sid:100004128; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"du-wizards.com",nocase; classtype:trojan-activity; sid:100004129; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"duque.guantanameratravel.com",nocase; classtype:trojan-activity; sid:100004130; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dutapp.wisolve.co.za",nocase; classtype:trojan-activity; sid:100004131; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"duvalcharter.dekitout.com",nocase; classtype:trojan-activity; sid:100004132; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dx.qqyewu.com",nocase; classtype:trojan-activity; sid:100004133; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"dzinestudio87.co.uk",nocase; classtype:trojan-activity; sid:100004134; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"e-commerce.saleensuporte.com.br",nocase; classtype:trojan-activity; sid:100004135; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"e.sldov.ru",nocase; classtype:trojan-activity; sid:100004136; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ebruyatkin.com",nocase; classtype:trojan-activity; sid:100004137; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"econews.treegle.org",nocase; classtype:trojan-activity; sid:100004138; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"efficientegroup.com",nocase; classtype:trojan-activity; sid:100004139; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"elliot.newreadermedia.net",nocase; classtype:trojan-activity; sid:100004140; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"en.baoend.com",nocase; classtype:trojan-activity; sid:100004141; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"enc-tech.com",nocase; classtype:trojan-activity; sid:100004142; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"endurotanzania.co.tz",nocase; classtype:trojan-activity; sid:100004143; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ennovate.elin.co.za",nocase; classtype:trojan-activity; sid:100004144; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"enriquecendocomconsorcio.com.br",nocase; classtype:trojan-activity; sid:100004145; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"envios.petpienso.cl",nocase; classtype:trojan-activity; sid:100004146; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"equimination.ee",nocase; classtype:trojan-activity; sid:100004147; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"escola.probommar.org.br",nocase; classtype:trojan-activity; sid:100004148; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"esnconsultants.com",nocase; classtype:trojan-activity; sid:100004149; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"essentia.org.br",nocase; classtype:trojan-activity; sid:100004150; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"eubanks7.com",nocase; classtype:trojan-activity; sid:100004151; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"evidencemarketing.ca",nocase; classtype:trojan-activity; sid:100004152; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exilum.com",nocase; classtype:trojan-activity; sid:100004153; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exitoalfaomega.co",nocase; classtype:trojan-activity; sid:100004154; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"extrovertoffers.com",nocase; classtype:trojan-activity; sid:100004155; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"f1sol.com",nocase; classtype:trojan-activity; sid:100004156; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"familydentist.site",nocase; classtype:trojan-activity; sid:100004157; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"farmaciasdrogaminas.com.br",nocase; classtype:trojan-activity; sid:100004158; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"faveraprojects.com",nocase; classtype:trojan-activity; sid:100004159; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fc.co.mz",nocase; classtype:trojan-activity; sid:100004160; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"felicienne.nl",nocase; classtype:trojan-activity; sid:100004161; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fi.bonitastores.com",nocase; classtype:trojan-activity; sid:100004162; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"files.martellexpress.us",nocase; classtype:trojan-activity; sid:100004163; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"files6.uludagbilisim.com",nocase; classtype:trojan-activity; sid:100004164; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"final.makkahkmcc.com",nocase; classtype:trojan-activity; sid:100004165; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fineartgallerym.com",nocase; classtype:trojan-activity; sid:100004166; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fkd.derpcity.ru",nocase; classtype:trojan-activity; sid:100004167; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"flintspin.com",nocase; classtype:trojan-activity; sid:100004168; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"flyingbuddhadesign.com",nocase; classtype:trojan-activity; sid:100004169; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fmjplastering.co.uk",nocase; classtype:trojan-activity; sid:100004170; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fms.buladde.or.ug",nocase; classtype:trojan-activity; sid:100004171; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"foothills.com.br",nocase; classtype:trojan-activity; sid:100004172; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"footweardirect.elin.co.za",nocase; classtype:trojan-activity; sid:100004173; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"forum.mdb.nu",nocase; classtype:trojan-activity; sid:100004174; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fotoobjetivo.com",nocase; classtype:trojan-activity; sid:100004175; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"foundationrepairhoustontx.net",nocase; classtype:trojan-activity; sid:100004176; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"foxeps.com.br",nocase; classtype:trojan-activity; sid:100004177; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"freecnetdownload.com",nocase; classtype:trojan-activity; sid:100004178; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"freisites.com.br",nocase; classtype:trojan-activity; sid:100004179; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ftp.n3twork30cm.ml",nocase; classtype:trojan-activity; sid:100004180; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fullelectronica.com.ar",nocase; classtype:trojan-activity; sid:100004181; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"funletters.net",nocase; classtype:trojan-activity; sid:100004182; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"fusionfiresolutions.com",nocase; classtype:trojan-activity; sid:100004183; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"futuregraphics.com.ar",nocase; classtype:trojan-activity; sid:100004184; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gametwogame.com",nocase; classtype:trojan-activity; sid:100004185; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"garayvidalabogados.com",nocase; classtype:trojan-activity; sid:100004186; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"garciadogshow.com",nocase; classtype:trojan-activity; sid:100004187; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"garenanow.myvnc.com",nocase; classtype:trojan-activity; sid:100004188; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"garenanow4.myvnc.com",nocase; classtype:trojan-activity; sid:100004189; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gbbulls.co.uk",nocase; classtype:trojan-activity; sid:100004190; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gcpc.co.id.chronoscurtain.com",nocase; classtype:trojan-activity; sid:100004191; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"generaldeviales.com",nocase; classtype:trojan-activity; sid:100004192; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gfmodd1.webselffiles01.com",nocase; classtype:trojan-activity; sid:100004193; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gfold1.webselffiles01.com",nocase; classtype:trojan-activity; sid:100004194; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ghettohub.co.za",nocase; classtype:trojan-activity; sid:100004195; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ghislain.dartois.pagesperso-orange.fr",nocase; classtype:trojan-activity; sid:100004196; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"giadungg7.com",nocase; classtype:trojan-activity; sid:100004197; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"giddos.ga",nocase; classtype:trojan-activity; sid:100004198; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gilliem.com",nocase; classtype:trojan-activity; sid:100004199; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"girotexuniformes.com",nocase; classtype:trojan-activity; sid:100004200; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"giteletropical.com",nocase; classtype:trojan-activity; sid:100004201; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"globaltask.ar",nocase; classtype:trojan-activity; sid:100004202; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"glowinmedia.co.ke",nocase; classtype:trojan-activity; sid:100004203; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gmtransformationacademy.com",nocase; classtype:trojan-activity; sid:100004204; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gmvadmission.org",nocase; classtype:trojan-activity; sid:100004205; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gnimelf.net",nocase; classtype:trojan-activity; sid:100004206; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gnscrew.ro",nocase; classtype:trojan-activity; sid:100004207; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gold.investforex.id",nocase; classtype:trojan-activity; sid:100004208; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldcake.co.id",nocase; classtype:trojan-activity; sid:100004209; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldcoastoffice365.com",nocase; classtype:trojan-activity; sid:100004210; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldcoastoffice365.com.au",nocase; classtype:trojan-activity; sid:100004211; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldcupmortgage.com",nocase; classtype:trojan-activity; sid:100004212; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"golden-memories-funerals.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004213; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"goldmen.in",nocase; classtype:trojan-activity; sid:100004214; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gorecycle.fahadjutt.com",nocase; classtype:trojan-activity; sid:100004215; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gracejukes.com",nocase; classtype:trojan-activity; sid:100004216; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"grupoinmare.com",nocase; classtype:trojan-activity; sid:100004217; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gruposelt.000webhostapp.com",nocase; classtype:trojan-activity; sid:100004218; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gs.monerorx.com",nocase; classtype:trojan-activity; sid:100004219; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"guide-to-cell-phones.com",nocase; classtype:trojan-activity; sid:100004220; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gulfac-house.com",nocase; classtype:trojan-activity; sid:100004221; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gvpcdpgc.edu.in",nocase; classtype:trojan-activity; sid:100004222; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"habbotips.free.fr",nocase; classtype:trojan-activity; sid:100004223; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hagebakken.no",nocase; classtype:trojan-activity; sid:100004224; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"harrisauto.no",nocase; classtype:trojan-activity; sid:100004225; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"harshraval.in",nocase; classtype:trojan-activity; sid:100004226; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hd11315.com",nocase; classtype:trojan-activity; sid:100004227; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hdkamera2003.hu",nocase; classtype:trojan-activity; sid:100004228; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hdrest.fastlinktz.com",nocase; classtype:trojan-activity; sid:100004229; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hds.sz4h.com",nocase; classtype:trojan-activity; sid:100004230; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"healthy20.net",nocase; classtype:trojan-activity; sid:100004231; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hechiceriadeamormaestrabelen.com.hechiceriadeamormaestrabelen.com",nocase; classtype:trojan-activity; sid:100004232; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hellogorgeous.com.au",nocase; classtype:trojan-activity; sid:100004233; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"help.hizuko.com",nocase; classtype:trojan-activity; sid:100004234; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"herchinfitout.com.sg",nocase; classtype:trojan-activity; sid:100004235; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hhaward.org",nocase; classtype:trojan-activity; sid:100004236; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"highlandroadcoc.com",nocase; classtype:trojan-activity; sid:100004237; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"highlandslasvegas.atakdev.com",nocase; classtype:trojan-activity; sid:100004238; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hindi.factsriver.com",nocase; classtype:trojan-activity; sid:100004239; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hiptool.net",nocase; classtype:trojan-activity; sid:100004240; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hitpe.com",nocase; classtype:trojan-activity; sid:100004241; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hitstation.nl",nocase; classtype:trojan-activity; sid:100004242; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hmpmall.co.kr",nocase; classtype:trojan-activity; sid:100004243; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hoagietesting10.com",nocase; classtype:trojan-activity; sid:100004244; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hoayeuthuong-my.sharepoint.com",nocase; classtype:trojan-activity; sid:100004245; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"holmesprpmgmt.com",nocase; classtype:trojan-activity; sid:100004246; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"homefindersolutions.com",nocase; classtype:trojan-activity; sid:100004247; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hongluosi.com",nocase; classtype:trojan-activity; sid:100004248; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hookedupboatclub.com",nocase; classtype:trojan-activity; sid:100004249; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hostelkielce.com",nocase; classtype:trojan-activity; sid:100004250; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hostzaa.com",nocase; classtype:trojan-activity; sid:100004251; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"houstonshutters.site",nocase; classtype:trojan-activity; sid:100004252; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hr2019.vrcom7.com",nocase; classtype:trojan-activity; sid:100004253; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hseda.com",nocase; classtype:trojan-activity; sid:100004254; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hsmwebapp.com",nocase; classtype:trojan-activity; sid:100004255; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"htownbars.com",nocase; classtype:trojan-activity; sid:100004256; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hubtech.co.za",nocase; classtype:trojan-activity; sid:100004257; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hunggiang.vn",nocase; classtype:trojan-activity; sid:100004258; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"husamiyahschool.com",nocase; classtype:trojan-activity; sid:100004259; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iam313.com",nocase; classtype:trojan-activity; sid:100004260; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"icon.shatangmu.cn",nocase; classtype:trojan-activity; sid:100004261; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idea-secure-login.com",nocase; classtype:trojan-activity; sid:100004262; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idilsoft.com",nocase; classtype:trojan-activity; sid:100004263; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idj.no",nocase; classtype:trojan-activity; sid:100004264; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"idvindia.com",nocase; classtype:trojan-activity; sid:100004265; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iesanjosemonitos.edu.co",nocase; classtype:trojan-activity; sid:100004266; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ikexpert.com",nocase; classtype:trojan-activity; sid:100004267; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ilrafrica.com",nocase; classtype:trojan-activity; sid:100004268; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"images.jermiau.com",nocase; classtype:trojan-activity; sid:100004269; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"imbueautoworx.co.za",nocase; classtype:trojan-activity; sid:100004270; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"imperiumtherapy.co.za",nocase; classtype:trojan-activity; sid:100004271; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"in-tune2016.com",nocase; classtype:trojan-activity; sid:100004272; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"incodimsa.com",nocase; classtype:trojan-activity; sid:100004273; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"incrediblepixels.com",nocase; classtype:trojan-activity; sid:100004274; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"incredicole.com",nocase; classtype:trojan-activity; sid:100004275; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"industriasyuli.com",nocase; classtype:trojan-activity; sid:100004276; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"infair.vn",nocase; classtype:trojan-activity; sid:100004277; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"infovator.com",nocase; classtype:trojan-activity; sid:100004278; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"innatosbrand.com",nocase; classtype:trojan-activity; sid:100004279; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"inodesthetotaldesigners.com",nocase; classtype:trojan-activity; sid:100004280; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"inovations.searchkero.com",nocase; classtype:trojan-activity; sid:100004281; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"inrajahmundry.co.in",nocase; classtype:trojan-activity; sid:100004282; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"insignificantfinecore.testmail4.repl.co",nocase; classtype:trojan-activity; sid:100004283; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"instantindialoan.com",nocase; classtype:trojan-activity; sid:100004284; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"instvisionmexico.edu.mx",nocase; classtype:trojan-activity; sid:100004285; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"intellectsmart.in",nocase; classtype:trojan-activity; sid:100004286; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"intersel-idf.org",nocase; classtype:trojan-activity; sid:100004287; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"intuitiveideas.com.my",nocase; classtype:trojan-activity; sid:100004288; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"inversiones.arrayanfinanciero.cl",nocase; classtype:trojan-activity; sid:100004289; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"invest.xpcorporative.com.br",nocase; classtype:trojan-activity; sid:100004290; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ipmes.ma",nocase; classtype:trojan-activity; sid:100004291; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iremart.es",nocase; classtype:trojan-activity; sid:100004292; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iris101.co.uk",nocase; classtype:trojan-activity; sid:100004293; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iscamenabe.com",nocase; classtype:trojan-activity; sid:100004294; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ismf.com.ng",nocase; classtype:trojan-activity; sid:100004295; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"iso-dubai.net",nocase; classtype:trojan-activity; sid:100004296; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"israrulhaq.me",nocase; classtype:trojan-activity; sid:100004297; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"isrorg.com",nocase; classtype:trojan-activity; sid:100004298; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"issmbour.falllo.com",nocase; classtype:trojan-activity; sid:100004299; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"isso.ps",nocase; classtype:trojan-activity; sid:100004300; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"it123.ru",nocase; classtype:trojan-activity; sid:100004301; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"itc-demo.softgig.co.ke",nocase; classtype:trojan-activity; sid:100004302; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"itconsultus.com.co",nocase; classtype:trojan-activity; sid:100004303; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jamesjorgensen.newreadermedia.net",nocase; classtype:trojan-activity; sid:100004304; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jamiekaylive.com",nocase; classtype:trojan-activity; sid:100004305; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jamshed.pk",nocase; classtype:trojan-activity; sid:100004306; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jansen-heesch.nl",nocase; classtype:trojan-activity; sid:100004307; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jathra.co.uk",nocase; classtype:trojan-activity; sid:100004308; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jay.diamondrelationscrm.us",nocase; classtype:trojan-activity; sid:100004309; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jebs.net.au",nocase; classtype:trojan-activity; sid:100004310; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jeffdahlke.com",nocase; classtype:trojan-activity; sid:100004311; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jhayesconsulting.com",nocase; classtype:trojan-activity; sid:100004312; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jiaoyuzixun.cn",nocase; classtype:trojan-activity; sid:100004313; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jing-da.com.tw",nocase; classtype:trojan-activity; sid:100004314; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jktnet.xyz",nocase; classtype:trojan-activity; sid:100004315; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jmtc.91756.cn",nocase; classtype:trojan-activity; sid:100004316; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jnanbharati.com",nocase; classtype:trojan-activity; sid:100004317; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jobs.thebeessolution.com",nocase; classtype:trojan-activity; sid:100004318; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"joelbonissilver.com",nocase; classtype:trojan-activity; sid:100004319; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"join.cl8movement.co.za",nocase; classtype:trojan-activity; sid:100004320; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"josegene.com",nocase; classtype:trojan-activity; sid:100004321; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"josuarochoa.com",nocase; classtype:trojan-activity; sid:100004322; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jpwoodfordco.com",nocase; classtype:trojan-activity; sid:100004323; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jumpmanualjacobhiller.com",nocase; classtype:trojan-activity; sid:100004324; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jupiter.toxsl.in",nocase; classtype:trojan-activity; sid:100004325; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jurgensen.newreadermedia.net",nocase; classtype:trojan-activity; sid:100004326; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"justinscott.com.au",nocase; classtype:trojan-activity; sid:100004327; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kaizenjanitorial.com",nocase; classtype:trojan-activity; sid:100004328; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kalawatihomes.com",nocase; classtype:trojan-activity; sid:100004329; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kalpataru-elitus-mulund.thakkers.in",nocase; classtype:trojan-activity; sid:100004330; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"karer.by",nocase; classtype:trojan-activity; sid:100004331; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"katanvetov.co.il",nocase; classtype:trojan-activity; sid:100004332; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kbdom.com",nocase; classtype:trojan-activity; sid:100004333; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kensingtondriving.com",nocase; classtype:trojan-activity; sid:100004334; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kevinjewelry.com.co",nocase; classtype:trojan-activity; sid:100004335; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"keywatch.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004336; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kingssa.co.za",nocase; classtype:trojan-activity; sid:100004337; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kjcpromo.com",nocase; classtype:trojan-activity; sid:100004338; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kleinendeli.co.za",nocase; classtype:trojan-activity; sid:100004339; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"korrectconceptservices.com",nocase; classtype:trojan-activity; sid:100004340; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ktb.sch.id",nocase; classtype:trojan-activity; sid:100004341; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kubatoglubaklava.com.tr",nocase; classtype:trojan-activity; sid:100004342; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kumaralok.in",nocase; classtype:trojan-activity; sid:100004343; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kwanfromhongkong.com",nocase; classtype:trojan-activity; sid:100004344; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kz.sldov.ru",nocase; classtype:trojan-activity; sid:100004345; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lab18.it",nocase; classtype:trojan-activity; sid:100004346; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lacasadelosalebrijes.com",nocase; classtype:trojan-activity; sid:100004347; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ladylabonde.com",nocase; classtype:trojan-activity; sid:100004348; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lameguard.ru",nocase; classtype:trojan-activity; sid:100004349; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"landing.yetiapp.ec",nocase; classtype:trojan-activity; sid:100004350; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"laodongnhat.vn",nocase; classtype:trojan-activity; sid:100004351; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"laravel.pointersoftwares.com.br",nocase; classtype:trojan-activity; sid:100004352; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lasermobilesounds.co.uk",nocase; classtype:trojan-activity; sid:100004353; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lauratomismith.com",nocase; classtype:trojan-activity; sid:100004354; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lautarosanmiguel.com",nocase; classtype:trojan-activity; sid:100004355; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lawforall.edu.lk",nocase; classtype:trojan-activity; sid:100004356; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lceventos.net",nocase; classtype:trojan-activity; sid:100004357; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ld.mediaget.com",nocase; classtype:trojan-activity; sid:100004358; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ldgcorp.com",nocase; classtype:trojan-activity; sid:100004359; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"learning.real-academy.net",nocase; classtype:trojan-activity; sid:100004360; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"leasiacherise.com",nocase; classtype:trojan-activity; sid:100004361; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"leczkregoslup.acelero.pl",nocase; classtype:trojan-activity; sid:100004362; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"legend.nu",nocase; classtype:trojan-activity; sid:100004363; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"leluibuffet.com.br",nocase; classtype:trojan-activity; sid:100004364; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lestesteux.ca",nocase; classtype:trojan-activity; sid:100004365; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"libantravel.pl",nocase; classtype:trojan-activity; sid:100004366; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"library.arihantmbainstitute.ac.in",nocase; classtype:trojan-activity; sid:100004367; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"library.uib.ac.id",nocase; classtype:trojan-activity; sid:100004368; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lickmylash.com",nocase; classtype:trojan-activity; sid:100004369; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lidoraggiodisole.it",nocase; classtype:trojan-activity; sid:100004370; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lifebeam.elin.co.za",nocase; classtype:trojan-activity; sid:100004371; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lindnerelektroanlagen.de",nocase; classtype:trojan-activity; sid:100004372; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"linkintec.cn",nocase; classtype:trojan-activity; sid:100004373; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"litroxlitro.com",nocase; classtype:trojan-activity; sid:100004374; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"livetrack.in",nocase; classtype:trojan-activity; sid:100004375; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lloydsindian.co.uk",nocase; classtype:trojan-activity; sid:100004376; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lm.stagingarea.co.za",nocase; classtype:trojan-activity; sid:100004377; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lmaancha.co.il",nocase; classtype:trojan-activity; sid:100004378; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lms.cstdevs.com",nocase; classtype:trojan-activity; sid:100004379; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lms.login2.in",nocase; classtype:trojan-activity; sid:100004380; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lmvirtualbookkeeping.com",nocase; classtype:trojan-activity; sid:100004381; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lnt-rejuve-360.thakkers.in",nocase; classtype:trojan-activity; sid:100004382; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"location-voitures.ma",nocase; classtype:trojan-activity; sid:100004383; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"login.trezor.com.stockfootagesindia.com",nocase; classtype:trojan-activity; sid:100004384; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"logotypfabriken.se",nocase; classtype:trojan-activity; sid:100004385; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lotix.de",nocase; classtype:trojan-activity; sid:100004386; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lotusanddragonfly.com",nocase; classtype:trojan-activity; sid:100004387; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lp.definerisco.com",nocase; classtype:trojan-activity; sid:100004388; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lp.difusodesign.com",nocase; classtype:trojan-activity; sid:100004389; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lp.juancamilogarciareyes.com",nocase; classtype:trojan-activity; sid:100004390; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"lp.tecnimasdecolombia.com.co",nocase; classtype:trojan-activity; sid:100004391; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ltc.typoten.com",nocase; classtype:trojan-activity; sid:100004392; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"luckybrownie.com",nocase; classtype:trojan-activity; sid:100004393; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"luminouspneuma.com",nocase; classtype:trojan-activity; sid:100004394; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"luxomodels.com",nocase; classtype:trojan-activity; sid:100004395; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"m-technics.kz",nocase; classtype:trojan-activity; sid:100004396; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"m.estudiomoros.com.ar",nocase; classtype:trojan-activity; sid:100004397; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"madicon.co.za",nocase; classtype:trojan-activity; sid:100004398; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"magianegramagiablancayamarres.com",nocase; classtype:trojan-activity; sid:100004399; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mail.bs-eiendomme.co.za",nocase; classtype:trojan-activity; sid:100004400; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mail.golimoapp.com",nocase; classtype:trojan-activity; sid:100004401; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mail.jeffsono.org",nocase; classtype:trojan-activity; sid:100004402; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"maksi.feb.unib.ac.id",nocase; classtype:trojan-activity; sid:100004403; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"malaya.tv",nocase; classtype:trojan-activity; sid:100004404; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"malwarecoding.github.io",nocase; classtype:trojan-activity; sid:100004405; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"managed.oss-cn-beijing.aliyuncs.com",nocase; classtype:trojan-activity; sid:100004406; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"managemysalon.in",nocase; classtype:trojan-activity; sid:100004407; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"manantialesdelnorte.uy",nocase; classtype:trojan-activity; sid:100004408; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marcapinyo.ru",nocase; classtype:trojan-activity; sid:100004409; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mario-sunjic.com",nocase; classtype:trojan-activity; sid:100004410; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mariobrown.net",nocase; classtype:trojan-activity; sid:100004411; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mariotessarollo.com",nocase; classtype:trojan-activity; sid:100004412; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marketinfosales.com",nocase; classtype:trojan-activity; sid:100004413; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marketing.enexusgroup.com.au",nocase; classtype:trojan-activity; sid:100004414; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"marksidfgs.ug",nocase; classtype:trojan-activity; sid:100004415; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"masjidhabeebiyarazviya.mysunni.com",nocase; classtype:trojan-activity; sid:100004416; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"materialescantu.com",nocase; classtype:trojan-activity; sid:100004417; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"matruchhaya.co.in",nocase; classtype:trojan-activity; sid:100004418; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mattysplayground.com",nocase; classtype:trojan-activity; sid:100004419; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"maxtox.com.pk",nocase; classtype:trojan-activity; sid:100004420; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mbgrm.com",nocase; classtype:trojan-activity; sid:100004421; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mbsolutions.ge",nocase; classtype:trojan-activity; sid:100004422; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mdasa.elin.co.za",nocase; classtype:trojan-activity; sid:100004423; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"medevlb.org",nocase; classtype:trojan-activity; sid:100004424; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"media-server.skyinternet.com.pk",nocase; classtype:trojan-activity; sid:100004425; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mediamaster.co.za",nocase; classtype:trojan-activity; sid:100004426; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"medianews.ge",nocase; classtype:trojan-activity; sid:100004427; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"medistaffconsulting.com",nocase; classtype:trojan-activity; sid:100004428; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"meditreat.itwebservice.in",nocase; classtype:trojan-activity; sid:100004429; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"meeweb.com",nocase; classtype:trojan-activity; sid:100004430; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"megamart.afnan-amc.com",nocase; classtype:trojan-activity; sid:100004431; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"merbay.ru",nocase; classtype:trojan-activity; sid:100004432; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"merkathink.com",nocase; classtype:trojan-activity; sid:100004433; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mertlog.com",nocase; classtype:trojan-activity; sid:100004434; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"metalin-cr.com",nocase; classtype:trojan-activity; sid:100004435; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mettaanand.org",nocase; classtype:trojan-activity; sid:100004436; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"meuoculosnanet.com.br",nocase; classtype:trojan-activity; sid:100004437; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mfevr.com",nocase; classtype:trojan-activity; sid:100004438; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mhkdhotbot.myvnc.com",nocase; classtype:trojan-activity; sid:100004439; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mhkdhotbot80.myvnc.com",nocase; classtype:trojan-activity; sid:100004440; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"micalle.com.au",nocase; classtype:trojan-activity; sid:100004441; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"michaelphilip.com",nocase; classtype:trojan-activity; sid:100004442; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"michimal2.000webhostapp.com",nocase; classtype:trojan-activity; sid:100004443; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"microblading.mirliandias.com.br",nocase; classtype:trojan-activity; sid:100004444; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"microcomm-group.com",nocase; classtype:trojan-activity; sid:100004445; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"midlandtexasconstruction.com",nocase; classtype:trojan-activity; sid:100004446; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mindfulbuildingandliving.com",nocase; classtype:trojan-activity; sid:100004447; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mingguanwms.com",nocase; classtype:trojan-activity; sid:100004448; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"minuevavida.org",nocase; classtype:trojan-activity; sid:100004449; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mis.nbcc.ac.th",nocase; classtype:trojan-activity; sid:100004450; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"misterson.com",nocase; classtype:trojan-activity; sid:100004451; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mixr.at",nocase; classtype:trojan-activity; sid:100004452; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mkontakt.az",nocase; classtype:trojan-activity; sid:100004453; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mktf.mx",nocase; classtype:trojan-activity; sid:100004454; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mmogollon.com.mx",nocase; classtype:trojan-activity; sid:100004455; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mncarteam.com",nocase; classtype:trojan-activity; sid:100004456; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mobile.illumetechnology.com",nocase; classtype:trojan-activity; sid:100004457; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"modelhouseturkey.com",nocase; classtype:trojan-activity; sid:100004458; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"modernmanna.org",nocase; classtype:trojan-activity; sid:100004459; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"monetization.business",nocase; classtype:trojan-activity; sid:100004460; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"moninediy.com",nocase; classtype:trojan-activity; sid:100004461; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mopai.sg",nocase; classtype:trojan-activity; sid:100004462; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"motorcomunicacion.com",nocase; classtype:trojan-activity; sid:100004463; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"msacontabil.com.br",nocase; classtype:trojan-activity; sid:100004464; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mtspsmjeli.sch.id",nocase; classtype:trojan-activity; sid:100004465; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"muzimbiti.xigubo.co.mz",nocase; classtype:trojan-activity; sid:100004466; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mxpiqw.am.files.1drv.com",nocase; classtype:trojan-activity; sid:100004467; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mydatebook.in",nocase; classtype:trojan-activity; sid:100004468; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mymlql.com",nocase; classtype:trojan-activity; sid:100004469; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"myritz.vettickal.com",nocase; classtype:trojan-activity; sid:100004470; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"myscape.in",nocase; classtype:trojan-activity; sid:100004471; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"mysura.it",nocase; classtype:trojan-activity; sid:100004472; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"namnyak.co.ke",nocase; classtype:trojan-activity; sid:100004473; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nap.mgsservers.com",nocase; classtype:trojan-activity; sid:100004474; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"navayurveda.in",nocase; classtype:trojan-activity; sid:100004475; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nec-i.com",nocase; classtype:trojan-activity; sid:100004476; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nelitrianggraeni.000webhostapp.com",nocase; classtype:trojan-activity; sid:100004477; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nerve.untergrund.net",nocase; classtype:trojan-activity; sid:100004478; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nettube.com.br",nocase; classtype:trojan-activity; sid:100004479; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"networkwheels.co.za",nocase; classtype:trojan-activity; sid:100004480; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"neuroenergy.fahadjutt.com",nocase; classtype:trojan-activity; sid:100004481; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"neuromedic.com.br",nocase; classtype:trojan-activity; sid:100004482; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"neverseenshop.com.mx",nocase; classtype:trojan-activity; sid:100004483; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newinfinitysynergy.com",nocase; classtype:trojan-activity; sid:100004484; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"news.dbstrony.pl",nocase; classtype:trojan-activity; sid:100004485; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newtreedesign.co.uk",nocase; classtype:trojan-activity; sid:100004486; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newtrendeg.com",nocase; classtype:trojan-activity; sid:100004487; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newvisionopticallab.com",nocase; classtype:trojan-activity; sid:100004488; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newxing.com",nocase; classtype:trojan-activity; sid:100004489; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nextdigitalday.ru",nocase; classtype:trojan-activity; sid:100004490; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ngdaycare.co.za",nocase; classtype:trojan-activity; sid:100004491; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nguyenkekhuyen.com",nocase; classtype:trojan-activity; sid:100004492; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nhorangtreem.com",nocase; classtype:trojan-activity; sid:100004493; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nicolas.ug",nocase; classtype:trojan-activity; sid:100004494; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nidhi.iexist.in",nocase; classtype:trojan-activity; sid:100004495; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nikanpolimer.ir",nocase; classtype:trojan-activity; sid:100004496; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nilehouse.co.ug",nocase; classtype:trojan-activity; sid:100004497; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nilinkeji.com",nocase; classtype:trojan-activity; sid:100004498; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"njtiledesigncenter.com",nocase; classtype:trojan-activity; sid:100004499; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nobius.org",nocase; classtype:trojan-activity; sid:100004500; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nocalnoodle.elin.co.za",nocase; classtype:trojan-activity; sid:100004501; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nomadicbees.com",nocase; classtype:trojan-activity; sid:100004502; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nonnarina.ax",nocase; classtype:trojan-activity; sid:100004503; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"notamuzikaletleri.com",nocase; classtype:trojan-activity; sid:100004504; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"notif1.priruz.co.in",nocase; classtype:trojan-activity; sid:100004505; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ns1.the-widyantos.com",nocase; classtype:trojan-activity; sid:100004506; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nsb.org.uk",nocase; classtype:trojan-activity; sid:100004507; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nsheldon.co.uk",nocase; classtype:trojan-activity; sid:100004508; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nurmarkaz.org",nocase; classtype:trojan-activity; sid:100004509; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nuthuassociates.com",nocase; classtype:trojan-activity; sid:100004510; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nuwagi.com",nocase; classtype:trojan-activity; sid:100004511; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nyeh2o.com.au",nocase; classtype:trojan-activity; sid:100004512; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oakleyandfriends.co.uk",nocase; classtype:trojan-activity; sid:100004513; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"obseques-conseils.com",nocase; classtype:trojan-activity; sid:100004514; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ocean.tecnasulstore.com.br",nocase; classtype:trojan-activity; sid:100004515; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ohe.ie",nocase; classtype:trojan-activity; sid:100004516; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ohsewgorgeous.co.uk",nocase; classtype:trojan-activity; sid:100004517; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oknoplastik.sk",nocase; classtype:trojan-activity; sid:100004518; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oleholeh.memangbeda.website",nocase; classtype:trojan-activity; sid:100004519; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"olirecords.mixture.ltd",nocase; classtype:trojan-activity; sid:100004520; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"olooom.com",nocase; classtype:trojan-activity; sid:100004521; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omaia.org",nocase; classtype:trojan-activity; sid:100004522; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omaromatic.com",nocase; classtype:trojan-activity; sid:100004523; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omega.az",nocase; classtype:trojan-activity; sid:100004524; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oms.pappai.com",nocase; classtype:trojan-activity; sid:100004525; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"omscoc.pappai.com",nocase; classtype:trojan-activity; sid:100004526; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedigitalcard.granvizionnecorp.com",nocase; classtype:trojan-activity; sid:100004527; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.listifyapp.co",nocase; classtype:trojan-activity; sid:100004528; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"online.creedglobal.in",nocase; classtype:trojan-activity; sid:100004529; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onlinestatis.bar",nocase; classtype:trojan-activity; sid:100004530; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ont.proman.id",nocase; classtype:trojan-activity; sid:100004531; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"open.warehousesaas.co.uk",nocase; classtype:trojan-activity; sid:100004532; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"opolis.io",nocase; classtype:trojan-activity; sid:100004533; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"optimus.com.sg",nocase; classtype:trojan-activity; sid:100004534; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"optitechsa.co.za",nocase; classtype:trojan-activity; sid:100004535; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"order.bizpeed.com",nocase; classtype:trojan-activity; sid:100004536; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"orientgatewayltd.com",nocase; classtype:trojan-activity; sid:100004537; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"orion445.com",nocase; classtype:trojan-activity; sid:100004538; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oserve.pk",nocase; classtype:trojan-activity; sid:100004539; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"otolithenrichment.fahadjutt.com",nocase; classtype:trojan-activity; sid:100004540; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ottimade.com",nocase; classtype:trojan-activity; sid:100004541; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ourteam.searchkero.com",nocase; classtype:trojan-activity; sid:100004542; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ozemag.com",nocase; classtype:trojan-activity; sid:100004543; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"p1.lingpao8.com",nocase; classtype:trojan-activity; sid:100004544; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"p3.zbjimg.com",nocase; classtype:trojan-activity; sid:100004545; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"p6.zbjimg.com",nocase; classtype:trojan-activity; sid:100004546; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pablobrothel.com.ar",nocase; classtype:trojan-activity; sid:100004547; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pacificgroup.ws",nocase; classtype:trojan-activity; sid:100004548; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pacwebdesigns.com",nocase; classtype:trojan-activity; sid:100004549; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pagos.krayem.com.mx",nocase; classtype:trojan-activity; sid:100004550; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"palochusvet.szm.com",nocase; classtype:trojan-activity; sid:100004551; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"parallel.rockvideos.at",nocase; classtype:trojan-activity; sid:100004552; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"parejasfelices.mi-fs.com",nocase; classtype:trojan-activity; sid:100004553; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"parkhussion.com",nocase; classtype:trojan-activity; sid:100004554; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pastorpaulocosta.com",nocase; classtype:trojan-activity; sid:100004555; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"patch2.51lg.com",nocase; classtype:trojan-activity; sid:100004556; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"patch2.99ddd.com",nocase; classtype:trojan-activity; sid:100004557; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"patch3.99ddd.com",nocase; classtype:trojan-activity; sid:100004558; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"paths.elin.co.za",nocase; classtype:trojan-activity; sid:100004559; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"paulmercier.biz",nocase; classtype:trojan-activity; sid:100004560; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"payerrealty.com",nocase; classtype:trojan-activity; sid:100004561; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"payments.atifsiddiqui.me",nocase; classtype:trojan-activity; sid:100004562; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pcsoori.com",nocase; classtype:trojan-activity; sid:100004563; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pd.oceaniarp.net",nocase; classtype:trojan-activity; sid:100004564; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"perpus.onlineman7-jombang.sch.id",nocase; classtype:trojan-activity; sid:100004565; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"perpustekim.untirta.ac.id",nocase; classtype:trojan-activity; sid:100004566; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pestoclean.co.uk",nocase; classtype:trojan-activity; sid:100004567; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"petercollie.com",nocase; classtype:trojan-activity; sid:100004568; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ph4s.ru",nocase; classtype:trojan-activity; sid:100004569; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"phenhuong.sanpham.online",nocase; classtype:trojan-activity; sid:100004570; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"phittc.com",nocase; classtype:trojan-activity; sid:100004571; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"photo360.kubooking.com",nocase; classtype:trojan-activity; sid:100004572; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"photographytipsclub.com",nocase; classtype:trojan-activity; sid:100004573; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pink99.com",nocase; classtype:trojan-activity; sid:100004574; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pizzabarletta.com.br",nocase; classtype:trojan-activity; sid:100004575; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"plasfan.ind.br",nocase; classtype:trojan-activity; sid:100004576; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pmglance.startwriteup.com",nocase; classtype:trojan-activity; sid:100004577; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pokojewewladyslawowie.pl",nocase; classtype:trojan-activity; sid:100004578; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pole.com.vc",nocase; classtype:trojan-activity; sid:100004579; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pool.phxdir.com",nocase; classtype:trojan-activity; sid:100004580; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pooltablemoversdenver.net",nocase; classtype:trojan-activity; sid:100004581; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"posmicrosystems.com",nocase; classtype:trojan-activity; sid:100004582; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"poulman.panagiotopoulos-tours.gr",nocase; classtype:trojan-activity; sid:100004583; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ppdb.smk-ciptaskill.sch.id",nocase; classtype:trojan-activity; sid:100004584; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prestasicash.com.ar",nocase; classtype:trojan-activity; sid:100004585; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prestigehomeautomation.net",nocase; classtype:trojan-activity; sid:100004586; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prishaartcreations.com",nocase; classtype:trojan-activity; sid:100004587; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"production.sparshims.com",nocase; classtype:trojan-activity; sid:100004588; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"programaoperadoronline.com.br",nocase; classtype:trojan-activity; sid:100004589; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"project.exquitec.com",nocase; classtype:trojan-activity; sid:100004590; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"promolyko.com",nocase; classtype:trojan-activity; sid:100004591; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"promotoradescomplica.com.br",nocase; classtype:trojan-activity; sid:100004592; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"promoversdubai.com",nocase; classtype:trojan-activity; sid:100004593; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"propertiq.elin.co.za",nocase; classtype:trojan-activity; sid:100004594; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"propertiq2.elin.co.za",nocase; classtype:trojan-activity; sid:100004595; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prosoc.nl",nocase; classtype:trojan-activity; sid:100004596; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prostar.priruz.co.in",nocase; classtype:trojan-activity; sid:100004597; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prosyarmakassar.com",nocase; classtype:trojan-activity; sid:100004598; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"provence.elin.co.za",nocase; classtype:trojan-activity; sid:100004599; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"prueba.danielluza.com",nocase; classtype:trojan-activity; sid:100004600; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pujashoppe.in",nocase; classtype:trojan-activity; sid:100004601; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"punchdialogues.com",nocase; classtype:trojan-activity; sid:100004602; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"punjabdevelopersassociation.com.pk",nocase; classtype:trojan-activity; sid:100004603; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pvcprinting.co.uk",nocase; classtype:trojan-activity; sid:100004604; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qadir.tickfa.ir",nocase; classtype:trojan-activity; sid:100004605; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qatarglobalconsulting.com",nocase; classtype:trojan-activity; sid:100004606; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qmsled.com",nocase; classtype:trojan-activity; sid:100004607; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"quartier-midi.be",nocase; classtype:trojan-activity; sid:100004608; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"querocar.com",nocase; classtype:trojan-activity; sid:100004609; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rachmat-assuhaimi.my.id",nocase; classtype:trojan-activity; sid:100004610; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rainbowisp.info",nocase; classtype:trojan-activity; sid:100004611; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raodigitalmedia.com",nocase; classtype:trojan-activity; sid:100004612; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rarlabarchiver.ac",nocase; classtype:trojan-activity; sid:100004613; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rasadbar.ir",nocase; classtype:trojan-activity; sid:100004614; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rashika.ascarvalho.co.za",nocase; classtype:trojan-activity; sid:100004615; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ratemyfenancialadvisor.com",nocase; classtype:trojan-activity; sid:100004616; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ravenproductionsltd.com",nocase; classtype:trojan-activity; sid:100004617; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rc.ixiaoyang.cn",nocase; classtype:trojan-activity; sid:100004618; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"readymmade.com",nocase; classtype:trojan-activity; sid:100004619; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"redchillicrackers.com",nocase; classtype:trojan-activity; sid:100004620; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"reifenquick.de",nocase; classtype:trojan-activity; sid:100004621; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"relaxindulge.co.nz",nocase; classtype:trojan-activity; sid:100004622; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"renehavis.com.ua",nocase; classtype:trojan-activity; sid:100004623; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"repatriacioncolombia.com",nocase; classtype:trojan-activity; sid:100004624; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"res.uf1.cn",nocase; classtype:trojan-activity; sid:100004625; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"reseller.digimitra.in",nocase; classtype:trojan-activity; sid:100004626; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"resuco.net",nocase; classtype:trojan-activity; sid:100004627; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rezkabum.ru",nocase; classtype:trojan-activity; sid:100004628; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rhema.com.sg",nocase; classtype:trojan-activity; sid:100004629; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"richancyber.info",nocase; classtype:trojan-activity; sid:100004630; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"richmondminerals.co.zm",nocase; classtype:trojan-activity; sid:100004631; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rinaefoundation.org.za",nocase; classtype:trojan-activity; sid:100004632; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rinkaisystem-ht.com",nocase; classtype:trojan-activity; sid:100004633; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"riverfox.co.za",nocase; classtype:trojan-activity; sid:100004634; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rkcable.co.in",nocase; classtype:trojan-activity; sid:100004635; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rkverify.securestudies.com",nocase; classtype:trojan-activity; sid:100004636; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"roadfurylifts.com",nocase; classtype:trojan-activity; sid:100004637; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"robertmcardle.com",nocase; classtype:trojan-activity; sid:100004638; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"robertsinclair.net",nocase; classtype:trojan-activity; sid:100004639; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"robinhood-sports.com",nocase; classtype:trojan-activity; sid:100004640; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"romanianpoints.com",nocase; classtype:trojan-activity; sid:100004641; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ronnietucker.co.uk",nocase; classtype:trojan-activity; sid:100004642; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"roomsvc.servegate.kr",nocase; classtype:trojan-activity; sid:100004643; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"roshan.academy",nocase; classtype:trojan-activity; sid:100004644; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"roshnijewellery.com",nocase; classtype:trojan-activity; sid:100004645; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rs-toolkit.mikestclair.org",nocase; classtype:trojan-activity; sid:100004646; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rsgym.net",nocase; classtype:trojan-activity; sid:100004647; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rubazar.pro",nocase; classtype:trojan-activity; sid:100004648; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rubycityvietnam.com",nocase; classtype:trojan-activity; sid:100004649; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ruch.newreadermedia.net",nocase; classtype:trojan-activity; sid:100004650; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ruisgood.ru",nocase; classtype:trojan-activity; sid:100004651; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ruwadalkuwait.com",nocase; classtype:trojan-activity; sid:100004652; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"rzminc.com",nocase; classtype:trojan-activity; sid:100004653; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"s.51shijuan.com",nocase; classtype:trojan-activity; sid:100004654; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"s.thechinesemuslim.com",nocase; classtype:trojan-activity; sid:100004655; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sacredscentsonline.com",nocase; classtype:trojan-activity; sid:100004656; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"safcol-colors.com",nocase; classtype:trojan-activity; sid:100004657; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"safehubsecurity.ca",nocase; classtype:trojan-activity; sid:100004658; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"safety.nanotechproautocare.com",nocase; classtype:trojan-activity; sid:100004659; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sahathaikasetpan.com",nocase; classtype:trojan-activity; sid:100004660; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"saisoftwareinc.com",nocase; classtype:trojan-activity; sid:100004661; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"salecorner.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004662; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sandovalgraphics.com",nocase; classtype:trojan-activity; sid:100004663; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"santebarleyshop.jakewebtechs.ml",nocase; classtype:trojan-activity; sid:100004664; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"santyago.org",nocase; classtype:trojan-activity; sid:100004665; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sarakem.cl",nocase; classtype:trojan-activity; sid:100004666; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sasystemsuk.com",nocase; classtype:trojan-activity; sid:100004667; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"savasaachi.systems",nocase; classtype:trojan-activity; sid:100004668; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"scarfaceindustries.com",nocase; classtype:trojan-activity; sid:100004669; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"scglobal.co.th",nocase; classtype:trojan-activity; sid:100004670; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"schalke04rss.de",nocase; classtype:trojan-activity; sid:100004671; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"scheff.com",nocase; classtype:trojan-activity; sid:100004672; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"schoolbustracker.softgig.co.ke",nocase; classtype:trojan-activity; sid:100004673; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sec-doc-w.com",nocase; classtype:trojan-activity; sid:100004674; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"secure-doc-reader.com",nocase; classtype:trojan-activity; sid:100004675; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"segalsmetals.elin.co.za",nocase; classtype:trojan-activity; sid:100004676; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sellmyphonela.com",nocase; classtype:trojan-activity; sid:100004677; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"senbiaojita.com",nocase; classtype:trojan-activity; sid:100004678; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sentierodelviandante.ml",nocase; classtype:trojan-activity; sid:100004679; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"serendibsourcing.com",nocase; classtype:trojan-activity; sid:100004680; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"servicemhkd.myvnc.com",nocase; classtype:trojan-activity; sid:100004681; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"servicemhkd80.myvnc.com",nocase; classtype:trojan-activity; sid:100004682; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"serviciovirtual.com.ar",nocase; classtype:trojan-activity; sid:100004683; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"seyranikenger.com.tr",nocase; classtype:trojan-activity; sid:100004684; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sgessy.com.br",nocase; classtype:trojan-activity; sid:100004685; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shaheentbfoundation.com",nocase; classtype:trojan-activity; sid:100004686; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shahikhana.cstdevs.com",nocase; classtype:trojan-activity; sid:100004687; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sharkrigs.com",nocase; classtype:trojan-activity; sid:100004688; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sharpelevators.in",nocase; classtype:trojan-activity; sid:100004689; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shembefoundation.com",nocase; classtype:trojan-activity; sid:100004690; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shivakunwar.com.np",nocase; classtype:trojan-activity; sid:100004691; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shoblasaathitrust.org",nocase; classtype:trojan-activity; sid:100004692; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shooka-co.com",nocase; classtype:trojan-activity; sid:100004693; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shop.goldspot.agency",nocase; classtype:trojan-activity; sid:100004694; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shopsofe.com",nocase; classtype:trojan-activity; sid:100004695; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shrushtiinfotech.com",nocase; classtype:trojan-activity; sid:100004696; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sibernetix.fr",nocase; classtype:trojan-activity; sid:100004697; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"siddharthpanditpautra.com",nocase; classtype:trojan-activity; sid:100004698; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sige.brisainformatica.com.br",nocase; classtype:trojan-activity; sid:100004699; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"signatureads.co.in",nocase; classtype:trojan-activity; sid:100004700; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"siili.net",nocase; classtype:trojan-activity; sid:100004701; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"simoneporzi.it",nocase; classtype:trojan-activity; sid:100004702; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"simplithy.co.uk",nocase; classtype:trojan-activity; sid:100004703; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sindicato1ucm.cl",nocase; classtype:trojan-activity; sid:100004704; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sindpol.tiejuris.com.br",nocase; classtype:trojan-activity; sid:100004705; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sinergidwireka.com",nocase; classtype:trojan-activity; sid:100004706; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sipahielektrik.com",nocase; classtype:trojan-activity; sid:100004707; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"siperb.in",nocase; classtype:trojan-activity; sid:100004708; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sistelligent.com",nocase; classtype:trojan-activity; sid:100004709; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"skkksolo.beweiretail.com",nocase; classtype:trojan-activity; sid:100004710; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"skyflyfares.com",nocase; classtype:trojan-activity; sid:100004711; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"skyscan.com",nocase; classtype:trojan-activity; sid:100004712; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smarthouseforum.ru",nocase; classtype:trojan-activity; sid:100004713; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smarts.tj",nocase; classtype:trojan-activity; sid:100004714; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smartzedu.com",nocase; classtype:trojan-activity; sid:100004715; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smokeandgrowrichtour.com",nocase; classtype:trojan-activity; sid:100004716; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"smokesolutionindia.com",nocase; classtype:trojan-activity; sid:100004717; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sobethuacademy.com",nocase; classtype:trojan-activity; sid:100004718; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"soft.officelabo.net",nocase; classtype:trojan-activity; sid:100004719; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sohs.conceptechs.info",nocase; classtype:trojan-activity; sid:100004720; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"solar.amazingtribe.lk",nocase; classtype:trojan-activity; sid:100004721; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"solo2.dbstrony.pl",nocase; classtype:trojan-activity; sid:100004722; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"somcorbera.cat",nocase; classtype:trojan-activity; sid:100004723; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"somir.com.mx",nocase; classtype:trojan-activity; sid:100004724; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"soralapps.com",nocase; classtype:trojan-activity; sid:100004725; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sorteio.orgaostalita.com.br",nocase; classtype:trojan-activity; sid:100004726; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sosgsm.fr",nocase; classtype:trojan-activity; sid:100004727; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sota-france.fr",nocase; classtype:trojan-activity; sid:100004728; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sowingminerals.cl",nocase; classtype:trojan-activity; sid:100004729; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"space.proactint.org",nocase; classtype:trojan-activity; sid:100004730; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spaceframe.mobi.space-frame.co.za",nocase; classtype:trojan-activity; sid:100004731; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"special-key.cf",nocase; classtype:trojan-activity; sid:100004732; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spent.com.pl",nocase; classtype:trojan-activity; sid:100004733; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spetsesyachtcharter.gr",nocase; classtype:trojan-activity; sid:100004734; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spititourism.com",nocase; classtype:trojan-activity; sid:100004735; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"spittinfire.com",nocase; classtype:trojan-activity; sid:100004736; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sports-net.de",nocase; classtype:trojan-activity; sid:100004737; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"src1.minibai.com",nocase; classtype:trojan-activity; sid:100004738; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sreenivasapaintingworks.com",nocase; classtype:trojan-activity; sid:100004739; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sriglobalit.com",nocase; classtype:trojan-activity; sid:100004740; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"srvmanos.no-ip.info",nocase; classtype:trojan-activity; sid:100004741; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ss.monita.co.id",nocase; classtype:trojan-activity; sid:100004742; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"staging.apparelpunch.com",nocase; classtype:trojan-activity; sid:100004743; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"starcountry.net",nocase; classtype:trojan-activity; sid:100004744; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"static.3001.net",nocase; classtype:trojan-activity; sid:100004745; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"statsres.com",nocase; classtype:trojan-activity; sid:100004746; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"statssound.com",nocase; classtype:trojan-activity; sid:100004747; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"statsspot.com",nocase; classtype:trojan-activity; sid:100004748; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"statsvilla.com",nocase; classtype:trojan-activity; sid:100004749; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stattilion.bar",nocase; classtype:trojan-activity; sid:100004750; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stiepancasetia.ac.id",nocase; classtype:trojan-activity; sid:100004751; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stott-thompson.co.uk",nocase; classtype:trojan-activity; sid:100004752; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"stratexec.co.za",nocase; classtype:trojan-activity; sid:100004753; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"streetdemo.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004754; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"suboldesign.com",nocase; classtype:trojan-activity; sid:100004755; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sumerians.org",nocase; classtype:trojan-activity; sid:100004756; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sunbrero.com.au",nocase; classtype:trojan-activity; sid:100004757; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sunmarkholidays.com",nocase; classtype:trojan-activity; sid:100004758; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"supermercadostia.com",nocase; classtype:trojan-activity; sid:100004759; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"support-4-free.com",nocase; classtype:trojan-activity; sid:100004760; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"support.clz.kr",nocase; classtype:trojan-activity; sid:100004761; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"supportit.online",nocase; classtype:trojan-activity; sid:100004762; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"surestdysbonescagexc.dns.army",nocase; classtype:trojan-activity; sid:100004763; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sw.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004764; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sweaty.dk",nocase; classtype:trojan-activity; sid:100004765; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sweet-diet.com",nocase; classtype:trojan-activity; sid:100004766; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"swentsai.com",nocase; classtype:trojan-activity; sid:100004767; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"swiftlogisticseg.com",nocase; classtype:trojan-activity; sid:100004768; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"swwbia.com",nocase; classtype:trojan-activity; sid:100004769; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"syedpro.dezinetimes.com",nocase; classtype:trojan-activity; sid:100004770; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"syracusecoffee.com",nocase; classtype:trojan-activity; sid:100004771; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sys.pbmadu.co.id",nocase; classtype:trojan-activity; sid:100004772; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"systemsecuritylock.com",nocase; classtype:trojan-activity; sid:100004773; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sytraders.co",nocase; classtype:trojan-activity; sid:100004774; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"t.honker.info",nocase; classtype:trojan-activity; sid:100004775; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tacticohosting.com",nocase; classtype:trojan-activity; sid:100004776; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tadoo.ca",nocase; classtype:trojan-activity; sid:100004777; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tafsantoursandtravels.com",nocase; classtype:trojan-activity; sid:100004778; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tallyinvoicecustomization.com",nocase; classtype:trojan-activity; sid:100004779; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"taltus.co.uk",nocase; classtype:trojan-activity; sid:100004780; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tapalkoedacoffee.com",nocase; classtype:trojan-activity; sid:100004781; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tarravalleyfoods.com.au",nocase; classtype:trojan-activity; sid:100004782; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"taurus.ug",nocase; classtype:trojan-activity; sid:100004783; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"taxicabsrilanka.com",nocase; classtype:trojan-activity; sid:100004784; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"taxpos.com",nocase; classtype:trojan-activity; sid:100004785; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tc.snpsresidential.com",nocase; classtype:trojan-activity; sid:100004786; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tcy.198424.com",nocase; classtype:trojan-activity; sid:100004787; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tdsp.yngw518.com",nocase; classtype:trojan-activity; sid:100004788; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"techgms.com",nocase; classtype:trojan-activity; sid:100004789; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"technogreen.crmmanivela.com",nocase; classtype:trojan-activity; sid:100004790; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"technohub.searchkero.com",nocase; classtype:trojan-activity; sid:100004791; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tecnicaencolectores.com.mx",nocase; classtype:trojan-activity; sid:100004792; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tecnologyschool.com",nocase; classtype:trojan-activity; sid:100004793; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"teduae.com",nocase; classtype:trojan-activity; sid:100004794; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"teleargentina.com",nocase; classtype:trojan-activity; sid:100004795; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"telescopelms.com",nocase; classtype:trojan-activity; sid:100004796; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"telmed.cl",nocase; classtype:trojan-activity; sid:100004797; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"temptmag.com",nocase; classtype:trojan-activity; sid:100004798; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tennisafrica.com",nocase; classtype:trojan-activity; sid:100004799; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tentandoserfitness.000webhostapp.com",nocase; classtype:trojan-activity; sid:100004800; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.adventser.com",nocase; classtype:trojan-activity; sid:100004801; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.letraele.es",nocase; classtype:trojan-activity; sid:100004802; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.typoten.com",nocase; classtype:trojan-activity; sid:100004803; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test.wanepghana.org",nocase; classtype:trojan-activity; sid:100004804; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test1.asistencia247.com",nocase; classtype:trojan-activity; sid:100004805; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test1.milenial.id",nocase; classtype:trojan-activity; sid:100004806; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test1.tenplusone.my",nocase; classtype:trojan-activity; sid:100004807; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test2.basis-web.com",nocase; classtype:trojan-activity; sid:100004808; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"test2.marrenconstruction.ie",nocase; classtype:trojan-activity; sid:100004809; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"testing.clickitsolutionsmw.com",nocase; classtype:trojan-activity; sid:100004810; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"testing.thinkingcorp.in",nocase; classtype:trojan-activity; sid:100004811; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"testnew.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004812; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"teteaffiche.stephanebillon.com",nocase; classtype:trojan-activity; sid:100004813; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tewoerd.eu",nocase; classtype:trojan-activity; sid:100004814; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"textile.softberg.ro",nocase; classtype:trojan-activity; sid:100004815; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"texturesbyvinita.com",nocase; classtype:trojan-activity; sid:100004816; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thecleaningladiespdx.com",nocase; classtype:trojan-activity; sid:100004817; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thecreativecafe.co.uk",nocase; classtype:trojan-activity; sid:100004818; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thefuturelife.in",nocase; classtype:trojan-activity; sid:100004819; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thehighlightinterior.com",nocase; classtype:trojan-activity; sid:100004820; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thehouseofpragya.com",nocase; classtype:trojan-activity; sid:100004821; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thekassia.co.uk",nocase; classtype:trojan-activity; sid:100004822; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thelaunchpadteam.com",nocase; classtype:trojan-activity; sid:100004823; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thelogicalgroup.co.uk",nocase; classtype:trojan-activity; sid:100004824; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thesummitpc.net",nocase; classtype:trojan-activity; sid:100004825; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"theurbantutors.com",nocase; classtype:trojan-activity; sid:100004826; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thewwpc.com",nocase; classtype:trojan-activity; sid:100004827; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"thosewebbs.com",nocase; classtype:trojan-activity; sid:100004828; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tianangdep.com",nocase; classtype:trojan-activity; sid:100004829; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tickfood.tickme.lk",nocase; classtype:trojan-activity; sid:100004830; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tickjobs.tickme.lk",nocase; classtype:trojan-activity; sid:100004831; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tickmart.tickme.lk",nocase; classtype:trojan-activity; sid:100004832; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"timegonebuy.com",nocase; classtype:trojan-activity; sid:100004833; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tksb.net",nocase; classtype:trojan-activity; sid:100004834; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tlcc.com.gt",nocase; classtype:trojan-activity; sid:100004835; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"todoapp.cstdevs.com",nocase; classtype:trojan-activity; sid:100004836; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tonydong.com",nocase; classtype:trojan-activity; sid:100004837; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tonyzone.com",nocase; classtype:trojan-activity; sid:100004838; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tooba.tenplusone.my",nocase; classtype:trojan-activity; sid:100004839; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"topcell9.com",nocase; classtype:trojan-activity; sid:100004840; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"topicsnepal.com",nocase; classtype:trojan-activity; sid:100004841; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"toplevel.com.br",nocase; classtype:trojan-activity; sid:100004842; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"torresquinterocorp.com",nocase; classtype:trojan-activity; sid:100004843; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"towme.services",nocase; classtype:trojan-activity; sid:100004844; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"toyotacollege.ac.th",nocase; classtype:trojan-activity; sid:100004845; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tpef.lsoftdemo.com",nocase; classtype:trojan-activity; sid:100004846; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tpke.hu",nocase; classtype:trojan-activity; sid:100004847; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tradezone.ejuicysolutions.com",nocase; classtype:trojan-activity; sid:100004848; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"translaterjemah.com",nocase; classtype:trojan-activity; sid:100004849; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"travel.travelwadi.com",nocase; classtype:trojan-activity; sid:100004850; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"travelwithmanta.co.za",nocase; classtype:trojan-activity; sid:100004851; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"trezors.io.mahlongwa.com",nocase; classtype:trojan-activity; sid:100004852; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"triplonet.com.br",nocase; classtype:trojan-activity; sid:100004853; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"troki.com.co",nocase; classtype:trojan-activity; sid:100004854; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tropics.codeleek.net",nocase; classtype:trojan-activity; sid:100004855; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"trudelfavreau.com",nocase; classtype:trojan-activity; sid:100004856; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tsd.jxwan.com",nocase; classtype:trojan-activity; sid:100004857; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tulli.info",nocase; classtype:trojan-activity; sid:100004858; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tupperware.michaelroberge.ca",nocase; classtype:trojan-activity; sid:100004859; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"turanggaresources.com",nocase; classtype:trojan-activity; sid:100004860; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uat.indianfilmzone.com",nocase; classtype:trojan-activity; sid:100004861; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ublretailerdemo.cstdevs.com",nocase; classtype:trojan-activity; sid:100004862; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"udesk.searchkero.com",nocase; classtype:trojan-activity; sid:100004863; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ugprs-ubih.org",nocase; classtype:trojan-activity; sid:100004864; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ultimate-24.de",nocase; classtype:trojan-activity; sid:100004865; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"umwelt-kirchhof.de",nocase; classtype:trojan-activity; sid:100004866; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"unicorpbrunei.com",nocase; classtype:trojan-activity; sid:100004867; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uniengrisb.com",nocase; classtype:trojan-activity; sid:100004868; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"unisoftcc.com",nocase; classtype:trojan-activity; sid:100004869; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"unyazitelecom.com",nocase; classtype:trojan-activity; sid:100004870; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"upcbpta.com",nocase; classtype:trojan-activity; sid:100004871; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"urbane.dezinetimes.com",nocase; classtype:trojan-activity; sid:100004872; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"useformoney.000webhostapp.com",nocase; classtype:trojan-activity; sid:100004873; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"usmadetshirts.com",nocase; classtype:trojan-activity; sid:100004874; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uss.ac.th",nocase; classtype:trojan-activity; sid:100004875; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"uzzepay.com.br",nocase; classtype:trojan-activity; sid:100004876; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vanzare.cabanabrazi2.ro",nocase; classtype:trojan-activity; sid:100004877; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vbcargo.hu",nocase; classtype:trojan-activity; sid:100004878; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vcah.co.uk",nocase; classtype:trojan-activity; sid:100004879; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vegadelcasero.cl",nocase; classtype:trojan-activity; sid:100004880; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vendas.lidiacarmeli.com.br",nocase; classtype:trojan-activity; sid:100004881; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"verify.aicosoft.com",nocase; classtype:trojan-activity; sid:100004882; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vfocus.net",nocase; classtype:trojan-activity; sid:100004883; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vidmattic.com",nocase; classtype:trojan-activity; sid:100004884; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vienen.gblix.srv.br",nocase; classtype:trojan-activity; sid:100004885; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"villamarand.com",nocase; classtype:trojan-activity; sid:100004886; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"villatera.com",nocase; classtype:trojan-activity; sid:100004887; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"violinstop.com",nocase; classtype:trojan-activity; sid:100004888; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"viraltalking.com",nocase; classtype:trojan-activity; sid:100004889; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"visions.alnisamart.com",nocase; classtype:trojan-activity; sid:100004890; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"visualhome.cl",nocase; classtype:trojan-activity; sid:100004891; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vitoriamodaintima.com.br",nocase; classtype:trojan-activity; sid:100004892; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vivationdesign.com",nocase; classtype:trojan-activity; sid:100004893; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"viveirodoiscorregos.com.br",nocase; classtype:trojan-activity; sid:100004894; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vksales.com",nocase; classtype:trojan-activity; sid:100004895; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vladimirinternational.com",nocase; classtype:trojan-activity; sid:100004896; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vokasi.ub.ac.id",nocase; classtype:trojan-activity; sid:100004897; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vologroup.com.br",nocase; classtype:trojan-activity; sid:100004898; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"voteyouramerica.dekitout.com",nocase; classtype:trojan-activity; sid:100004899; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vstsample.com",nocase; classtype:trojan-activity; sid:100004900; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vtube.fadlymotivator.com",nocase; classtype:trojan-activity; sid:100004901; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vvsskmodinationalschool.com",nocase; classtype:trojan-activity; sid:100004902; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wanepliberia.org",nocase; classtype:trojan-activity; sid:100004903; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wanepniger.org",nocase; classtype:trojan-activity; sid:100004904; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"weareactum.com",nocase; classtype:trojan-activity; sid:100004905; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.eng.ubu.ac.th",nocase; classtype:trojan-activity; sid:100004906; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.geetle.ga",nocase; classtype:trojan-activity; sid:100004907; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.geomegasoft.net",nocase; classtype:trojan-activity; sid:100004908; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.newinnovationtechnology.com",nocase; classtype:trojan-activity; sid:100004909; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.smarts-works.com",nocase; classtype:trojan-activity; sid:100004910; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.thebeessolution.com",nocase; classtype:trojan-activity; sid:100004911; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"webgis.perumdasolo.com",nocase; classtype:trojan-activity; sid:100004912; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"webmailwindstreamnetmessagesecureapp1rqr.ga",nocase; classtype:trojan-activity; sid:100004913; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"webpresario.com",nocase; classtype:trojan-activity; sid:100004914; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"website-work.com",nocase; classtype:trojan-activity; sid:100004915; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"weinsteincounseling.com",nocase; classtype:trojan-activity; sid:100004916; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wexfashion.com",nocase; classtype:trojan-activity; sid:100004917; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"whcms.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004918; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"whiteglovetailgate.com",nocase; classtype:trojan-activity; sid:100004919; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"whiteresponse.com",nocase; classtype:trojan-activity; sid:100004920; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"whynt.xyz",nocase; classtype:trojan-activity; sid:100004921; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wi522012.ferozo.com",nocase; classtype:trojan-activity; sid:100004922; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wikalen.co.za",nocase; classtype:trojan-activity; sid:100004923; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wildnights.co.uk",nocase; classtype:trojan-activity; sid:100004924; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wildtrust.mediadevstaging.com",nocase; classtype:trojan-activity; sid:100004925; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wimbamusica.com",nocase; classtype:trojan-activity; sid:100004926; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wishesconcierge.com",nocase; classtype:trojan-activity; sid:100004927; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"woezon.agency",nocase; classtype:trojan-activity; sid:100004928; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wolfgang-brodte.de",nocase; classtype:trojan-activity; sid:100004929; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"woodsytech.com",nocase; classtype:trojan-activity; sid:100004930; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wordpress.saleensuporte.com.br",nocase; classtype:trojan-activity; sid:100004931; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wozata.000webhostapp.com",nocase; classtype:trojan-activity; sid:100004932; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wp.readhere.in",nocase; classtype:trojan-activity; sid:100004933; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wpdemo.101clients.com.au",nocase; classtype:trojan-activity; sid:100004934; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"writtendeer.com",nocase; classtype:trojan-activity; sid:100004935; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ws5588.f3322.net",nocase; classtype:trojan-activity; sid:100004936; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wyklej.pl",nocase; classtype:trojan-activity; sid:100004937; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"x2vn.com",nocase; classtype:trojan-activity; sid:100004938; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xia.beihaixue.com",nocase; classtype:trojan-activity; sid:100004939; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xixaoclothing.com",nocase; classtype:trojan-activity; sid:100004940; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xk.996is.com",nocase; classtype:trojan-activity; sid:100004941; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xn--80akinnkiib6h.xn--90ais",nocase; classtype:trojan-activity; sid:100004942; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"xn--polimerbizmimarlk-rvc.com",nocase; classtype:trojan-activity; sid:100004943; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ybom.urbanolab.com",nocase; classtype:trojan-activity; sid:100004944; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yeichner.com",nocase; classtype:trojan-activity; sid:100004945; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ylfpremium.com",nocase; classtype:trojan-activity; sid:100004946; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yoast.yourpageserver.com",nocase; classtype:trojan-activity; sid:100004947; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"youtubetrainingacademy.com",nocase; classtype:trojan-activity; sid:100004948; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yskadvisors.com",nocase; classtype:trojan-activity; sid:100004949; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yummyyogaudaipur.com",nocase; classtype:trojan-activity; sid:100004950; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yzkzixun.com",nocase; classtype:trojan-activity; sid:100004951; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"zakra.tecnasulstore.com.br",nocase; classtype:trojan-activity; sid:100004952; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"zytrox.tk",nocase; classtype:trojan-activity; sid:100004953; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"zz.690tx.com",nocase; classtype:trojan-activity; sid:100004954; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.indexsinas.me:811",nocase; http_uri; content:"/64.exe",nocase; classtype:trojan-activity; sid:100004955; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.indexsinas.me:811",nocase; http_uri; content:"/86.exe",nocase; classtype:trojan-activity; sid:100004956; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"2.indexsinas.me:811",nocase; http_uri; content:"/c64.exe",nocase; classtype:trojan-activity; sid:100004957; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"amumufree.weebly.com",nocase; http_uri; content:"/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe",nocase; classtype:trojan-activity; sid:100004958; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"analogx.com",nocase; http_uri; content:"/files/proxyi.exe",nocase; classtype:trojan-activity; sid:100004959; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe",nocase; classtype:trojan-activity; sid:100004960; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/densjons/bro/downloads/rew.exe",nocase; classtype:trojan-activity; sid:100004961; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/dvdfv/anjj/downloads/jami.exe",nocase; classtype:trojan-activity; sid:100004962; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/jpavelski/chpock/downloads/4.exe",nocase; classtype:trojan-activity; sid:100004963; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/jpavelski/chpock/downloads/6.exe",nocase; classtype:trojan-activity; sid:100004964; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/clr.exe",nocase; classtype:trojan-activity; sid:100004965; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/clr3.exe",nocase; classtype:trojan-activity; sid:100004966; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/instaler.exe",nocase; classtype:trojan-activity; sid:100004967; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/installer.exe",nocase; classtype:trojan-activity; sid:100004968; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/updatej.exe",nocase; classtype:trojan-activity; sid:100004969; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/updatev.exe",nocase; classtype:trojan-activity; sid:100004970; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/mminminminmin05/testtest/downloads/work.exe",nocase; classtype:trojan-activity; sid:100004971; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/player2012/rumpa1/downloads/component.exe",nocase; classtype:trojan-activity; sid:100004972; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/player2012/rumpa1/downloads/nordvpnsetup.exe",nocase; classtype:trojan-activity; sid:100004973; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/player2012/rumpa1/downloads/regsvc.exe",nocase; classtype:trojan-activity; sid:100004974; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/skygaming/updates/downloads/update.exe",nocase; classtype:trojan-activity; sid:100004975; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/001.txt",nocase; classtype:trojan-activity; sid:100004976; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1488.txt",nocase; classtype:trojan-activity; sid:100004977; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1_cr.txt",nocase; classtype:trojan-activity; sid:100004978; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1cr.txt",nocase; classtype:trojan-activity; sid:100004979; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/1fc2d.txt",nocase; classtype:trojan-activity; sid:100004980; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/26a5.txt",nocase; classtype:trojan-activity; sid:100004981; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/6e7_2021-01-19_18-04.txt",nocase; classtype:trojan-activity; sid:100004982; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/abjects.txt",nocase; classtype:trojan-activity; sid:100004983; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/attached.txt",nocase; classtype:trojan-activity; sid:100004984; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/b7f2c.exe",nocase; classtype:trojan-activity; sid:100004985; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/battletext.txt",nocase; classtype:trojan-activity; sid:100004986; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/bkghj_nowin.exe",nocase; classtype:trojan-activity; sid:100004987; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/bsdasdasd333.exe",nocase; classtype:trojan-activity; sid:100004988; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build.txt",nocase; classtype:trojan-activity; sid:100004989; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build_makros.exe",nocase; classtype:trojan-activity; sid:100004990; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build_silent.txt",nocase; classtype:trojan-activity; sid:100004991; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/build_sup.txt",nocase; classtype:trojan-activity; sid:100004992; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildcmobiler.exe",nocase; classtype:trojan-activity; sid:100004993; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildcmobiler.txt",nocase; classtype:trojan-activity; sid:100004994; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildcr.txt",nocase; classtype:trojan-activity; sid:100004995; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/buildss.txt",nocase; classtype:trojan-activity; sid:100004996; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/clientnik.txt",nocase; classtype:trojan-activity; sid:100004997; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/clientrevers.txt",nocase; classtype:trojan-activity; sid:100004998; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/dcrat.exe",nocase; classtype:trojan-activity; sid:100004999; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/dllservices.exe",nocase; classtype:trojan-activity; sid:100005000; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/dllservices2.exe",nocase; classtype:trojan-activity; sid:100005001; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/exe_morris.mcdermott.exe",nocase; classtype:trojan-activity; sid:100005002; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/hans.txt",nocase; classtype:trojan-activity; sid:100005003; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/hulu.txt",nocase; classtype:trojan-activity; sid:100005004; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelfive.txt",nocase; classtype:trojan-activity; sid:100005005; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelfour.txt",nocase; classtype:trojan-activity; sid:100005006; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelone.txt",nocase; classtype:trojan-activity; sid:100005007; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/intelthree.txt",nocase; classtype:trojan-activity; sid:100005008; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/inteltwo.txt",nocase; classtype:trojan-activity; sid:100005009; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/jjuufksfn.exe",nocase; classtype:trojan-activity; sid:100005010; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/kleiman.exe",nocase; classtype:trojan-activity; sid:100005011; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/lucky_fixed.exe",nocase; classtype:trojan-activity; sid:100005012; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/notepadplus.txt",nocase; classtype:trojan-activity; sid:100005013; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/osiris_qqkz_nauto.exe",nocase; classtype:trojan-activity; sid:100005014; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/out.exe",nocase; classtype:trojan-activity; sid:100005015; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/out.txt",nocase; classtype:trojan-activity; sid:100005016; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/pacbe_bin.txt",nocase; classtype:trojan-activity; sid:100005017; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/putty.txt",nocase; classtype:trojan-activity; sid:100005018; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/rockethcd.txt",nocase; classtype:trojan-activity; sid:100005019; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/scvhost900.exe",nocase; classtype:trojan-activity; sid:100005020; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/sessionwin.exe",nocase; classtype:trojan-activity; sid:100005021; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/siliculose.txt",nocase; classtype:trojan-activity; sid:100005022; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/statemobi.txt",nocase; classtype:trojan-activity; sid:100005023; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/stealers.exe",nocase; classtype:trojan-activity; sid:100005024; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/stealers2.exe",nocase; classtype:trojan-activity; sid:100005025; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/stgedo.exe",nocase; classtype:trojan-activity; sid:100005026; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/svcperf.txt",nocase; classtype:trojan-activity; sid:100005027; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/symptomaticshon5.exe",nocase; classtype:trojan-activity; sid:100005028; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/taurjok.txt",nocase; classtype:trojan-activity; sid:100005029; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/taurusbabac.exe",nocase; classtype:trojan-activity; sid:100005030; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/telekiller.exe",nocase; classtype:trojan-activity; sid:100005031; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/updateanddr.txt",nocase; classtype:trojan-activity; sid:100005032; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/updateandr.txt",nocase; classtype:trojan-activity; sid:100005033; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/vhajeja.txt",nocase; classtype:trojan-activity; sid:100005034; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/word.txt",nocase; classtype:trojan-activity; sid:100005035; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/www.txt",nocase; classtype:trojan-activity; sid:100005036; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/tanake5518/fi/downloads/xlsd.txt",nocase; classtype:trojan-activity; sid:100005037; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/teaserex/tease/downloads/b_kfmhkk172.bin",nocase; classtype:trojan-activity; sid:100005038; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"bitbucket.org",nocase; http_uri; content:"/teaserex/tease/downloads/macro_xmprohiq27.bin",nocase; classtype:trojan-activity; sid:100005039; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cd.textfiles.com",nocase; http_uri; content:"/hmatrix/data/hack1226.exe",nocase; classtype:trojan-activity; sid:100005040; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq",nocase; classtype:trojan-activity; sid:100005041; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/816070119281131570/816070273254162442/all.txt",nocase; classtype:trojan-activity; sid:100005042; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cdn.discordapp.com",nocase; http_uri; content:"/attachments/823355293043261515/823692323514482788/inquiry_-_rfq_hmg_u66_sw5558_pdf.iso",nocase; classtype:trojan-activity; sid:100005043; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"chiptune.com",nocase; http_uri; content:"/razor/rzr-winner_intro.zip",nocase; classtype:trojan-activity; sid:100005044; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cloudme.com",nocase; http_uri; content:"/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz",nocase; classtype:trojan-activity; sid:100005045; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"cloudme.com",nocase; http_uri; content:"/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar",nocase; classtype:trojan-activity; sid:100005046; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"codeload.github.com",nocase; http_uri; content:"/meteoradminz/hidden-tear/zip/master",nocase; classtype:trojan-activity; sid:100005047; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"colfincas.com",nocase; http_uri; content:"/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/",nocase; classtype:trojan-activity; sid:100005048; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"deepfreedom.org",nocase; http_uri; content:"/qz0h69.pdf",nocase; classtype:trojan-activity; sid:100005049; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com.it-barcelona.com",nocase; http_uri; content:"/frm0reseen/prntscrnofamzorderid.jpg.exe",nocase; classtype:trojan-activity; sid:100005050; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=0byfg0_4xbjgnwvuyev9ltuh4rmm",nocase; classtype:trojan-activity; sid:100005051; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=13vodfxml9fg8kcnexuafh64dzmnqv8ch",nocase; classtype:trojan-activity; sid:100005052; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=167imxqgc8ehepa1gisxa6q6ifcjxceox",nocase; classtype:trojan-activity; sid:100005053; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1a-herfdxr6xamxeabcdao0mqw9bimrig",nocase; classtype:trojan-activity; sid:100005054; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1aphk_vq7gtn368zxpd5bg5rv8nk0bnhn",nocase; classtype:trojan-activity; sid:100005055; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben",nocase; classtype:trojan-activity; sid:100005056; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1eqnvgn0qkunp7t6crk8oj7_e7rh5qxwi",nocase; classtype:trojan-activity; sid:100005057; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1in-rhdrss2qsjqj8xffb1hbwi9znp4je",nocase; classtype:trojan-activity; sid:100005058; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1iwc-lf99neesk6mvvo2al4futbmyoiev",nocase; classtype:trojan-activity; sid:100005059; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr",nocase; classtype:trojan-activity; sid:100005060; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1n8o4hbvi7o9ks9jqhofny7okposfaz4y",nocase; classtype:trojan-activity; sid:100005061; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1nio_cdsggt4zv1kdrpubrfpd0pzsyffd",nocase; classtype:trojan-activity; sid:100005062; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1oabvvnazifkxktvt-izbcdqpb7dm6nrw",nocase; classtype:trojan-activity; sid:100005063; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1prxtn1juykhcr_9ilw-vtirv5anyeoej",nocase; classtype:trojan-activity; sid:100005064; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1t1bd_itjnhsmozdl9was0gouehujm1fn",nocase; classtype:trojan-activity; sid:100005065; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1tsmbsikhechaqedk6nktlfzasus_tghw",nocase; classtype:trojan-activity; sid:100005066; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1uvtmu3-hcryp3rskqnpkiodcjuchtz55",nocase; classtype:trojan-activity; sid:100005067; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1vevblftithattyguwyjot1p0wptg7l5t",nocase; classtype:trojan-activity; sid:100005068; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e",nocase; classtype:trojan-activity; sid:100005069; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1yawygcfjs9inzoiwagqfcn3utaywxmwi",nocase; classtype:trojan-activity; sid:100005070; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1yhflwpk3yeyrdhlhanctlind-5j24iwv",nocase; classtype:trojan-activity; sid:100005071; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?export=download&id=1zbclvhabervgfryoyqklo4_oe6icd8sr",nocase; classtype:trojan-activity; sid:100005072; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drive.google.com",nocase; http_uri; content:"/uc?id=148pt6v0nlg8yoim7w6in7dpixkzaacbg&export=download&authuser=0",nocase; classtype:trojan-activity; sid:100005073; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drpamelageorge.com",nocase; http_uri; content:"/wp-includes/1zilg/",nocase; classtype:trojan-activity; sid:100005074; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"drpamelageorge.com",nocase; http_uri; content:"/wp-includes/qcgfmfvh/",nocase; classtype:trojan-activity; sid:100005075; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"e-mudhra.com",nocase; http_uri; content:"/downloads/emclick.zip",nocase; classtype:trojan-activity; sid:100005076; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"evertkok.nl",nocase; http_uri; content:"/informatica/informatica-actief/hoofdstuk1/extrasoftware/getallen.exe",nocase; classtype:trojan-activity; sid:100005077; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"evertkok.nl",nocase; http_uri; content:"/informatica/informatica-actief/hoofdstuk2/software/hksetup.exe",nocase; classtype:trojan-activity; sid:100005078; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"expeditionquest.com",nocase; http_uri; content:"/register/phpcaptcha/images/19dnqhg1p/sbhvtqlysxhxn/",nocase; classtype:trojan-activity; sid:100005079; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"expeditionquest.com",nocase; http_uri; content:"/register/phpcaptcha/images/35egphpl5uzpvdmz9bncmvon3p/",nocase; classtype:trojan-activity; sid:100005080; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"expeditionquest.com",nocase; http_uri; content:"/x/",nocase; classtype:trojan-activity; sid:100005081; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf/",nocase; classtype:trojan-activity; sid:100005082; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf//",nocase; classtype:trojan-activity; sid:100005083; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf///",nocase; classtype:trojan-activity; sid:100005084; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"exxonabnie.ir",nocase; http_uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf////",nocase; classtype:trojan-activity; sid:100005085; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"file.elecfans.com",nocase; http_uri; content:"/web1/m00/8f/36/o4ybafy-2m2aarfzaahkaiik5pi122.exe",nocase; classtype:trojan-activity; sid:100005086; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"files.constantcontact.com",nocase; http_uri; content:"/4cb7cebd101/e5fb4174-ab23-48e8-bf05-e80ec5fa2169.xls",nocase; classtype:trojan-activity; sid:100005087; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"files.constantcontact.com",nocase; http_uri; content:"/ee304de9001/7e533e73-e272-4a44-9d9e-138cab64bf19.docx",nocase; classtype:trojan-activity; sid:100005088; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"gist.githubusercontent.com",nocase; http_uri; content:"/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe",nocase; classtype:trojan-activity; sid:100005089; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hqdecig.com",nocase; http_uri; content:"/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/",nocase; classtype:trojan-activity; sid:100005090; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"hsecaravans.co.uk",nocase; http_uri; content:"/wp-admin/suy/",nocase; classtype:trojan-activity; sid:100005091; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ia801802.us.archive.org",nocase; http_uri; content:"/19/items/startup_20210219/startup.txt",nocase; classtype:trojan-activity; sid:100005092; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"ie-best.net",nocase; http_uri; content:"/online-timer-kvhxz/ilxl/",nocase; classtype:trojan-activity; sid:100005093; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"indonesias.me:9998",nocase; http_uri; content:"/64.exe",nocase; classtype:trojan-activity; sid:100005094; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"indonesias.me:9998",nocase; http_uri; content:"/c64.exe",nocase; classtype:trojan-activity; sid:100005095; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jcedu.org",nocase; http_uri; content:"/ebook/cs17.exe",nocase; classtype:trojan-activity; sid:100005096; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jointings.org",nocase; http_uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/1",nocase; classtype:trojan-activity; sid:100005097; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jointings.org",nocase; http_uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/2",nocase; classtype:trojan-activity; sid:100005098; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"jointings.org",nocase; http_uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/3",nocase; classtype:trojan-activity; sid:100005099; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"justlficante.mediafire.com",nocase; http_uri; content:"/file/jl01o54yy09qrzg/fac215.tgz/file",nocase; classtype:trojan-activity; sid:100005100; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"karmakoincodes.weebly.com",nocase; http_uri; content:"/uploads/3/2/8/8/3288864/karma_koin_codes.exe",nocase; classtype:trojan-activity; sid:100005101; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kotakwarna.co.id",nocase; http_uri; content:"/dg/etrac/nf4emwz/",nocase; classtype:trojan-activity; sid:100005102; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"kuaizip.com",nocase; http_uri; content:"/down/affiliate/kuaizip_setup_10029.exe",nocase; classtype:trojan-activity; sid:100005103; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"linuxforensicsbook.com.s3.amazonaws.com",nocase; http_uri; content:"/linuxforensicscode.zip",nocase; classtype:trojan-activity; sid:100005104; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"minpic.de",nocase; http_uri; content:"/k/big5/1giof6/",nocase; classtype:trojan-activity; sid:100005105; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"morrobaydrugandgift.com",nocase; http_uri; content:"/wp-contentbak/t9m/",nocase; classtype:trojan-activity; sid:100005106; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"my.cloudme.com",nocase; http_uri; content:"/v1/ws2/:gianni1962/:ie6setup/ie6setup.exe",nocase; classtype:trojan-activity; sid:100005107; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nch.com.au",nocase; http_uri; content:"/components/aacenc.exe",nocase; classtype:trojan-activity; sid:100005108; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nch.com.au",nocase; http_uri; content:"/components/doxillionsetup.exe",nocase; classtype:trojan-activity; sid:100005109; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"newyarlfm.weebly.com",nocase; http_uri; content:"/uploads/4/1/6/6/4166984/keygen.exe",nocase; classtype:trojan-activity; sid:100005110; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"nhipcauytevietnhat.com",nocase; http_uri; content:"/efficiency-all-iuehb/bjug3jyhuyilwhcqs3ykssaqqw7tpyvmypb91wtzdbluio1ekope5vrbbcx8zhdar9yt/",nocase; classtype:trojan-activity; sid:100005111; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"note.youdao.com",nocase; http_uri; content:"/yws/api/personal/file/web3a243b322cf83ca7cae587a92916bac7?method=download&inline=true&sharekey=649ac0bb5d5b13d15cbf50b2609e193a",nocase; classtype:trojan-activity; sid:100005112; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"oldschoolvalue.s3.amazonaws.com",nocase; http_uri; content:"/spreadsheets/osv_stock_valuation-sample-dummy.exe",nocase; classtype:trojan-activity; sid:100005113; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=81445407a9f44d37!197&authkey=apuz15kftzlrysa",nocase; classtype:trojan-activity; sid:100005114; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=81445407a9f44d37!198&authkey=ags5rgb15_esaqq",nocase; classtype:trojan-activity; sid:100005115; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=b4c15a27928f663b!229&authkey=aiarm61fwmd_npe",nocase; classtype:trojan-activity; sid:100005116; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=b4c15a27928f663b!230&authkey=ancu1eabetiubzg",nocase; classtype:trojan-activity; sid:100005117; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=b4c15a27928f663b!231&authkey=ai9h3sk_luxran0",nocase; classtype:trojan-activity; sid:100005118; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?&resid=c127f9e0fb7cbbea!214&authkey=aat73nvghhjdr9g",nocase; classtype:trojan-activity; sid:100005119; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=!aase4ma0-vo_cls&cid=4df11eda676a355f&resid=4df11eda676a355f!140",nocase; classtype:trojan-activity; sid:100005120; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=!akd6uxvljtlvpxu&cid=4df11eda676a355f&resid=4df11eda676a355f!130",nocase; classtype:trojan-activity; sid:100005121; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135",nocase; classtype:trojan-activity; sid:100005122; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?authkey=adf5p_kn8rjf29y&cid=34224e3e49966a27&resid=34224e3e49966a27%211732",nocase; classtype:trojan-activity; sid:100005123; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=013413cfbbbcfae4&resid=13413cfbbbcfae4%211656&authkey=ai9wpcp_k9okgk4",nocase; classtype:trojan-activity; sid:100005124; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c!111&authkey=aemrwamaaaiyyjc",nocase; classtype:trojan-activity; sid:100005125; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c%21111&authkey=aemrwamaaaiyyjc",nocase; classtype:trojan-activity; sid:100005126; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0175cdbe2d2944c5&resid=175cdbe2d2944c5%21107&authkey=al6uptubjmmugo0",nocase; classtype:trojan-activity; sid:100005127; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!157&authkey=aagcsm7chqez6uu",nocase; classtype:trojan-activity; sid:100005128; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!158&authkey=amsoii5nr6pomhc",nocase; classtype:trojan-activity; sid:100005129; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21157&authkey=aagcsm7chqez6uu",nocase; classtype:trojan-activity; sid:100005130; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21158&authkey=amsoii5nr6pomhc",nocase; classtype:trojan-activity; sid:100005131; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=023f39d21b700310&resid=23f39d21b700310%211204&authkey=an2utsuaopn0fhc",nocase; classtype:trojan-activity; sid:100005132; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211177&authkey=am0i98nwgvzgqvq",nocase; classtype:trojan-activity; sid:100005133; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211183&authkey=anv33trmzmi5cko",nocase; classtype:trojan-activity; sid:100005134; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw",nocase; classtype:trojan-activity; sid:100005135; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=03286724f74117f9&resid=3286724f74117f9!1179&authkey=acr-_rvrgp39kk4",nocase; classtype:trojan-activity; sid:100005136; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=03286724f74117f9&resid=3286724f74117f9%211179&authkey=acr-_rvrgp39kk4",nocase; classtype:trojan-activity; sid:100005137; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48",nocase; classtype:trojan-activity; sid:100005138; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq",nocase; classtype:trojan-activity; sid:100005139; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg",nocase; classtype:trojan-activity; sid:100005140; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw",nocase; classtype:trojan-activity; sid:100005141; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq",nocase; classtype:trojan-activity; sid:100005142; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!273&authkey=ae2m69e5nu3rrea",nocase; classtype:trojan-activity; sid:100005143; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!274&authkey=acqg0akutoxdpgo",nocase; classtype:trojan-activity; sid:100005144; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21273&authkey=ae2m69e5nu3rrea",nocase; classtype:trojan-activity; sid:100005145; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21274&authkey=acqg0akutoxdpgo",nocase; classtype:trojan-activity; sid:100005146; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0e26b39babdbf63c&resid=e26b39babdbf63c%21137&authkey=anshbgxg1_qa2h4",nocase; classtype:trojan-activity; sid:100005147; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242!309&authkey=alfe36drai1zmwc",nocase; classtype:trojan-activity; sid:100005148; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242%21309&authkey=alfe36drai1zmwc",nocase; classtype:trojan-activity; sid:100005149; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21123&authkey=aco5hiwppfq8vrw",nocase; classtype:trojan-activity; sid:100005150; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21124&authkey=ai6sfa2z-kqf6x0",nocase; classtype:trojan-activity; sid:100005151; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=115bffdddaa40942&resid=115bffdddaa40942!540&authkey=aamhnqgfdtdsoxk",nocase; classtype:trojan-activity; sid:100005152; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=115bffdddaa40942&resid=115bffdddaa40942%21540&authkey=aamhnqgfdtdsoxk",nocase; classtype:trojan-activity; sid:100005153; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a",nocase; classtype:trojan-activity; sid:100005154; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=13b301f1cb48f8cd&resid=13b301f1cb48f8cd%21106&authkey=aiae3olcs4lulz4",nocase; classtype:trojan-activity; sid:100005155; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=14f52af71b98dbc5&resid=14f52af71b98dbc5%212449&authkey=anfs_n5cs1noojo",nocase; classtype:trojan-activity; sid:100005156; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte",nocase; classtype:trojan-activity; sid:100005157; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7%21118&authkey=antash3ig98aqte",nocase; classtype:trojan-activity; sid:100005158; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f%21286&authkey=almwisomhv3c0zc",nocase; classtype:trojan-activity; sid:100005159; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e!348&authkey=ahnjoxa4ufoxa54",nocase; classtype:trojan-activity; sid:100005160; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e%21348&authkey=ahnjoxa4ufoxa54",nocase; classtype:trojan-activity; sid:100005161; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!126&authkey=ad4yflrisq6d82g",nocase; classtype:trojan-activity; sid:100005162; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!129&authkey=apqoonsrce0ari4",nocase; classtype:trojan-activity; sid:100005163; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21126&authkey=ad4yflrisq6d82g",nocase; classtype:trojan-activity; sid:100005164; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21129&authkey=apqoonsrce0ari4",nocase; classtype:trojan-activity; sid:100005165; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=196e83840ef8c152&resid=196e83840ef8c152%21107&authkey=ah2lhjyd0ukjcve",nocase; classtype:trojan-activity; sid:100005166; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1a162e8fcaaef5fa&resid=1a162e8fcaaef5fa%215495&authkey=aic7rmj1cm3rt2w",nocase; classtype:trojan-activity; sid:100005167; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558!8182&authkey=aautw8tvzxr5v3a",nocase; classtype:trojan-activity; sid:100005168; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558%218182&authkey=aautw8tvzxr5v3a",nocase; classtype:trojan-activity; sid:100005169; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1cbd82dd55d70086&resid=1cbd82dd55d70086%212526&authkey=aogaboensav3jrg",nocase; classtype:trojan-activity; sid:100005170; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1dbdf62bc3c2b05b&resid=1dbdf62bc3c2b05b!134&authkey=ape6bhxn7c89z60",nocase; classtype:trojan-activity; sid:100005171; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg",nocase; classtype:trojan-activity; sid:100005172; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4",nocase; classtype:trojan-activity; sid:100005173; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c",nocase; classtype:trojan-activity; sid:100005174; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!123&authkey=am1rcmkppbht8v0",nocase; classtype:trojan-activity; sid:100005175; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!124&authkey=am5sltharf-j_cc",nocase; classtype:trojan-activity; sid:100005176; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!125&authkey=acgvgbbuowodg4c",nocase; classtype:trojan-activity; sid:100005177; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21122&authkey=aa2f8su-5bfjlvs",nocase; classtype:trojan-activity; sid:100005178; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0",nocase; classtype:trojan-activity; sid:100005179; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0&c=3ii9gcd&r=7azia71ojgc8rxd0dmkukm&k=7s1&s=htgxfkpr86ttvokhkcn3enmimk12ewqfiglklz23spd",nocase; classtype:trojan-activity; sid:100005180; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21124&authkey=am5sltharf-j_cc",nocase; classtype:trojan-activity; sid:100005181; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21125&authkey=acgvgbbuowodg4c",nocase; classtype:trojan-activity; sid:100005182; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21154&authkey=alkjikpdfxvm8po",nocase; classtype:trojan-activity; sid:100005183; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21155&authkey=afu-yax_gxxddoe",nocase; classtype:trojan-activity; sid:100005184; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21156&authkey=alqvv8nixrvsqrk",nocase; classtype:trojan-activity; sid:100005185; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f!191&authkey=ajvumpkzpla_nca",nocase; classtype:trojan-activity; sid:100005186; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f%21191&authkey=ajvumpkzpla_nca",nocase; classtype:trojan-activity; sid:100005187; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=26bbd7d5ad88dd29&resid=26bbd7d5ad88dd29%21115&authkey=acipfa3gbiqqcvu",nocase; classtype:trojan-activity; sid:100005188; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=26f87316a7e32bb5&resid=26f87316a7e32bb5%21106&authkey=aepqo5hlkxn1t1k",nocase; classtype:trojan-activity; sid:100005189; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2831401bbac0235e&resid=2831401bbac0235e%211037&authkey=aagnkp6l76yhrlo",nocase; classtype:trojan-activity; sid:100005190; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!182&authkey=apogh8yf-fj8xvk",nocase; classtype:trojan-activity; sid:100005191; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!183&authkey=am4thhgmi0nlxei",nocase; classtype:trojan-activity; sid:100005192; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!185&authkey=akttgkvu39ugyte",nocase; classtype:trojan-activity; sid:100005193; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21182&authkey=apogh8yf-fj8xvk",nocase; classtype:trojan-activity; sid:100005194; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21183&authkey=am4thhgmi0nlxei",nocase; classtype:trojan-activity; sid:100005195; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21185&authkey=akttgkvu39ugyte",nocase; classtype:trojan-activity; sid:100005196; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2894380eb084b79e&resid=2894380eb084b79e%21253&authkey=aimqerwvuylzjga",nocase; classtype:trojan-activity; sid:100005197; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2992e4d36c2a7dae&resid=2992e4d36c2a7dae%21132&authkey=af05vsjkocy8lly",nocase; classtype:trojan-activity; sid:100005198; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2b6e98d9e0cf1a17&resid=2b6e98d9e0cf1a17!2471&authkey=ai5r4hqy9i0g1qs",nocase; classtype:trojan-activity; sid:100005199; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2b6e98d9e0cf1a17&resid=2b6e98d9e0cf1a17%212471&authkey=ai5r4hqy9i0g1qs",nocase; classtype:trojan-activity; sid:100005200; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c1abc526306a6e1&resid=2c1abc526306a6e1%21106&authkey=adjthwhvjkbioc0",nocase; classtype:trojan-activity; sid:100005201; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21109&authkey=aopcxq3owfiv620",nocase; classtype:trojan-activity; sid:100005202; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21114&authkey=ajzoj0ujggsnxlo",nocase; classtype:trojan-activity; sid:100005203; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21115&authkey=aglznnsx71tbe9e",nocase; classtype:trojan-activity; sid:100005204; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37!183&authkey=akon9i9zzhusiuk",nocase; classtype:trojan-activity; sid:100005205; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37%21183&authkey=akon9i9zzhusiuk",nocase; classtype:trojan-activity; sid:100005206; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6!161&authkey=aovldmsenzzpjrw",nocase; classtype:trojan-activity; sid:100005207; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6%21161&authkey=aovldmsenzzpjrw",nocase; classtype:trojan-activity; sid:100005208; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f01a497b687285e&resid=2f01a497b687285e!734&authkey=aiumuxtp3phppy4",nocase; classtype:trojan-activity; sid:100005209; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f01a497b687285e&resid=2f01a497b687285e%21734&authkey=aiumuxtp3phppy4",nocase; classtype:trojan-activity; sid:100005210; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!116&authkey=!abwledjhfsqwap4",nocase; classtype:trojan-activity; sid:100005211; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!121&authkey=!aa0qbuuss-wb13w",nocase; classtype:trojan-activity; sid:100005212; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1!119&authkey=apmakx2cqb9rimu",nocase; classtype:trojan-activity; sid:100005213; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21118&authkey=acrl2iiem-zjer8",nocase; classtype:trojan-activity; sid:100005214; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21119&authkey=apmakx2cqb9rimu",nocase; classtype:trojan-activity; sid:100005215; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=2ffaa48ef4bec51a&resid=2ffaa48ef4bec51a%21107&authkey=aiohrvrc3uuo_cw",nocase; classtype:trojan-activity; sid:100005216; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=30e33fc2c147c72f&resid=30e33fc2c147c72f!2742&authkey=ajviks-nvgb4gqs",nocase; classtype:trojan-activity; sid:100005217; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=30e33fc2c147c72f&resid=30e33fc2c147c72f!2743&authkey=ao4um908kkhavqg",nocase; classtype:trojan-activity; sid:100005218; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=30e33fc2c147c72f&resid=30e33fc2c147c72f%212742&authkey=ajviks-nvgb4gqs",nocase; classtype:trojan-activity; sid:100005219; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=30e33fc2c147c72f&resid=30e33fc2c147c72f%212743&authkey=ao4um908kkhavqg",nocase; classtype:trojan-activity; sid:100005220; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!320&authkey=aooujzuf408dclw",nocase; classtype:trojan-activity; sid:100005221; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!321&authkey=almpxnbtsbzauna",nocase; classtype:trojan-activity; sid:100005222; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21320&authkey=aooujzuf408dclw",nocase; classtype:trojan-activity; sid:100005223; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21321&authkey=almpxnbtsbzauna",nocase; classtype:trojan-activity; sid:100005224; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3164ddeba70d2263&resid=3164ddeba70d2263%21106&authkey=afkvqrm4zoor8qq",nocase; classtype:trojan-activity; sid:100005225; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=31771958ea3373a1&resid=31771958ea3373a1%21108&authkey=aiofxduo9rdb_-o",nocase; classtype:trojan-activity; sid:100005226; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=34207675f7506d94&resid=34207675f7506d94%21137&authkey=angxnhqpe2x5koc",nocase; classtype:trojan-activity; sid:100005227; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0",nocase; classtype:trojan-activity; sid:100005228; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa",nocase; classtype:trojan-activity; sid:100005229; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa",nocase; classtype:trojan-activity; sid:100005230; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!198&authkey=acyz0gbpl6bp9mo",nocase; classtype:trojan-activity; sid:100005231; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!199&authkey=admaszabh84m8ou",nocase; classtype:trojan-activity; sid:100005232; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e%21198&authkey=acyz0gbpl6bp9mo",nocase; classtype:trojan-activity; sid:100005233; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e%21199&authkey=admaszabh84m8ou",nocase; classtype:trojan-activity; sid:100005234; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!152&authkey=am09sv26njxzyn0",nocase; classtype:trojan-activity; sid:100005235; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!153&authkey=ajs0jkoeqkqjrze",nocase; classtype:trojan-activity; sid:100005236; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21152&authkey=am09sv26njxzyn0",nocase; classtype:trojan-activity; sid:100005237; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21153&authkey=ajs0jkoeqkqjrze",nocase; classtype:trojan-activity; sid:100005238; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3a1715e2cb964f25&resid=3a1715e2cb964f25%213713&authkey=aortxmfnibnoqkk",nocase; classtype:trojan-activity; sid:100005239; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21432&authkey=aa_npsupyqb2kge",nocase; classtype:trojan-activity; sid:100005240; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21435&authkey=admsjhgpkbtcqzs",nocase; classtype:trojan-activity; sid:100005241; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog",nocase; classtype:trojan-activity; sid:100005242; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f%21154&authkey=aasj15d0g_p2pog",nocase; classtype:trojan-activity; sid:100005243; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f!134&authkey=aaipzy8nllirlky",nocase; classtype:trojan-activity; sid:100005244; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f%21134&authkey=aaipzy8nllirlky",nocase; classtype:trojan-activity; sid:100005245; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=40cbf21d67b770f7&resid=40cbf21d67b770f7%21140&authkey=ah0uewz9k7-lzd0",nocase; classtype:trojan-activity; sid:100005246; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2!106&authkey=aoigmqhuw6vqijm",nocase; classtype:trojan-activity; sid:100005247; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2%21106&authkey=aoigmqhuw6vqijm",nocase; classtype:trojan-activity; sid:100005248; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21108&authkey=akr9cesktucbqik",nocase; classtype:trojan-activity; sid:100005249; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21109&authkey=adzxmpjk-etbkjq",nocase; classtype:trojan-activity; sid:100005250; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=45f0213456d899c0&resid=45f0213456d899c0%211133&authkey=alwgkm79xod8hpy",nocase; classtype:trojan-activity; sid:100005251; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa!450&authkey=ahw0j-cme0jg6pw",nocase; classtype:trojan-activity; sid:100005252; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa%21450&authkey=ahw0j-cme0jg6pw",nocase; classtype:trojan-activity; sid:100005253; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=489dd700ea74963a&resid=489dd700ea74963a%21206&authkey=acgkmxuk000jse8",nocase; classtype:trojan-activity; sid:100005254; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=489dd700ea74963a&resid=489dd700ea74963a%21210&authkey=aotjil_l-s-xh1c",nocase; classtype:trojan-activity; sid:100005255; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ada4e22fff3e13&resid=48ada4e22fff3e13%21421&authkey=acd1sidm8c5fk0y",nocase; classtype:trojan-activity; sid:100005256; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13805&authkey=ae-zbfo2uwln_gg",nocase; classtype:trojan-activity; sid:100005257; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13806&authkey=aakiq-ymrjjodns",nocase; classtype:trojan-activity; sid:100005258; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113805&authkey=ae-zbfo2uwln_gg",nocase; classtype:trojan-activity; sid:100005259; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113806&authkey=aakiq-ymrjjodns",nocase; classtype:trojan-activity; sid:100005260; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4ab7eafa48707b54&resid=4ab7eafa48707b54%21105&authkey=amb4gnkdn8igw8y",nocase; classtype:trojan-activity; sid:100005261; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4b676ea3ff139b93&resid=4b676ea3ff139b93!133&authkey=amfix63glytflgo",nocase; classtype:trojan-activity; sid:100005262; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21127&authkey=ablg20r-aat_ob4",nocase; classtype:trojan-activity; sid:100005263; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21131&authkey=akbwlkrrtso_bqm",nocase; classtype:trojan-activity; sid:100005264; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4df11eda676a355f&resid=4df11eda676a355f!130&authkey=!akd6uxvljtlvpxu",nocase; classtype:trojan-activity; sid:100005265; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b!108&authkey=anbjpqxg-iwr4g8",nocase; classtype:trojan-activity; sid:100005266; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b%21108&authkey=anbjpqxg-iwr4g8",nocase; classtype:trojan-activity; sid:100005267; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc",nocase; classtype:trojan-activity; sid:100005268; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y",nocase; classtype:trojan-activity; sid:100005269; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21105&authkey=ajkwu0e9dzantl8",nocase; classtype:trojan-activity; sid:100005270; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21107&authkey=apd9um4_12-kpe0",nocase; classtype:trojan-activity; sid:100005271; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21116&authkey=anbj_rrcgyturjc",nocase; classtype:trojan-activity; sid:100005272; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21119&authkey=amrs3-3hsvcmtfs",nocase; classtype:trojan-activity; sid:100005273; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21158&authkey=aodderdrnvhruts",nocase; classtype:trojan-activity; sid:100005274; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21161&authkey=agdsfxdnre82jjc",nocase; classtype:trojan-activity; sid:100005275; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21192&authkey=agn2xvrvup-xvtg",nocase; classtype:trojan-activity; sid:100005276; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21206&authkey=ai1r52mhtbdnm2y",nocase; classtype:trojan-activity; sid:100005277; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21247&authkey=ae6weny1fa4pday",nocase; classtype:trojan-activity; sid:100005278; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21252&authkey=aphl0oi4r6lrty0",nocase; classtype:trojan-activity; sid:100005279; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21257&authkey=afnyvqwcghnyoas",nocase; classtype:trojan-activity; sid:100005280; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21265&authkey=abxqdhlwiurjvve",nocase; classtype:trojan-activity; sid:100005281; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21271&authkey=ae5qwlr5ceeptmy",nocase; classtype:trojan-activity; sid:100005282; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21272&authkey=ahrqeoaynibwt14",nocase; classtype:trojan-activity; sid:100005283; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21275&authkey=af_sgsaxsmaxg7i",nocase; classtype:trojan-activity; sid:100005284; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21289&authkey=angyngbqixtrjaa",nocase; classtype:trojan-activity; sid:100005285; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu",nocase; classtype:trojan-activity; sid:100005286; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c",nocase; classtype:trojan-activity; sid:100005287; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21306&authkey=ahpivoukyerzcjy",nocase; classtype:trojan-activity; sid:100005288; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21314&authkey=aex2uv2-eiofr8q",nocase; classtype:trojan-activity; sid:100005289; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21332&authkey=ad0jmjxgbaebvbm",nocase; classtype:trojan-activity; sid:100005290; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21335&authkey=ah0vupcfbdfa6g4",nocase; classtype:trojan-activity; sid:100005291; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21357&authkey=ap8sswuqjjjexho",nocase; classtype:trojan-activity; sid:100005292; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21366&authkey=aoblpmbmx7o_v18",nocase; classtype:trojan-activity; sid:100005293; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21379&authkey=air-bsjj46et47q",nocase; classtype:trojan-activity; sid:100005294; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21389&authkey=aduenohuq_rbyhm",nocase; classtype:trojan-activity; sid:100005295; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21391&authkey=aa15sw51njbn_na",nocase; classtype:trojan-activity; sid:100005296; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21392&authkey=abp0heeg6ybn0lk",nocase; classtype:trojan-activity; sid:100005297; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21393&authkey=aa1pmur8sy8xtwe",nocase; classtype:trojan-activity; sid:100005298; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212718&authkey=aie0v1d-cusuabi",nocase; classtype:trojan-activity; sid:100005299; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212725&authkey=aanrz9et3bym3lc",nocase; classtype:trojan-activity; sid:100005300; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212728&authkey=ahsmbkltfrwgqjc",nocase; classtype:trojan-activity; sid:100005301; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!395&authkey=alwvub_yhtogjxw",nocase; classtype:trojan-activity; sid:100005302; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!398&authkey=abaa_tjd7ohh4so",nocase; classtype:trojan-activity; sid:100005303; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!406&authkey=aarnp48wumgu6tq",nocase; classtype:trojan-activity; sid:100005304; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!415&authkey=aglzsd6-g0nzj7s",nocase; classtype:trojan-activity; sid:100005305; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!420&authkey=akk5droung_ecww",nocase; classtype:trojan-activity; sid:100005306; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!440&authkey=ai7-dpr11wnzyq8",nocase; classtype:trojan-activity; sid:100005307; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21395&authkey=alwvub_yhtogjxw",nocase; classtype:trojan-activity; sid:100005308; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21398&authkey=abaa_tjd7ohh4so",nocase; classtype:trojan-activity; sid:100005309; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21406&authkey=aarnp48wumgu6tq",nocase; classtype:trojan-activity; sid:100005310; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21415&authkey=aglzsd6-g0nzj7s",nocase; classtype:trojan-activity; sid:100005311; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21420&authkey=akk5droung_ecww",nocase; classtype:trojan-activity; sid:100005312; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21440&authkey=ai7-dpr11wnzyq8",nocase; classtype:trojan-activity; sid:100005313; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211121&authkey=al_fmezwfay4za4",nocase; classtype:trojan-activity; sid:100005314; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211122&authkey=anz_q5njlanv2mu",nocase; classtype:trojan-activity; sid:100005315; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21110&authkey=akars6koxqzdwgi",nocase; classtype:trojan-activity; sid:100005316; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21112&authkey=aadare1gec7nzy8",nocase; classtype:trojan-activity; sid:100005317; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8",nocase; classtype:trojan-activity; sid:100005318; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8&em=2",nocase; classtype:trojan-activity; sid:100005319; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d%21109&authkey=adriswrtwdpbuc8&em=2",nocase; classtype:trojan-activity; sid:100005320; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=53c5e6b8f6893887&resid=53c5e6b8f6893887!802&authkey=aapuufivkn2zwu8",nocase; classtype:trojan-activity; sid:100005321; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!106&authkey=anzlf1ksptbqok8",nocase; classtype:trojan-activity; sid:100005322; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!107&authkey=ag4dr58jrjuxfyq",nocase; classtype:trojan-activity; sid:100005323; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21106&authkey=anzlf1ksptbqok8",nocase; classtype:trojan-activity; sid:100005324; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21107&authkey=ag4dr58jrjuxfyq",nocase; classtype:trojan-activity; sid:100005325; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g",nocase; classtype:trojan-activity; sid:100005326; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum",nocase; classtype:trojan-activity; sid:100005327; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5521b68dc17baf21&resid=5521b68dc17baf21%21129&authkey=ajdr2dbh-9h63wa",nocase; classtype:trojan-activity; sid:100005328; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi",nocase; classtype:trojan-activity; sid:100005329; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613!157&authkey=an55tjzt-9vbjfy",nocase; classtype:trojan-activity; sid:100005330; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613%21156&authkey=agiuawekkbxb_4o",nocase; classtype:trojan-activity; sid:100005331; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=55c9feaf3907aae5&resid=55c9feaf3907aae5%21208&authkey=adwuyrapfdzkyoa",nocase; classtype:trojan-activity; sid:100005332; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950!280&authkey=advq4p3xhfhinq8",nocase; classtype:trojan-activity; sid:100005333; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950%21280&authkey=advq4p3xhfhinq8",nocase; classtype:trojan-activity; sid:100005334; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5629da828892367d&resid=5629da828892367d!803&authkey=aphjbq-bsg7ohpc",nocase; classtype:trojan-activity; sid:100005335; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21383&authkey=adldpuaya7kj1dk",nocase; classtype:trojan-activity; sid:100005336; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21384&authkey=alsuxvtsof32vea",nocase; classtype:trojan-activity; sid:100005337; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3599&authkey=am4yicme6lrjpki",nocase; classtype:trojan-activity; sid:100005338; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3604&authkey=al6pb71mtq4jr1s",nocase; classtype:trojan-activity; sid:100005339; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213599&authkey=am4yicme6lrjpki",nocase; classtype:trojan-activity; sid:100005340; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213604&authkey=al6pb71mtq4jr1s",nocase; classtype:trojan-activity; sid:100005341; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b!68197&authkey=aowpm7ocl_21-oc",nocase; classtype:trojan-activity; sid:100005342; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b%2168197&authkey=aowpm7ocl_21-oc",nocase; classtype:trojan-activity; sid:100005343; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=59389d626d829e8c&resid=59389d626d829e8c%212940&authkey=anx1ngd27vqeiwo",nocase; classtype:trojan-activity; sid:100005344; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211568&authkey=aemrnwoi75oflva",nocase; classtype:trojan-activity; sid:100005345; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211572&authkey=aelz-gxlrxcwtnc",nocase; classtype:trojan-activity; sid:100005346; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211573&authkey=ahksfdvda0doles",nocase; classtype:trojan-activity; sid:100005347; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg",nocase; classtype:trojan-activity; sid:100005348; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai",nocase; classtype:trojan-activity; sid:100005349; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!407&authkey=adnh8af-rvoxlcc",nocase; classtype:trojan-activity; sid:100005350; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21406&authkey=aeyeq5j9zfepgai",nocase; classtype:trojan-activity; sid:100005351; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21407&authkey=adnh8af-rvoxlcc",nocase; classtype:trojan-activity; sid:100005352; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21892&authkey=apwphufzjdtsedw",nocase; classtype:trojan-activity; sid:100005353; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8",nocase; classtype:trojan-activity; sid:100005354; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21121&authkey=adjzlorvgx_ezhq",nocase; classtype:trojan-activity; sid:100005355; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21123&authkey=ancfnepawtbmnug",nocase; classtype:trojan-activity; sid:100005356; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21124&authkey=ao7bknnuodxtfua",nocase; classtype:trojan-activity; sid:100005357; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21126&authkey=an6sswp8an1kfoe",nocase; classtype:trojan-activity; sid:100005358; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6196314c52185efc&resid=6196314c52185efc%21106&authkey=ape4rx1hrtmrxxe",nocase; classtype:trojan-activity; sid:100005359; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!490&authkey=aljraz5ktivqax4",nocase; classtype:trojan-activity; sid:100005360; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!491&authkey=aopwdha2wyjx0aa",nocase; classtype:trojan-activity; sid:100005361; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!492&authkey=akwg8p5adkpjm5w",nocase; classtype:trojan-activity; sid:100005362; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!493&authkey=aeg__7wcf7esydo",nocase; classtype:trojan-activity; sid:100005363; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21490&authkey=aljraz5ktivqax4",nocase; classtype:trojan-activity; sid:100005364; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21491&authkey=aopwdha2wyjx0aa",nocase; classtype:trojan-activity; sid:100005365; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21492&authkey=akwg8p5adkpjm5w",nocase; classtype:trojan-activity; sid:100005366; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21493&authkey=aeg__7wcf7esydo",nocase; classtype:trojan-activity; sid:100005367; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi",nocase; classtype:trojan-activity; sid:100005368; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e",nocase; classtype:trojan-activity; sid:100005369; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1094&authkey=anqjzd7pr18fu90",nocase; classtype:trojan-activity; sid:100005370; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211094&authkey=anqjzd7pr18fu90",nocase; classtype:trojan-activity; sid:100005371; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21129&authkey=ak5szbnikeklmzk",nocase; classtype:trojan-activity; sid:100005372; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21132&authkey=ad3ia_1wkq0lyd4",nocase; classtype:trojan-activity; sid:100005373; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6608a4dea9ff5918&resid=6608a4dea9ff5918%21399&authkey=aoya7flv_s9toxo",nocase; classtype:trojan-activity; sid:100005374; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2%21505&authkey=ag7xi3lcnvi_hji",nocase; classtype:trojan-activity; sid:100005375; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad!1421&authkey=adixg2-asekemjw",nocase; classtype:trojan-activity; sid:100005376; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad%211421&authkey=adixg2-asekemjw",nocase; classtype:trojan-activity; sid:100005377; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213096&authkey=aob-cm9vv6erxqg",nocase; classtype:trojan-activity; sid:100005378; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213097&authkey=abcuevfyu6pdw70",nocase; classtype:trojan-activity; sid:100005379; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=69b503a3f081a183&resid=69b503a3f081a183%21111&authkey=aazm9wlg1rvgzoc",nocase; classtype:trojan-activity; sid:100005380; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!112&authkey=aasndgbcwol3mys",nocase; classtype:trojan-activity; sid:100005381; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!113&authkey=ak3tzu1lg4uuh5m",nocase; classtype:trojan-activity; sid:100005382; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21112&authkey=aasndgbcwol3mys",nocase; classtype:trojan-activity; sid:100005383; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21113&authkey=ak3tzu1lg4uuh5m",nocase; classtype:trojan-activity; sid:100005384; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21108&authkey=ameouv2jdxo5obw",nocase; classtype:trojan-activity; sid:100005385; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21119&authkey=aazzzrl7mv2xbwq",nocase; classtype:trojan-activity; sid:100005386; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6a7b40a2bc530c6c&resid=6a7b40a2bc530c6c%21112&authkey=afuov36rbymlvxm",nocase; classtype:trojan-activity; sid:100005387; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3!118&authkey=aepf8f3mfmlsng0",nocase; classtype:trojan-activity; sid:100005388; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3%21118&authkey=aepf8f3mfmlsng0",nocase; classtype:trojan-activity; sid:100005389; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b61e983f930f79f&resid=6b61e983f930f79f!540&authkey=ap2n5w41ifew0i8",nocase; classtype:trojan-activity; sid:100005390; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7!1154&authkey=acnbdscb8-rbmcu",nocase; classtype:trojan-activity; sid:100005391; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7%211154&authkey=acnbdscb8-rbmcu",nocase; classtype:trojan-activity; sid:100005392; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21106&authkey=apvhok6edhtogfu",nocase; classtype:trojan-activity; sid:100005393; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21115&authkey=amc_k1nnlywdc4i",nocase; classtype:trojan-activity; sid:100005394; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=724b5c509337556e&resid=724b5c509337556e%21908&authkey=agcbb3nakpteyam",nocase; classtype:trojan-activity; sid:100005395; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7285f51e65036769&resid=7285f51e65036769%21264&authkey=akyjvrz006qlble",nocase; classtype:trojan-activity; sid:100005396; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21243&authkey=apivjmxivosek60",nocase; classtype:trojan-activity; sid:100005397; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21256&authkey=adljht0ogfq775k",nocase; classtype:trojan-activity; sid:100005398; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21260&authkey=aig6cydr4_e-qj8",nocase; classtype:trojan-activity; sid:100005399; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21262&authkey=ak4fiz1-a1ks8rg",nocase; classtype:trojan-activity; sid:100005400; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21264&authkey=aizkjymvlgqwpte",nocase; classtype:trojan-activity; sid:100005401; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=77518d098ad4dfb0&resid=77518d098ad4dfb0%21939&authkey=akzqobxxxn89z34",nocase; classtype:trojan-activity; sid:100005402; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w",nocase; classtype:trojan-activity; sid:100005403; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta",nocase; classtype:trojan-activity; sid:100005404; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21117&authkey=aivf1ddcvvu22em",nocase; classtype:trojan-activity; sid:100005405; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb!211&authkey=anxavz-oaf9pv_c",nocase; classtype:trojan-activity; sid:100005406; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21210&authkey=agpl0pgvft8faaa",nocase; classtype:trojan-activity; sid:100005407; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21211&authkey=anxavz-oaf9pv_c",nocase; classtype:trojan-activity; sid:100005408; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto",nocase; classtype:trojan-activity; sid:100005409; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum",nocase; classtype:trojan-activity; sid:100005410; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto",nocase; classtype:trojan-activity; sid:100005411; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21120&authkey=ajj7ueqjvobgfum",nocase; classtype:trojan-activity; sid:100005412; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c1fc7da38ab958e&resid=7c1fc7da38ab958e!146&authkey=aktmjqz8n4s_sbm",nocase; classtype:trojan-activity; sid:100005413; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125575&authkey=ahnmpmvzshrwoyq",nocase; classtype:trojan-activity; sid:100005414; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125579&authkey=amhnrbwecb4hp_k",nocase; classtype:trojan-activity; sid:100005415; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5295&authkey=aasceqj1mdodeuo",nocase; classtype:trojan-activity; sid:100005416; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5296&authkey=ank3vz5syaf6bny",nocase; classtype:trojan-activity; sid:100005417; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5298&authkey=albzyizuqczfv9s",nocase; classtype:trojan-activity; sid:100005418; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215295&authkey=aasceqj1mdodeuo",nocase; classtype:trojan-activity; sid:100005419; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215296&authkey=ank3vz5syaf6bny",nocase; classtype:trojan-activity; sid:100005420; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215298&authkey=albzyizuqczfv9s",nocase; classtype:trojan-activity; sid:100005421; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7d109f249b512466&resid=7d109f249b512466!543&authkey=acqc4xjghclmwbs",nocase; classtype:trojan-activity; sid:100005422; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b!183&authkey=aggjy50pjuecoli",nocase; classtype:trojan-activity; sid:100005423; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21181&authkey=ama3betib0dac18",nocase; classtype:trojan-activity; sid:100005424; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21183&authkey=aggjy50pjuecoli",nocase; classtype:trojan-activity; sid:100005425; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!443&authkey=abue79u9di9axjm",nocase; classtype:trojan-activity; sid:100005426; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!444&authkey=abzxvycu0ggtmg8",nocase; classtype:trojan-activity; sid:100005427; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0%21443&authkey=abue79u9di9axjm",nocase; classtype:trojan-activity; sid:100005428; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0%21444&authkey=abzxvycu0ggtmg8",nocase; classtype:trojan-activity; sid:100005429; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7e81645429ac5a22&resid=7e81645429ac5a22%21105&authkey=aa691jwf5wqi80c",nocase; classtype:trojan-activity; sid:100005430; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=7fed4fbea32e3c1e&resid=7fed4fbea32e3c1e%21107&authkey=aeoxfycpolifch0",nocase; classtype:trojan-activity; sid:100005431; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=806bac90dc071edf&resid=806bac90dc071edf!105&authkey=!ao7jyz6-licb8hq",nocase; classtype:trojan-activity; sid:100005432; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=81c2d8b116274e17&resid=81c2d8b116274e17%21107&authkey=aaqw-t4dx2sbvda",nocase; classtype:trojan-activity; sid:100005433; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=82977114b1af209d&resid=82977114b1af209d!220&authkey=abuin5vdedjughm",nocase; classtype:trojan-activity; sid:100005434; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=860a0980486c93fa&resid=860a0980486c93fa!303&authkey=!agcmlab4r6syfvk",nocase; classtype:trojan-activity; sid:100005435; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21164&authkey=agbeiinncf8ok_4",nocase; classtype:trojan-activity; sid:100005436; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21165&authkey=aiof8rdvxglnm-c",nocase; classtype:trojan-activity; sid:100005437; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4!2402&authkey=amigiam45mt6jia",nocase; classtype:trojan-activity; sid:100005438; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4%212402&authkey=amigiam45mt6jia",nocase; classtype:trojan-activity; sid:100005439; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=890837b4e4ca07c6&resid=890837b4e4ca07c6%21289&authkey=abujc0akmtbsxf4",nocase; classtype:trojan-activity; sid:100005440; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8983011c6ecfb1d8&resid=8983011c6ecfb1d8%21132&authkey=ah0vja7wpyfjj84",nocase; classtype:trojan-activity; sid:100005441; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8a1574ed0cecd68a&resid=8a1574ed0cecd68a%21395&authkey=ane01evt0sz-1wk",nocase; classtype:trojan-activity; sid:100005442; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8c77cee60e33a6b1&resid=8c77cee60e33a6b1%21106&authkey=af8h8jn801bjnbk",nocase; classtype:trojan-activity; sid:100005443; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8ca507baa15fdb5c&resid=8ca507baa15fdb5c!213&authkey=acyrjlhflcrypae",nocase; classtype:trojan-activity; sid:100005444; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=8ffd8cbd6540c065&resid=8ffd8cbd6540c065!822&authkey=acfj7bbrmktj1i0",nocase; classtype:trojan-activity; sid:100005445; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!243&authkey=aeiqd4ihuqopwm8",nocase; classtype:trojan-activity; sid:100005446; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my",nocase; classtype:trojan-activity; sid:100005447; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25!130&authkey=ais_g9dqoddonsc",nocase; classtype:trojan-activity; sid:100005448; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby",nocase; classtype:trojan-activity; sid:100005449; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21109&authkey=akr1n3qxtmnttuo",nocase; classtype:trojan-activity; sid:100005450; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21113&authkey=ajpvf1h89sqstti",nocase; classtype:trojan-activity; sid:100005451; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!289&authkey=aoiy68zx8ddnjhe",nocase; classtype:trojan-activity; sid:100005452; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!290&authkey=afn1bhvmpaicari",nocase; classtype:trojan-activity; sid:100005453; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!291&authkey=aknqfhnxttsrvz4",nocase; classtype:trojan-activity; sid:100005454; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!297&authkey=agy0f-5almc6_ia",nocase; classtype:trojan-activity; sid:100005455; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!298&authkey=ajiut2kebcaycok",nocase; classtype:trojan-activity; sid:100005456; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21288&authkey=ag9wi9pub-q4jly",nocase; classtype:trojan-activity; sid:100005457; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21289&authkey=aoiy68zx8ddnjhe",nocase; classtype:trojan-activity; sid:100005458; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21290&authkey=afn1bhvmpaicari",nocase; classtype:trojan-activity; sid:100005459; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21291&authkey=aknqfhnxttsrvz4",nocase; classtype:trojan-activity; sid:100005460; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21295&authkey=afvy6r0mspzeb6m",nocase; classtype:trojan-activity; sid:100005461; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21297&authkey=agy0f-5almc6_ia",nocase; classtype:trojan-activity; sid:100005462; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21298&authkey=ajiut2kebcaycok",nocase; classtype:trojan-activity; sid:100005463; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21299&authkey=agmfs3scdvngolm",nocase; classtype:trojan-activity; sid:100005464; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21105&authkey=ah9x7rn0p03kd_m",nocase; classtype:trojan-activity; sid:100005465; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21110&authkey=ammswulpdsjeu4w",nocase; classtype:trojan-activity; sid:100005466; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3!107&authkey=ac-m9dlvo5l7wfk",nocase; classtype:trojan-activity; sid:100005467; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3%21107&authkey=ac-m9dlvo5l7wfk",nocase; classtype:trojan-activity; sid:100005468; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=96a54b19ff5f6bab&resid=96a54b19ff5f6bab%21107&authkey=anxv07ez7s5sh_k",nocase; classtype:trojan-activity; sid:100005469; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21410&authkey=acwug6bewxk0pli",nocase; classtype:trojan-activity; sid:100005470; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21411&authkey=aj8o1fcvfhibmlm",nocase; classtype:trojan-activity; sid:100005471; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=96fd249b957988a2&resid=96fd249b957988a2%211303&authkey=ah_etf1fqofknue",nocase; classtype:trojan-activity; sid:100005472; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935!778&authkey=aaezyk4ypt-elma",nocase; classtype:trojan-activity; sid:100005473; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21772&authkey=akeozmv0aafqlbg",nocase; classtype:trojan-activity; sid:100005474; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21774&authkey=aly_m3fnrvh6dfq",nocase; classtype:trojan-activity; sid:100005475; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21775&authkey=abblpjxi4mwomgs",nocase; classtype:trojan-activity; sid:100005476; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21777&authkey=ahmuwqi4jg8rvho",nocase; classtype:trojan-activity; sid:100005477; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=98103c88c2d68867&resid=98103c88c2d68867!773&authkey=akptbml43mi4ufc",nocase; classtype:trojan-activity; sid:100005478; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211925&authkey=amhhfhcsigeue9w",nocase; classtype:trojan-activity; sid:100005479; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211927&authkey=an_3paqpemptbvm",nocase; classtype:trojan-activity; sid:100005480; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211953&authkey=abdfqiyruwplpo0",nocase; classtype:trojan-activity; sid:100005481; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211954&authkey=aok-srkhxjazccy",nocase; classtype:trojan-activity; sid:100005482; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21172&authkey=ahharhcv0fmn5fm",nocase; classtype:trojan-activity; sid:100005483; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21173&authkey=aecb3qcquacvzhi",nocase; classtype:trojan-activity; sid:100005484; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21174&authkey=afv7cprqwxezgsi",nocase; classtype:trojan-activity; sid:100005485; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8",nocase; classtype:trojan-activity; sid:100005486; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq",nocase; classtype:trojan-activity; sid:100005487; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq",nocase; classtype:trojan-activity; sid:100005488; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o",nocase; classtype:trojan-activity; sid:100005489; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4",nocase; classtype:trojan-activity; sid:100005490; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi",nocase; classtype:trojan-activity; sid:100005491; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340!997&authkey=akw6btyej2zht08",nocase; classtype:trojan-activity; sid:100005492; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340%21997&authkey=akw6btyej2zht08",nocase; classtype:trojan-activity; sid:100005493; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a1c8c8055848b889&resid=a1c8c8055848b889!111&authkey=agzlftsgr4lspvo",nocase; classtype:trojan-activity; sid:100005494; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a2cd2cdb93584d7e&resid=a2cd2cdb93584d7e%21106&authkey=aeifpqbwo1s3dyq",nocase; classtype:trojan-activity; sid:100005495; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211064&authkey=apebndb6tstxywi",nocase; classtype:trojan-activity; sid:100005496; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211065&authkey=aca4_dggi5gbbfs",nocase; classtype:trojan-activity; sid:100005497; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211067&authkey=ae-3ej9zzj4ibhw",nocase; classtype:trojan-activity; sid:100005498; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211069&authkey=agx6b8qjt_clm-o",nocase; classtype:trojan-activity; sid:100005499; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a4acaf66051e469e&resid=a4acaf66051e469e!189&authkey=alnhzcg0wzhusdc",nocase; classtype:trojan-activity; sid:100005500; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a502994ea313f5c7&resid=a502994ea313f5c7%21215&authkey=aiydvejv0l8stbs",nocase; classtype:trojan-activity; sid:100005501; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21!6053&authkey=agfh0ahstj7rrki",nocase; classtype:trojan-activity; sid:100005502; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21%216053&authkey=agfh0ahstj7rrki",nocase; classtype:trojan-activity; sid:100005503; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fi",nocase; classtype:trojan-activity; sid:100005504; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21414&authkey=akf9uwwkitvhrvc",nocase; classtype:trojan-activity; sid:100005505; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21415&authkey=ag_5kthuezprnoy",nocase; classtype:trojan-activity; sid:100005506; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21416&authkey=airlma-pycgfkyc",nocase; classtype:trojan-activity; sid:100005507; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21419&authkey=ab1-sgyv2gibyey",nocase; classtype:trojan-activity; sid:100005508; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21422&authkey=acphsmdy415izjg",nocase; classtype:trojan-activity; sid:100005509; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21424&authkey=afvfwz5uvde1pui",nocase; classtype:trojan-activity; sid:100005510; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=a819c72315838312&resid=a819c72315838312%21112&authkey=abl1vflnfw3nrgi",nocase; classtype:trojan-activity; sid:100005511; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=aa4e252db942faec&resid=aa4e252db942faec%21168&authkey=anlnjo7xnwtswuk",nocase; classtype:trojan-activity; sid:100005512; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ae28961c75435487&resid=ae28961c75435487%21106&authkey=alph5awcis8r9iw",nocase; classtype:trojan-activity; sid:100005513; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992!113&authkey=agh9q_zzyjjcspc",nocase; classtype:trojan-activity; sid:100005514; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992%21113&authkey=agh9q_zzyjjcspc",nocase; classtype:trojan-activity; sid:100005515; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=af84ebf13dd5499c&resid=af84ebf13dd5499c!167&authkey=anqr_yvn_hdh2_e",nocase; classtype:trojan-activity; sid:100005516; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308!2152&authkey=abutaac83l5utks",nocase; classtype:trojan-activity; sid:100005517; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308%212152&authkey=abutaac83l5utks",nocase; classtype:trojan-activity; sid:100005518; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b0fddd36b3843d3b&resid=b0fddd36b3843d3b!561&authkey=abhena0pdghcveu",nocase; classtype:trojan-activity; sid:100005519; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b0fddd36b3843d3b&resid=b0fddd36b3843d3b%21561&authkey=abhena0pdghcveu",nocase; classtype:trojan-activity; sid:100005520; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21650&authkey=aht-wbxsofyx33u",nocase; classtype:trojan-activity; sid:100005521; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21651&authkey=aebbyk6sevdmzgm",nocase; classtype:trojan-activity; sid:100005522; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21652&authkey=afsw5wahxo5kwjy",nocase; classtype:trojan-activity; sid:100005523; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b1c3a5ef115e135c&resid=b1c3a5ef115e135c%216219&authkey=ahr7bklirbub0pc",nocase; classtype:trojan-activity; sid:100005524; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b2289382b9cf7ba8&resid=b2289382b9cf7ba8%21106&authkey=ajwobaztcbbpxmy",nocase; classtype:trojan-activity; sid:100005525; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21120&authkey=aozmspl2dqkgkgy",nocase; classtype:trojan-activity; sid:100005526; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21123&authkey=aj18p0rtfbtwa84",nocase; classtype:trojan-activity; sid:100005527; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21139&authkey=ahwfjvw4zmjukeo",nocase; classtype:trojan-activity; sid:100005528; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21140&authkey=aksvfpmrfqrrggw",nocase; classtype:trojan-activity; sid:100005529; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21141&authkey=acznh6clby0qyww",nocase; classtype:trojan-activity; sid:100005530; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21142&authkey=ajf7j1rr3d7jcxy",nocase; classtype:trojan-activity; sid:100005531; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21143&authkey=ahs21wnsqb_vu9w",nocase; classtype:trojan-activity; sid:100005532; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b50c4248502103d0&resid=b50c4248502103d0%21107&authkey=alf1nley7ja4dbq",nocase; classtype:trojan-activity; sid:100005533; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6!164&authkey=adfsfcdaw3biboy",nocase; classtype:trojan-activity; sid:100005534; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6%21164&authkey=adfsfcdaw3biboy",nocase; classtype:trojan-activity; sid:100005535; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b7cb31db66675eb4&resid=b7cb31db66675eb4%21922&authkey=aghayyucvwey7lg",nocase; classtype:trojan-activity; sid:100005536; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b86046e8cbd4254b&resid=b86046e8cbd4254b%21115&authkey=agwstptwpaquleg",nocase; classtype:trojan-activity; sid:100005537; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b!7521&authkey=ablt9zdyq2d4rb0",nocase; classtype:trojan-activity; sid:100005538; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b%217521&authkey=ablt9zdyq2d4rb0",nocase; classtype:trojan-activity; sid:100005539; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b90c1aa3b6cd0326&resid=b90c1aa3b6cd0326%21471&authkey=aoil8ra4oc4s_2m",nocase; classtype:trojan-activity; sid:100005540; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=b9690a1860a591d0&resid=b9690a1860a591d0%21161&authkey=aehawjpwf6tqtm8",nocase; classtype:trojan-activity; sid:100005541; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b!246&authkey=afyrchdutalpu90",nocase; classtype:trojan-activity; sid:100005542; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b%21246&authkey=afyrchdutalpu90",nocase; classtype:trojan-activity; sid:100005543; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=bf83d9247c2329e0&resid=bf83d9247c2329e0%211108&authkey=absaw-bpqrc6mpq",nocase; classtype:trojan-activity; sid:100005544; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214199&authkey=adgqe8qiyu92bqm",nocase; classtype:trojan-activity; sid:100005545; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214200&authkey=adqtju8i3nmlgai",nocase; classtype:trojan-activity; sid:100005546; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214201&authkey=ahqber27s7gg8kk",nocase; classtype:trojan-activity; sid:100005547; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019!1251&authkey=act34eizpzjugfa",nocase; classtype:trojan-activity; sid:100005548; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019%211251&authkey=act34eizpzjugfa",nocase; classtype:trojan-activity; sid:100005549; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1337&authkey=afnvu1fsuczht5e",nocase; classtype:trojan-activity; sid:100005550; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1338&authkey=ajngambosws75_c",nocase; classtype:trojan-activity; sid:100005551; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1340&authkey=al1ay3fbtude6d8",nocase; classtype:trojan-activity; sid:100005552; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1342&authkey=acpr_htn2jtaxfu",nocase; classtype:trojan-activity; sid:100005553; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1343&authkey=abodysrxu9l2xxu",nocase; classtype:trojan-activity; sid:100005554; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1344&authkey=aozerppd6mnokwy",nocase; classtype:trojan-activity; sid:100005555; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1345&authkey=aevvyhonxhtcdh0",nocase; classtype:trojan-activity; sid:100005556; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1346&authkey=achrnf5vlov1gf4",nocase; classtype:trojan-activity; sid:100005557; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1347&authkey=al-zge-ttvr921s",nocase; classtype:trojan-activity; sid:100005558; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211337&authkey=afnvu1fsuczht5e",nocase; classtype:trojan-activity; sid:100005559; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211338&authkey=ajngambosws75_c",nocase; classtype:trojan-activity; sid:100005560; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211340&authkey=al1ay3fbtude6d8",nocase; classtype:trojan-activity; sid:100005561; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211342&authkey=acpr_htn2jtaxfu",nocase; classtype:trojan-activity; sid:100005562; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211343&authkey=abodysrxu9l2xxu",nocase; classtype:trojan-activity; sid:100005563; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211344&authkey=aozerppd6mnokwy",nocase; classtype:trojan-activity; sid:100005564; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211345&authkey=aevvyhonxhtcdh0",nocase; classtype:trojan-activity; sid:100005565; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211346&authkey=achrnf5vlov1gf4",nocase; classtype:trojan-activity; sid:100005566; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211347&authkey=al-zge-ttvr921s",nocase; classtype:trojan-activity; sid:100005567; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c701663053a57d59&resid=c701663053a57d59%211009&authkey=ahowgkak7j0p2q8",nocase; classtype:trojan-activity; sid:100005568; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21486&authkey=amy4euf_rrlcykc",nocase; classtype:trojan-activity; sid:100005569; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21489&authkey=ako3anwfnqfohnc",nocase; classtype:trojan-activity; sid:100005570; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c7c32628aba70e70&resid=c7c32628aba70e70%21114&authkey=agdy8xpuh32sluw",nocase; classtype:trojan-activity; sid:100005571; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c80630c4d385fb9d&resid=c80630c4d385fb9d%21286&authkey=amgaucv8bld_5qs",nocase; classtype:trojan-activity; sid:100005572; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c8b0c7dc2b2570c5&resid=c8b0c7dc2b2570c5!122&authkey=aa4yfqt4cckzxhe",nocase; classtype:trojan-activity; sid:100005573; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=c8b0c7dc2b2570c5&resid=c8b0c7dc2b2570c5%21122&authkey=aa4yfqt4cckzxhe",nocase; classtype:trojan-activity; sid:100005574; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21546&authkey=aa6q-ryiifnet5m",nocase; classtype:trojan-activity; sid:100005575; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21547&authkey=aipm8qnwbgo4yga",nocase; classtype:trojan-activity; sid:100005576; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!355&authkey=aajjwf_sm4xdqdk",nocase; classtype:trojan-activity; sid:100005577; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!357&authkey=alw3vqqxz6myrle",nocase; classtype:trojan-activity; sid:100005578; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21354&authkey=aa_ukeour7rex1s",nocase; classtype:trojan-activity; sid:100005579; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21355&authkey=aajjwf_sm4xdqdk",nocase; classtype:trojan-activity; sid:100005580; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21357&authkey=alw3vqqxz6myrle",nocase; classtype:trojan-activity; sid:100005581; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ca897bdd16fc7940&resid=ca897bdd16fc7940%21106&authkey=aniklpt8vtlahbg",nocase; classtype:trojan-activity; sid:100005582; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2!109&authkey=ac4gxwjoopafr9a",nocase; classtype:trojan-activity; sid:100005583; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2%21109&authkey=ac4gxwjoopafr9a",nocase; classtype:trojan-activity; sid:100005584; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cbb66cac420484bc&resid=cbb66cac420484bc!10968&authkey=aj9bjkobu-rlnaw",nocase; classtype:trojan-activity; sid:100005585; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!742&authkey=akbxju17f8g0r2s",nocase; classtype:trojan-activity; sid:100005586; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!744&authkey=adak4zftd0yhhhs",nocase; classtype:trojan-activity; sid:100005587; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21742&authkey=akbxju17f8g0r2s",nocase; classtype:trojan-activity; sid:100005588; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21744&authkey=adak4zftd0yhhhs",nocase; classtype:trojan-activity; sid:100005589; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!872&authkey=ap9hchztywo8zuo",nocase; classtype:trojan-activity; sid:100005590; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!874&authkey=alkzcbxz-dscgum",nocase; classtype:trojan-activity; sid:100005591; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!875&authkey=aka55ybdhqnoc6c",nocase; classtype:trojan-activity; sid:100005592; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21872&authkey=ap9hchztywo8zuo",nocase; classtype:trojan-activity; sid:100005593; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21874&authkey=alkzcbxz-dscgum",nocase; classtype:trojan-activity; sid:100005594; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21875&authkey=aka55ybdhqnoc6c",nocase; classtype:trojan-activity; sid:100005595; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d2f3748954f6f8a8&resid=d2f3748954f6f8a8%21119&authkey=aex5s9uoun2zps0",nocase; classtype:trojan-activity; sid:100005596; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1029&authkey=ann3uz8huqi7ogw",nocase; classtype:trojan-activity; sid:100005597; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1030&authkey=aeqnasuksxccax4",nocase; classtype:trojan-activity; sid:100005598; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1031&authkey=acxtarrhbwrqt20",nocase; classtype:trojan-activity; sid:100005599; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1032&authkey=aemitbkn-vma9yk",nocase; classtype:trojan-activity; sid:100005600; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1033&authkey=abiydifgst6musa",nocase; classtype:trojan-activity; sid:100005601; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1035&authkey=ahd_ichsrf8ok_u",nocase; classtype:trojan-activity; sid:100005602; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1038&authkey=anxf-kuw1jn9-8y",nocase; classtype:trojan-activity; sid:100005603; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211029&authkey=ann3uz8huqi7ogw",nocase; classtype:trojan-activity; sid:100005604; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211030&authkey=aeqnasuksxccax4",nocase; classtype:trojan-activity; sid:100005605; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211031&authkey=acxtarrhbwrqt20",nocase; classtype:trojan-activity; sid:100005606; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211032&authkey=aemitbkn-vma9yk",nocase; classtype:trojan-activity; sid:100005607; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211033&authkey=abiydifgst6musa",nocase; classtype:trojan-activity; sid:100005608; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211035&authkey=ahd_ichsrf8ok_u",nocase; classtype:trojan-activity; sid:100005609; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!191&authkey=ajl2uegqunsgc3q",nocase; classtype:trojan-activity; sid:100005610; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!192&authkey=acd_hx4bka3z0nw",nocase; classtype:trojan-activity; sid:100005611; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21191&authkey=ajl2uegqunsgc3q",nocase; classtype:trojan-activity; sid:100005612; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21192&authkey=acd_hx4bka3z0nw",nocase; classtype:trojan-activity; sid:100005613; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy",nocase; classtype:trojan-activity; sid:100005614; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21107&authkey=alo4lep7wht05na",nocase; classtype:trojan-activity; sid:100005615; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21109&authkey=adnbm6mekgzvvh8",nocase; classtype:trojan-activity; sid:100005616; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!141&authkey=alya4infudqs53o",nocase; classtype:trojan-activity; sid:100005617; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!142&authkey=aiemnxi-s-5vrz0",nocase; classtype:trojan-activity; sid:100005618; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21141&authkey=alya4infudqs53o",nocase; classtype:trojan-activity; sid:100005619; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21142&authkey=aiemnxi-s-5vrz0",nocase; classtype:trojan-activity; sid:100005620; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21142&authkey=aiemnxi-s-5vrz0&c=3ii9gcd&r=5onulz3wldybwlmup37su3&k=7s1&s=kzymn52eroemh1tamvmlsfsn9jtvwguukky5hlxcfgw",nocase; classtype:trojan-activity; sid:100005621; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=db0fc77df51690e1&resid=db0fc77df51690e1%21802&authkey=apefr8w_rdk--pe",nocase; classtype:trojan-activity; sid:100005622; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=db5548cd728f142b&resid=db5548cd728f142b%21187&authkey=aansxudby0o7uwq",nocase; classtype:trojan-activity; sid:100005623; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=db62f747c6d887d0&resid=db62f747c6d887d0%21111&authkey=ai2guftczvfehs4",nocase; classtype:trojan-activity; sid:100005624; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dcd65237fcd1a1a9&resid=dcd65237fcd1a1a9%21162&authkey=aprqs0hugnfo6uq",nocase; classtype:trojan-activity; sid:100005625; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7527&authkey=aipybipwht56um8",nocase; classtype:trojan-activity; sid:100005626; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7530&authkey=am9p2ic6zdkgfmy",nocase; classtype:trojan-activity; sid:100005627; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7532&authkey=aonjnubquvon_uk",nocase; classtype:trojan-activity; sid:100005628; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217527&authkey=aipybipwht56um8",nocase; classtype:trojan-activity; sid:100005629; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217530&authkey=am9p2ic6zdkgfmy",nocase; classtype:trojan-activity; sid:100005630; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217532&authkey=aonjnubquvon_uk",nocase; classtype:trojan-activity; sid:100005631; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21107&authkey=akrabrcroiddkxw",nocase; classtype:trojan-activity; sid:100005632; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21115&authkey=ad1ncwtj_zcjsh0",nocase; classtype:trojan-activity; sid:100005633; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21132&authkey=akpbxohbtjebyn4",nocase; classtype:trojan-activity; sid:100005634; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21150&authkey=aevazjbqnu7cmjs",nocase; classtype:trojan-activity; sid:100005635; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21160&authkey=aiendf-9lyln0x0",nocase; classtype:trojan-activity; sid:100005636; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e1065ab3e86a5fc2&resid=e1065ab3e86a5fc2%211443&authkey=apybkcvf4iwxp_q",nocase; classtype:trojan-activity; sid:100005637; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e3ddc3980f743711&resid=e3ddc3980f743711%21795&authkey=aptivsvyk2we5xc",nocase; classtype:trojan-activity; sid:100005638; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21745&authkey=ah1i_jo73zgdxpc",nocase; classtype:trojan-activity; sid:100005639; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21746&authkey=ag1mhwlznwdxpw0",nocase; classtype:trojan-activity; sid:100005640; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e43694f4bd6f68d1&resid=e43694f4bd6f68d1!563&authkey=aj8ovsob9ll6r-c",nocase; classtype:trojan-activity; sid:100005641; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!509&authkey=akmdyqkzcsuf_gg",nocase; classtype:trojan-activity; sid:100005642; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!511&authkey=agfs0q7dz7os1lu",nocase; classtype:trojan-activity; sid:100005643; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c%21511&authkey=agfs0q7dz7os1lu",nocase; classtype:trojan-activity; sid:100005644; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e54ea4e0368d023b&resid=e54ea4e0368d023b%21106&authkey=aozas6g9pm0fzvq",nocase; classtype:trojan-activity; sid:100005645; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21349&authkey=ae9ea8jdsa7vmom",nocase; classtype:trojan-activity; sid:100005646; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21350&authkey=ao-vuexoihzj7da",nocase; classtype:trojan-activity; sid:100005647; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2!142&authkey=ais88uad5aom6qu",nocase; classtype:trojan-activity; sid:100005648; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2%21142&authkey=ais88uad5aom6qu",nocase; classtype:trojan-activity; sid:100005649; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e97110434470423e&resid=e97110434470423e%21113&authkey=afowclex54if0g0",nocase; classtype:trojan-activity; sid:100005650; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw",nocase; classtype:trojan-activity; sid:100005651; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw",nocase; classtype:trojan-activity; sid:100005652; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211215&authkey=ac1jr_bieufz0ai",nocase; classtype:trojan-activity; sid:100005653; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211219&authkey=akgo75rmvr4khlc",nocase; classtype:trojan-activity; sid:100005654; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ebacca5dec27fd20&resid=ebacca5dec27fd20%2118735&authkey=ajfyl1mzidnylc8",nocase; classtype:trojan-activity; sid:100005655; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21113&authkey=aovavpmokd2jrns",nocase; classtype:trojan-activity; sid:100005656; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21116&authkey=aadnj5xyfasugu8",nocase; classtype:trojan-activity; sid:100005657; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ef04dd7f0a6a5f7c&resid=ef04dd7f0a6a5f7c%21142&authkey=aad-nuysvlhc-i4",nocase; classtype:trojan-activity; sid:100005658; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!202&authkey=ah1gjq8j29darw4",nocase; classtype:trojan-activity; sid:100005659; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!203&authkey=af8xr99mrqp8um8",nocase; classtype:trojan-activity; sid:100005660; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!204&authkey=ad0nbzlscbg-0sa",nocase; classtype:trojan-activity; sid:100005661; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21202&authkey=ah1gjq8j29darw4",nocase; classtype:trojan-activity; sid:100005662; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21203&authkey=af8xr99mrqp8um8",nocase; classtype:trojan-activity; sid:100005663; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21204&authkey=ad0nbzlscbg-0sa",nocase; classtype:trojan-activity; sid:100005664; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21489&authkey=ads_gff3tjkd0w0",nocase; classtype:trojan-activity; sid:100005665; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21490&authkey=aj_rld7xooge6aw",nocase; classtype:trojan-activity; sid:100005666; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21492&authkey=ahdb75ptd1_uc8e",nocase; classtype:trojan-activity; sid:100005667; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f06038a5f7dbd6d6&resid=f06038a5f7dbd6d6%215498&authkey=aiozi3z5qzdysmu",nocase; classtype:trojan-activity; sid:100005668; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f293cebb54e5ea71&resid=f293cebb54e5ea71%21293&authkey=aha74rsqiuewnpq",nocase; classtype:trojan-activity; sid:100005669; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21566&authkey=aevafh7rydhi19k",nocase; classtype:trojan-activity; sid:100005670; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21581&authkey=agx0b8ho87w4uie",nocase; classtype:trojan-activity; sid:100005671; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21582&authkey=af-9_xwysl1o7-c",nocase; classtype:trojan-activity; sid:100005672; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21598&authkey=ah-gkc-b7fa8h-g",nocase; classtype:trojan-activity; sid:100005673; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21599&authkey=aajunhe1ex_-zta",nocase; classtype:trojan-activity; sid:100005674; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!216&authkey=alslscyemd7hr_o",nocase; classtype:trojan-activity; sid:100005675; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!223&authkey=ajbtso2laio00ao",nocase; classtype:trojan-activity; sid:100005676; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21216&authkey=alslscyemd7hr_o",nocase; classtype:trojan-activity; sid:100005677; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f50a3aff00683adc&resid=f50a3aff00683adc%21108&authkey=ac44gtgp13l9xpw",nocase; classtype:trojan-activity; sid:100005678; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f50a3aff00683adc&resid=f50a3aff00683adc%21139&authkey=aovmqh4ookdlkty",nocase; classtype:trojan-activity; sid:100005679; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f79e41c0e32d3314&resid=f79e41c0e32d3314%211182&authkey=aiqtptberyvlgqk&em=2%22",nocase; classtype:trojan-activity; sid:100005680; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806!1368&authkey=anphh1fijhvzv6c",nocase; classtype:trojan-activity; sid:100005681; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806%211368&authkey=anphh1fijhvzv6c",nocase; classtype:trojan-activity; sid:100005682; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382!159&authkey=ai4_8srrzf48hw0",nocase; classtype:trojan-activity; sid:100005683; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382%21159&authkey=ai4_8srrzf48hw0",nocase; classtype:trojan-activity; sid:100005684; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fb2177c192eed796&resid=fb2177c192eed796%21124&authkey=abotnmdhu_tg7bc",nocase; classtype:trojan-activity; sid:100005685; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fd50774e5ce0e314&resid=fd50774e5ce0e314%21778&authkey=aoxb2vhhz3qodiu",nocase; classtype:trojan-activity; sid:100005686; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fe85161c3947f2c1&resid=fe85161c3947f2c1%211441&authkey=agb6c1ecr91svrw",nocase; classtype:trojan-activity; sid:100005687; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e!192&authkey=ab_lrrmyxmcfrjc",nocase; classtype:trojan-activity; sid:100005688; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e%21192&authkey=ab_lrrmyxmcfrjc",nocase; classtype:trojan-activity; sid:100005689; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!693&authkey=agcpkhnewfte_yc",nocase; classtype:trojan-activity; sid:100005690; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!694&authkey=aa5jqzjsp0esr1s",nocase; classtype:trojan-activity; sid:100005691; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21693&authkey=agcpkhnewfte_yc",nocase; classtype:trojan-activity; sid:100005692; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21694&authkey=aa5jqzjsp0esr1s",nocase; classtype:trojan-activity; sid:100005693; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!330&authkey=adxnzkb0a09pizw",nocase; classtype:trojan-activity; sid:100005694; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!334&authkey=agsvox_t7qim4ta",nocase; classtype:trojan-activity; sid:100005695; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!335&authkey=ach14e6omcghwgg",nocase; classtype:trojan-activity; sid:100005696; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21330&authkey=adxnzkb0a09pizw",nocase; classtype:trojan-activity; sid:100005697; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21333&authkey=aielwtaiuvcttlm",nocase; classtype:trojan-activity; sid:100005698; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"onedrive.live.com",nocase; http_uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta",nocase; classtype:trojan-activity; sid:100005699; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pastebin.com",nocase; http_uri; content:"/raw/yqvsvlvq",nocase; classtype:trojan-activity; sid:100005700; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pierreconsulting.info",nocase; http_uri; content:"/wp-admin/llc/mwcacs65xienqdp/",nocase; classtype:trojan-activity; sid:100005701; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"pioneiraagronegocio.com.br",nocase; http_uri; content:"/bayesian-forecasting-amj5e/s5hqmf6/",nocase; classtype:trojan-activity; sid:100005702; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"procrossover.ru",nocase; http_uri; content:"/wp-content/uploads/2020/10/skoda22.jpg",nocase; classtype:trojan-activity; sid:100005703; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"procrossover.ru",nocase; http_uri; content:"/wp-content/uploads/2020/10/skodaqq.jpg",nocase; classtype:trojan-activity; sid:100005704; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"qjbutterflyevents.co.za",nocase; http_uri; content:"/wp-admin/zzcoiatsr5wujrwagsgbnm2wkjxldvgu/",nocase; classtype:trojan-activity; sid:100005705; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"quen.s3.us-east-2.amazonaws.com",nocase; http_uri; content:"/order+acknowledgement+bc202374++stock++20021+dem+p4.ace",nocase; classtype:trojan-activity; sid:100005706; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"quen.s3.us-east-2.amazonaws.com",nocase; http_uri; content:"/purchasing+ordersigned+contractinv-30067121.ace",nocase; classtype:trojan-activity; sid:100005707; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/arntsonl/calc_security_poc/master/dll/calc.dll",nocase; classtype:trojan-activity; sid:100005708; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/bero1985/berotinypascal/e34bd4164f4b7c27e7cf667dffd9274d33d6dfbe/bin/btpc.exe",nocase; classtype:trojan-activity; sid:100005709; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/evil-coder66/defendercontrol/main/defendercontrol.exe",nocase; classtype:trojan-activity; sid:100005710; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/fuzzbunch/fuzzbunch/master/payloads/doublepulsar-1.3.1.exe",nocase; classtype:trojan-activity; sid:100005711; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe",nocase; classtype:trojan-activity; sid:100005712; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/malwares/webshell/master/ajax_php%20command%20shell.rar",nocase; classtype:trojan-activity; sid:100005713; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/myqseeaccount/one/main/one.htm",nocase; classtype:trojan-activity; sid:100005714; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/realtek25556/rhti2/gh-pages/90hfnvo69vk2ot.bmp",nocase; classtype:trojan-activity; sid:100005715; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/secwiki/windows-kernel-exploits/master/ms15-076/binary/trebuchet.exe",nocase; classtype:trojan-activity; sid:100005716; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/secwiki/windows-kernel-exploits/master/ms16-098/bfill.exe",nocase; classtype:trojan-activity; sid:100005717; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"raw.githubusercontent.com",nocase; http_uri; content:"/tennc/webshell/master/other/small_shell.txt",nocase; classtype:trojan-activity; sid:100005718; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"res.yeshen.com",nocase; http_uri; content:"/player/launch/2017/09/12/da5f9a1c23034353852750488feeaf36.exe",nocase; classtype:trojan-activity; sid:100005719; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sendspace.com",nocase; http_uri; content:"/pro/dl/q05z91",nocase; classtype:trojan-activity; sid:100005720; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"shribharatvatika.com",nocase; http_uri; content:"/ey4lpx8rx.zip",nocase; classtype:trojan-activity; sid:100005721; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"sites.google.com",nocase; http_uri; content:"/site/stormqk/dn/stormagent.apk?attredirects=0",nocase; classtype:trojan-activity; sid:100005722; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6ca94027662tilxa4p/base.txt",nocase; classtype:trojan-activity; sid:100005723; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt",nocase; classtype:trojan-activity; sid:100005724; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6cd19c87f44r9fomit/base64jef.txt",nocase; classtype:trojan-activity; sid:100005725; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6e2cbda22efxk3t7x2/base64.txt",nocase; classtype:trojan-activity; sid:100005726; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6e2f6c8c5adup2yiwx/basejefin.txt",nocase; classtype:trojan-activity; sid:100005727; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6eab37b8dadmy1gx7c/base3.5.txt",nocase; classtype:trojan-activity; sid:100005728; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6eb2aa215a8cvwcf6s/fudjs.txt",nocase; classtype:trojan-activity; sid:100005729; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aamus8/go.jpeg",nocase; classtype:trojan-activity; sid:100005730; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c7921a2cf26cunjcgvm/nanocoregomes.txt",nocase; classtype:trojan-activity; sid:100005731; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"storage.googleapis.com",nocase; http_uri; content:"/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt",nocase; classtype:trojan-activity; sid:100005732; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"technologydistilled.com",nocase; http_uri; content:"/a-nurse-ss8d9/z/",nocase; classtype:trojan-activity; sid:100005733; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"truemerit.io",nocase; http_uri; content:"/databases/merit.php",nocase; classtype:trojan-activity; sid:100005734; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"tsrv4.ws",nocase; http_uri; content:"/23.exe",nocase; classtype:trojan-activity; sid:100005735; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"users.skynet.be",nocase; http_uri; content:"/crisanar/defis/jek_crackme1.7.zip",nocase; classtype:trojan-activity; sid:100005736; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vniel.co.kr",nocase; http_uri; content:"/gnuboard/data/scan/amowvegfrt9ja/",nocase; classtype:trojan-activity; sid:100005737; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"vniel.co.kr",nocase; http_uri; content:"/gnuboard/data/scan/fu6jvxzzs46uqlp7l/",nocase; classtype:trojan-activity; sid:100005738; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.mit.edu",nocase; http_uri; content:"/kolya/.f/root/net.mit.edu/net/user/chris/winnt/mit_agenda2a.doc",nocase; classtype:trojan-activity; sid:100005739; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"web.mit.edu",nocase; http_uri; content:"/kolya/.f/root/net.mit.edu/sipb/user/kolya/afs/root.afs/net/user/chris/winnt/mit_agenda2a.doc",nocase; classtype:trojan-activity; sid:100005740; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/136_140/flt_shovemydiscoupyourarse.exe",nocase; classtype:trojan-activity; sid:100005741; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/136_140/kb%5efr_ouverture.exe",nocase; classtype:trojan-activity; sid:100005742; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/136_140/kb^fr_ouverture.exe",nocase; classtype:trojan-activity; sid:100005743; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/146_150/bc_memories_from_the_mcp.exe",nocase; classtype:trojan-activity; sid:100005744; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"websound.ru",nocase; http_uri; content:"/issues/151_155/tidex_-_short_stuff.exe",nocase; classtype:trojan-activity; sid:100005745; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"wikileaks.org",nocase; http_uri; content:"/syria-files/attach/222/222051_instruction.zip",nocase; classtype:trojan-activity; sid:100005746; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; http_header:field host; content:"yp.hnggzyjy.cn",nocase; http_uri; content:"/common/yz.vbs",nocase; classtype:trojan-activity; sid:100005747; rev:1;)
diff --git a/urlhaus-filter-suricata-online.rules b/urlhaus-filter-suricata-online.rules
index c15e3691..eb7b0b46 100644
--- a/urlhaus-filter-suricata-online.rules
+++ b/urlhaus-filter-suricata-online.rules
@@ -1,5 +1,5 @@
 # Title: Online Malicious URL Suricata Ruleset
-# Updated: Thu, 25 Mar 2021 12:12:40 UTC
+# Updated: Fri, 26 Mar 2021 00:12:29 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -12,29 +12,29 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.192.180.19"; classtype:trojan-activity; sid:100000006; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.222.140.251"; classtype:trojan-activity; sid:100000007; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.222.196.60"; classtype:trojan-activity; sid:100000008; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.24.132.118"; classtype:trojan-activity; sid:100000009; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.245.4.163"; classtype:trojan-activity; sid:100000010; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.107"; classtype:trojan-activity; sid:100000011; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.109"; classtype:trojan-activity; sid:100000012; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.127"; classtype:trojan-activity; sid:100000013; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.134"; classtype:trojan-activity; sid:100000014; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.14"; classtype:trojan-activity; sid:100000015; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.153"; classtype:trojan-activity; sid:100000016; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.16"; classtype:trojan-activity; sid:100000017; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.165"; classtype:trojan-activity; sid:100000018; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.245.4.163"; classtype:trojan-activity; sid:100000009; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.107"; classtype:trojan-activity; sid:100000010; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.109"; classtype:trojan-activity; sid:100000011; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.127"; classtype:trojan-activity; sid:100000012; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.134"; classtype:trojan-activity; sid:100000013; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.14"; classtype:trojan-activity; sid:100000014; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.153"; classtype:trojan-activity; sid:100000015; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.16"; classtype:trojan-activity; sid:100000016; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.165"; classtype:trojan-activity; sid:100000017; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.228"; classtype:trojan-activity; sid:100000018; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.232"; classtype:trojan-activity; sid:100000019; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.234"; classtype:trojan-activity; sid:100000020; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.245"; classtype:trojan-activity; sid:100000021; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.249"; classtype:trojan-activity; sid:100000022; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.38"; classtype:trojan-activity; sid:100000023; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.41"; classtype:trojan-activity; sid:100000024; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.43"; classtype:trojan-activity; sid:100000025; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.45"; classtype:trojan-activity; sid:100000026; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.56"; classtype:trojan-activity; sid:100000027; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.69"; classtype:trojan-activity; sid:100000028; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.8"; classtype:trojan-activity; sid:100000029; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.80"; classtype:trojan-activity; sid:100000030; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.9"; classtype:trojan-activity; sid:100000031; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.237"; classtype:trojan-activity; sid:100000021; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.245"; classtype:trojan-activity; sid:100000022; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.249"; classtype:trojan-activity; sid:100000023; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.38"; classtype:trojan-activity; sid:100000024; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.41"; classtype:trojan-activity; sid:100000025; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.43"; classtype:trojan-activity; sid:100000026; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.45"; classtype:trojan-activity; sid:100000027; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.56"; classtype:trojan-activity; sid:100000028; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.69"; classtype:trojan-activity; sid:100000029; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.8"; classtype:trojan-activity; sid:100000030; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.80"; classtype:trojan-activity; sid:100000031; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.222.98"; classtype:trojan-activity; sid:100000032; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.10"; classtype:trojan-activity; sid:100000033; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.246.223.103"; classtype:trojan-activity; sid:100000034; rev:1;)
@@ -66,72 +66,72 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.250.159.41"; classtype:trojan-activity; sid:100000060; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.252.102.28"; classtype:trojan-activity; sid:100000061; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.254.250.52"; classtype:trojan-activity; sid:100000062; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.60.77.53"; classtype:trojan-activity; sid:100000063; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.62.195.101"; classtype:trojan-activity; sid:100000064; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.58.223.96"; classtype:trojan-activity; sid:100000063; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.60.77.53"; classtype:trojan-activity; sid:100000064; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.65.166.225"; classtype:trojan-activity; sid:100000065; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.82.104.89"; classtype:trojan-activity; sid:100000066; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1.85.84.38"; classtype:trojan-activity; sid:100000067; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"100.12.184.63"; classtype:trojan-activity; sid:100000068; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"100.2.131.143"; classtype:trojan-activity; sid:100000069; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"100.8.77.4"; classtype:trojan-activity; sid:100000070; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1008691.com"; classtype:trojan-activity; sid:100000071; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.108.130.108"; classtype:trojan-activity; sid:100000072; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.108.131.202"; classtype:trojan-activity; sid:100000073; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.108.133.231"; classtype:trojan-activity; sid:100000074; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.16.183.179"; classtype:trojan-activity; sid:100000075; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.16.98.170"; classtype:trojan-activity; sid:100000076; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.229.85.127"; classtype:trojan-activity; sid:100000077; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.255.36.154"; classtype:trojan-activity; sid:100000078; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.28.102.38"; classtype:trojan-activity; sid:100000079; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.28.105.132"; classtype:trojan-activity; sid:100000080; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.28.106.134"; classtype:trojan-activity; sid:100000081; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.28.145.2"; classtype:trojan-activity; sid:100000082; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.28.76.34"; classtype:trojan-activity; sid:100000083; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.30.128.184"; classtype:trojan-activity; sid:100000084; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.64.119.250"; classtype:trojan-activity; sid:100000085; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.64.161.70"; classtype:trojan-activity; sid:100000086; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.75.157.99"; classtype:trojan-activity; sid:100000087; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"102.130.115.14"; classtype:trojan-activity; sid:100000088; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"102.141.240.139"; classtype:trojan-activity; sid:100000089; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.106.29.148"; classtype:trojan-activity; sid:100000090; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.107.113.22"; classtype:trojan-activity; sid:100000091; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.113.99.79"; classtype:trojan-activity; sid:100000092; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.124.104.118"; classtype:trojan-activity; sid:100000093; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.125.218.107"; classtype:trojan-activity; sid:100000094; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.136.82.50"; classtype:trojan-activity; sid:100000095; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.139.89.205"; classtype:trojan-activity; sid:100000096; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.141.138.12"; classtype:trojan-activity; sid:100000097; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.144.36.20"; classtype:trojan-activity; sid:100000098; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.145.13.24"; classtype:trojan-activity; sid:100000099; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.146.174.208"; classtype:trojan-activity; sid:100000100; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.156.221.66"; classtype:trojan-activity; sid:100000101; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.16.145.25"; classtype:trojan-activity; sid:100000102; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.217.215.21"; classtype:trojan-activity; sid:100000103; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.224.200.40"; classtype:trojan-activity; sid:100000104; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.233.64.182"; classtype:trojan-activity; sid:100000105; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.235.165.183"; classtype:trojan-activity; sid:100000106; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.238.228.3"; classtype:trojan-activity; sid:100000107; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.238.228.4"; classtype:trojan-activity; sid:100000108; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.240.249.121"; classtype:trojan-activity; sid:100000109; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.70.160.51"; classtype:trojan-activity; sid:100000110; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.79.112.254"; classtype:trojan-activity; sid:100000111; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.82.145.111"; classtype:trojan-activity; sid:100000112; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.82.98.170"; classtype:trojan-activity; sid:100000113; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.84.240.130"; classtype:trojan-activity; sid:100000114; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.84.240.228"; classtype:trojan-activity; sid:100000115; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.11"; classtype:trojan-activity; sid:100000116; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.12"; classtype:trojan-activity; sid:100000117; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.17"; classtype:trojan-activity; sid:100000118; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.19"; classtype:trojan-activity; sid:100000119; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.20"; classtype:trojan-activity; sid:100000120; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.3"; classtype:trojan-activity; sid:100000121; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.36"; classtype:trojan-activity; sid:100000122; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"100.12.184.63"; classtype:trojan-activity; sid:100000067; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"100.2.131.143"; classtype:trojan-activity; sid:100000068; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"100.8.77.4"; classtype:trojan-activity; sid:100000069; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1008691.com"; classtype:trojan-activity; sid:100000070; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.108.130.108"; classtype:trojan-activity; sid:100000071; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.16.183.179"; classtype:trojan-activity; sid:100000072; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.16.98.170"; classtype:trojan-activity; sid:100000073; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.229.85.127"; classtype:trojan-activity; sid:100000074; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.255.36.154"; classtype:trojan-activity; sid:100000075; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.28.105.132"; classtype:trojan-activity; sid:100000076; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.28.106.134"; classtype:trojan-activity; sid:100000077; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.28.145.2"; classtype:trojan-activity; sid:100000078; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.28.76.34"; classtype:trojan-activity; sid:100000079; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.30.128.184"; classtype:trojan-activity; sid:100000080; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.64.119.250"; classtype:trojan-activity; sid:100000081; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.64.161.70"; classtype:trojan-activity; sid:100000082; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"101.75.157.99"; classtype:trojan-activity; sid:100000083; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"102.130.115.14"; classtype:trojan-activity; sid:100000084; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"102.141.240.139"; classtype:trojan-activity; sid:100000085; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.107.113.22"; classtype:trojan-activity; sid:100000086; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.113.99.79"; classtype:trojan-activity; sid:100000087; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.124.104.118"; classtype:trojan-activity; sid:100000088; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.125.218.107"; classtype:trojan-activity; sid:100000089; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.136.82.50"; classtype:trojan-activity; sid:100000090; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.141.138.12"; classtype:trojan-activity; sid:100000091; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.144.36.20"; classtype:trojan-activity; sid:100000092; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.145.13.24"; classtype:trojan-activity; sid:100000093; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.146.174.208"; classtype:trojan-activity; sid:100000094; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.156.221.66"; classtype:trojan-activity; sid:100000095; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.16.145.25"; classtype:trojan-activity; sid:100000096; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.161.232.16"; classtype:trojan-activity; sid:100000097; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.207.0.134"; classtype:trojan-activity; sid:100000098; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.217.215.21"; classtype:trojan-activity; sid:100000099; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.224.200.40"; classtype:trojan-activity; sid:100000100; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.233.64.182"; classtype:trojan-activity; sid:100000101; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.238.228.3"; classtype:trojan-activity; sid:100000102; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.238.228.4"; classtype:trojan-activity; sid:100000103; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.240.249.121"; classtype:trojan-activity; sid:100000104; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.4.117.26"; classtype:trojan-activity; sid:100000105; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.70.160.51"; classtype:trojan-activity; sid:100000106; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.79.112.254"; classtype:trojan-activity; sid:100000107; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.82.144.197"; classtype:trojan-activity; sid:100000108; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.82.145.111"; classtype:trojan-activity; sid:100000109; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.82.98.151"; classtype:trojan-activity; sid:100000110; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.82.98.170"; classtype:trojan-activity; sid:100000111; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.84.240.228"; classtype:trojan-activity; sid:100000112; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.12"; classtype:trojan-activity; sid:100000113; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.16"; classtype:trojan-activity; sid:100000114; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.17"; classtype:trojan-activity; sid:100000115; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.19"; classtype:trojan-activity; sid:100000116; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.20"; classtype:trojan-activity; sid:100000117; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.27"; classtype:trojan-activity; sid:100000118; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.3"; classtype:trojan-activity; sid:100000119; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.30"; classtype:trojan-activity; sid:100000120; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.36"; classtype:trojan-activity; sid:100000121; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.41"; classtype:trojan-activity; sid:100000122; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.46"; classtype:trojan-activity; sid:100000123; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.47"; classtype:trojan-activity; sid:100000124; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.91.245.54"; classtype:trojan-activity; sid:100000125; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.92.25.90"; classtype:trojan-activity; sid:100000126; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"103.92.25.95"; classtype:trojan-activity; sid:100000127; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.168.44.57"; classtype:trojan-activity; sid:100000128; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.168.98.105"; classtype:trojan-activity; sid:100000128; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.184.75.123"; classtype:trojan-activity; sid:100000129; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.33.52.85"; classtype:trojan-activity; sid:100000130; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"104.61.86.37"; classtype:trojan-activity; sid:100000131; rev:1;)
@@ -140,5638 +140,5614 @@ alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious web
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.104.193.155"; classtype:trojan-activity; sid:100000134; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.113.145.32"; classtype:trojan-activity; sid:100000135; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.113.177.60"; classtype:trojan-activity; sid:100000136; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.172.134.48"; classtype:trojan-activity; sid:100000137; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.172.193.132"; classtype:trojan-activity; sid:100000138; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.172.249.148"; classtype:trojan-activity; sid:100000139; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.173.155.54"; classtype:trojan-activity; sid:100000140; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.174.144.195"; classtype:trojan-activity; sid:100000141; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.175.197.135"; classtype:trojan-activity; sid:100000142; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.181.136.96"; classtype:trojan-activity; sid:100000143; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.194.242.170"; classtype:trojan-activity; sid:100000144; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.219.185.75"; classtype:trojan-activity; sid:100000145; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.220.119.25"; classtype:trojan-activity; sid:100000146; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.221.96.202"; classtype:trojan-activity; sid:100000147; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"108.190.201.37"; classtype:trojan-activity; sid:100000148; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"108.190.250.48"; classtype:trojan-activity; sid:100000149; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"108.55.199.65"; classtype:trojan-activity; sid:100000150; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.104.151.108"; classtype:trojan-activity; sid:100000151; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.124.90.229"; classtype:trojan-activity; sid:100000152; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.233.196.232"; classtype:trojan-activity; sid:100000153; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.235.7.228"; classtype:trojan-activity; sid:100000154; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.248.58.238"; classtype:trojan-activity; sid:100000155; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"106.4.138.95"; classtype:trojan-activity; sid:100000137; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.172.134.48"; classtype:trojan-activity; sid:100000138; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.172.193.132"; classtype:trojan-activity; sid:100000139; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.172.249.148"; classtype:trojan-activity; sid:100000140; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.173.155.54"; classtype:trojan-activity; sid:100000141; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.174.144.195"; classtype:trojan-activity; sid:100000142; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.175.197.135"; classtype:trojan-activity; sid:100000143; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.181.136.96"; classtype:trojan-activity; sid:100000144; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.194.242.170"; classtype:trojan-activity; sid:100000145; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.219.185.75"; classtype:trojan-activity; sid:100000146; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.220.119.25"; classtype:trojan-activity; sid:100000147; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"107.221.96.202"; classtype:trojan-activity; sid:100000148; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"108.190.201.37"; classtype:trojan-activity; sid:100000149; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"108.190.250.48"; classtype:trojan-activity; sid:100000150; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"108.55.199.65"; classtype:trojan-activity; sid:100000151; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.104.151.108"; classtype:trojan-activity; sid:100000152; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.124.90.229"; classtype:trojan-activity; sid:100000153; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.233.196.232"; classtype:trojan-activity; sid:100000154; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.235.7.228"; classtype:trojan-activity; sid:100000155; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.86.85.253"; classtype:trojan-activity; sid:100000156; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.95.200.102"; classtype:trojan-activity; sid:100000157; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.95.200.230"; classtype:trojan-activity; sid:100000158; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.96.127.90"; classtype:trojan-activity; sid:100000159; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.96.57.246"; classtype:trojan-activity; sid:100000160; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.99.37.97"; classtype:trojan-activity; sid:100000161; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"10abcabc0.cf"; classtype:trojan-activity; sid:100000162; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.10.58.38"; classtype:trojan-activity; sid:100000163; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.12.123.11"; classtype:trojan-activity; sid:100000164; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.14.58.190"; classtype:trojan-activity; sid:100000165; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.187.229.182"; classtype:trojan-activity; sid:100000166; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.228.190.50"; classtype:trojan-activity; sid:100000167; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.228.195.46"; classtype:trojan-activity; sid:100000168; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.241.119.168"; classtype:trojan-activity; sid:100000169; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.241.23.107"; classtype:trojan-activity; sid:100000170; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.248.124.254"; classtype:trojan-activity; sid:100000171; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.248.224.19"; classtype:trojan-activity; sid:100000172; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.248.251.194"; classtype:trojan-activity; sid:100000173; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.251.10.18"; classtype:trojan-activity; sid:100000174; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.253.103.53"; classtype:trojan-activity; sid:100000175; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.253.213.198"; classtype:trojan-activity; sid:100000176; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.253.51.112"; classtype:trojan-activity; sid:100000177; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.255.101.184"; classtype:trojan-activity; sid:100000178; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.255.167.147"; classtype:trojan-activity; sid:100000179; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.145.127"; classtype:trojan-activity; sid:100000180; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.208.21"; classtype:trojan-activity; sid:100000181; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.209.175"; classtype:trojan-activity; sid:100000182; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.221.77"; classtype:trojan-activity; sid:100000183; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.88.185.119"; classtype:trojan-activity; sid:100000157; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.95.200.102"; classtype:trojan-activity; sid:100000158; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.95.200.230"; classtype:trojan-activity; sid:100000159; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.96.127.90"; classtype:trojan-activity; sid:100000160; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.96.57.246"; classtype:trojan-activity; sid:100000161; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"109.99.37.97"; classtype:trojan-activity; sid:100000162; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"10abcabc0.cf"; classtype:trojan-activity; sid:100000163; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.10.58.38"; classtype:trojan-activity; sid:100000164; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.12.123.11"; classtype:trojan-activity; sid:100000165; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.14.58.190"; classtype:trojan-activity; sid:100000166; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.187.229.182"; classtype:trojan-activity; sid:100000167; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.228.190.50"; classtype:trojan-activity; sid:100000168; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.228.195.46"; classtype:trojan-activity; sid:100000169; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.241.119.168"; classtype:trojan-activity; sid:100000170; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.241.23.107"; classtype:trojan-activity; sid:100000171; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.247.151.4"; classtype:trojan-activity; sid:100000172; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.248.124.254"; classtype:trojan-activity; sid:100000173; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.248.224.19"; classtype:trojan-activity; sid:100000174; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.248.251.194"; classtype:trojan-activity; sid:100000175; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.251.10.18"; classtype:trojan-activity; sid:100000176; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.253.103.53"; classtype:trojan-activity; sid:100000177; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.253.213.198"; classtype:trojan-activity; sid:100000178; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.253.51.112"; classtype:trojan-activity; sid:100000179; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.255.101.184"; classtype:trojan-activity; sid:100000180; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.255.167.147"; classtype:trojan-activity; sid:100000181; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.208.21"; classtype:trojan-activity; sid:100000182; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.209.175"; classtype:trojan-activity; sid:100000183; rev:1;)
 alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.223.92"; classtype:trojan-activity; sid:100000184; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.235.57"; classtype:trojan-activity; sid:100000185; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.4.2"; classtype:trojan-activity; sid:100000186; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.82.195.88"; classtype:trojan-activity; sid:100000187; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110fss.net"; classtype:trojan-activity; sid:100000188; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.118.124.223"; classtype:trojan-activity; sid:100000189; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.118.41.173"; classtype:trojan-activity; sid:100000190; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.118.88.61"; classtype:trojan-activity; sid:100000191; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.125.67.125"; classtype:trojan-activity; sid:100000192; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.160.112.142"; classtype:trojan-activity; sid:100000193; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.162.224.14"; classtype:trojan-activity; sid:100000194; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.163.50.120"; classtype:trojan-activity; sid:100000195; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.17.186.194"; classtype:trojan-activity; sid:100000196; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.170.84.182"; classtype:trojan-activity; sid:100000197; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.170.86.133"; classtype:trojan-activity; sid:100000198; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.172.164.104"; classtype:trojan-activity; sid:100000199; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.176.182.149"; classtype:trojan-activity; sid:100000200; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.179.153.69"; classtype:trojan-activity; sid:100000201; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.179.243.126"; classtype:trojan-activity; sid:100000202; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.182.232.18"; classtype:trojan-activity; sid:100000203; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.177.85"; classtype:trojan-activity; sid:100000204; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.23.84"; classtype:trojan-activity; sid:100000205; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.230.136"; classtype:trojan-activity; sid:100000206; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.27.9"; classtype:trojan-activity; sid:100000207; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.48.248"; classtype:trojan-activity; sid:100000208; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.103.122"; classtype:trojan-activity; sid:100000209; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.103.13"; classtype:trojan-activity; sid:100000210; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.103.66"; classtype:trojan-activity; sid:100000211; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.104.141"; classtype:trojan-activity; sid:100000212; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.104.165"; classtype:trojan-activity; sid:100000213; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.106.128"; classtype:trojan-activity; sid:100000214; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.106.19"; classtype:trojan-activity; sid:100000215; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.106.48"; classtype:trojan-activity; sid:100000216; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.121.222"; classtype:trojan-activity; sid:100000217; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.121.223"; classtype:trojan-activity; sid:100000218; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.121.228"; classtype:trojan-activity; sid:100000219; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.123.18"; classtype:trojan-activity; sid:100000220; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.123.184"; classtype:trojan-activity; sid:100000221; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.123.197"; classtype:trojan-activity; sid:100000222; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.123.200"; classtype:trojan-activity; sid:100000223; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.123.23"; classtype:trojan-activity; sid:100000224; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.26.173"; classtype:trojan-activity; sid:100000225; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.26.243"; classtype:trojan-activity; sid:100000226; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.8.81"; classtype:trojan-activity; sid:100000227; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.61.52.53"; classtype:trojan-activity; sid:100000228; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.73.99.162"; classtype:trojan-activity; sid:100000229; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.91.185.131"; classtype:trojan-activity; sid:100000230; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.93.169.90"; classtype:trojan-activity; sid:100000231; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.105.117.227"; classtype:trojan-activity; sid:100000232; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.111.100.236"; classtype:trojan-activity; sid:100000233; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.111.108.184"; classtype:trojan-activity; sid:100000234; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.111.31.175"; classtype:trojan-activity; sid:100000235; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.122.36.108"; classtype:trojan-activity; sid:100000236; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.123.109.156"; classtype:trojan-activity; sid:100000237; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.123.200.47"; classtype:trojan-activity; sid:100000238; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.123.61.115"; classtype:trojan-activity; sid:100000239; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.132.134.106"; classtype:trojan-activity; sid:100000240; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.170.124.75"; classtype:trojan-activity; sid:100000241; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.170.233.9"; classtype:trojan-activity; sid:100000242; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.186.210.211"; classtype:trojan-activity; sid:100000243; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.186.96.252"; classtype:trojan-activity; sid:100000244; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.187.91.117"; classtype:trojan-activity; sid:100000245; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.214.127.42"; classtype:trojan-activity; sid:100000246; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.187.19"; classtype:trojan-activity; sid:100000247; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.236.77"; classtype:trojan-activity; sid:100000248; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.43.27"; classtype:trojan-activity; sid:100000249; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.52.145"; classtype:trojan-activity; sid:100000250; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.82.4"; classtype:trojan-activity; sid:100000251; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.118.229"; classtype:trojan-activity; sid:100000252; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.176.167"; classtype:trojan-activity; sid:100000253; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.195.104"; classtype:trojan-activity; sid:100000254; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.202.111"; classtype:trojan-activity; sid:100000255; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.205.96"; classtype:trojan-activity; sid:100000256; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.47.235"; classtype:trojan-activity; sid:100000257; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.67.193"; classtype:trojan-activity; sid:100000258; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.92.34"; classtype:trojan-activity; sid:100000259; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.228.100.15"; classtype:trojan-activity; sid:100000260; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.228.180.95"; classtype:trojan-activity; sid:100000261; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.228.79.114"; classtype:trojan-activity; sid:100000262; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.228.79.137"; classtype:trojan-activity; sid:100000263; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.229.178.109"; classtype:trojan-activity; sid:100000264; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.229.188.28"; classtype:trojan-activity; sid:100000265; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.229.199.19"; classtype:trojan-activity; sid:100000266; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.234.134.244"; classtype:trojan-activity; sid:100000267; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.234.16.252"; classtype:trojan-activity; sid:100000268; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.234.194.178"; classtype:trojan-activity; sid:100000269; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.234.216.151"; classtype:trojan-activity; sid:100000270; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.234.218.202"; classtype:trojan-activity; sid:100000271; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.235.149.73"; classtype:trojan-activity; sid:100000272; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.235.188.86"; classtype:trojan-activity; sid:100000273; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.236.126.177"; classtype:trojan-activity; sid:100000274; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.236.171.69"; classtype:trojan-activity; sid:100000275; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.236.228.21"; classtype:trojan-activity; sid:100000276; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.141.241"; classtype:trojan-activity; sid:100000277; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.144.226"; classtype:trojan-activity; sid:100000278; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.197.144"; classtype:trojan-activity; sid:100000279; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.230.192"; classtype:trojan-activity; sid:100000280; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.75.157"; classtype:trojan-activity; sid:100000281; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.89.82"; classtype:trojan-activity; sid:100000282; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.143.135"; classtype:trojan-activity; sid:100000283; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.17.120"; classtype:trojan-activity; sid:100000284; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.190.207"; classtype:trojan-activity; sid:100000285; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.194.18"; classtype:trojan-activity; sid:100000286; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.227.228"; classtype:trojan-activity; sid:100000287; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.73.181"; classtype:trojan-activity; sid:100000288; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.240.184.162"; classtype:trojan-activity; sid:100000289; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.240.216.17"; classtype:trojan-activity; sid:100000290; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.242.106.228"; classtype:trojan-activity; sid:100000291; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.242.18.128"; classtype:trojan-activity; sid:100000292; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.242.2.247"; classtype:trojan-activity; sid:100000293; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.243.115.183"; classtype:trojan-activity; sid:100000294; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.245.12.89"; classtype:trojan-activity; sid:100000295; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.245.246.253"; classtype:trojan-activity; sid:100000296; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.245.5.141"; classtype:trojan-activity; sid:100000297; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.245.8.24"; classtype:trojan-activity; sid:100000298; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.246.162.50"; classtype:trojan-activity; sid:100000299; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.100.14"; classtype:trojan-activity; sid:100000300; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.121.39"; classtype:trojan-activity; sid:100000301; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.14.135"; classtype:trojan-activity; sid:100000302; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.161.45"; classtype:trojan-activity; sid:100000303; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.191.118"; classtype:trojan-activity; sid:100000304; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.214.146"; classtype:trojan-activity; sid:100000305; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.240.226"; classtype:trojan-activity; sid:100000306; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.81.173"; classtype:trojan-activity; sid:100000307; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.82.122"; classtype:trojan-activity; sid:100000308; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.89.81"; classtype:trojan-activity; sid:100000309; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.248.148.90"; classtype:trojan-activity; sid:100000310; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.248.197.164"; classtype:trojan-activity; sid:100000311; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.248.44.153"; classtype:trojan-activity; sid:100000312; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.109.217"; classtype:trojan-activity; sid:100000313; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.118.157"; classtype:trojan-activity; sid:100000314; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.26.129"; classtype:trojan-activity; sid:100000315; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.41.142"; classtype:trojan-activity; sid:100000316; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.250.102.173"; classtype:trojan-activity; sid:100000317; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.250.57.99"; classtype:trojan-activity; sid:100000318; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.251.17.5"; classtype:trojan-activity; sid:100000319; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.251.218.210"; classtype:trojan-activity; sid:100000320; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.251.23.55"; classtype:trojan-activity; sid:100000321; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.136.84"; classtype:trojan-activity; sid:100000322; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.199.150"; classtype:trojan-activity; sid:100000323; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.221.244"; classtype:trojan-activity; sid:100000324; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.236.40"; classtype:trojan-activity; sid:100000325; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.237.109"; classtype:trojan-activity; sid:100000326; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.239.103"; classtype:trojan-activity; sid:100000327; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.245.249"; classtype:trojan-activity; sid:100000328; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.254.208.123"; classtype:trojan-activity; sid:100000329; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.255.38.10"; classtype:trojan-activity; sid:100000330; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.255.52.179"; classtype:trojan-activity; sid:100000331; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.255.8.235"; classtype:trojan-activity; sid:100000332; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.121.163"; classtype:trojan-activity; sid:100000333; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.123.174"; classtype:trojan-activity; sid:100000334; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.109"; classtype:trojan-activity; sid:100000335; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.110"; classtype:trojan-activity; sid:100000336; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.111"; classtype:trojan-activity; sid:100000337; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.112"; classtype:trojan-activity; sid:100000338; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.117"; classtype:trojan-activity; sid:100000339; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.119"; classtype:trojan-activity; sid:100000340; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.120"; classtype:trojan-activity; sid:100000341; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.122"; classtype:trojan-activity; sid:100000342; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.127"; classtype:trojan-activity; sid:100000343; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.128"; classtype:trojan-activity; sid:100000344; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.130"; classtype:trojan-activity; sid:100000345; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.131"; classtype:trojan-activity; sid:100000346; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.132"; classtype:trojan-activity; sid:100000347; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.133"; classtype:trojan-activity; sid:100000348; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.136"; classtype:trojan-activity; sid:100000349; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.139"; classtype:trojan-activity; sid:100000350; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.140"; classtype:trojan-activity; sid:100000351; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.142"; classtype:trojan-activity; sid:100000352; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.143"; classtype:trojan-activity; sid:100000353; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.144"; classtype:trojan-activity; sid:100000354; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.146"; classtype:trojan-activity; sid:100000355; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.149"; classtype:trojan-activity; sid:100000356; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.150"; classtype:trojan-activity; sid:100000357; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.151"; classtype:trojan-activity; sid:100000358; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.155"; classtype:trojan-activity; sid:100000359; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.158"; classtype:trojan-activity; sid:100000360; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.160"; classtype:trojan-activity; sid:100000361; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.162"; classtype:trojan-activity; sid:100000362; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.163"; classtype:trojan-activity; sid:100000363; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.165"; classtype:trojan-activity; sid:100000364; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.168"; classtype:trojan-activity; sid:100000365; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.171"; classtype:trojan-activity; sid:100000366; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.172"; classtype:trojan-activity; sid:100000367; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.175"; classtype:trojan-activity; sid:100000368; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.176"; classtype:trojan-activity; sid:100000369; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.178"; classtype:trojan-activity; sid:100000370; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.179"; classtype:trojan-activity; sid:100000371; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.71"; classtype:trojan-activity; sid:100000372; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.126.243"; classtype:trojan-activity; sid:100000373; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.127.155"; classtype:trojan-activity; sid:100000374; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.80.120"; classtype:trojan-activity; sid:100000375; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.80.121"; classtype:trojan-activity; sid:100000376; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.80.98"; classtype:trojan-activity; sid:100000377; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.82.29"; classtype:trojan-activity; sid:100000378; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.83.182"; classtype:trojan-activity; sid:100000379; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.83.23"; classtype:trojan-activity; sid:100000380; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.87.213"; classtype:trojan-activity; sid:100000381; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.88.116"; classtype:trojan-activity; sid:100000382; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.91.212"; classtype:trojan-activity; sid:100000383; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.91.247"; classtype:trojan-activity; sid:100000384; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.150"; classtype:trojan-activity; sid:100000385; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.158"; classtype:trojan-activity; sid:100000386; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.159"; classtype:trojan-activity; sid:100000387; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.168"; classtype:trojan-activity; sid:100000388; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.177"; classtype:trojan-activity; sid:100000389; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.178"; classtype:trojan-activity; sid:100000390; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.181"; classtype:trojan-activity; sid:100000391; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.188"; classtype:trojan-activity; sid:100000392; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.194"; classtype:trojan-activity; sid:100000393; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.197"; classtype:trojan-activity; sid:100000394; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.200"; classtype:trojan-activity; sid:100000395; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.211"; classtype:trojan-activity; sid:100000396; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.219"; classtype:trojan-activity; sid:100000397; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.229"; classtype:trojan-activity; sid:100000398; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.230"; classtype:trojan-activity; sid:100000399; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.245"; classtype:trojan-activity; sid:100000400; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.247"; classtype:trojan-activity; sid:100000401; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.54"; classtype:trojan-activity; sid:100000402; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.55"; classtype:trojan-activity; sid:100000403; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.57"; classtype:trojan-activity; sid:100000404; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.60"; classtype:trojan-activity; sid:100000405; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.90"; classtype:trojan-activity; sid:100000406; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.91"; classtype:trojan-activity; sid:100000407; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.100.228"; classtype:trojan-activity; sid:100000408; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.27"; classtype:trojan-activity; sid:100000409; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.30"; classtype:trojan-activity; sid:100000410; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.31"; classtype:trojan-activity; sid:100000411; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.32"; classtype:trojan-activity; sid:100000412; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.33"; classtype:trojan-activity; sid:100000413; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.37"; classtype:trojan-activity; sid:100000414; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.38"; classtype:trojan-activity; sid:100000415; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.41"; classtype:trojan-activity; sid:100000416; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.42"; classtype:trojan-activity; sid:100000417; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.43"; classtype:trojan-activity; sid:100000418; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.52"; classtype:trojan-activity; sid:100000419; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.55"; classtype:trojan-activity; sid:100000420; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.57"; classtype:trojan-activity; sid:100000421; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.58"; classtype:trojan-activity; sid:100000422; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.60"; classtype:trojan-activity; sid:100000423; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.62"; classtype:trojan-activity; sid:100000424; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.64"; classtype:trojan-activity; sid:100000425; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.35.237"; classtype:trojan-activity; sid:100000426; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.38.100"; classtype:trojan-activity; sid:100000427; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.38.19"; classtype:trojan-activity; sid:100000428; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.118"; classtype:trojan-activity; sid:100000429; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.119"; classtype:trojan-activity; sid:100000430; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.121"; classtype:trojan-activity; sid:100000431; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.136"; classtype:trojan-activity; sid:100000432; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.37"; classtype:trojan-activity; sid:100000433; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.52"; classtype:trojan-activity; sid:100000434; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.53"; classtype:trojan-activity; sid:100000435; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.73"; classtype:trojan-activity; sid:100000436; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.77"; classtype:trojan-activity; sid:100000437; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.90"; classtype:trojan-activity; sid:100000438; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.31.211.135"; classtype:trojan-activity; sid:100000439; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.53.224.79"; classtype:trojan-activity; sid:100000440; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.53.227.57"; classtype:trojan-activity; sid:100000441; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.53.227.66"; classtype:trojan-activity; sid:100000442; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.65.53.175"; classtype:trojan-activity; sid:100000443; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.153.37"; classtype:trojan-activity; sid:100000444; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.162.159"; classtype:trojan-activity; sid:100000445; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.162.49"; classtype:trojan-activity; sid:100000446; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.162.53"; classtype:trojan-activity; sid:100000447; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.175.147"; classtype:trojan-activity; sid:100000448; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.176.112"; classtype:trojan-activity; sid:100000449; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.176.84"; classtype:trojan-activity; sid:100000450; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.226.202"; classtype:trojan-activity; sid:100000451; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.231.35"; classtype:trojan-activity; sid:100000452; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.78.45.158"; classtype:trojan-activity; sid:100000453; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.80.118.16"; classtype:trojan-activity; sid:100000454; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.80.127.91"; classtype:trojan-activity; sid:100000455; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.80.215.101"; classtype:trojan-activity; sid:100000456; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.81.161.10"; classtype:trojan-activity; sid:100000457; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.81.199.218"; classtype:trojan-activity; sid:100000458; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.81.49.200"; classtype:trojan-activity; sid:100000459; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.131.124"; classtype:trojan-activity; sid:100000460; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.141.200"; classtype:trojan-activity; sid:100000461; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.146.253"; classtype:trojan-activity; sid:100000462; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.148.146"; classtype:trojan-activity; sid:100000463; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.18.255"; classtype:trojan-activity; sid:100000464; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.224.139"; classtype:trojan-activity; sid:100000465; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.227.41"; classtype:trojan-activity; sid:100000466; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.228.175"; classtype:trojan-activity; sid:100000467; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.86.133.125"; classtype:trojan-activity; sid:100000468; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.86.23.41"; classtype:trojan-activity; sid:100000469; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.86.253.238"; classtype:trojan-activity; sid:100000470; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.9.140.247"; classtype:trojan-activity; sid:100000471; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.93.29.211"; classtype:trojan-activity; sid:100000472; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.95.22.17"; classtype:trojan-activity; sid:100000473; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.95.23.121"; classtype:trojan-activity; sid:100000474; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.103.10.209"; classtype:trojan-activity; sid:100000475; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.105.71.239"; classtype:trojan-activity; sid:100000476; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.11.95.254"; classtype:trojan-activity; sid:100000477; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.110.247.207"; classtype:trojan-activity; sid:100000478; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.116.121.167"; classtype:trojan-activity; sid:100000479; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.116.149.83"; classtype:trojan-activity; sid:100000480; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.116.246.109"; classtype:trojan-activity; sid:100000481; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.116.48.217"; classtype:trojan-activity; sid:100000482; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.118.195.247"; classtype:trojan-activity; sid:100000483; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.122.238.68"; classtype:trojan-activity; sid:100000484; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.122.59.84"; classtype:trojan-activity; sid:100000485; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.161.58.249"; classtype:trojan-activity; sid:100000486; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.172.250.35"; classtype:trojan-activity; sid:100000487; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.179.129.99"; classtype:trojan-activity; sid:100000488; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.188.76.31"; classtype:trojan-activity; sid:100000489; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.194.133.9"; classtype:trojan-activity; sid:100000490; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.194.135.154"; classtype:trojan-activity; sid:100000491; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.195.163.26"; classtype:trojan-activity; sid:100000492; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.195.166.46"; classtype:trojan-activity; sid:100000493; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.224.225.172"; classtype:trojan-activity; sid:100000494; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.226.42.250"; classtype:trojan-activity; sid:100000495; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.227.128.9"; classtype:trojan-activity; sid:100000496; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.227.169.170"; classtype:trojan-activity; sid:100000497; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.227.35.229"; classtype:trojan-activity; sid:100000498; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.231.211.131"; classtype:trojan-activity; sid:100000499; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.231.93.142"; classtype:trojan-activity; sid:100000500; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.232.141.23"; classtype:trojan-activity; sid:100000501; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.232.211.182"; classtype:trojan-activity; sid:100000502; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.235.116.209"; classtype:trojan-activity; sid:100000503; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.237.129.7"; classtype:trojan-activity; sid:100000504; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.245.218.18"; classtype:trojan-activity; sid:100000505; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.254.169.251"; classtype:trojan-activity; sid:100000506; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.3.153.57"; classtype:trojan-activity; sid:100000507; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.3.155.199"; classtype:trojan-activity; sid:100000508; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.133.16"; classtype:trojan-activity; sid:100000509; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.136.39"; classtype:trojan-activity; sid:100000510; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.144.42"; classtype:trojan-activity; sid:100000511; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.154.21"; classtype:trojan-activity; sid:100000512; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.191.47"; classtype:trojan-activity; sid:100000513; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.61.204.205"; classtype:trojan-activity; sid:100000514; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.86.204.13"; classtype:trojan-activity; sid:100000515; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.87.175.112"; classtype:trojan-activity; sid:100000516; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.87.32.93"; classtype:trojan-activity; sid:100000517; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.88.208.189"; classtype:trojan-activity; sid:100000518; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.88.232.36"; classtype:trojan-activity; sid:100000519; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.88.38.232"; classtype:trojan-activity; sid:100000520; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.89.41.33"; classtype:trojan-activity; sid:100000521; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.89.41.51"; classtype:trojan-activity; sid:100000522; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.92.156.196"; classtype:trojan-activity; sid:100000523; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.93.225.12"; classtype:trojan-activity; sid:100000524; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.199.204.37"; classtype:trojan-activity; sid:100000525; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.199.253.235"; classtype:trojan-activity; sid:100000526; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.223.122.19"; classtype:trojan-activity; sid:100000527; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.226.100.56"; classtype:trojan-activity; sid:100000528; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.227.156.119"; classtype:trojan-activity; sid:100000529; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.228.205.101"; classtype:trojan-activity; sid:100000530; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.228.242.109"; classtype:trojan-activity; sid:100000531; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.229.165.194"; classtype:trojan-activity; sid:100000532; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.229.52.14"; classtype:trojan-activity; sid:100000533; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.235.115.236"; classtype:trojan-activity; sid:100000534; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.235.42.152"; classtype:trojan-activity; sid:100000535; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.30.54.64"; classtype:trojan-activity; sid:100000536; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.79.161.94"; classtype:trojan-activity; sid:100000537; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.79.172.42"; classtype:trojan-activity; sid:100000538; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.165.216.112"; classtype:trojan-activity; sid:100000539; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.193.130.126"; classtype:trojan-activity; sid:100000540; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.208.101.195"; classtype:trojan-activity; sid:100000541; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.223.159.80"; classtype:trojan-activity; sid:100000542; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.23.88.135"; classtype:trojan-activity; sid:100000543; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.42.47.36"; classtype:trojan-activity; sid:100000544; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.48.130.181"; classtype:trojan-activity; sid:100000545; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.48.141.239"; classtype:trojan-activity; sid:100000546; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.48.198.142"; classtype:trojan-activity; sid:100000547; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.48.215.189"; classtype:trojan-activity; sid:100000548; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.48.22.130"; classtype:trojan-activity; sid:100000549; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.48.228.176"; classtype:trojan-activity; sid:100000550; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.48.9.246"; classtype:trojan-activity; sid:100000551; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.49.100.124"; classtype:trojan-activity; sid:100000552; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.49.18.53"; classtype:trojan-activity; sid:100000553; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.49.216.150"; classtype:trojan-activity; sid:100000554; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.49.60.231"; classtype:trojan-activity; sid:100000555; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.1.143"; classtype:trojan-activity; sid:100000556; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.158.223"; classtype:trojan-activity; sid:100000557; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.2.251"; classtype:trojan-activity; sid:100000558; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.219.100"; classtype:trojan-activity; sid:100000559; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.22.86"; classtype:trojan-activity; sid:100000560; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.220.156"; classtype:trojan-activity; sid:100000561; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.224.175"; classtype:trojan-activity; sid:100000562; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.230.43"; classtype:trojan-activity; sid:100000563; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.232.149"; classtype:trojan-activity; sid:100000564; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.239.222"; classtype:trojan-activity; sid:100000565; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.3.25"; classtype:trojan-activity; sid:100000566; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.56.198"; classtype:trojan-activity; sid:100000567; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.8.131"; classtype:trojan-activity; sid:100000568; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.81.194"; classtype:trojan-activity; sid:100000569; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.51.104.85"; classtype:trojan-activity; sid:100000570; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.51.123.216"; classtype:trojan-activity; sid:100000571; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.51.93.76"; classtype:trojan-activity; sid:100000572; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.52.112.200"; classtype:trojan-activity; sid:100000573; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.52.19.250"; classtype:trojan-activity; sid:100000574; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.52.200.245"; classtype:trojan-activity; sid:100000575; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.52.21.5"; classtype:trojan-activity; sid:100000576; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.54.192.172"; classtype:trojan-activity; sid:100000577; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.54.222.126"; classtype:trojan-activity; sid:100000578; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.54.236.22"; classtype:trojan-activity; sid:100000579; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.54.241.122"; classtype:trojan-activity; sid:100000580; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.54.73.162"; classtype:trojan-activity; sid:100000581; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.105.163"; classtype:trojan-activity; sid:100000582; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.144.146"; classtype:trojan-activity; sid:100000583; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.144.222"; classtype:trojan-activity; sid:100000584; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.144.42"; classtype:trojan-activity; sid:100000585; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.145.147"; classtype:trojan-activity; sid:100000586; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.149.30"; classtype:trojan-activity; sid:100000587; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.178.67"; classtype:trojan-activity; sid:100000588; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.198.209"; classtype:trojan-activity; sid:100000589; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.211.86"; classtype:trojan-activity; sid:100000590; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.42.200"; classtype:trojan-activity; sid:100000591; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.53.51"; classtype:trojan-activity; sid:100000592; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.134.116"; classtype:trojan-activity; sid:100000593; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.134.220"; classtype:trojan-activity; sid:100000594; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.139.122"; classtype:trojan-activity; sid:100000595; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.142.251"; classtype:trojan-activity; sid:100000596; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.143.241"; classtype:trojan-activity; sid:100000597; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.148.22"; classtype:trojan-activity; sid:100000598; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.155.72"; classtype:trojan-activity; sid:100000599; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.156.185"; classtype:trojan-activity; sid:100000600; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.162.173"; classtype:trojan-activity; sid:100000601; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.178.107"; classtype:trojan-activity; sid:100000602; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.188.24"; classtype:trojan-activity; sid:100000603; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.31.54"; classtype:trojan-activity; sid:100000604; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.67.22"; classtype:trojan-activity; sid:100000605; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.86.251"; classtype:trojan-activity; sid:100000606; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.87.42"; classtype:trojan-activity; sid:100000607; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.98.205"; classtype:trojan-activity; sid:100000608; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.111.222"; classtype:trojan-activity; sid:100000609; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.119.171"; classtype:trojan-activity; sid:100000610; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.134.143"; classtype:trojan-activity; sid:100000611; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.141.177"; classtype:trojan-activity; sid:100000612; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.83.233"; classtype:trojan-activity; sid:100000613; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.88.163"; classtype:trojan-activity; sid:100000614; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.93.151"; classtype:trojan-activity; sid:100000615; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.197.123"; classtype:trojan-activity; sid:100000616; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.198.165"; classtype:trojan-activity; sid:100000617; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.210.228"; classtype:trojan-activity; sid:100000618; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.235.229"; classtype:trojan-activity; sid:100000619; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.253.202"; classtype:trojan-activity; sid:100000620; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.26.134"; classtype:trojan-activity; sid:100000621; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.63.220"; classtype:trojan-activity; sid:100000622; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.107.203"; classtype:trojan-activity; sid:100000623; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.111.142"; classtype:trojan-activity; sid:100000624; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.119.187"; classtype:trojan-activity; sid:100000625; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.119.198"; classtype:trojan-activity; sid:100000626; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.119.77"; classtype:trojan-activity; sid:100000627; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.125.184"; classtype:trojan-activity; sid:100000628; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.137.47"; classtype:trojan-activity; sid:100000629; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.180.193"; classtype:trojan-activity; sid:100000630; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.182.138"; classtype:trojan-activity; sid:100000631; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.185.246"; classtype:trojan-activity; sid:100000632; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.97.190"; classtype:trojan-activity; sid:100000633; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.62.26.39"; classtype:trojan-activity; sid:100000634; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.62.60.206"; classtype:trojan-activity; sid:100000635; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.63.135.206"; classtype:trojan-activity; sid:100000636; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.63.4.244"; classtype:trojan-activity; sid:100000637; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.63.56.176"; classtype:trojan-activity; sid:100000638; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.73.3.11"; classtype:trojan-activity; sid:100000639; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.74.217.2"; classtype:trojan-activity; sid:100000640; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.75.217.79"; classtype:trojan-activity; sid:100000641; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.92.174.231"; classtype:trojan-activity; sid:100000642; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.124.219.2"; classtype:trojan-activity; sid:100000643; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.127.207.224"; classtype:trojan-activity; sid:100000644; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.149.119.185"; classtype:trojan-activity; sid:100000645; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.2.100.221"; classtype:trojan-activity; sid:100000646; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.2.66.3"; classtype:trojan-activity; sid:100000647; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.206.164.46"; classtype:trojan-activity; sid:100000648; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.211.100.26"; classtype:trojan-activity; sid:100000649; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.212.142.215"; classtype:trojan-activity; sid:100000650; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.24.153.40"; classtype:trojan-activity; sid:100000651; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.72.201.93"; classtype:trojan-activity; sid:100000652; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.75.192.140"; classtype:trojan-activity; sid:100000653; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.76.114.71"; classtype:trojan-activity; sid:100000654; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.88.65.131"; classtype:trojan-activity; sid:100000655; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.11.234.35"; classtype:trojan-activity; sid:100000656; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.11.95.179"; classtype:trojan-activity; sid:100000657; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.15.201.1"; classtype:trojan-activity; sid:100000658; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.192.224.243"; classtype:trojan-activity; sid:100000659; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.192.225.29"; classtype:trojan-activity; sid:100000660; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.192.226.96"; classtype:trojan-activity; sid:100000661; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.194.162.116"; classtype:trojan-activity; sid:100000662; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.194.163.237"; classtype:trojan-activity; sid:100000663; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.204.138"; classtype:trojan-activity; sid:100000664; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.204.5"; classtype:trojan-activity; sid:100000665; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.210.52"; classtype:trojan-activity; sid:100000666; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.220.126"; classtype:trojan-activity; sid:100000667; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.236.14"; classtype:trojan-activity; sid:100000668; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.243.40"; classtype:trojan-activity; sid:100000669; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.200.76.54"; classtype:trojan-activity; sid:100000670; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.200.76.60"; classtype:trojan-activity; sid:100000671; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.201.128.152"; classtype:trojan-activity; sid:100000672; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.202.66.23"; classtype:trojan-activity; sid:100000673; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.202.67.181"; classtype:trojan-activity; sid:100000674; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.202.67.218"; classtype:trojan-activity; sid:100000675; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.202.68.75"; classtype:trojan-activity; sid:100000676; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.213.41.18"; classtype:trojan-activity; sid:100000677; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.213.42.147"; classtype:trojan-activity; sid:100000678; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.213.42.226"; classtype:trojan-activity; sid:100000679; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.213.44.184"; classtype:trojan-activity; sid:100000680; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.213.45.119"; classtype:trojan-activity; sid:100000681; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.213.45.150"; classtype:trojan-activity; sid:100000682; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.213.45.204"; classtype:trojan-activity; sid:100000683; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.213.46.124"; classtype:trojan-activity; sid:100000684; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.213.46.243"; classtype:trojan-activity; sid:100000685; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.215.213.155"; classtype:trojan-activity; sid:100000686; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.215.215.188"; classtype:trojan-activity; sid:100000687; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.222.160.86"; classtype:trojan-activity; sid:100000688; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.222.165.221"; classtype:trojan-activity; sid:100000689; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.222.166.6"; classtype:trojan-activity; sid:100000690; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.222.169.193"; classtype:trojan-activity; sid:100000691; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.222.170.122"; classtype:trojan-activity; sid:100000692; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.222.175.220"; classtype:trojan-activity; sid:100000693; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.241.66.200"; classtype:trojan-activity; sid:100000694; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.241.67.68"; classtype:trojan-activity; sid:100000695; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.242.211.217"; classtype:trojan-activity; sid:100000696; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.247.204.33"; classtype:trojan-activity; sid:100000697; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.247.206.195"; classtype:trojan-activity; sid:100000698; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.248.60.21"; classtype:trojan-activity; sid:100000699; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.251.56.191"; classtype:trojan-activity; sid:100000700; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.251.56.244"; classtype:trojan-activity; sid:100000701; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.251.56.64"; classtype:trojan-activity; sid:100000702; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.251.56.73"; classtype:trojan-activity; sid:100000703; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.251.60.161"; classtype:trojan-activity; sid:100000704; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.251.63.211"; classtype:trojan-activity; sid:100000705; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.26.110.17"; classtype:trojan-activity; sid:100000706; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.26.235.164"; classtype:trojan-activity; sid:100000707; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.27.10.73"; classtype:trojan-activity; sid:100000708; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.63.113.146"; classtype:trojan-activity; sid:100000709; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.63.195.140"; classtype:trojan-activity; sid:100000710; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.63.252.82"; classtype:trojan-activity; sid:100000711; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.63.53.15"; classtype:trojan-activity; sid:100000712; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.87.170.32"; classtype:trojan-activity; sid:100000713; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.90.78.120"; classtype:trojan-activity; sid:100000714; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.93.115.242"; classtype:trojan-activity; sid:100000715; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.93.79.40"; classtype:trojan-activity; sid:100000716; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.176.104.35"; classtype:trojan-activity; sid:100000717; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.176.157.64"; classtype:trojan-activity; sid:100000718; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.176.7.132"; classtype:trojan-activity; sid:100000719; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.211.38.112"; classtype:trojan-activity; sid:100000720; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.223.32.74"; classtype:trojan-activity; sid:100000721; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.223.5.149"; classtype:trojan-activity; sid:100000722; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.223.72.141"; classtype:trojan-activity; sid:100000723; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.128.147"; classtype:trojan-activity; sid:100000724; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.208.215"; classtype:trojan-activity; sid:100000725; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.209.108"; classtype:trojan-activity; sid:100000726; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.214.72"; classtype:trojan-activity; sid:100000727; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.88.146"; classtype:trojan-activity; sid:100000728; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.96.150"; classtype:trojan-activity; sid:100000729; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.96.6"; classtype:trojan-activity; sid:100000730; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.233.165.213"; classtype:trojan-activity; sid:100000731; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.233.221.162"; classtype:trojan-activity; sid:100000732; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.233.65.93"; classtype:trojan-activity; sid:100000733; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.249.136.112"; classtype:trojan-activity; sid:100000734; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.250.51.192"; classtype:trojan-activity; sid:100000735; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.38.189.207"; classtype:trojan-activity; sid:100000736; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.42.125.246"; classtype:trojan-activity; sid:100000737; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.43.180.33"; classtype:trojan-activity; sid:100000738; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.68.245.69"; classtype:trojan-activity; sid:100000739; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.75.50.253"; classtype:trojan-activity; sid:100000740; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.75.70.70"; classtype:trojan-activity; sid:100000741; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.125.92"; classtype:trojan-activity; sid:100000742; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.143.45"; classtype:trojan-activity; sid:100000743; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.218.157"; classtype:trojan-activity; sid:100000744; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.50.203"; classtype:trojan-activity; sid:100000745; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.58.82"; classtype:trojan-activity; sid:100000746; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.73.123"; classtype:trojan-activity; sid:100000747; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.83.79.43"; classtype:trojan-activity; sid:100000748; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.99.179.164"; classtype:trojan-activity; sid:100000749; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.99.183.235"; classtype:trojan-activity; sid:100000750; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.99.239.217"; classtype:trojan-activity; sid:100000751; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.100.40.250"; classtype:trojan-activity; sid:100000752; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.108.188.238"; classtype:trojan-activity; sid:100000753; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.108.252.237"; classtype:trojan-activity; sid:100000754; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.109.34.245"; classtype:trojan-activity; sid:100000755; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.112.22.58"; classtype:trojan-activity; sid:100000756; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.118.251.73"; classtype:trojan-activity; sid:100000757; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.119.52.202"; classtype:trojan-activity; sid:100000758; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.123.219.137"; classtype:trojan-activity; sid:100000759; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.14.143.145"; classtype:trojan-activity; sid:100000760; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.147.213.57"; classtype:trojan-activity; sid:100000761; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.162.109.111"; classtype:trojan-activity; sid:100000762; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.163.144.208"; classtype:trojan-activity; sid:100000763; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.163.93.191"; classtype:trojan-activity; sid:100000764; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.164.18.235"; classtype:trojan-activity; sid:100000765; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.164.31.76"; classtype:trojan-activity; sid:100000766; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.164.74.153"; classtype:trojan-activity; sid:100000767; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.107.93"; classtype:trojan-activity; sid:100000768; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.163.220"; classtype:trojan-activity; sid:100000769; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.174.63"; classtype:trojan-activity; sid:100000770; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.241.222"; classtype:trojan-activity; sid:100000771; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.27.77"; classtype:trojan-activity; sid:100000772; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.68.145"; classtype:trojan-activity; sid:100000773; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.166.170.241"; classtype:trojan-activity; sid:100000774; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.166.19.254"; classtype:trojan-activity; sid:100000775; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.166.97.6"; classtype:trojan-activity; sid:100000776; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.167.1.13"; classtype:trojan-activity; sid:100000777; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.167.2.214"; classtype:trojan-activity; sid:100000778; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.167.26.33"; classtype:trojan-activity; sid:100000779; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.167.63.195"; classtype:trojan-activity; sid:100000780; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.176.231.217"; classtype:trojan-activity; sid:100000781; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.178.201.188"; classtype:trojan-activity; sid:100000782; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.178.248.123"; classtype:trojan-activity; sid:100000783; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.178.249.140"; classtype:trojan-activity; sid:100000784; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.157.219"; classtype:trojan-activity; sid:100000785; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.16.149"; classtype:trojan-activity; sid:100000786; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.170.212"; classtype:trojan-activity; sid:100000787; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.27.213"; classtype:trojan-activity; sid:100000788; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.43.1"; classtype:trojan-activity; sid:100000789; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.75.8"; classtype:trojan-activity; sid:100000790; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.18.38.144"; classtype:trojan-activity; sid:100000791; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.101.151"; classtype:trojan-activity; sid:100000792; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.106.217"; classtype:trojan-activity; sid:100000793; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.108.227"; classtype:trojan-activity; sid:100000794; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.108.79"; classtype:trojan-activity; sid:100000795; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.11.29"; classtype:trojan-activity; sid:100000796; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.231.79"; classtype:trojan-activity; sid:100000797; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.33.161"; classtype:trojan-activity; sid:100000798; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.80.69"; classtype:trojan-activity; sid:100000799; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.94.80"; classtype:trojan-activity; sid:100000800; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.181.124.203"; classtype:trojan-activity; sid:100000801; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.181.43.18"; classtype:trojan-activity; sid:100000802; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.183.109.21"; classtype:trojan-activity; sid:100000803; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.183.115.103"; classtype:trojan-activity; sid:100000804; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.183.9.82"; classtype:trojan-activity; sid:100000805; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.184.14.112"; classtype:trojan-activity; sid:100000806; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.184.172.199"; classtype:trojan-activity; sid:100000807; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.184.172.53"; classtype:trojan-activity; sid:100000808; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.185.102.182"; classtype:trojan-activity; sid:100000809; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.185.237.89"; classtype:trojan-activity; sid:100000810; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.185.39.240"; classtype:trojan-activity; sid:100000811; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.185.43.193"; classtype:trojan-activity; sid:100000812; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.186.22.245"; classtype:trojan-activity; sid:100000813; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.187.195.161"; classtype:trojan-activity; sid:100000814; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.187.220.115"; classtype:trojan-activity; sid:100000815; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.187.62.80"; classtype:trojan-activity; sid:100000816; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.189.137.195"; classtype:trojan-activity; sid:100000817; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.189.227.244"; classtype:trojan-activity; sid:100000818; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.190.211.99"; classtype:trojan-activity; sid:100000819; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.190.240.238"; classtype:trojan-activity; sid:100000820; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.150.85"; classtype:trojan-activity; sid:100000821; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.187.206"; classtype:trojan-activity; sid:100000822; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.215.221"; classtype:trojan-activity; sid:100000823; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.253.206"; classtype:trojan-activity; sid:100000824; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.204.30.144"; classtype:trojan-activity; sid:100000825; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.250.218.177"; classtype:trojan-activity; sid:100000826; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.251.105.221"; classtype:trojan-activity; sid:100000827; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.251.12.85"; classtype:trojan-activity; sid:100000828; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.251.14.251"; classtype:trojan-activity; sid:100000829; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.131.155"; classtype:trojan-activity; sid:100000830; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.143.46"; classtype:trojan-activity; sid:100000831; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.143.71"; classtype:trojan-activity; sid:100000832; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.148.115"; classtype:trojan-activity; sid:100000833; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.155.57"; classtype:trojan-activity; sid:100000834; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.172.28"; classtype:trojan-activity; sid:100000835; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.175.41"; classtype:trojan-activity; sid:100000836; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.206.43"; classtype:trojan-activity; sid:100000837; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.220.170"; classtype:trojan-activity; sid:100000838; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.96.37.55"; classtype:trojan-activity; sid:100000839; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.96.70.116"; classtype:trojan-activity; sid:100000840; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.99.188.187"; classtype:trojan-activity; sid:100000841; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.99.190.152"; classtype:trojan-activity; sid:100000842; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.99.232.62"; classtype:trojan-activity; sid:100000843; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.132.113.2"; classtype:trojan-activity; sid:100000844; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.15.69.83"; classtype:trojan-activity; sid:100000845; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.6"; classtype:trojan-activity; sid:100000846; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.7"; classtype:trojan-activity; sid:100000847; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.8"; classtype:trojan-activity; sid:100000848; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.9"; classtype:trojan-activity; sid:100000849; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.207.39.227"; classtype:trojan-activity; sid:100000850; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.12.144.232"; classtype:trojan-activity; sid:100000851; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.12.153.54"; classtype:trojan-activity; sid:100000852; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.142.222.22"; classtype:trojan-activity; sid:100000853; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.150.213.110"; classtype:trojan-activity; sid:100000854; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.151.248.134"; classtype:trojan-activity; sid:100000855; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.177"; classtype:trojan-activity; sid:100000856; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.178"; classtype:trojan-activity; sid:100000857; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.180"; classtype:trojan-activity; sid:100000858; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.181"; classtype:trojan-activity; sid:100000859; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.183"; classtype:trojan-activity; sid:100000860; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.184"; classtype:trojan-activity; sid:100000861; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.185"; classtype:trojan-activity; sid:100000862; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.186"; classtype:trojan-activity; sid:100000863; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.188"; classtype:trojan-activity; sid:100000864; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.191"; classtype:trojan-activity; sid:100000865; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.193"; classtype:trojan-activity; sid:100000866; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.196"; classtype:trojan-activity; sid:100000867; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.197"; classtype:trojan-activity; sid:100000868; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.198"; classtype:trojan-activity; sid:100000869; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.199"; classtype:trojan-activity; sid:100000870; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.200"; classtype:trojan-activity; sid:100000871; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.201"; classtype:trojan-activity; sid:100000872; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.202"; classtype:trojan-activity; sid:100000873; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.203"; classtype:trojan-activity; sid:100000874; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.204"; classtype:trojan-activity; sid:100000875; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.207"; classtype:trojan-activity; sid:100000876; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.208"; classtype:trojan-activity; sid:100000877; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.209"; classtype:trojan-activity; sid:100000878; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.212"; classtype:trojan-activity; sid:100000879; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.213"; classtype:trojan-activity; sid:100000880; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.215"; classtype:trojan-activity; sid:100000881; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.233"; classtype:trojan-activity; sid:100000882; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.93.227"; classtype:trojan-activity; sid:100000883; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.121.243"; classtype:trojan-activity; sid:100000884; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.206"; classtype:trojan-activity; sid:100000885; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.214"; classtype:trojan-activity; sid:100000886; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.240"; classtype:trojan-activity; sid:100000887; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.243"; classtype:trojan-activity; sid:100000888; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.25"; classtype:trojan-activity; sid:100000889; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.60"; classtype:trojan-activity; sid:100000890; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.127.187"; classtype:trojan-activity; sid:100000891; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.99.127"; classtype:trojan-activity; sid:100000892; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.210.89.79"; classtype:trojan-activity; sid:100000893; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.43.54.218"; classtype:trojan-activity; sid:100000894; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.50.66.60"; classtype:trojan-activity; sid:100000895; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.50.93.115"; classtype:trojan-activity; sid:100000896; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.59.245.212"; classtype:trojan-activity; sid:100000897; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.6.141.142"; classtype:trojan-activity; sid:100000898; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.6.8.11"; classtype:trojan-activity; sid:100000899; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.69.113.208"; classtype:trojan-activity; sid:100000900; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.69.131.51"; classtype:trojan-activity; sid:100000901; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.7.90.104"; classtype:trojan-activity; sid:100000902; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.165.141"; classtype:trojan-activity; sid:100000903; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.169.138"; classtype:trojan-activity; sid:100000904; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.174.165"; classtype:trojan-activity; sid:100000905; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.174.175"; classtype:trojan-activity; sid:100000906; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.186.112"; classtype:trojan-activity; sid:100000907; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.237.129"; classtype:trojan-activity; sid:100000908; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.239.77"; classtype:trojan-activity; sid:100000909; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.86.84.72"; classtype:trojan-activity; sid:100000910; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.9.32.51"; classtype:trojan-activity; sid:100000911; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.100.114.164"; classtype:trojan-activity; sid:100000912; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.100.96.8"; classtype:trojan-activity; sid:100000913; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.121.44.222"; classtype:trojan-activity; sid:100000914; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.123.53.25"; classtype:trojan-activity; sid:100000915; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.127.155.220"; classtype:trojan-activity; sid:100000916; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.141.11.56"; classtype:trojan-activity; sid:100000917; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.15.142.137"; classtype:trojan-activity; sid:100000918; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.151.78.190"; classtype:trojan-activity; sid:100000919; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.159.22.144"; classtype:trojan-activity; sid:100000920; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.16.155.206"; classtype:trojan-activity; sid:100000921; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.17.103.176"; classtype:trojan-activity; sid:100000922; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.170.234.142"; classtype:trojan-activity; sid:100000923; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.185.31.2"; classtype:trojan-activity; sid:100000924; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.190.36.8"; classtype:trojan-activity; sid:100000925; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.205.229.200"; classtype:trojan-activity; sid:100000926; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.225.11.163"; classtype:trojan-activity; sid:100000927; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.226.82.202"; classtype:trojan-activity; sid:100000928; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.23.18.18"; classtype:trojan-activity; sid:100000929; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.230.171.198"; classtype:trojan-activity; sid:100000930; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.231.103.95"; classtype:trojan-activity; sid:100000931; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.237.225.91"; classtype:trojan-activity; sid:100000932; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.238.175.87"; classtype:trojan-activity; sid:100000933; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.239.15.74"; classtype:trojan-activity; sid:100000934; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.24.116.173"; classtype:trojan-activity; sid:100000935; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.25.101.86"; classtype:trojan-activity; sid:100000936; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.254.43.215"; classtype:trojan-activity; sid:100000937; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.61.101.93"; classtype:trojan-activity; sid:100000938; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.61.102.1"; classtype:trojan-activity; sid:100000939; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.61.107.189"; classtype:trojan-activity; sid:100000940; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.61.97.195"; classtype:trojan-activity; sid:100000941; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.61.98.151"; classtype:trojan-activity; sid:100000942; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.88.99.236"; classtype:trojan-activity; sid:100000943; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.100.150.204"; classtype:trojan-activity; sid:100000944; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.137.52.122"; classtype:trojan-activity; sid:100000945; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.160.147.53"; classtype:trojan-activity; sid:100000946; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.192.190.203"; classtype:trojan-activity; sid:100000947; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.194.191.57"; classtype:trojan-activity; sid:100000948; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.199.72.23"; classtype:trojan-activity; sid:100000949; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.199.79.27"; classtype:trojan-activity; sid:100000950; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.199.83.86"; classtype:trojan-activity; sid:100000951; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.202.37.85"; classtype:trojan-activity; sid:100000952; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.202.41.23"; classtype:trojan-activity; sid:100000953; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.252.241.170"; classtype:trojan-activity; sid:100000954; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.252.250.22"; classtype:trojan-activity; sid:100000955; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.254.183.207"; classtype:trojan-activity; sid:100000956; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.254.29.37"; classtype:trojan-activity; sid:100000957; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.254.33.214"; classtype:trojan-activity; sid:100000958; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.0.240.58"; classtype:trojan-activity; sid:100000959; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.10.128.46"; classtype:trojan-activity; sid:100000960; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.10.140.225"; classtype:trojan-activity; sid:100000961; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.10.210.87"; classtype:trojan-activity; sid:100000962; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.10.36.124"; classtype:trojan-activity; sid:100000963; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.10.41.32"; classtype:trojan-activity; sid:100000964; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.11.1.232"; classtype:trojan-activity; sid:100000965; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.11.74.72"; classtype:trojan-activity; sid:100000966; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.124.238"; classtype:trojan-activity; sid:100000967; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.124.244"; classtype:trojan-activity; sid:100000968; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.170.237"; classtype:trojan-activity; sid:100000969; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.182.187"; classtype:trojan-activity; sid:100000970; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.19.248"; classtype:trojan-activity; sid:100000971; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.200.98"; classtype:trojan-activity; sid:100000972; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.238.188"; classtype:trojan-activity; sid:100000973; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.12.238.89"; classtype:trojan-activity; sid:100000974; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.12.3.58"; classtype:trojan-activity; sid:100000975; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.128.128.205"; classtype:trojan-activity; sid:100000976; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.128.133.91"; classtype:trojan-activity; sid:100000977; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.129.84.36"; classtype:trojan-activity; sid:100000978; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.129.88.123"; classtype:trojan-activity; sid:100000979; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.169.45"; classtype:trojan-activity; sid:100000980; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.208.52"; classtype:trojan-activity; sid:100000981; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.23.110"; classtype:trojan-activity; sid:100000982; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.37.182"; classtype:trojan-activity; sid:100000983; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.61.210"; classtype:trojan-activity; sid:100000984; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.131.186.250"; classtype:trojan-activity; sid:100000985; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.132.219.147"; classtype:trojan-activity; sid:100000986; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.133.125.77"; classtype:trojan-activity; sid:100000987; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.133.144.138"; classtype:trojan-activity; sid:100000988; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.133.98.135"; classtype:trojan-activity; sid:100000989; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.134.14.130"; classtype:trojan-activity; sid:100000990; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.134.50.186"; classtype:trojan-activity; sid:100000991; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.135.157.193"; classtype:trojan-activity; sid:100000992; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.135.39.36"; classtype:trojan-activity; sid:100000993; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.135.71.150"; classtype:trojan-activity; sid:100000994; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.101.111"; classtype:trojan-activity; sid:100000995; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.150.79"; classtype:trojan-activity; sid:100000996; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.217.22"; classtype:trojan-activity; sid:100000997; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.235.65"; classtype:trojan-activity; sid:100000998; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.248.97"; classtype:trojan-activity; sid:100000999; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.76.38"; classtype:trojan-activity; sid:100001000; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.88.195"; classtype:trojan-activity; sid:100001001; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.152.42.4"; classtype:trojan-activity; sid:100001002; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.152.43.21"; classtype:trojan-activity; sid:100001003; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.154.94.1"; classtype:trojan-activity; sid:100001004; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.155.118.36"; classtype:trojan-activity; sid:100001005; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.156.136.21"; classtype:trojan-activity; sid:100001006; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.159.137.101"; classtype:trojan-activity; sid:100001007; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.159.31.110"; classtype:trojan-activity; sid:100001008; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.159.8.100"; classtype:trojan-activity; sid:100001009; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.191.173.88"; classtype:trojan-activity; sid:100001010; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.192.101.163"; classtype:trojan-activity; sid:100001011; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.192.194.233"; classtype:trojan-activity; sid:100001012; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.193.149.235"; classtype:trojan-activity; sid:100001013; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.193.53.237"; classtype:trojan-activity; sid:100001014; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.235.37"; classtype:trojan-activity; sid:100001015; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.35.146"; classtype:trojan-activity; sid:100001016; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.52.79"; classtype:trojan-activity; sid:100001017; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.60.238"; classtype:trojan-activity; sid:100001018; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.195.112.240"; classtype:trojan-activity; sid:100001019; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.195.184.191"; classtype:trojan-activity; sid:100001020; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.195.98.141"; classtype:trojan-activity; sid:100001021; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.212.29.154"; classtype:trojan-activity; sid:100001022; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.213.225.130"; classtype:trojan-activity; sid:100001023; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.233.130.162"; classtype:trojan-activity; sid:100001024; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.233.152.249"; classtype:trojan-activity; sid:100001025; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.234.100.219"; classtype:trojan-activity; sid:100001026; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.234.116.110"; classtype:trojan-activity; sid:100001027; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.234.184.57"; classtype:trojan-activity; sid:100001028; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.234.246.103"; classtype:trojan-activity; sid:100001029; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.235.107.135"; classtype:trojan-activity; sid:100001030; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.240.103.89"; classtype:trojan-activity; sid:100001031; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.240.181.57"; classtype:trojan-activity; sid:100001032; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.240.79.61"; classtype:trojan-activity; sid:100001033; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.241.148.58"; classtype:trojan-activity; sid:100001034; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.241.184.124"; classtype:trojan-activity; sid:100001035; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.27.44.219"; classtype:trojan-activity; sid:100001036; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.28.217.23"; classtype:trojan-activity; sid:100001037; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.193.171"; classtype:trojan-activity; sid:100001038; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.44.217"; classtype:trojan-activity; sid:100001039; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.85.76"; classtype:trojan-activity; sid:100001040; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.88.225"; classtype:trojan-activity; sid:100001041; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.92.3"; classtype:trojan-activity; sid:100001042; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.5.123.162"; classtype:trojan-activity; sid:100001043; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.5.13.128"; classtype:trojan-activity; sid:100001044; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.5.178.213"; classtype:trojan-activity; sid:100001045; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.5.27.66"; classtype:trojan-activity; sid:100001046; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.8.253.37"; classtype:trojan-activity; sid:100001047; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.8.254.172"; classtype:trojan-activity; sid:100001048; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.8.40.20"; classtype:trojan-activity; sid:100001049; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.8.41.63"; classtype:trojan-activity; sid:100001050; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.8.62.165"; classtype:trojan-activity; sid:100001051; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.9.110.119"; classtype:trojan-activity; sid:100001052; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.9.243.93"; classtype:trojan-activity; sid:100001053; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.9.245.134"; classtype:trojan-activity; sid:100001054; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.105.105.222"; classtype:trojan-activity; sid:100001055; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.129.162.169"; classtype:trojan-activity; sid:100001056; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.129.221.150"; classtype:trojan-activity; sid:100001057; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.129.76.230"; classtype:trojan-activity; sid:100001058; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.130.167.20"; classtype:trojan-activity; sid:100001059; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.104.82"; classtype:trojan-activity; sid:100001060; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.130.95"; classtype:trojan-activity; sid:100001061; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.136.75"; classtype:trojan-activity; sid:100001062; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.151.135"; classtype:trojan-activity; sid:100001063; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.21.39"; classtype:trojan-activity; sid:100001064; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.26.78"; classtype:trojan-activity; sid:100001065; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.54.33"; classtype:trojan-activity; sid:100001066; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.70.49"; classtype:trojan-activity; sid:100001067; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.72.208"; classtype:trojan-activity; sid:100001068; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.132.110.150"; classtype:trojan-activity; sid:100001069; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.135.34.49"; classtype:trojan-activity; sid:100001070; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.153.236.6"; classtype:trojan-activity; sid:100001071; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.160.126.238"; classtype:trojan-activity; sid:100001072; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.138.104"; classtype:trojan-activity; sid:100001073; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.167.54"; classtype:trojan-activity; sid:100001074; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.65.64"; classtype:trojan-activity; sid:100001075; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.72.102"; classtype:trojan-activity; sid:100001076; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.77.191"; classtype:trojan-activity; sid:100001077; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.90.243"; classtype:trojan-activity; sid:100001078; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.165.123.7"; classtype:trojan-activity; sid:100001079; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.167.186.211"; classtype:trojan-activity; sid:100001080; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.187.111.160"; classtype:trojan-activity; sid:100001081; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.199.56.198"; classtype:trojan-activity; sid:100001082; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.226.24.117"; classtype:trojan-activity; sid:100001083; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.230.174.233"; classtype:trojan-activity; sid:100001084; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.234.6.130"; classtype:trojan-activity; sid:100001085; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.5.92.20"; classtype:trojan-activity; sid:100001086; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.6.0.4"; classtype:trojan-activity; sid:100001087; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.7.254.85"; classtype:trojan-activity; sid:100001088; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.80.46.73"; classtype:trojan-activity; sid:100001089; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.92.132.207"; classtype:trojan-activity; sid:100001090; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.92.148.218"; classtype:trojan-activity; sid:100001091; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.106.125.119"; classtype:trojan-activity; sid:100001092; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.128.28.161"; classtype:trojan-activity; sid:100001093; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.142.93.34"; classtype:trojan-activity; sid:100001094; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.168.10.234"; classtype:trojan-activity; sid:100001095; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.191.113.212"; classtype:trojan-activity; sid:100001096; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.1.127"; classtype:trojan-activity; sid:100001097; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.107.252"; classtype:trojan-activity; sid:100001098; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.113.66"; classtype:trojan-activity; sid:100001099; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.150.131"; classtype:trojan-activity; sid:100001100; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.16.231"; classtype:trojan-activity; sid:100001101; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.163.112"; classtype:trojan-activity; sid:100001102; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.65.120"; classtype:trojan-activity; sid:100001103; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.73.6"; classtype:trojan-activity; sid:100001104; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.74.153"; classtype:trojan-activity; sid:100001105; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.75.22"; classtype:trojan-activity; sid:100001106; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.0.209"; classtype:trojan-activity; sid:100001107; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.106.180"; classtype:trojan-activity; sid:100001108; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.138.208"; classtype:trojan-activity; sid:100001109; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.189.235"; classtype:trojan-activity; sid:100001110; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.191.183"; classtype:trojan-activity; sid:100001111; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.196.151"; classtype:trojan-activity; sid:100001112; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.2.58"; classtype:trojan-activity; sid:100001113; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.204.126"; classtype:trojan-activity; sid:100001114; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.205.197"; classtype:trojan-activity; sid:100001115; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.245.135"; classtype:trojan-activity; sid:100001116; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.6.192"; classtype:trojan-activity; sid:100001117; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.7.204"; classtype:trojan-activity; sid:100001118; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.80.153"; classtype:trojan-activity; sid:100001119; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.86.72"; classtype:trojan-activity; sid:100001120; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.96.53"; classtype:trojan-activity; sid:100001121; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.97.22"; classtype:trojan-activity; sid:100001122; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.42.124.114"; classtype:trojan-activity; sid:100001123; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.42.234.197"; classtype:trojan-activity; sid:100001124; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.42.96.17"; classtype:trojan-activity; sid:100001125; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.42.96.209"; classtype:trojan-activity; sid:100001126; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.42.98.24"; classtype:trojan-activity; sid:100001127; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.106.162"; classtype:trojan-activity; sid:100001128; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.112.123"; classtype:trojan-activity; sid:100001129; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.126.184"; classtype:trojan-activity; sid:100001130; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.136.23"; classtype:trojan-activity; sid:100001131; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.177.48"; classtype:trojan-activity; sid:100001132; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.26.36"; classtype:trojan-activity; sid:100001133; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.34.132"; classtype:trojan-activity; sid:100001134; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.5.247"; classtype:trojan-activity; sid:100001135; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.53.9"; classtype:trojan-activity; sid:100001136; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.93.164"; classtype:trojan-activity; sid:100001137; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.168.169"; classtype:trojan-activity; sid:100001138; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.213.216"; classtype:trojan-activity; sid:100001139; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.248.76"; classtype:trojan-activity; sid:100001140; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.29.38"; classtype:trojan-activity; sid:100001141; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.30.143"; classtype:trojan-activity; sid:100001142; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.42.12"; classtype:trojan-activity; sid:100001143; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.61.172"; classtype:trojan-activity; sid:100001144; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.8.227"; classtype:trojan-activity; sid:100001145; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.45.65.166"; classtype:trojan-activity; sid:100001146; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.46.184.28"; classtype:trojan-activity; sid:100001147; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.46.203.85"; classtype:trojan-activity; sid:100001148; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.46.206.206"; classtype:trojan-activity; sid:100001149; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.193.134"; classtype:trojan-activity; sid:100001150; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.200.11"; classtype:trojan-activity; sid:100001151; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.207.239"; classtype:trojan-activity; sid:100001152; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.209.166"; classtype:trojan-activity; sid:100001153; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.244.201"; classtype:trojan-activity; sid:100001154; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.29.173"; classtype:trojan-activity; sid:100001155; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.36.171"; classtype:trojan-activity; sid:100001156; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.45.218"; classtype:trojan-activity; sid:100001157; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.71.30"; classtype:trojan-activity; sid:100001158; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.90.82"; classtype:trojan-activity; sid:100001159; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.91.51"; classtype:trojan-activity; sid:100001160; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"128.116.133.92"; classtype:trojan-activity; sid:100001161; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"130.255.159.133"; classtype:trojan-activity; sid:100001162; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"134.195.139.4"; classtype:trojan-activity; sid:100001163; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"134.236.252.28"; classtype:trojan-activity; sid:100001164; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"138.99.204.224"; classtype:trojan-activity; sid:100001165; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.159.226.180"; classtype:trojan-activity; sid:100001166; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.170.173.198"; classtype:trojan-activity; sid:100001167; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.170.174.162"; classtype:trojan-activity; sid:100001168; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.216.102.151"; classtype:trojan-activity; sid:100001169; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.227.46.137"; classtype:trojan-activity; sid:100001170; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.102.17.222"; classtype:trojan-activity; sid:100001171; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.102.97.204"; classtype:trojan-activity; sid:100001172; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.136.80.242"; classtype:trojan-activity; sid:100001173; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.138.109.129"; classtype:trojan-activity; sid:100001174; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.138.109.26"; classtype:trojan-activity; sid:100001175; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.138.8.215"; classtype:trojan-activity; sid:100001176; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.138.8.51"; classtype:trojan-activity; sid:100001177; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.155.220.240"; classtype:trojan-activity; sid:100001178; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.155.223.79"; classtype:trojan-activity; sid:100001179; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.169.164.77"; classtype:trojan-activity; sid:100001180; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.189.247.118"; classtype:trojan-activity; sid:100001181; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.205.201.192"; classtype:trojan-activity; sid:100001182; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.37.222.190"; classtype:trojan-activity; sid:100001183; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.45.127.110"; classtype:trojan-activity; sid:100001184; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.46.25.17"; classtype:trojan-activity; sid:100001185; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.46.98.241"; classtype:trojan-activity; sid:100001186; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.55.29.2"; classtype:trojan-activity; sid:100001187; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"142.11.216.5"; classtype:trojan-activity; sid:100001188; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"142.177.56.127"; classtype:trojan-activity; sid:100001189; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"146.71.79.230"; classtype:trojan-activity; sid:100001190; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"148.69.108.177"; classtype:trojan-activity; sid:100001191; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.121"; classtype:trojan-activity; sid:100001192; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.180"; classtype:trojan-activity; sid:100001193; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.182"; classtype:trojan-activity; sid:100001194; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.87"; classtype:trojan-activity; sid:100001195; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.3.36.210"; classtype:trojan-activity; sid:100001196; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"150.116.207.99"; classtype:trojan-activity; sid:100001197; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"151.177.163.87"; classtype:trojan-activity; sid:100001198; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"151.33.230.191"; classtype:trojan-activity; sid:100001199; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"151.51.158.195"; classtype:trojan-activity; sid:100001200; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"151.73.124.231"; classtype:trojan-activity; sid:100001201; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.101.225.96"; classtype:trojan-activity; sid:100001202; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.101.234.167"; classtype:trojan-activity; sid:100001203; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.3.123.47"; classtype:trojan-activity; sid:100001204; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.3.43.136"; classtype:trojan-activity; sid:100001205; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.3.44.44"; classtype:trojan-activity; sid:100001206; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.34.135.92"; classtype:trojan-activity; sid:100001207; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.34.23.76"; classtype:trojan-activity; sid:100001208; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.34.29.28"; classtype:trojan-activity; sid:100001209; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.34.52.74"; classtype:trojan-activity; sid:100001210; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.35.27.49"; classtype:trojan-activity; sid:100001211; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.36.126.35"; classtype:trojan-activity; sid:100001212; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"154.126.178.16"; classtype:trojan-activity; sid:100001213; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"158.101.165.14"; classtype:trojan-activity; sid:100001214; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"158.174.213.128"; classtype:trojan-activity; sid:100001215; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"158.51.125.115"; classtype:trojan-activity; sid:100001216; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"159.224.74.112"; classtype:trojan-activity; sid:100001217; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.191.165.238"; classtype:trojan-activity; sid:100001218; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.191.205.175"; classtype:trojan-activity; sid:100001219; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.191.249.195"; classtype:trojan-activity; sid:100001220; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.194.28.60"; classtype:trojan-activity; sid:100001221; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.209.98.174"; classtype:trojan-activity; sid:100001222; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.212.203.250"; classtype:trojan-activity; sid:100001223; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.195.108"; classtype:trojan-activity; sid:100001224; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.200.233"; classtype:trojan-activity; sid:100001225; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.200.73"; classtype:trojan-activity; sid:100001226; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.203.85"; classtype:trojan-activity; sid:100001227; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.223.16"; classtype:trojan-activity; sid:100001228; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.53.206.228"; classtype:trojan-activity; sid:100001229; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"165.90.16.5"; classtype:trojan-activity; sid:100001230; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"170.78.39.3"; classtype:trojan-activity; sid:100001231; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"170.81.238.178"; classtype:trojan-activity; sid:100001232; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.118.18.184"; classtype:trojan-activity; sid:100001233; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.118.210.67"; classtype:trojan-activity; sid:100001234; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.119.217.149"; classtype:trojan-activity; sid:100001235; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.119.218.208"; classtype:trojan-activity; sid:100001236; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.119.219.150"; classtype:trojan-activity; sid:100001237; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.119.255.96"; classtype:trojan-activity; sid:100001238; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.120.125.147"; classtype:trojan-activity; sid:100001239; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.121.6.162"; classtype:trojan-activity; sid:100001240; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.123.189.154"; classtype:trojan-activity; sid:100001241; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.125.114.254"; classtype:trojan-activity; sid:100001242; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.125.30.233"; classtype:trojan-activity; sid:100001243; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.125.30.93"; classtype:trojan-activity; sid:100001244; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.125.64.223"; classtype:trojan-activity; sid:100001245; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.126.109.145"; classtype:trojan-activity; sid:100001246; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.34.112.42"; classtype:trojan-activity; sid:100001247; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.34.179.178"; classtype:trojan-activity; sid:100001248; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.35.161.234"; classtype:trojan-activity; sid:100001249; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.35.162.156"; classtype:trojan-activity; sid:100001250; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.35.173.151"; classtype:trojan-activity; sid:100001251; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.35.174.198"; classtype:trojan-activity; sid:100001252; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.38.219.189"; classtype:trojan-activity; sid:100001253; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.44.254.4"; classtype:trojan-activity; sid:100001254; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.105.36.168"; classtype:trojan-activity; sid:100001255; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.114.244.127"; classtype:trojan-activity; sid:100001256; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.245.5.185"; classtype:trojan-activity; sid:100001257; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.93.176.137"; classtype:trojan-activity; sid:100001258; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.167.85.89"; classtype:trojan-activity; sid:100001259; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.169.46.85"; classtype:trojan-activity; sid:100001260; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.19.58.108"; classtype:trojan-activity; sid:100001261; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.220.222.227"; classtype:trojan-activity; sid:100001262; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.233.85.171"; classtype:trojan-activity; sid:100001263; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.235.209.70"; classtype:trojan-activity; sid:100001264; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.237.254.251"; classtype:trojan-activity; sid:100001265; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.25.113.8"; classtype:trojan-activity; sid:100001266; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.52.95.134"; classtype:trojan-activity; sid:100001267; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.52.97.25"; classtype:trojan-activity; sid:100001268; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.56.119.108"; classtype:trojan-activity; sid:100001269; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.56.92.166"; classtype:trojan-activity; sid:100001270; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.106.33.85"; classtype:trojan-activity; sid:100001271; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.48.181.23"; classtype:trojan-activity; sid:100001272; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.73.246.193"; classtype:trojan-activity; sid:100001273; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.81.78.7"; classtype:trojan-activity; sid:100001274; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.84.148.29"; classtype:trojan-activity; sid:100001275; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.96.30.156"; classtype:trojan-activity; sid:100001276; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.10.147.167"; classtype:trojan-activity; sid:100001277; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.10.48.233"; classtype:trojan-activity; sid:100001278; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.11.212.203"; classtype:trojan-activity; sid:100001279; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.11.96.155"; classtype:trojan-activity; sid:100001280; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.115.241.87"; classtype:trojan-activity; sid:100001281; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.117.66.74"; classtype:trojan-activity; sid:100001282; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.145.200.216"; classtype:trojan-activity; sid:100001283; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.153.144.2"; classtype:trojan-activity; sid:100001284; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.162.69.13"; classtype:trojan-activity; sid:100001285; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.169.172.216"; classtype:trojan-activity; sid:100001286; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.173.196.162"; classtype:trojan-activity; sid:100001287; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.174.93.57"; classtype:trojan-activity; sid:100001288; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.199.33.139"; classtype:trojan-activity; sid:100001289; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.201.104.192"; classtype:trojan-activity; sid:100001290; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.208.230.8"; classtype:trojan-activity; sid:100001291; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.212.6.169"; classtype:trojan-activity; sid:100001292; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.42.46.118"; classtype:trojan-activity; sid:100001293; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.9.24.110"; classtype:trojan-activity; sid:100001294; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.14"; classtype:trojan-activity; sid:100001295; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.35"; classtype:trojan-activity; sid:100001296; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.63"; classtype:trojan-activity; sid:100001297; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.66"; classtype:trojan-activity; sid:100001298; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.67"; classtype:trojan-activity; sid:100001299; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.104"; classtype:trojan-activity; sid:100001300; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.113"; classtype:trojan-activity; sid:100001301; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.120"; classtype:trojan-activity; sid:100001302; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.128"; classtype:trojan-activity; sid:100001303; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.138"; classtype:trojan-activity; sid:100001304; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.59"; classtype:trojan-activity; sid:100001305; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.65"; classtype:trojan-activity; sid:100001306; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.66"; classtype:trojan-activity; sid:100001307; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.84"; classtype:trojan-activity; sid:100001308; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.88"; classtype:trojan-activity; sid:100001309; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.91"; classtype:trojan-activity; sid:100001310; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.174.139"; classtype:trojan-activity; sid:100001311; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.12.117.70"; classtype:trojan-activity; sid:100001312; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.123.4.115"; classtype:trojan-activity; sid:100001313; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.123.7.115"; classtype:trojan-activity; sid:100001314; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.123.7.127"; classtype:trojan-activity; sid:100001315; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.123.9.243"; classtype:trojan-activity; sid:100001316; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.124.7.225"; classtype:trojan-activity; sid:100001317; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.240.40.142"; classtype:trojan-activity; sid:100001318; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.240.84.106"; classtype:trojan-activity; sid:100001319; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.32.151.180"; classtype:trojan-activity; sid:100001320; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.229.64.218"; classtype:trojan-activity; sid:100001321; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.44.61.243"; classtype:trojan-activity; sid:100001322; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.54.82.154"; classtype:trojan-activity; sid:100001323; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.86.235.143"; classtype:trojan-activity; sid:100001324; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.124.182.187"; classtype:trojan-activity; sid:100001325; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.136.195.90"; classtype:trojan-activity; sid:100001326; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.141.210.251"; classtype:trojan-activity; sid:100001327; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.141.25.82"; classtype:trojan-activity; sid:100001328; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.141.57.166"; classtype:trojan-activity; sid:100001329; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.150.174.65"; classtype:trojan-activity; sid:100001330; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.165.122.141"; classtype:trojan-activity; sid:100001331; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.0.140"; classtype:trojan-activity; sid:100001332; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.109"; classtype:trojan-activity; sid:100001333; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.247"; classtype:trojan-activity; sid:100001334; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.250"; classtype:trojan-activity; sid:100001335; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.80"; classtype:trojan-activity; sid:100001336; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.10.108"; classtype:trojan-activity; sid:100001337; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.10.156"; classtype:trojan-activity; sid:100001338; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.10.26"; classtype:trojan-activity; sid:100001339; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.129"; classtype:trojan-activity; sid:100001340; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.180"; classtype:trojan-activity; sid:100001341; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.190"; classtype:trojan-activity; sid:100001342; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.223"; classtype:trojan-activity; sid:100001343; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.4"; classtype:trojan-activity; sid:100001344; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.101.110"; classtype:trojan-activity; sid:100001345; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.134"; classtype:trojan-activity; sid:100001346; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.136"; classtype:trojan-activity; sid:100001347; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.152"; classtype:trojan-activity; sid:100001348; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.228"; classtype:trojan-activity; sid:100001349; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.232"; classtype:trojan-activity; sid:100001350; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.245"; classtype:trojan-activity; sid:100001351; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.81"; classtype:trojan-activity; sid:100001352; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.103.172"; classtype:trojan-activity; sid:100001353; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.103.91"; classtype:trojan-activity; sid:100001354; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.120"; classtype:trojan-activity; sid:100001355; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.128"; classtype:trojan-activity; sid:100001356; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.153"; classtype:trojan-activity; sid:100001357; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.16"; classtype:trojan-activity; sid:100001358; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.161"; classtype:trojan-activity; sid:100001359; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.169"; classtype:trojan-activity; sid:100001360; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.183"; classtype:trojan-activity; sid:100001361; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.206"; classtype:trojan-activity; sid:100001362; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.220"; classtype:trojan-activity; sid:100001363; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.49"; classtype:trojan-activity; sid:100001364; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.80"; classtype:trojan-activity; sid:100001365; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.111"; classtype:trojan-activity; sid:100001366; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.146"; classtype:trojan-activity; sid:100001367; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.217"; classtype:trojan-activity; sid:100001368; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.245"; classtype:trojan-activity; sid:100001369; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.247"; classtype:trojan-activity; sid:100001370; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.27"; classtype:trojan-activity; sid:100001371; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.49"; classtype:trojan-activity; sid:100001372; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.85"; classtype:trojan-activity; sid:100001373; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.118"; classtype:trojan-activity; sid:100001374; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.18"; classtype:trojan-activity; sid:100001375; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.193"; classtype:trojan-activity; sid:100001376; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.219"; classtype:trojan-activity; sid:100001377; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.37"; classtype:trojan-activity; sid:100001378; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.63"; classtype:trojan-activity; sid:100001379; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.77"; classtype:trojan-activity; sid:100001380; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.87"; classtype:trojan-activity; sid:100001381; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.0"; classtype:trojan-activity; sid:100001382; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.133"; classtype:trojan-activity; sid:100001383; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.83"; classtype:trojan-activity; sid:100001384; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.116"; classtype:trojan-activity; sid:100001385; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.145"; classtype:trojan-activity; sid:100001386; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.148"; classtype:trojan-activity; sid:100001387; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.16"; classtype:trojan-activity; sid:100001388; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.179"; classtype:trojan-activity; sid:100001389; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.18"; classtype:trojan-activity; sid:100001390; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.67"; classtype:trojan-activity; sid:100001391; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.87"; classtype:trojan-activity; sid:100001392; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.109.1"; classtype:trojan-activity; sid:100001393; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.109.77"; classtype:trojan-activity; sid:100001394; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.176"; classtype:trojan-activity; sid:100001395; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.184"; classtype:trojan-activity; sid:100001396; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.204"; classtype:trojan-activity; sid:100001397; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.57"; classtype:trojan-activity; sid:100001398; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.150"; classtype:trojan-activity; sid:100001399; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.155"; classtype:trojan-activity; sid:100001400; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.173"; classtype:trojan-activity; sid:100001401; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.214"; classtype:trojan-activity; sid:100001402; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.221"; classtype:trojan-activity; sid:100001403; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.43"; classtype:trojan-activity; sid:100001404; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.90"; classtype:trojan-activity; sid:100001405; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.97"; classtype:trojan-activity; sid:100001406; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.105"; classtype:trojan-activity; sid:100001407; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.157"; classtype:trojan-activity; sid:100001408; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.16"; classtype:trojan-activity; sid:100001409; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.190"; classtype:trojan-activity; sid:100001410; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.206"; classtype:trojan-activity; sid:100001411; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.36"; classtype:trojan-activity; sid:100001412; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.84"; classtype:trojan-activity; sid:100001413; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.159"; classtype:trojan-activity; sid:100001414; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.26"; classtype:trojan-activity; sid:100001415; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.4"; classtype:trojan-activity; sid:100001416; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.113.130"; classtype:trojan-activity; sid:100001417; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.113.150"; classtype:trojan-activity; sid:100001418; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.113.171"; classtype:trojan-activity; sid:100001419; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.113.174"; classtype:trojan-activity; sid:100001420; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.113.35"; classtype:trojan-activity; sid:100001421; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.113.85"; classtype:trojan-activity; sid:100001422; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.107"; classtype:trojan-activity; sid:100001423; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.211"; classtype:trojan-activity; sid:100001424; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.215"; classtype:trojan-activity; sid:100001425; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.234"; classtype:trojan-activity; sid:100001426; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.238"; classtype:trojan-activity; sid:100001427; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.241"; classtype:trojan-activity; sid:100001428; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.254"; classtype:trojan-activity; sid:100001429; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.27"; classtype:trojan-activity; sid:100001430; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.5"; classtype:trojan-activity; sid:100001431; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.55"; classtype:trojan-activity; sid:100001432; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.63"; classtype:trojan-activity; sid:100001433; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.82"; classtype:trojan-activity; sid:100001434; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.90"; classtype:trojan-activity; sid:100001435; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.99"; classtype:trojan-activity; sid:100001436; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.1"; classtype:trojan-activity; sid:100001437; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.13"; classtype:trojan-activity; sid:100001438; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.142"; classtype:trojan-activity; sid:100001439; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.143"; classtype:trojan-activity; sid:100001440; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.19"; classtype:trojan-activity; sid:100001441; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.221"; classtype:trojan-activity; sid:100001442; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.222"; classtype:trojan-activity; sid:100001443; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.242"; classtype:trojan-activity; sid:100001444; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.35"; classtype:trojan-activity; sid:100001445; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.116.48"; classtype:trojan-activity; sid:100001446; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.116.64"; classtype:trojan-activity; sid:100001447; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.116.87"; classtype:trojan-activity; sid:100001448; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.117.215"; classtype:trojan-activity; sid:100001449; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.117.32"; classtype:trojan-activity; sid:100001450; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.117.51"; classtype:trojan-activity; sid:100001451; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.117.63"; classtype:trojan-activity; sid:100001452; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.117.90"; classtype:trojan-activity; sid:100001453; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.112"; classtype:trojan-activity; sid:100001454; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.192"; classtype:trojan-activity; sid:100001455; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.225"; classtype:trojan-activity; sid:100001456; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.34"; classtype:trojan-activity; sid:100001457; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.60"; classtype:trojan-activity; sid:100001458; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.205"; classtype:trojan-activity; sid:100001459; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.209"; classtype:trojan-activity; sid:100001460; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.86"; classtype:trojan-activity; sid:100001461; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.88"; classtype:trojan-activity; sid:100001462; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.179"; classtype:trojan-activity; sid:100001463; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.252"; classtype:trojan-activity; sid:100001464; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.53"; classtype:trojan-activity; sid:100001465; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.97"; classtype:trojan-activity; sid:100001466; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.120.133"; classtype:trojan-activity; sid:100001467; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.120.184"; classtype:trojan-activity; sid:100001468; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.120.203"; classtype:trojan-activity; sid:100001469; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.120.251"; classtype:trojan-activity; sid:100001470; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.123"; classtype:trojan-activity; sid:100001471; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.155"; classtype:trojan-activity; sid:100001472; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.55"; classtype:trojan-activity; sid:100001473; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.62"; classtype:trojan-activity; sid:100001474; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.68"; classtype:trojan-activity; sid:100001475; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.99"; classtype:trojan-activity; sid:100001476; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.144"; classtype:trojan-activity; sid:100001477; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.172"; classtype:trojan-activity; sid:100001478; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.245"; classtype:trojan-activity; sid:100001479; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.28"; classtype:trojan-activity; sid:100001480; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.113"; classtype:trojan-activity; sid:100001481; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.2"; classtype:trojan-activity; sid:100001482; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.20"; classtype:trojan-activity; sid:100001483; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.223"; classtype:trojan-activity; sid:100001484; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.56"; classtype:trojan-activity; sid:100001485; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.60"; classtype:trojan-activity; sid:100001486; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.109"; classtype:trojan-activity; sid:100001487; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.122"; classtype:trojan-activity; sid:100001488; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.131"; classtype:trojan-activity; sid:100001489; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.141"; classtype:trojan-activity; sid:100001490; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.157"; classtype:trojan-activity; sid:100001491; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.175"; classtype:trojan-activity; sid:100001492; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.211"; classtype:trojan-activity; sid:100001493; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.233"; classtype:trojan-activity; sid:100001494; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.4"; classtype:trojan-activity; sid:100001495; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.79"; classtype:trojan-activity; sid:100001496; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.89"; classtype:trojan-activity; sid:100001497; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.9"; classtype:trojan-activity; sid:100001498; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.118"; classtype:trojan-activity; sid:100001499; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.14"; classtype:trojan-activity; sid:100001500; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.143"; classtype:trojan-activity; sid:100001501; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.153"; classtype:trojan-activity; sid:100001502; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.156"; classtype:trojan-activity; sid:100001503; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.174"; classtype:trojan-activity; sid:100001504; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.219"; classtype:trojan-activity; sid:100001505; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.39"; classtype:trojan-activity; sid:100001506; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.54"; classtype:trojan-activity; sid:100001507; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.101"; classtype:trojan-activity; sid:100001508; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.131"; classtype:trojan-activity; sid:100001509; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.141"; classtype:trojan-activity; sid:100001510; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.167"; classtype:trojan-activity; sid:100001511; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.220"; classtype:trojan-activity; sid:100001512; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.222"; classtype:trojan-activity; sid:100001513; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.237"; classtype:trojan-activity; sid:100001514; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.80"; classtype:trojan-activity; sid:100001515; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.83"; classtype:trojan-activity; sid:100001516; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.109"; classtype:trojan-activity; sid:100001517; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.116"; classtype:trojan-activity; sid:100001518; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.142"; classtype:trojan-activity; sid:100001519; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.15"; classtype:trojan-activity; sid:100001520; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.182"; classtype:trojan-activity; sid:100001521; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.212"; classtype:trojan-activity; sid:100001522; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.230"; classtype:trojan-activity; sid:100001523; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.231"; classtype:trojan-activity; sid:100001524; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.236"; classtype:trojan-activity; sid:100001525; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.63"; classtype:trojan-activity; sid:100001526; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.75"; classtype:trojan-activity; sid:100001527; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.14.106"; classtype:trojan-activity; sid:100001528; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.14.185"; classtype:trojan-activity; sid:100001529; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.14.246"; classtype:trojan-activity; sid:100001530; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.14.28"; classtype:trojan-activity; sid:100001531; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.14.60"; classtype:trojan-activity; sid:100001532; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.17"; classtype:trojan-activity; sid:100001533; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.217"; classtype:trojan-activity; sid:100001534; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.252"; classtype:trojan-activity; sid:100001535; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.35"; classtype:trojan-activity; sid:100001536; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.45"; classtype:trojan-activity; sid:100001537; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.85"; classtype:trojan-activity; sid:100001538; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.1"; classtype:trojan-activity; sid:100001539; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.108"; classtype:trojan-activity; sid:100001540; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.121"; classtype:trojan-activity; sid:100001541; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.17"; classtype:trojan-activity; sid:100001542; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.179"; classtype:trojan-activity; sid:100001543; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.208"; classtype:trojan-activity; sid:100001544; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.97"; classtype:trojan-activity; sid:100001545; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.17.176"; classtype:trojan-activity; sid:100001546; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.17.245"; classtype:trojan-activity; sid:100001547; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.18.238"; classtype:trojan-activity; sid:100001548; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.18.6"; classtype:trojan-activity; sid:100001549; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.18.93"; classtype:trojan-activity; sid:100001550; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.144"; classtype:trojan-activity; sid:100001551; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.150"; classtype:trojan-activity; sid:100001552; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.163"; classtype:trojan-activity; sid:100001553; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.174"; classtype:trojan-activity; sid:100001554; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.242"; classtype:trojan-activity; sid:100001555; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.44"; classtype:trojan-activity; sid:100001556; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.47"; classtype:trojan-activity; sid:100001557; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.110"; classtype:trojan-activity; sid:100001558; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.237"; classtype:trojan-activity; sid:100001559; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.245"; classtype:trojan-activity; sid:100001560; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.41"; classtype:trojan-activity; sid:100001561; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.5"; classtype:trojan-activity; sid:100001562; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.80"; classtype:trojan-activity; sid:100001563; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.117"; classtype:trojan-activity; sid:100001564; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.145"; classtype:trojan-activity; sid:100001565; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.170"; classtype:trojan-activity; sid:100001566; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.21"; classtype:trojan-activity; sid:100001567; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.225"; classtype:trojan-activity; sid:100001568; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.227"; classtype:trojan-activity; sid:100001569; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.237"; classtype:trojan-activity; sid:100001570; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.238"; classtype:trojan-activity; sid:100001571; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.24"; classtype:trojan-activity; sid:100001572; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.38"; classtype:trojan-activity; sid:100001573; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.70"; classtype:trojan-activity; sid:100001574; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.149"; classtype:trojan-activity; sid:100001575; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.184"; classtype:trojan-activity; sid:100001576; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.238"; classtype:trojan-activity; sid:100001577; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.58"; classtype:trojan-activity; sid:100001578; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.76"; classtype:trojan-activity; sid:100001579; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.23.156"; classtype:trojan-activity; sid:100001580; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.23.250"; classtype:trojan-activity; sid:100001581; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.13"; classtype:trojan-activity; sid:100001582; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.138"; classtype:trojan-activity; sid:100001583; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.15"; classtype:trojan-activity; sid:100001584; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.171"; classtype:trojan-activity; sid:100001585; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.227"; classtype:trojan-activity; sid:100001586; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.239"; classtype:trojan-activity; sid:100001587; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.251"; classtype:trojan-activity; sid:100001588; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.117"; classtype:trojan-activity; sid:100001589; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.156"; classtype:trojan-activity; sid:100001590; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.244"; classtype:trojan-activity; sid:100001591; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.28"; classtype:trojan-activity; sid:100001592; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.56"; classtype:trojan-activity; sid:100001593; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.64"; classtype:trojan-activity; sid:100001594; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.77"; classtype:trojan-activity; sid:100001595; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.134"; classtype:trojan-activity; sid:100001596; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.164"; classtype:trojan-activity; sid:100001597; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.168"; classtype:trojan-activity; sid:100001598; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.219"; classtype:trojan-activity; sid:100001599; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.224"; classtype:trojan-activity; sid:100001600; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.246"; classtype:trojan-activity; sid:100001601; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.38"; classtype:trojan-activity; sid:100001602; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.69"; classtype:trojan-activity; sid:100001603; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.122"; classtype:trojan-activity; sid:100001604; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.138"; classtype:trojan-activity; sid:100001605; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.14"; classtype:trojan-activity; sid:100001606; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.167"; classtype:trojan-activity; sid:100001607; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.169"; classtype:trojan-activity; sid:100001608; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.179"; classtype:trojan-activity; sid:100001609; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.199"; classtype:trojan-activity; sid:100001610; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.202"; classtype:trojan-activity; sid:100001611; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.215"; classtype:trojan-activity; sid:100001612; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.225"; classtype:trojan-activity; sid:100001613; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.233"; classtype:trojan-activity; sid:100001614; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.239"; classtype:trojan-activity; sid:100001615; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.241"; classtype:trojan-activity; sid:100001616; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.68"; classtype:trojan-activity; sid:100001617; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.69"; classtype:trojan-activity; sid:100001618; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.84"; classtype:trojan-activity; sid:100001619; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.28.118"; classtype:trojan-activity; sid:100001620; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.28.124"; classtype:trojan-activity; sid:100001621; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.28.128"; classtype:trojan-activity; sid:100001622; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.28.167"; classtype:trojan-activity; sid:100001623; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.28.168"; classtype:trojan-activity; sid:100001624; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.28.8"; classtype:trojan-activity; sid:100001625; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.16"; classtype:trojan-activity; sid:100001626; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.173"; classtype:trojan-activity; sid:100001627; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.174"; classtype:trojan-activity; sid:100001628; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.184"; classtype:trojan-activity; sid:100001629; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.207"; classtype:trojan-activity; sid:100001630; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.116"; classtype:trojan-activity; sid:100001631; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.130"; classtype:trojan-activity; sid:100001632; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.172"; classtype:trojan-activity; sid:100001633; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.190"; classtype:trojan-activity; sid:100001634; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.196"; classtype:trojan-activity; sid:100001635; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.214"; classtype:trojan-activity; sid:100001636; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.56"; classtype:trojan-activity; sid:100001637; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.81"; classtype:trojan-activity; sid:100001638; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.0"; classtype:trojan-activity; sid:100001639; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.213"; classtype:trojan-activity; sid:100001640; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.255"; classtype:trojan-activity; sid:100001641; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.77"; classtype:trojan-activity; sid:100001642; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.31.211"; classtype:trojan-activity; sid:100001643; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.31.232"; classtype:trojan-activity; sid:100001644; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.31.249"; classtype:trojan-activity; sid:100001645; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.31.251"; classtype:trojan-activity; sid:100001646; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.0"; classtype:trojan-activity; sid:100001647; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.105"; classtype:trojan-activity; sid:100001648; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.141"; classtype:trojan-activity; sid:100001649; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.172"; classtype:trojan-activity; sid:100001650; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.196"; classtype:trojan-activity; sid:100001651; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.198"; classtype:trojan-activity; sid:100001652; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.208"; classtype:trojan-activity; sid:100001653; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.211"; classtype:trojan-activity; sid:100001654; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.243"; classtype:trojan-activity; sid:100001655; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.32"; classtype:trojan-activity; sid:100001656; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.42"; classtype:trojan-activity; sid:100001657; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.89"; classtype:trojan-activity; sid:100001658; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.112"; classtype:trojan-activity; sid:100001659; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.118"; classtype:trojan-activity; sid:100001660; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.151"; classtype:trojan-activity; sid:100001661; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.155"; classtype:trojan-activity; sid:100001662; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.161"; classtype:trojan-activity; sid:100001663; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.162"; classtype:trojan-activity; sid:100001664; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.170"; classtype:trojan-activity; sid:100001665; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.174"; classtype:trojan-activity; sid:100001666; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.181"; classtype:trojan-activity; sid:100001667; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.2"; classtype:trojan-activity; sid:100001668; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.216"; classtype:trojan-activity; sid:100001669; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.234"; classtype:trojan-activity; sid:100001670; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.236"; classtype:trojan-activity; sid:100001671; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.239"; classtype:trojan-activity; sid:100001672; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.26"; classtype:trojan-activity; sid:100001673; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.34.96"; classtype:trojan-activity; sid:100001674; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.35.160"; classtype:trojan-activity; sid:100001675; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.35.21"; classtype:trojan-activity; sid:100001676; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.35.215"; classtype:trojan-activity; sid:100001677; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.35.253"; classtype:trojan-activity; sid:100001678; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.35.38"; classtype:trojan-activity; sid:100001679; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.35.83"; classtype:trojan-activity; sid:100001680; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.35.89"; classtype:trojan-activity; sid:100001681; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.0"; classtype:trojan-activity; sid:100001682; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.1"; classtype:trojan-activity; sid:100001683; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.102"; classtype:trojan-activity; sid:100001684; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.112"; classtype:trojan-activity; sid:100001685; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.12"; classtype:trojan-activity; sid:100001686; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.16"; classtype:trojan-activity; sid:100001687; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.199"; classtype:trojan-activity; sid:100001688; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.200"; classtype:trojan-activity; sid:100001689; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.218"; classtype:trojan-activity; sid:100001690; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.22"; classtype:trojan-activity; sid:100001691; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.223"; classtype:trojan-activity; sid:100001692; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.33"; classtype:trojan-activity; sid:100001693; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.88"; classtype:trojan-activity; sid:100001694; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.121"; classtype:trojan-activity; sid:100001695; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.135"; classtype:trojan-activity; sid:100001696; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.159"; classtype:trojan-activity; sid:100001697; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.6"; classtype:trojan-activity; sid:100001698; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.1"; classtype:trojan-activity; sid:100001699; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.126"; classtype:trojan-activity; sid:100001700; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.132"; classtype:trojan-activity; sid:100001701; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.148"; classtype:trojan-activity; sid:100001702; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.162"; classtype:trojan-activity; sid:100001703; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.165"; classtype:trojan-activity; sid:100001704; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.191"; classtype:trojan-activity; sid:100001705; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.7"; classtype:trojan-activity; sid:100001706; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.98"; classtype:trojan-activity; sid:100001707; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.39.167"; classtype:trojan-activity; sid:100001708; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.39.245"; classtype:trojan-activity; sid:100001709; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.222"; classtype:trojan-activity; sid:100001710; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.42"; classtype:trojan-activity; sid:100001711; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.58"; classtype:trojan-activity; sid:100001712; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.95"; classtype:trojan-activity; sid:100001713; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.1"; classtype:trojan-activity; sid:100001714; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.151"; classtype:trojan-activity; sid:100001715; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.166"; classtype:trojan-activity; sid:100001716; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.191"; classtype:trojan-activity; sid:100001717; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.199"; classtype:trojan-activity; sid:100001718; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.226"; classtype:trojan-activity; sid:100001719; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.41"; classtype:trojan-activity; sid:100001720; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.5"; classtype:trojan-activity; sid:100001721; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.67"; classtype:trojan-activity; sid:100001722; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.70"; classtype:trojan-activity; sid:100001723; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.71"; classtype:trojan-activity; sid:100001724; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.73"; classtype:trojan-activity; sid:100001725; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.82"; classtype:trojan-activity; sid:100001726; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.165"; classtype:trojan-activity; sid:100001727; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.178"; classtype:trojan-activity; sid:100001728; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.203"; classtype:trojan-activity; sid:100001729; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.210"; classtype:trojan-activity; sid:100001730; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.216"; classtype:trojan-activity; sid:100001731; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.246"; classtype:trojan-activity; sid:100001732; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.34"; classtype:trojan-activity; sid:100001733; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.162"; classtype:trojan-activity; sid:100001734; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.166"; classtype:trojan-activity; sid:100001735; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.200"; classtype:trojan-activity; sid:100001736; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.211"; classtype:trojan-activity; sid:100001737; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.221"; classtype:trojan-activity; sid:100001738; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.27"; classtype:trojan-activity; sid:100001739; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.31"; classtype:trojan-activity; sid:100001740; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.1"; classtype:trojan-activity; sid:100001741; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.121"; classtype:trojan-activity; sid:100001742; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.125"; classtype:trojan-activity; sid:100001743; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.147"; classtype:trojan-activity; sid:100001744; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.17"; classtype:trojan-activity; sid:100001745; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.176"; classtype:trojan-activity; sid:100001746; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.22"; classtype:trojan-activity; sid:100001747; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.33"; classtype:trojan-activity; sid:100001748; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.44"; classtype:trojan-activity; sid:100001749; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.47"; classtype:trojan-activity; sid:100001750; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.134"; classtype:trojan-activity; sid:100001751; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.143"; classtype:trojan-activity; sid:100001752; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.155"; classtype:trojan-activity; sid:100001753; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.218"; classtype:trojan-activity; sid:100001754; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.22"; classtype:trojan-activity; sid:100001755; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.241"; classtype:trojan-activity; sid:100001756; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.89"; classtype:trojan-activity; sid:100001757; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.90"; classtype:trojan-activity; sid:100001758; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.45.205"; classtype:trojan-activity; sid:100001759; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.45.221"; classtype:trojan-activity; sid:100001760; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.45.224"; classtype:trojan-activity; sid:100001761; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.45.230"; classtype:trojan-activity; sid:100001762; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.187"; classtype:trojan-activity; sid:100001763; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.141"; classtype:trojan-activity; sid:100001764; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.151"; classtype:trojan-activity; sid:100001765; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.48.121"; classtype:trojan-activity; sid:100001766; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.48.195"; classtype:trojan-activity; sid:100001767; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.48.243"; classtype:trojan-activity; sid:100001768; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.107"; classtype:trojan-activity; sid:100001769; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.247"; classtype:trojan-activity; sid:100001770; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.3"; classtype:trojan-activity; sid:100001771; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.98"; classtype:trojan-activity; sid:100001772; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.5.16"; classtype:trojan-activity; sid:100001773; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.5.247"; classtype:trojan-activity; sid:100001774; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.5.251"; classtype:trojan-activity; sid:100001775; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.5.70"; classtype:trojan-activity; sid:100001776; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.131"; classtype:trojan-activity; sid:100001777; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.177"; classtype:trojan-activity; sid:100001778; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.201"; classtype:trojan-activity; sid:100001779; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.218"; classtype:trojan-activity; sid:100001780; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.236"; classtype:trojan-activity; sid:100001781; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.237"; classtype:trojan-activity; sid:100001782; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.47"; classtype:trojan-activity; sid:100001783; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.51.150"; classtype:trojan-activity; sid:100001784; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.51.197"; classtype:trojan-activity; sid:100001785; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.51.202"; classtype:trojan-activity; sid:100001786; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.51.223"; classtype:trojan-activity; sid:100001787; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.51.37"; classtype:trojan-activity; sid:100001788; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.51.66"; classtype:trojan-activity; sid:100001789; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.149"; classtype:trojan-activity; sid:100001790; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.161"; classtype:trojan-activity; sid:100001791; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.79"; classtype:trojan-activity; sid:100001792; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.103"; classtype:trojan-activity; sid:100001793; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.15"; classtype:trojan-activity; sid:100001794; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.186"; classtype:trojan-activity; sid:100001795; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.20"; classtype:trojan-activity; sid:100001796; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.4"; classtype:trojan-activity; sid:100001797; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.5"; classtype:trojan-activity; sid:100001798; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.79"; classtype:trojan-activity; sid:100001799; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.105"; classtype:trojan-activity; sid:100001800; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.205"; classtype:trojan-activity; sid:100001801; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.214"; classtype:trojan-activity; sid:100001802; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.72"; classtype:trojan-activity; sid:100001803; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.101"; classtype:trojan-activity; sid:100001804; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.111"; classtype:trojan-activity; sid:100001805; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.163"; classtype:trojan-activity; sid:100001806; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.204"; classtype:trojan-activity; sid:100001807; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.216"; classtype:trojan-activity; sid:100001808; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.29"; classtype:trojan-activity; sid:100001809; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.41"; classtype:trojan-activity; sid:100001810; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.77"; classtype:trojan-activity; sid:100001811; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.86"; classtype:trojan-activity; sid:100001812; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.103"; classtype:trojan-activity; sid:100001813; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.196"; classtype:trojan-activity; sid:100001814; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.33"; classtype:trojan-activity; sid:100001815; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.75"; classtype:trojan-activity; sid:100001816; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.94"; classtype:trojan-activity; sid:100001817; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.57.141"; classtype:trojan-activity; sid:100001818; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.57.178"; classtype:trojan-activity; sid:100001819; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.57.192"; classtype:trojan-activity; sid:100001820; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.57.7"; classtype:trojan-activity; sid:100001821; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.58.117"; classtype:trojan-activity; sid:100001822; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.58.141"; classtype:trojan-activity; sid:100001823; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.58.223"; classtype:trojan-activity; sid:100001824; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.142"; classtype:trojan-activity; sid:100001825; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.161"; classtype:trojan-activity; sid:100001826; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.229"; classtype:trojan-activity; sid:100001827; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.33"; classtype:trojan-activity; sid:100001828; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.46"; classtype:trojan-activity; sid:100001829; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.54"; classtype:trojan-activity; sid:100001830; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.91"; classtype:trojan-activity; sid:100001831; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.134"; classtype:trojan-activity; sid:100001832; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.151"; classtype:trojan-activity; sid:100001833; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.154"; classtype:trojan-activity; sid:100001834; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.162"; classtype:trojan-activity; sid:100001835; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.171"; classtype:trojan-activity; sid:100001836; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.60.154"; classtype:trojan-activity; sid:100001837; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.60.181"; classtype:trojan-activity; sid:100001838; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.60.32"; classtype:trojan-activity; sid:100001839; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.60.99"; classtype:trojan-activity; sid:100001840; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.151"; classtype:trojan-activity; sid:100001841; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.156"; classtype:trojan-activity; sid:100001842; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.219"; classtype:trojan-activity; sid:100001843; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.229"; classtype:trojan-activity; sid:100001844; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.234"; classtype:trojan-activity; sid:100001845; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.253"; classtype:trojan-activity; sid:100001846; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.40"; classtype:trojan-activity; sid:100001847; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.96"; classtype:trojan-activity; sid:100001848; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.110"; classtype:trojan-activity; sid:100001849; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.115"; classtype:trojan-activity; sid:100001850; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.43"; classtype:trojan-activity; sid:100001851; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.63.185"; classtype:trojan-activity; sid:100001852; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.63.21"; classtype:trojan-activity; sid:100001853; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.63.218"; classtype:trojan-activity; sid:100001854; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.116"; classtype:trojan-activity; sid:100001855; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.12"; classtype:trojan-activity; sid:100001856; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.142"; classtype:trojan-activity; sid:100001857; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.158"; classtype:trojan-activity; sid:100001858; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.30"; classtype:trojan-activity; sid:100001859; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.66"; classtype:trojan-activity; sid:100001860; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.65.115"; classtype:trojan-activity; sid:100001861; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.65.136"; classtype:trojan-activity; sid:100001862; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.65.171"; classtype:trojan-activity; sid:100001863; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.65.223"; classtype:trojan-activity; sid:100001864; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.65.70"; classtype:trojan-activity; sid:100001865; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.65.95"; classtype:trojan-activity; sid:100001866; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.65.96"; classtype:trojan-activity; sid:100001867; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.105"; classtype:trojan-activity; sid:100001868; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.170"; classtype:trojan-activity; sid:100001869; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.177"; classtype:trojan-activity; sid:100001870; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.186"; classtype:trojan-activity; sid:100001871; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.199"; classtype:trojan-activity; sid:100001872; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.211"; classtype:trojan-activity; sid:100001873; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.228"; classtype:trojan-activity; sid:100001874; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.237"; classtype:trojan-activity; sid:100001875; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.93"; classtype:trojan-activity; sid:100001876; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.0"; classtype:trojan-activity; sid:100001877; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.184"; classtype:trojan-activity; sid:100001878; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.185"; classtype:trojan-activity; sid:100001879; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.201"; classtype:trojan-activity; sid:100001880; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.254"; classtype:trojan-activity; sid:100001881; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.31"; classtype:trojan-activity; sid:100001882; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.109"; classtype:trojan-activity; sid:100001883; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.126"; classtype:trojan-activity; sid:100001884; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.166"; classtype:trojan-activity; sid:100001885; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.170"; classtype:trojan-activity; sid:100001886; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.227"; classtype:trojan-activity; sid:100001887; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.232"; classtype:trojan-activity; sid:100001888; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.29"; classtype:trojan-activity; sid:100001889; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.44"; classtype:trojan-activity; sid:100001890; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.66"; classtype:trojan-activity; sid:100001891; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.83"; classtype:trojan-activity; sid:100001892; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.111"; classtype:trojan-activity; sid:100001893; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.119"; classtype:trojan-activity; sid:100001894; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.128"; classtype:trojan-activity; sid:100001895; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.138"; classtype:trojan-activity; sid:100001896; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.149"; classtype:trojan-activity; sid:100001897; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.188"; classtype:trojan-activity; sid:100001898; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.205"; classtype:trojan-activity; sid:100001899; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.77"; classtype:trojan-activity; sid:100001900; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.7.163"; classtype:trojan-activity; sid:100001901; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.119"; classtype:trojan-activity; sid:100001902; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.12"; classtype:trojan-activity; sid:100001903; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.147"; classtype:trojan-activity; sid:100001904; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.18"; classtype:trojan-activity; sid:100001905; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.200"; classtype:trojan-activity; sid:100001906; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.38"; classtype:trojan-activity; sid:100001907; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.53"; classtype:trojan-activity; sid:100001908; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.54"; classtype:trojan-activity; sid:100001909; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.148"; classtype:trojan-activity; sid:100001910; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.153"; classtype:trojan-activity; sid:100001911; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.185"; classtype:trojan-activity; sid:100001912; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.196"; classtype:trojan-activity; sid:100001913; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.22"; classtype:trojan-activity; sid:100001914; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.55"; classtype:trojan-activity; sid:100001915; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.63"; classtype:trojan-activity; sid:100001916; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.84"; classtype:trojan-activity; sid:100001917; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.89"; classtype:trojan-activity; sid:100001918; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.113"; classtype:trojan-activity; sid:100001919; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.13"; classtype:trojan-activity; sid:100001920; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.164"; classtype:trojan-activity; sid:100001921; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.173"; classtype:trojan-activity; sid:100001922; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.196"; classtype:trojan-activity; sid:100001923; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.222"; classtype:trojan-activity; sid:100001924; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.47"; classtype:trojan-activity; sid:100001925; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.75"; classtype:trojan-activity; sid:100001926; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.91"; classtype:trojan-activity; sid:100001927; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.98"; classtype:trojan-activity; sid:100001928; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.73.220"; classtype:trojan-activity; sid:100001929; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.74.182"; classtype:trojan-activity; sid:100001930; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.74.48"; classtype:trojan-activity; sid:100001931; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.75.135"; classtype:trojan-activity; sid:100001932; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.75.181"; classtype:trojan-activity; sid:100001933; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.75.19"; classtype:trojan-activity; sid:100001934; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.75.209"; classtype:trojan-activity; sid:100001935; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.75.249"; classtype:trojan-activity; sid:100001936; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.75.54"; classtype:trojan-activity; sid:100001937; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.75.84"; classtype:trojan-activity; sid:100001938; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.75.87"; classtype:trojan-activity; sid:100001939; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.109"; classtype:trojan-activity; sid:100001940; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.167"; classtype:trojan-activity; sid:100001941; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.187"; classtype:trojan-activity; sid:100001942; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.214"; classtype:trojan-activity; sid:100001943; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.215"; classtype:trojan-activity; sid:100001944; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.217"; classtype:trojan-activity; sid:100001945; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.24"; classtype:trojan-activity; sid:100001946; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.77.132"; classtype:trojan-activity; sid:100001947; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.77.145"; classtype:trojan-activity; sid:100001948; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.77.46"; classtype:trojan-activity; sid:100001949; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.77.47"; classtype:trojan-activity; sid:100001950; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.77.95"; classtype:trojan-activity; sid:100001951; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.106"; classtype:trojan-activity; sid:100001952; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.202"; classtype:trojan-activity; sid:100001953; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.233"; classtype:trojan-activity; sid:100001954; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.46"; classtype:trojan-activity; sid:100001955; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.76"; classtype:trojan-activity; sid:100001956; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.79.156"; classtype:trojan-activity; sid:100001957; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.79.227"; classtype:trojan-activity; sid:100001958; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.79.24"; classtype:trojan-activity; sid:100001959; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.79.247"; classtype:trojan-activity; sid:100001960; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.79.45"; classtype:trojan-activity; sid:100001961; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.79.77"; classtype:trojan-activity; sid:100001962; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.8.100"; classtype:trojan-activity; sid:100001963; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.8.165"; classtype:trojan-activity; sid:100001964; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.8.199"; classtype:trojan-activity; sid:100001965; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.8.205"; classtype:trojan-activity; sid:100001966; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.8.217"; classtype:trojan-activity; sid:100001967; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.8.254"; classtype:trojan-activity; sid:100001968; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.237"; classtype:trojan-activity; sid:100001969; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.244"; classtype:trojan-activity; sid:100001970; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.79"; classtype:trojan-activity; sid:100001971; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.86"; classtype:trojan-activity; sid:100001972; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.1"; classtype:trojan-activity; sid:100001973; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.141"; classtype:trojan-activity; sid:100001974; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.15"; classtype:trojan-activity; sid:100001975; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.152"; classtype:trojan-activity; sid:100001976; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.17"; classtype:trojan-activity; sid:100001977; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.194"; classtype:trojan-activity; sid:100001978; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.216"; classtype:trojan-activity; sid:100001979; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.226"; classtype:trojan-activity; sid:100001980; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.244"; classtype:trojan-activity; sid:100001981; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.50"; classtype:trojan-activity; sid:100001982; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.82"; classtype:trojan-activity; sid:100001983; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.82.61"; classtype:trojan-activity; sid:100001984; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.83.147"; classtype:trojan-activity; sid:100001985; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.83.196"; classtype:trojan-activity; sid:100001986; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.102"; classtype:trojan-activity; sid:100001987; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.109"; classtype:trojan-activity; sid:100001988; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.148"; classtype:trojan-activity; sid:100001989; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.159"; classtype:trojan-activity; sid:100001990; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.215"; classtype:trojan-activity; sid:100001991; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.42"; classtype:trojan-activity; sid:100001992; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.153"; classtype:trojan-activity; sid:100001993; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.165"; classtype:trojan-activity; sid:100001994; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.183"; classtype:trojan-activity; sid:100001995; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.190"; classtype:trojan-activity; sid:100001996; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.229"; classtype:trojan-activity; sid:100001997; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.87"; classtype:trojan-activity; sid:100001998; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.9"; classtype:trojan-activity; sid:100001999; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.86.119"; classtype:trojan-activity; sid:100002000; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.86.218"; classtype:trojan-activity; sid:100002001; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.107"; classtype:trojan-activity; sid:100002002; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.123"; classtype:trojan-activity; sid:100002003; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.162"; classtype:trojan-activity; sid:100002004; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.253"; classtype:trojan-activity; sid:100002005; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.90"; classtype:trojan-activity; sid:100002006; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.180"; classtype:trojan-activity; sid:100002007; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.181"; classtype:trojan-activity; sid:100002008; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.78"; classtype:trojan-activity; sid:100002009; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.89.130"; classtype:trojan-activity; sid:100002010; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.89.19"; classtype:trojan-activity; sid:100002011; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.89.37"; classtype:trojan-activity; sid:100002012; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.89.51"; classtype:trojan-activity; sid:100002013; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.178"; classtype:trojan-activity; sid:100002014; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.183"; classtype:trojan-activity; sid:100002015; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.215"; classtype:trojan-activity; sid:100002016; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.217"; classtype:trojan-activity; sid:100002017; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.245"; classtype:trojan-activity; sid:100002018; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.45"; classtype:trojan-activity; sid:100002019; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.80"; classtype:trojan-activity; sid:100002020; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.84"; classtype:trojan-activity; sid:100002021; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.95"; classtype:trojan-activity; sid:100002022; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.115"; classtype:trojan-activity; sid:100002023; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.160"; classtype:trojan-activity; sid:100002024; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.178"; classtype:trojan-activity; sid:100002025; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.187"; classtype:trojan-activity; sid:100002026; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.21"; classtype:trojan-activity; sid:100002027; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.212"; classtype:trojan-activity; sid:100002028; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.4"; classtype:trojan-activity; sid:100002029; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.8"; classtype:trojan-activity; sid:100002030; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.15"; classtype:trojan-activity; sid:100002031; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.165"; classtype:trojan-activity; sid:100002032; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.172"; classtype:trojan-activity; sid:100002033; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.191"; classtype:trojan-activity; sid:100002034; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.253"; classtype:trojan-activity; sid:100002035; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.47"; classtype:trojan-activity; sid:100002036; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.58"; classtype:trojan-activity; sid:100002037; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.71"; classtype:trojan-activity; sid:100002038; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.96"; classtype:trojan-activity; sid:100002039; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.132"; classtype:trojan-activity; sid:100002040; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.186"; classtype:trojan-activity; sid:100002041; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.201"; classtype:trojan-activity; sid:100002042; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.208"; classtype:trojan-activity; sid:100002043; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.215"; classtype:trojan-activity; sid:100002044; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.224"; classtype:trojan-activity; sid:100002045; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.231"; classtype:trojan-activity; sid:100002046; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.248"; classtype:trojan-activity; sid:100002047; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.45"; classtype:trojan-activity; sid:100002048; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.143"; classtype:trojan-activity; sid:100002049; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.150"; classtype:trojan-activity; sid:100002050; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.155"; classtype:trojan-activity; sid:100002051; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.198"; classtype:trojan-activity; sid:100002052; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.225"; classtype:trojan-activity; sid:100002053; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.245"; classtype:trojan-activity; sid:100002054; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.31"; classtype:trojan-activity; sid:100002055; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.4"; classtype:trojan-activity; sid:100002056; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.45"; classtype:trojan-activity; sid:100002057; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.6"; classtype:trojan-activity; sid:100002058; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.116"; classtype:trojan-activity; sid:100002059; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.184"; classtype:trojan-activity; sid:100002060; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.195"; classtype:trojan-activity; sid:100002061; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.238"; classtype:trojan-activity; sid:100002062; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.40"; classtype:trojan-activity; sid:100002063; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.147"; classtype:trojan-activity; sid:100002064; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.227"; classtype:trojan-activity; sid:100002065; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.244"; classtype:trojan-activity; sid:100002066; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.249"; classtype:trojan-activity; sid:100002067; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.4"; classtype:trojan-activity; sid:100002068; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.89"; classtype:trojan-activity; sid:100002069; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.99"; classtype:trojan-activity; sid:100002070; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.96.13"; classtype:trojan-activity; sid:100002071; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.96.180"; classtype:trojan-activity; sid:100002072; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.96.195"; classtype:trojan-activity; sid:100002073; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.96.24"; classtype:trojan-activity; sid:100002074; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.96.6"; classtype:trojan-activity; sid:100002075; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.97.111"; classtype:trojan-activity; sid:100002076; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.97.181"; classtype:trojan-activity; sid:100002077; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.97.243"; classtype:trojan-activity; sid:100002078; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.98.140"; classtype:trojan-activity; sid:100002079; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.98.228"; classtype:trojan-activity; sid:100002080; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.98.254"; classtype:trojan-activity; sid:100002081; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.98.50"; classtype:trojan-activity; sid:100002082; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.98.68"; classtype:trojan-activity; sid:100002083; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.108"; classtype:trojan-activity; sid:100002084; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.123"; classtype:trojan-activity; sid:100002085; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.130"; classtype:trojan-activity; sid:100002086; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.22"; classtype:trojan-activity; sid:100002087; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.45"; classtype:trojan-activity; sid:100002088; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.75"; classtype:trojan-activity; sid:100002089; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.8"; classtype:trojan-activity; sid:100002090; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.91"; classtype:trojan-activity; sid:100002091; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.19.183.14"; classtype:trojan-activity; sid:100002092; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.205.101.33"; classtype:trojan-activity; sid:100002093; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.21.164.68"; classtype:trojan-activity; sid:100002094; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.217.8.194"; classtype:trojan-activity; sid:100002095; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.22.117.102"; classtype:trojan-activity; sid:100002096; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.222.252.130"; classtype:trojan-activity; sid:100002097; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.34.183.30"; classtype:trojan-activity; sid:100002098; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.92.246.246"; classtype:trojan-activity; sid:100002099; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.93.112.88"; classtype:trojan-activity; sid:100002100; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.95.115.33"; classtype:trojan-activity; sid:100002101; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.159.58.134"; classtype:trojan-activity; sid:100002102; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.4.187.39"; classtype:trojan-activity; sid:100002103; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.48.156.252"; classtype:trojan-activity; sid:100002104; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.60.84.7"; classtype:trojan-activity; sid:100002105; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.99.210.161"; classtype:trojan-activity; sid:100002106; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.109.36.244"; classtype:trojan-activity; sid:100002107; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.111.101.141"; classtype:trojan-activity; sid:100002108; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.114.111.153"; classtype:trojan-activity; sid:100002109; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.116.203.220"; classtype:trojan-activity; sid:100002110; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.120.149.106"; classtype:trojan-activity; sid:100002111; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.122.13.227"; classtype:trojan-activity; sid:100002112; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.125.155.69"; classtype:trojan-activity; sid:100002113; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.125.44.194"; classtype:trojan-activity; sid:100002114; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.157.66.204"; classtype:trojan-activity; sid:100002115; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.175.93.52"; classtype:trojan-activity; sid:100002116; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.105.41"; classtype:trojan-activity; sid:100002117; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.110.243"; classtype:trojan-activity; sid:100002118; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.165.230"; classtype:trojan-activity; sid:100002119; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.214.171"; classtype:trojan-activity; sid:100002120; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.34.51"; classtype:trojan-activity; sid:100002121; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.96.248"; classtype:trojan-activity; sid:100002122; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.177.104.65"; classtype:trojan-activity; sid:100002123; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.177.242.73"; classtype:trojan-activity; sid:100002124; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.218.5.171"; classtype:trojan-activity; sid:100002125; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.248.80.38"; classtype:trojan-activity; sid:100002126; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.66.111.36"; classtype:trojan-activity; sid:100002127; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.66.53.93"; classtype:trojan-activity; sid:100002128; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.94.170.166"; classtype:trojan-activity; sid:100002129; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.112.138.154"; classtype:trojan-activity; sid:100002130; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.112.218.238"; classtype:trojan-activity; sid:100002131; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.112.218.6"; classtype:trojan-activity; sid:100002132; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.143.60.163"; classtype:trojan-activity; sid:100002133; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.174.63.114"; classtype:trojan-activity; sid:100002134; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.193.107.10"; classtype:trojan-activity; sid:100002135; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.199.170.210"; classtype:trojan-activity; sid:100002136; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.199.170.222"; classtype:trojan-activity; sid:100002137; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.199.170.230"; classtype:trojan-activity; sid:100002138; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.199.170.240"; classtype:trojan-activity; sid:100002139; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.210.45.42"; classtype:trojan-activity; sid:100002140; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.215.47.82"; classtype:trojan-activity; sid:100002141; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.224.242.131"; classtype:trojan-activity; sid:100002142; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.49.236.4"; classtype:trojan-activity; sid:100002143; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.49.59.162"; classtype:trojan-activity; sid:100002144; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.112.0.33"; classtype:trojan-activity; sid:100002145; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.112.15.49"; classtype:trojan-activity; sid:100002146; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.112.39.201"; classtype:trojan-activity; sid:100002147; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.112.52.131"; classtype:trojan-activity; sid:100002148; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.113.0.79"; classtype:trojan-activity; sid:100002149; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.113.222.154"; classtype:trojan-activity; sid:100002150; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.113.24.21"; classtype:trojan-activity; sid:100002151; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.106.207"; classtype:trojan-activity; sid:100002152; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.122.228"; classtype:trojan-activity; sid:100002153; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.202.186"; classtype:trojan-activity; sid:100002154; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.31.65"; classtype:trojan-activity; sid:100002155; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.50.124"; classtype:trojan-activity; sid:100002156; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.50.93"; classtype:trojan-activity; sid:100002157; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.64.27"; classtype:trojan-activity; sid:100002158; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.70.177"; classtype:trojan-activity; sid:100002159; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.93.165"; classtype:trojan-activity; sid:100002160; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.94.255"; classtype:trojan-activity; sid:100002161; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.101.82"; classtype:trojan-activity; sid:100002162; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.104.125"; classtype:trojan-activity; sid:100002163; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.110.31"; classtype:trojan-activity; sid:100002164; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.44.70"; classtype:trojan-activity; sid:100002165; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.49.171"; classtype:trojan-activity; sid:100002166; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.60.73"; classtype:trojan-activity; sid:100002167; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.61.252"; classtype:trojan-activity; sid:100002168; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.65.157"; classtype:trojan-activity; sid:100002169; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.65.245"; classtype:trojan-activity; sid:100002170; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.68.40"; classtype:trojan-activity; sid:100002171; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.69.37"; classtype:trojan-activity; sid:100002172; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.69.47"; classtype:trojan-activity; sid:100002173; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.94.196"; classtype:trojan-activity; sid:100002174; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.99.17"; classtype:trojan-activity; sid:100002175; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.155.204"; classtype:trojan-activity; sid:100002176; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.25.120"; classtype:trojan-activity; sid:100002177; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.26.235"; classtype:trojan-activity; sid:100002178; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.27.150"; classtype:trojan-activity; sid:100002179; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.29.74"; classtype:trojan-activity; sid:100002180; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.43.27"; classtype:trojan-activity; sid:100002181; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.118.140.117"; classtype:trojan-activity; sid:100002182; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.100.228"; classtype:trojan-activity; sid:100002183; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.14.252"; classtype:trojan-activity; sid:100002184; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.166.208"; classtype:trojan-activity; sid:100002185; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.211.69"; classtype:trojan-activity; sid:100002186; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.220.48"; classtype:trojan-activity; sid:100002187; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.227.82"; classtype:trojan-activity; sid:100002188; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.229.96"; classtype:trojan-activity; sid:100002189; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.236.21"; classtype:trojan-activity; sid:100002190; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.50.155"; classtype:trojan-activity; sid:100002191; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.81.33"; classtype:trojan-activity; sid:100002192; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.10.21"; classtype:trojan-activity; sid:100002193; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.16.22"; classtype:trojan-activity; sid:100002194; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.16.46"; classtype:trojan-activity; sid:100002195; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.37.251"; classtype:trojan-activity; sid:100002196; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.43.0"; classtype:trojan-activity; sid:100002197; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.101.100"; classtype:trojan-activity; sid:100002198; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.109.190"; classtype:trojan-activity; sid:100002199; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.125.170"; classtype:trojan-activity; sid:100002200; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.129.232"; classtype:trojan-activity; sid:100002201; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.131.69"; classtype:trojan-activity; sid:100002202; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.133.200"; classtype:trojan-activity; sid:100002203; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.135.160"; classtype:trojan-activity; sid:100002204; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.148.236"; classtype:trojan-activity; sid:100002205; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.157.221"; classtype:trojan-activity; sid:100002206; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.200.151"; classtype:trojan-activity; sid:100002207; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.206.132"; classtype:trojan-activity; sid:100002208; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.219.239"; classtype:trojan-activity; sid:100002209; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.233.191"; classtype:trojan-activity; sid:100002210; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.249.26"; classtype:trojan-activity; sid:100002211; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.68.100"; classtype:trojan-activity; sid:100002212; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.81.241"; classtype:trojan-activity; sid:100002213; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.92.113"; classtype:trojan-activity; sid:100002214; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.93.174"; classtype:trojan-activity; sid:100002215; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.98.21"; classtype:trojan-activity; sid:100002216; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.122.170.19"; classtype:trojan-activity; sid:100002217; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.122.220.203"; classtype:trojan-activity; sid:100002218; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.122.229.102"; classtype:trojan-activity; sid:100002219; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.122.245.2"; classtype:trojan-activity; sid:100002220; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.122.249.24"; classtype:trojan-activity; sid:100002221; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.124.188.23"; classtype:trojan-activity; sid:100002222; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.124.53.111"; classtype:trojan-activity; sid:100002223; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.113.127"; classtype:trojan-activity; sid:100002224; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.117.41"; classtype:trojan-activity; sid:100002225; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.124.47"; classtype:trojan-activity; sid:100002226; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.126.203"; classtype:trojan-activity; sid:100002227; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.127.40"; classtype:trojan-activity; sid:100002228; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.139.193"; classtype:trojan-activity; sid:100002229; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.139.66"; classtype:trojan-activity; sid:100002230; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.140.30"; classtype:trojan-activity; sid:100002231; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.178.187"; classtype:trojan-activity; sid:100002232; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.82.29"; classtype:trojan-activity; sid:100002233; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.83.79"; classtype:trojan-activity; sid:100002234; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.87.58"; classtype:trojan-activity; sid:100002235; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.95.209"; classtype:trojan-activity; sid:100002236; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.155.157"; classtype:trojan-activity; sid:100002237; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.166.232"; classtype:trojan-activity; sid:100002238; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.210.107"; classtype:trojan-activity; sid:100002239; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.6.12"; classtype:trojan-activity; sid:100002240; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.78.61"; classtype:trojan-activity; sid:100002241; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.87.72"; classtype:trojan-activity; sid:100002242; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.91.161"; classtype:trojan-activity; sid:100002243; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.172.36.164"; classtype:trojan-activity; sid:100002244; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.207.219.164"; classtype:trojan-activity; sid:100002245; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.233.0.252"; classtype:trojan-activity; sid:100002246; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.235.252.31"; classtype:trojan-activity; sid:100002247; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.53.197.62"; classtype:trojan-activity; sid:100002248; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.88.235.221"; classtype:trojan-activity; sid:100002249; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.105.104.83"; classtype:trojan-activity; sid:100002250; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.105.225.154"; classtype:trojan-activity; sid:100002251; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.109.169.45"; classtype:trojan-activity; sid:100002252; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.11.238.228"; classtype:trojan-activity; sid:100002253; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.136.252.233"; classtype:trojan-activity; sid:100002254; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.150.138.131"; classtype:trojan-activity; sid:100002255; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.16.208.172"; classtype:trojan-activity; sid:100002256; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.187.163.176"; classtype:trojan-activity; sid:100002257; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.188.151.225"; classtype:trojan-activity; sid:100002258; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.188.180.116"; classtype:trojan-activity; sid:100002259; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.188.180.68"; classtype:trojan-activity; sid:100002260; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.188.76.196"; classtype:trojan-activity; sid:100002261; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.83.14.35"; classtype:trojan-activity; sid:100002262; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.83.15.116"; classtype:trojan-activity; sid:100002263; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.83.23.138"; classtype:trojan-activity; sid:100002264; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.83.99.36"; classtype:trojan-activity; sid:100002265; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.92.195.140"; classtype:trojan-activity; sid:100002266; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.95.147.102"; classtype:trojan-activity; sid:100002267; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.97.22.14"; classtype:trojan-activity; sid:100002268; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"184.164.185.41"; classtype:trojan-activity; sid:100002269; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"184.74.149.230"; classtype:trojan-activity; sid:100002270; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.106.209.68"; classtype:trojan-activity; sid:100002271; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.107.3.8"; classtype:trojan-activity; sid:100002272; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.172.110.235"; classtype:trojan-activity; sid:100002273; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.181.10.234"; classtype:trojan-activity; sid:100002274; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.200.241.196"; classtype:trojan-activity; sid:100002275; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.112"; classtype:trojan-activity; sid:100002276; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.54"; classtype:trojan-activity; sid:100002277; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.77"; classtype:trojan-activity; sid:100002278; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.93"; classtype:trojan-activity; sid:100002279; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.219.133.122"; classtype:trojan-activity; sid:100002280; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.221.3.244"; classtype:trojan-activity; sid:100002281; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.228.141.74"; classtype:trojan-activity; sid:100002282; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.239.243.77"; classtype:trojan-activity; sid:100002283; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.26.113.95"; classtype:trojan-activity; sid:100002284; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.43.19.151"; classtype:trojan-activity; sid:100002285; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.55.1.182"; classtype:trojan-activity; sid:100002286; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.68.230.207"; classtype:trojan-activity; sid:100002287; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.81.157.186"; classtype:trojan-activity; sid:100002288; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.217.185"; classtype:trojan-activity; sid:100002289; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.217.213"; classtype:trojan-activity; sid:100002290; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.160"; classtype:trojan-activity; sid:100002291; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.161"; classtype:trojan-activity; sid:100002292; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.219"; classtype:trojan-activity; sid:100002293; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.80"; classtype:trojan-activity; sid:100002294; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.90.166.56"; classtype:trojan-activity; sid:100002295; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.151.144.85"; classtype:trojan-activity; sid:100002296; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.219.164"; classtype:trojan-activity; sid:100002297; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.243.112"; classtype:trojan-activity; sid:100002298; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.243.77"; classtype:trojan-activity; sid:100002299; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.253.150"; classtype:trojan-activity; sid:100002300; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.225.120.173"; classtype:trojan-activity; sid:100002301; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.227.148.107"; classtype:trojan-activity; sid:100002302; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.28.60.184"; classtype:trojan-activity; sid:100002303; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.4.125.48"; classtype:trojan-activity; sid:100002304; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.73.188.132"; classtype:trojan-activity; sid:100002305; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.12.10.98"; classtype:trojan-activity; sid:100002306; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.188.124.229"; classtype:trojan-activity; sid:100002307; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.212.200.162"; classtype:trojan-activity; sid:100002308; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.56.88.170"; classtype:trojan-activity; sid:100002309; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.75.218.102"; classtype:trojan-activity; sid:100002310; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.10.21.14"; classtype:trojan-activity; sid:100002311; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.10.231.246"; classtype:trojan-activity; sid:100002312; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.113.81.17"; classtype:trojan-activity; sid:100002313; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.127.224.149"; classtype:trojan-activity; sid:100002314; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.127.224.61"; classtype:trojan-activity; sid:100002315; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.127.227.99"; classtype:trojan-activity; sid:100002316; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.127.230.133"; classtype:trojan-activity; sid:100002317; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.127.231.226"; classtype:trojan-activity; sid:100002318; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.127.231.55"; classtype:trojan-activity; sid:100002319; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.127.235.232"; classtype:trojan-activity; sid:100002320; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.127.235.70"; classtype:trojan-activity; sid:100002321; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.127.235.71"; classtype:trojan-activity; sid:100002322; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.127.254.114"; classtype:trojan-activity; sid:100002323; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.13.179.87"; classtype:trojan-activity; sid:100002324; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.138.200.32"; classtype:trojan-activity; sid:100002325; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.152.41.141"; classtype:trojan-activity; sid:100002326; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.169.178.50"; classtype:trojan-activity; sid:100002327; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.169.199.59"; classtype:trojan-activity; sid:100002328; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.169.30.30"; classtype:trojan-activity; sid:100002329; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.169.36.163"; classtype:trojan-activity; sid:100002330; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.242.167.159"; classtype:trojan-activity; sid:100002331; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.242.242.144"; classtype:trojan-activity; sid:100002332; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.81.100.83"; classtype:trojan-activity; sid:100002333; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.83.202.25"; classtype:trojan-activity; sid:100002334; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.93.233.223"; classtype:trojan-activity; sid:100002335; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"189.222.157.241"; classtype:trojan-activity; sid:100002336; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"19.dbstrony.pl"; classtype:trojan-activity; sid:100002337; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.0.42.106"; classtype:trojan-activity; sid:100002338; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.110.161.252"; classtype:trojan-activity; sid:100002339; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.111.151.164"; classtype:trojan-activity; sid:100002340; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.119.207.58"; classtype:trojan-activity; sid:100002341; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.12.99.194"; classtype:trojan-activity; sid:100002342; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.121.194.18"; classtype:trojan-activity; sid:100002343; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.160"; classtype:trojan-activity; sid:100002344; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.3"; classtype:trojan-activity; sid:100002345; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.37"; classtype:trojan-activity; sid:100002346; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.41"; classtype:trojan-activity; sid:100002347; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.42"; classtype:trojan-activity; sid:100002348; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.130.15.212"; classtype:trojan-activity; sid:100002349; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.130.20.14"; classtype:trojan-activity; sid:100002350; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.141.117.41"; classtype:trojan-activity; sid:100002351; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.147.16.184"; classtype:trojan-activity; sid:100002352; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.159.240.9"; classtype:trojan-activity; sid:100002353; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.187.55.150"; classtype:trojan-activity; sid:100002354; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.210.214.130"; classtype:trojan-activity; sid:100002355; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.213.177.39"; classtype:trojan-activity; sid:100002356; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.213.226.63"; classtype:trojan-activity; sid:100002357; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.213.49.207"; classtype:trojan-activity; sid:100002358; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.214.24.194"; classtype:trojan-activity; sid:100002359; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.216.140.123"; classtype:trojan-activity; sid:100002360; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.35.225.36"; classtype:trojan-activity; sid:100002361; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.65.206.162"; classtype:trojan-activity; sid:100002362; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.92.4.231"; classtype:trojan-activity; sid:100002363; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.98.37.135"; classtype:trojan-activity; sid:100002364; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.98.37.200"; classtype:trojan-activity; sid:100002365; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.98.41.33"; classtype:trojan-activity; sid:100002366; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"191.255.248.220"; classtype:trojan-activity; sid:100002367; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.210.175.130"; classtype:trojan-activity; sid:100002368; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.210.241.200"; classtype:trojan-activity; sid:100002369; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.185.106"; classtype:trojan-activity; sid:100002370; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.209.27"; classtype:trojan-activity; sid:100002371; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.228.67"; classtype:trojan-activity; sid:100002372; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.3.73.205"; classtype:trojan-activity; sid:100002373; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.99.240.77"; classtype:trojan-activity; sid:100002374; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"193.228.135.144"; classtype:trojan-activity; sid:100002375; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"193.91.131.237"; classtype:trojan-activity; sid:100002376; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.152.35.139"; classtype:trojan-activity; sid:100002377; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.38.20.199"; classtype:trojan-activity; sid:100002378; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.123.208.140"; classtype:trojan-activity; sid:100002379; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.123.213.154"; classtype:trojan-activity; sid:100002380; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.139.126.51"; classtype:trojan-activity; sid:100002381; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.228.231.218"; classtype:trojan-activity; sid:100002382; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.24.94.187"; classtype:trojan-activity; sid:100002383; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.64.163.103"; classtype:trojan-activity; sid:100002384; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.202.26.182"; classtype:trojan-activity; sid:100002385; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.218.48.82"; classtype:trojan-activity; sid:100002386; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.221.148.90"; classtype:trojan-activity; sid:100002387; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.221.166.203"; classtype:trojan-activity; sid:100002388; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"197.159.2.106"; classtype:trojan-activity; sid:100002389; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"197.50.27.115"; classtype:trojan-activity; sid:100002390; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.133.218"; classtype:trojan-activity; sid:100002391; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.251.105"; classtype:trojan-activity; sid:100002392; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.46.201.76"; classtype:trojan-activity; sid:100002393; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.46.202.7"; classtype:trojan-activity; sid:100002394; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1am.co.nz"; classtype:trojan-activity; sid:100002395; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.229.89.119"; classtype:trojan-activity; sid:100002396; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.37.203.65"; classtype:trojan-activity; sid:100002397; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.45.111.158"; classtype:trojan-activity; sid:100002398; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.45.4.24"; classtype:trojan-activity; sid:100002399; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.55.125.182"; classtype:trojan-activity; sid:100002400; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.55.92.184"; classtype:trojan-activity; sid:100002401; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.83.152.16"; classtype:trojan-activity; sid:100002402; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"20.dbstrony.pl"; classtype:trojan-activity; sid:100002403; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.105.167.98"; classtype:trojan-activity; sid:100002404; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.111.189.70"; classtype:trojan-activity; sid:100002405; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.194.4.24"; classtype:trojan-activity; sid:100002406; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.2.161.171"; classtype:trojan-activity; sid:100002407; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.30.132.50"; classtype:trojan-activity; sid:100002408; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.142.147.89"; classtype:trojan-activity; sid:100002409; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.184.163.170"; classtype:trojan-activity; sid:100002410; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.184.248.190"; classtype:trojan-activity; sid:100002411; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.187.102.73"; classtype:trojan-activity; sid:100002412; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.193.17.190"; classtype:trojan-activity; sid:100002413; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.203.221.20"; classtype:trojan-activity; sid:100002414; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.215.84.97"; classtype:trojan-activity; sid:100002415; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.218.97.142"; classtype:trojan-activity; sid:100002416; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.107.233.41"; classtype:trojan-activity; sid:100002417; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.111.131.91"; classtype:trojan-activity; sid:100002418; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.150.176.100"; classtype:trojan-activity; sid:100002419; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.164.150.115"; classtype:trojan-activity; sid:100002420; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.166.217.54"; classtype:trojan-activity; sid:100002421; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.169.234.47"; classtype:trojan-activity; sid:100002422; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.169.234.52"; classtype:trojan-activity; sid:100002423; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.169.234.56"; classtype:trojan-activity; sid:100002424; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.178.113.26"; classtype:trojan-activity; sid:100002425; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.29.95.12"; classtype:trojan-activity; sid:100002426; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.4.124.58"; classtype:trojan-activity; sid:100002427; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.51.176.114"; classtype:trojan-activity; sid:100002428; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.51.191.174"; classtype:trojan-activity; sid:100002429; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.74.236.9"; classtype:trojan-activity; sid:100002430; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.109.201.243"; classtype:trojan-activity; sid:100002431; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.130.69.205"; classtype:trojan-activity; sid:100002432; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.170.105.156"; classtype:trojan-activity; sid:100002433; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.170.115.82"; classtype:trojan-activity; sid:100002434; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.189.156.107"; classtype:trojan-activity; sid:100002435; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.202.248.237"; classtype:trojan-activity; sid:100002436; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.204.232.18"; classtype:trojan-activity; sid:100002437; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.229.21.56"; classtype:trojan-activity; sid:100002438; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.236.190.28"; classtype:trojan-activity; sid:100002439; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.238.86.202"; classtype:trojan-activity; sid:100002440; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.70.166.107"; classtype:trojan-activity; sid:100002441; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.77.80.159"; classtype:trojan-activity; sid:100002442; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.80.119.166"; classtype:trojan-activity; sid:100002443; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.80.171.138"; classtype:trojan-activity; sid:100002444; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.82.36.34"; classtype:trojan-activity; sid:100002445; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.93.6.28"; classtype:trojan-activity; sid:100002446; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"204.195.116.171"; classtype:trojan-activity; sid:100002447; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"205.185.115.74"; classtype:trojan-activity; sid:100002448; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"205.185.123.217"; classtype:trojan-activity; sid:100002449; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"206.47.41.166"; classtype:trojan-activity; sid:100002450; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"207.200.247.187"; classtype:trojan-activity; sid:100002451; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"207.44.28.234"; classtype:trojan-activity; sid:100002452; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"207.5.32.6"; classtype:trojan-activity; sid:100002453; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"208.163.58.18"; classtype:trojan-activity; sid:100002454; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.133.223.130"; classtype:trojan-activity; sid:100002455; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.141.39.50"; classtype:trojan-activity; sid:100002456; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.141.40.190"; classtype:trojan-activity; sid:100002457; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.141.40.31"; classtype:trojan-activity; sid:100002458; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.145.60.38"; classtype:trojan-activity; sid:100002459; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.124.149.19"; classtype:trojan-activity; sid:100002460; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.216.152.122"; classtype:trojan-activity; sid:100002461; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.216.153.142"; classtype:trojan-activity; sid:100002462; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.57.234.131"; classtype:trojan-activity; sid:100002463; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.57.237.70"; classtype:trojan-activity; sid:100002464; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.68.242.114"; classtype:trojan-activity; sid:100002465; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.96.116.236"; classtype:trojan-activity; sid:100002466; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.116.220.37"; classtype:trojan-activity; sid:100002467; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.172.11.169"; classtype:trojan-activity; sid:100002468; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.179.243.103"; classtype:trojan-activity; sid:100002469; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.187.132.204"; classtype:trojan-activity; sid:100002470; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.187.75.220"; classtype:trojan-activity; sid:100002471; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.204.215.157"; classtype:trojan-activity; sid:100002472; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.210.66.179"; classtype:trojan-activity; sid:100002473; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.210.93.93"; classtype:trojan-activity; sid:100002474; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.216.66.105"; classtype:trojan-activity; sid:100002475; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.237.114.96"; classtype:trojan-activity; sid:100002476; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.237.120.13"; classtype:trojan-activity; sid:100002477; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.238.83.238"; classtype:trojan-activity; sid:100002478; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.247.113.49"; classtype:trojan-activity; sid:100002479; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.247.5.96"; classtype:trojan-activity; sid:100002480; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.32.122.110"; classtype:trojan-activity; sid:100002481; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.36.174.137"; classtype:trojan-activity; sid:100002482; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.47.102.51"; classtype:trojan-activity; sid:100002483; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.51.174.149"; classtype:trojan-activity; sid:100002484; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.122.86.105"; classtype:trojan-activity; sid:100002485; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.143.227.22"; classtype:trojan-activity; sid:100002486; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.156.215.178"; classtype:trojan-activity; sid:100002487; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.46.197.114"; classtype:trojan-activity; sid:100002488; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.56.197.230"; classtype:trojan-activity; sid:100002489; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.119.74.202"; classtype:trojan-activity; sid:100002490; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.123.206.197"; classtype:trojan-activity; sid:100002491; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.135.178.253"; classtype:trojan-activity; sid:100002492; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.14.173.117"; classtype:trojan-activity; sid:100002493; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.149.182.113"; classtype:trojan-activity; sid:100002494; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.149.190.193"; classtype:trojan-activity; sid:100002495; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.104.12"; classtype:trojan-activity; sid:100002496; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.104.20"; classtype:trojan-activity; sid:100002497; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.104.99"; classtype:trojan-activity; sid:100002498; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.100"; classtype:trojan-activity; sid:100002499; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.199"; classtype:trojan-activity; sid:100002500; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.225"; classtype:trojan-activity; sid:100002501; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.226"; classtype:trojan-activity; sid:100002502; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.237"; classtype:trojan-activity; sid:100002503; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.51"; classtype:trojan-activity; sid:100002504; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.79"; classtype:trojan-activity; sid:100002505; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.114.107"; classtype:trojan-activity; sid:100002506; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.114.36"; classtype:trojan-activity; sid:100002507; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.11"; classtype:trojan-activity; sid:100002508; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.15"; classtype:trojan-activity; sid:100002509; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.26"; classtype:trojan-activity; sid:100002510; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.71"; classtype:trojan-activity; sid:100002511; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.116.149"; classtype:trojan-activity; sid:100002512; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.116.160"; classtype:trojan-activity; sid:100002513; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.116.164"; classtype:trojan-activity; sid:100002514; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.116.203"; classtype:trojan-activity; sid:100002515; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.116.249"; classtype:trojan-activity; sid:100002516; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.116.33"; classtype:trojan-activity; sid:100002517; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.116.85"; classtype:trojan-activity; sid:100002518; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.117.97"; classtype:trojan-activity; sid:100002519; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.118.10"; classtype:trojan-activity; sid:100002520; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.118.144"; classtype:trojan-activity; sid:100002521; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.118.238"; classtype:trojan-activity; sid:100002522; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.119.24"; classtype:trojan-activity; sid:100002523; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.131"; classtype:trojan-activity; sid:100002524; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.243"; classtype:trojan-activity; sid:100002525; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.60"; classtype:trojan-activity; sid:100002526; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.61"; classtype:trojan-activity; sid:100002527; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.7"; classtype:trojan-activity; sid:100002528; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.96"; classtype:trojan-activity; sid:100002529; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.127.178"; classtype:trojan-activity; sid:100002530; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.127.217"; classtype:trojan-activity; sid:100002531; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.127.46"; classtype:trojan-activity; sid:100002532; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.189.178.163"; classtype:trojan-activity; sid:100002533; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.240.218.15"; classtype:trojan-activity; sid:100002534; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.249.156.189"; classtype:trojan-activity; sid:100002535; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.27.8.6"; classtype:trojan-activity; sid:100002536; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.80.44.17"; classtype:trojan-activity; sid:100002537; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.87.87.173"; classtype:trojan-activity; sid:100002538; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.92.254.214"; classtype:trojan-activity; sid:100002539; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.92.254.52"; classtype:trojan-activity; sid:100002540; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.92.255.36"; classtype:trojan-activity; sid:100002541; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.92.255.84"; classtype:trojan-activity; sid:100002542; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.12.93.132"; classtype:trojan-activity; sid:100002543; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.127.185.150"; classtype:trojan-activity; sid:100002544; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.170.240.98"; classtype:trojan-activity; sid:100002545; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.183.54.169"; classtype:trojan-activity; sid:100002546; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.24.72.12"; classtype:trojan-activity; sid:100002547; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.36.12.98"; classtype:trojan-activity; sid:100002548; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"217.11.75.162"; classtype:trojan-activity; sid:100002549; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"217.127.133.214"; classtype:trojan-activity; sid:100002550; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.104.175.64"; classtype:trojan-activity; sid:100002551; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.215.243.65"; classtype:trojan-activity; sid:100002552; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.238.246.3"; classtype:trojan-activity; sid:100002553; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.255.226.166"; classtype:trojan-activity; sid:100002554; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.28.160.174"; classtype:trojan-activity; sid:100002555; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.207.119"; classtype:trojan-activity; sid:100002556; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.227.133"; classtype:trojan-activity; sid:100002557; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.68.35"; classtype:trojan-activity; sid:100002558; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.81.81"; classtype:trojan-activity; sid:100002559; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.48.135.50"; classtype:trojan-activity; sid:100002560; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.56.93.129"; classtype:trojan-activity; sid:100002561; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.57.53.55"; classtype:trojan-activity; sid:100002562; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.58.3.119"; classtype:trojan-activity; sid:100002563; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.58.3.38"; classtype:trojan-activity; sid:100002564; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.59.116.203"; classtype:trojan-activity; sid:100002565; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.72.198.15"; classtype:trojan-activity; sid:100002566; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.72.248.42"; classtype:trojan-activity; sid:100002567; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.79.103.159"; classtype:trojan-activity; sid:100002568; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.104.209"; classtype:trojan-activity; sid:100002569; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.119.145"; classtype:trojan-activity; sid:100002570; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.182.197"; classtype:trojan-activity; sid:100002571; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.102.14"; classtype:trojan-activity; sid:100002572; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.14.17"; classtype:trojan-activity; sid:100002573; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.24.246"; classtype:trojan-activity; sid:100002574; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.26.37"; classtype:trojan-activity; sid:100002575; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.28.41"; classtype:trojan-activity; sid:100002576; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.31.15"; classtype:trojan-activity; sid:100002577; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.31.67"; classtype:trojan-activity; sid:100002578; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.9.202"; classtype:trojan-activity; sid:100002579; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.97.226"; classtype:trojan-activity; sid:100002580; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.156.21.73"; classtype:trojan-activity; sid:100002581; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.139.165"; classtype:trojan-activity; sid:100002582; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.146.200"; classtype:trojan-activity; sid:100002583; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.150.91"; classtype:trojan-activity; sid:100002584; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.162.205"; classtype:trojan-activity; sid:100002585; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.17.8"; classtype:trojan-activity; sid:100002586; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.177.232"; classtype:trojan-activity; sid:100002587; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.178.201"; classtype:trojan-activity; sid:100002588; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.183.29"; classtype:trojan-activity; sid:100002589; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.202.66"; classtype:trojan-activity; sid:100002590; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.215.242"; classtype:trojan-activity; sid:100002591; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.221.133"; classtype:trojan-activity; sid:100002592; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.32.244"; classtype:trojan-activity; sid:100002593; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.64.251"; classtype:trojan-activity; sid:100002594; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.241.6.180"; classtype:trojan-activity; sid:100002595; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.1.148"; classtype:trojan-activity; sid:100002596; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.1.84"; classtype:trojan-activity; sid:100002597; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.163.7"; classtype:trojan-activity; sid:100002598; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.171.144"; classtype:trojan-activity; sid:100002599; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.245.63"; classtype:trojan-activity; sid:100002600; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.251.32"; classtype:trojan-activity; sid:100002601; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.5.140"; classtype:trojan-activity; sid:100002602; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.69.71.186"; classtype:trojan-activity; sid:100002603; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.80.217.209"; classtype:trojan-activity; sid:100002604; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.85.145.194"; classtype:trojan-activity; sid:100002605; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"21robo.com"; classtype:trojan-activity; sid:100002606; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.118.168.155"; classtype:trojan-activity; sid:100002607; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.126.237.74"; classtype:trojan-activity; sid:100002608; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.173.160.53"; classtype:trojan-activity; sid:100002609; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.200.22.163"; classtype:trojan-activity; sid:100002610; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.71.239.115"; classtype:trojan-activity; sid:100002611; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.0.16.221"; classtype:trojan-activity; sid:100002612; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.1.162.82"; classtype:trojan-activity; sid:100002613; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.124.78.15"; classtype:trojan-activity; sid:100002614; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.14.122.127"; classtype:trojan-activity; sid:100002615; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.14.182.157"; classtype:trojan-activity; sid:100002616; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.14.46.33"; classtype:trojan-activity; sid:100002617; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.14.58.84"; classtype:trojan-activity; sid:100002618; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.124.188"; classtype:trojan-activity; sid:100002619; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.153.17"; classtype:trojan-activity; sid:100002620; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.160.67"; classtype:trojan-activity; sid:100002621; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.194.218"; classtype:trojan-activity; sid:100002622; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.199.35"; classtype:trojan-activity; sid:100002623; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.218.173"; classtype:trojan-activity; sid:100002624; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.234.159"; classtype:trojan-activity; sid:100002625; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.234.175"; classtype:trojan-activity; sid:100002626; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.54.237"; classtype:trojan-activity; sid:100002627; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.157.191.178"; classtype:trojan-activity; sid:100002628; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.160.136.213"; classtype:trojan-activity; sid:100002629; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.160.177.104"; classtype:trojan-activity; sid:100002630; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.160.177.107"; classtype:trojan-activity; sid:100002631; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.160.177.224"; classtype:trojan-activity; sid:100002632; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.196.12.96"; classtype:trojan-activity; sid:100002633; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.208.4.71"; classtype:trojan-activity; sid:100002634; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.214.130.147"; classtype:trojan-activity; sid:100002635; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.214.146.73"; classtype:trojan-activity; sid:100002636; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.214.162.109"; classtype:trojan-activity; sid:100002637; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.214.224.184"; classtype:trojan-activity; sid:100002638; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.116.167"; classtype:trojan-activity; sid:100002639; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.184.31"; classtype:trojan-activity; sid:100002640; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.237.220"; classtype:trojan-activity; sid:100002641; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.239.162"; classtype:trojan-activity; sid:100002642; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.252.64"; classtype:trojan-activity; sid:100002643; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.8.64"; classtype:trojan-activity; sid:100002644; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.232.1.82"; classtype:trojan-activity; sid:100002645; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.232.179.70"; classtype:trojan-activity; sid:100002646; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.235.137.36"; classtype:trojan-activity; sid:100002647; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.235.142.206"; classtype:trojan-activity; sid:100002648; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.112.125"; classtype:trojan-activity; sid:100002649; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.32.88"; classtype:trojan-activity; sid:100002650; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.34.43"; classtype:trojan-activity; sid:100002651; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.43.223"; classtype:trojan-activity; sid:100002652; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.68.16"; classtype:trojan-activity; sid:100002653; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.108.17.64"; classtype:trojan-activity; sid:100002654; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.119.65.145"; classtype:trojan-activity; sid:100002655; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.132.125.138"; classtype:trojan-activity; sid:100002656; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.133.102.202"; classtype:trojan-activity; sid:100002657; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.133.103.120"; classtype:trojan-activity; sid:100002658; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.133.105.87"; classtype:trojan-activity; sid:100002659; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.135.113.41"; classtype:trojan-activity; sid:100002660; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.135.219.29"; classtype:trojan-activity; sid:100002661; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.135.26.161"; classtype:trojan-activity; sid:100002662; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.136.21.126"; classtype:trojan-activity; sid:100002663; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.136.218.233"; classtype:trojan-activity; sid:100002664; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.136.231.197"; classtype:trojan-activity; sid:100002665; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.136.49.252"; classtype:trojan-activity; sid:100002666; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.101.251"; classtype:trojan-activity; sid:100002667; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.113.184"; classtype:trojan-activity; sid:100002668; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.120.3"; classtype:trojan-activity; sid:100002669; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.121.127"; classtype:trojan-activity; sid:100002670; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.136.241"; classtype:trojan-activity; sid:100002671; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.137.5"; classtype:trojan-activity; sid:100002672; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.137.94"; classtype:trojan-activity; sid:100002673; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.138.252"; classtype:trojan-activity; sid:100002674; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.139.170"; classtype:trojan-activity; sid:100002675; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.148.192"; classtype:trojan-activity; sid:100002676; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.152.35"; classtype:trojan-activity; sid:100002677; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.172.250"; classtype:trojan-activity; sid:100002678; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.175.242"; classtype:trojan-activity; sid:100002679; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.186.150"; classtype:trojan-activity; sid:100002680; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.221.128"; classtype:trojan-activity; sid:100002681; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.5.150"; classtype:trojan-activity; sid:100002682; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.72.146"; classtype:trojan-activity; sid:100002683; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.8.96"; classtype:trojan-activity; sid:100002684; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.81.67"; classtype:trojan-activity; sid:100002685; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.137.188"; classtype:trojan-activity; sid:100002686; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.143.84"; classtype:trojan-activity; sid:100002687; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.203.22"; classtype:trojan-activity; sid:100002688; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.232.159"; classtype:trojan-activity; sid:100002689; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.96.79"; classtype:trojan-activity; sid:100002690; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.139.59.63"; classtype:trojan-activity; sid:100002691; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.10.235"; classtype:trojan-activity; sid:100002692; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.117.221"; classtype:trojan-activity; sid:100002693; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.161.11"; classtype:trojan-activity; sid:100002694; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.163.112"; classtype:trojan-activity; sid:100002695; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.17.245"; classtype:trojan-activity; sid:100002696; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.209.222"; classtype:trojan-activity; sid:100002697; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.219.212"; classtype:trojan-activity; sid:100002698; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.39.66"; classtype:trojan-activity; sid:100002699; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.120.17"; classtype:trojan-activity; sid:100002700; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.147.104"; classtype:trojan-activity; sid:100002701; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.150.38"; classtype:trojan-activity; sid:100002702; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.40.136"; classtype:trojan-activity; sid:100002703; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.40.2"; classtype:trojan-activity; sid:100002704; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.41.155"; classtype:trojan-activity; sid:100002705; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.45.153"; classtype:trojan-activity; sid:100002706; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.45.255"; classtype:trojan-activity; sid:100002707; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.60.251"; classtype:trojan-activity; sid:100002708; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.85.128"; classtype:trojan-activity; sid:100002709; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.142.162.164"; classtype:trojan-activity; sid:100002710; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.142.192.66"; classtype:trojan-activity; sid:100002711; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.142.209.7"; classtype:trojan-activity; sid:100002712; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.142.65.30"; classtype:trojan-activity; sid:100002713; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.184.129.122"; classtype:trojan-activity; sid:100002714; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.185.116.233"; classtype:trojan-activity; sid:100002715; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.186.20.19"; classtype:trojan-activity; sid:100002716; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.187.9.178"; classtype:trojan-activity; sid:100002717; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.211.72.66"; classtype:trojan-activity; sid:100002718; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.218.220.219"; classtype:trojan-activity; sid:100002719; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.236.85.220"; classtype:trojan-activity; sid:100002720; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.238.230.7"; classtype:trojan-activity; sid:100002721; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.239.83.232"; classtype:trojan-activity; sid:100002722; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.248.64.253"; classtype:trojan-activity; sid:100002723; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.64.16.239"; classtype:trojan-activity; sid:100002724; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.83.150.240"; classtype:trojan-activity; sid:100002725; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.92.9.126"; classtype:trojan-activity; sid:100002726; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.99.171.192"; classtype:trojan-activity; sid:100002727; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.166.117.210"; classtype:trojan-activity; sid:100002728; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.167.118.17"; classtype:trojan-activity; sid:100002729; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.175.121.249"; classtype:trojan-activity; sid:100002730; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.212.225.68"; classtype:trojan-activity; sid:100002731; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.212.234.84"; classtype:trojan-activity; sid:100002732; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.212.252.180"; classtype:trojan-activity; sid:100002733; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.212.5.29"; classtype:trojan-activity; sid:100002734; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.212.57.78"; classtype:trojan-activity; sid:100002735; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.212.73.175"; classtype:trojan-activity; sid:100002736; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.213.164.81"; classtype:trojan-activity; sid:100002737; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.125.186.135"; classtype:trojan-activity; sid:100002738; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.126.120.25"; classtype:trojan-activity; sid:100002739; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.228.143.58"; classtype:trojan-activity; sid:100002740; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.24.213.121"; classtype:trojan-activity; sid:100002741; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.243.149.13"; classtype:trojan-activity; sid:100002742; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.243.21.167"; classtype:trojan-activity; sid:100002743; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.81.246.58"; classtype:trojan-activity; sid:100002744; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.95.89.21"; classtype:trojan-activity; sid:100002745; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.103.74.180"; classtype:trojan-activity; sid:100002746; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.11.141.134"; classtype:trojan-activity; sid:100002747; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.119.158.74"; classtype:trojan-activity; sid:100002748; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.137.147.95"; classtype:trojan-activity; sid:100002749; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.152.235.88"; classtype:trojan-activity; sid:100002750; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.158.25.98"; classtype:trojan-activity; sid:100002751; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.176.206.12"; classtype:trojan-activity; sid:100002752; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.184.1.41"; classtype:trojan-activity; sid:100002753; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.192.191.109"; classtype:trojan-activity; sid:100002754; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.225.114.161"; classtype:trojan-activity; sid:100002755; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.227.190.78"; classtype:trojan-activity; sid:100002756; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.35.245.52"; classtype:trojan-activity; sid:100002757; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.39.181.18"; classtype:trojan-activity; sid:100002758; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.39.34.242"; classtype:trojan-activity; sid:100002759; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.42.229.143"; classtype:trojan-activity; sid:100002760; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.45.4.1"; classtype:trojan-activity; sid:100002761; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.51.91.113"; classtype:trojan-activity; sid:100002762; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.53.163.10"; classtype:trojan-activity; sid:100002763; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.53.163.9"; classtype:trojan-activity; sid:100002764; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.dbstrony.pl"; classtype:trojan-activity; sid:100002765; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.1.245.16"; classtype:trojan-activity; sid:100002766; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.1.245.7"; classtype:trojan-activity; sid:100002767; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.105.106.201"; classtype:trojan-activity; sid:100002768; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.105.152.107"; classtype:trojan-activity; sid:100002769; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.116.84.57"; classtype:trojan-activity; sid:100002770; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.12.245.238"; classtype:trojan-activity; sid:100002771; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.13.83.77"; classtype:trojan-activity; sid:100002772; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.14.211.219"; classtype:trojan-activity; sid:100002773; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.141.218.17"; classtype:trojan-activity; sid:100002774; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.147.29.52"; classtype:trojan-activity; sid:100002775; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.147.40.128"; classtype:trojan-activity; sid:100002776; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.153.132.82"; classtype:trojan-activity; sid:100002777; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.153.207.1"; classtype:trojan-activity; sid:100002778; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.184.244.14"; classtype:trojan-activity; sid:100002779; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.184.54.199"; classtype:trojan-activity; sid:100002780; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.187.248.22"; classtype:trojan-activity; sid:100002781; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.193.196.190"; classtype:trojan-activity; sid:100002782; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.193.217.210"; classtype:trojan-activity; sid:100002783; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.194.149.142"; classtype:trojan-activity; sid:100002784; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.194.158.229"; classtype:trojan-activity; sid:100002785; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.194.166.45"; classtype:trojan-activity; sid:100002786; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.194.192.66"; classtype:trojan-activity; sid:100002787; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.194.210.20"; classtype:trojan-activity; sid:100002788; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.194.224.96"; classtype:trojan-activity; sid:100002789; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.197.17.88"; classtype:trojan-activity; sid:100002790; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.197.22.217"; classtype:trojan-activity; sid:100002791; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.197.23.215"; classtype:trojan-activity; sid:100002792; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.197.24.175"; classtype:trojan-activity; sid:100002793; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.199.232.65"; classtype:trojan-activity; sid:100002794; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.199.3.194"; classtype:trojan-activity; sid:100002795; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.199.34.48"; classtype:trojan-activity; sid:100002796; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.200.140.229"; classtype:trojan-activity; sid:100002797; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.200.23.62"; classtype:trojan-activity; sid:100002798; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.200.32.146"; classtype:trojan-activity; sid:100002799; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.202.182.201"; classtype:trojan-activity; sid:100002800; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.202.21.57"; classtype:trojan-activity; sid:100002801; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.202.66.46"; classtype:trojan-activity; sid:100002802; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.102.12"; classtype:trojan-activity; sid:100002803; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.126.194"; classtype:trojan-activity; sid:100002804; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.154.105"; classtype:trojan-activity; sid:100002805; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.165.138"; classtype:trojan-activity; sid:100002806; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.185.42"; classtype:trojan-activity; sid:100002807; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.185.48"; classtype:trojan-activity; sid:100002808; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.213.79"; classtype:trojan-activity; sid:100002809; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.234.76"; classtype:trojan-activity; sid:100002810; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.246.96"; classtype:trojan-activity; sid:100002811; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.255.42"; classtype:trojan-activity; sid:100002812; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.28.115"; classtype:trojan-activity; sid:100002813; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.4.188"; classtype:trojan-activity; sid:100002814; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.54.217"; classtype:trojan-activity; sid:100002815; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.87.75"; classtype:trojan-activity; sid:100002816; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.94.134"; classtype:trojan-activity; sid:100002817; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.204.253.74"; classtype:trojan-activity; sid:100002818; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.205.178.110"; classtype:trojan-activity; sid:100002819; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.136.101"; classtype:trojan-activity; sid:100002820; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.14.137"; classtype:trojan-activity; sid:100002821; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.148.106"; classtype:trojan-activity; sid:100002822; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.154.122"; classtype:trojan-activity; sid:100002823; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.185.118"; classtype:trojan-activity; sid:100002824; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.26.218"; classtype:trojan-activity; sid:100002825; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.81.66"; classtype:trojan-activity; sid:100002826; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.83.48"; classtype:trojan-activity; sid:100002827; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.97.81"; classtype:trojan-activity; sid:100002828; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.207.155.31"; classtype:trojan-activity; sid:100002829; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.207.194.254"; classtype:trojan-activity; sid:100002830; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.207.199.162"; classtype:trojan-activity; sid:100002831; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.152.10"; classtype:trojan-activity; sid:100002832; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.160.177"; classtype:trojan-activity; sid:100002833; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.164.18"; classtype:trojan-activity; sid:100002834; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.166.13"; classtype:trojan-activity; sid:100002835; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.201.212"; classtype:trojan-activity; sid:100002836; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.247.130"; classtype:trojan-activity; sid:100002837; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.34.2"; classtype:trojan-activity; sid:100002838; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.92.64"; classtype:trojan-activity; sid:100002839; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.209.160.222"; classtype:trojan-activity; sid:100002840; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.209.231.15"; classtype:trojan-activity; sid:100002841; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.209.60.21"; classtype:trojan-activity; sid:100002842; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.21.159.174"; classtype:trojan-activity; sid:100002843; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.107.125"; classtype:trojan-activity; sid:100002844; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.127.11"; classtype:trojan-activity; sid:100002845; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.172.245"; classtype:trojan-activity; sid:100002846; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.234.28"; classtype:trojan-activity; sid:100002847; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.236.134"; classtype:trojan-activity; sid:100002848; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.63.243"; classtype:trojan-activity; sid:100002849; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.211.251.162"; classtype:trojan-activity; sid:100002850; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.104.201"; classtype:trojan-activity; sid:100002851; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.109.105"; classtype:trojan-activity; sid:100002852; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.109.58"; classtype:trojan-activity; sid:100002853; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.175.208"; classtype:trojan-activity; sid:100002854; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.220.5"; classtype:trojan-activity; sid:100002855; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.255.202"; classtype:trojan-activity; sid:100002856; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.255.6"; classtype:trojan-activity; sid:100002857; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.84.74"; classtype:trojan-activity; sid:100002858; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.214.37.129"; classtype:trojan-activity; sid:100002859; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.139.242"; classtype:trojan-activity; sid:100002860; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.190.172"; classtype:trojan-activity; sid:100002861; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.212.209"; classtype:trojan-activity; sid:100002862; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.253.149"; classtype:trojan-activity; sid:100002863; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.34.242"; classtype:trojan-activity; sid:100002864; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.38.166"; classtype:trojan-activity; sid:100002865; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.71.243"; classtype:trojan-activity; sid:100002866; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.98.242"; classtype:trojan-activity; sid:100002867; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.144.66"; classtype:trojan-activity; sid:100002868; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.193.217"; classtype:trojan-activity; sid:100002869; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.197.193"; classtype:trojan-activity; sid:100002870; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.225.28"; classtype:trojan-activity; sid:100002871; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.234.98"; classtype:trojan-activity; sid:100002872; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.46.85"; classtype:trojan-activity; sid:100002873; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.58.120"; classtype:trojan-activity; sid:100002874; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.95.56"; classtype:trojan-activity; sid:100002875; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.217.120.226"; classtype:trojan-activity; sid:100002876; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.217.133.53"; classtype:trojan-activity; sid:100002877; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.217.155.141"; classtype:trojan-activity; sid:100002878; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.217.191.58"; classtype:trojan-activity; sid:100002879; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.217.31.245"; classtype:trojan-activity; sid:100002880; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.217.76.48"; classtype:trojan-activity; sid:100002881; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.218.180.172"; classtype:trojan-activity; sid:100002882; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.218.219.228"; classtype:trojan-activity; sid:100002883; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.218.248.121"; classtype:trojan-activity; sid:100002884; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.132.71"; classtype:trojan-activity; sid:100002885; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.151.83"; classtype:trojan-activity; sid:100002886; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.160.112"; classtype:trojan-activity; sid:100002887; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.172.175"; classtype:trojan-activity; sid:100002888; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.173.180"; classtype:trojan-activity; sid:100002889; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.176.72"; classtype:trojan-activity; sid:100002890; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.184.94"; classtype:trojan-activity; sid:100002891; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.192.223"; classtype:trojan-activity; sid:100002892; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.83.244"; classtype:trojan-activity; sid:100002893; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.220.243.172"; classtype:trojan-activity; sid:100002894; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.220.40.189"; classtype:trojan-activity; sid:100002895; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.220.85.168"; classtype:trojan-activity; sid:100002896; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.221.239.223"; classtype:trojan-activity; sid:100002897; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.222.241.223"; classtype:trojan-activity; sid:100002898; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.222.249.105"; classtype:trojan-activity; sid:100002899; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.222.249.210"; classtype:trojan-activity; sid:100002900; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.222.42.189"; classtype:trojan-activity; sid:100002901; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.222.50.170"; classtype:trojan-activity; sid:100002902; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.223.242.164"; classtype:trojan-activity; sid:100002903; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.223.44.106"; classtype:trojan-activity; sid:100002904; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.24.28.134"; classtype:trojan-activity; sid:100002905; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.127.129"; classtype:trojan-activity; sid:100002906; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.129.198"; classtype:trojan-activity; sid:100002907; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.154.13"; classtype:trojan-activity; sid:100002908; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.2.30"; classtype:trojan-activity; sid:100002909; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.212.124"; classtype:trojan-activity; sid:100002910; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.58.5"; classtype:trojan-activity; sid:100002911; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.36.143.238"; classtype:trojan-activity; sid:100002912; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.41.159.216"; classtype:trojan-activity; sid:100002913; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.41.36.15"; classtype:trojan-activity; sid:100002914; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.41.38.79"; classtype:trojan-activity; sid:100002915; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.46.45.90"; classtype:trojan-activity; sid:100002916; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.5.38.169"; classtype:trojan-activity; sid:100002917; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.5.41.251"; classtype:trojan-activity; sid:100002918; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.5.42.169"; classtype:trojan-activity; sid:100002919; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.6.196.172"; classtype:trojan-activity; sid:100002920; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.0.98.131"; classtype:trojan-activity; sid:100002921; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.11.51.57"; classtype:trojan-activity; sid:100002922; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.13.23.180"; classtype:trojan-activity; sid:100002923; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.154.234.3"; classtype:trojan-activity; sid:100002924; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.124.130"; classtype:trojan-activity; sid:100002925; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.179.83"; classtype:trojan-activity; sid:100002926; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.184.59"; classtype:trojan-activity; sid:100002927; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.191.243"; classtype:trojan-activity; sid:100002928; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.194.67"; classtype:trojan-activity; sid:100002929; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.216.132"; classtype:trojan-activity; sid:100002930; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.219.28"; classtype:trojan-activity; sid:100002931; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.24.115"; classtype:trojan-activity; sid:100002932; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.30.65"; classtype:trojan-activity; sid:100002933; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.60.234"; classtype:trojan-activity; sid:100002934; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.63.203"; classtype:trojan-activity; sid:100002935; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.65.233"; classtype:trojan-activity; sid:100002936; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.94.16"; classtype:trojan-activity; sid:100002937; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.179.201.26"; classtype:trojan-activity; sid:100002938; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.195.84.250"; classtype:trojan-activity; sid:100002939; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.204.174.180"; classtype:trojan-activity; sid:100002940; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.210.20.138"; classtype:trojan-activity; sid:100002941; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.210.20.177"; classtype:trojan-activity; sid:100002942; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.28.7.159"; classtype:trojan-activity; sid:100002943; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.30.119.23"; classtype:trojan-activity; sid:100002944; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"32.208.157.193"; classtype:trojan-activity; sid:100002945; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"32792.prolocksmithwinterpark.com"; classtype:trojan-activity; sid:100002946; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"35.184.169.169"; classtype:trojan-activity; sid:100002947; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.108.231.218"; classtype:trojan-activity; sid:100002948; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.109.132.50"; classtype:trojan-activity; sid:100002949; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.250.203.246"; classtype:trojan-activity; sid:100002950; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.157.225"; classtype:trojan-activity; sid:100002951; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.18.18"; classtype:trojan-activity; sid:100002952; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.19.88"; classtype:trojan-activity; sid:100002953; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.51.244"; classtype:trojan-activity; sid:100002954; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.255.90.219"; classtype:trojan-activity; sid:100002955; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.32.203.118"; classtype:trojan-activity; sid:100002956; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.32.25.158"; classtype:trojan-activity; sid:100002957; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.33.128.60"; classtype:trojan-activity; sid:100002958; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.33.160.167"; classtype:trojan-activity; sid:100002959; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.36.243.67"; classtype:trojan-activity; sid:100002960; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.66.105.159"; classtype:trojan-activity; sid:100002961; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.66.111.203"; classtype:trojan-activity; sid:100002962; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.66.133.125"; classtype:trojan-activity; sid:100002963; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.66.139.36"; classtype:trojan-activity; sid:100002964; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.67.152.161"; classtype:trojan-activity; sid:100002965; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.89.18.133"; classtype:trojan-activity; sid:100002966; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.91.89.187"; classtype:trojan-activity; sid:100002967; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.96.187.93"; classtype:trojan-activity; sid:100002968; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"360.lcy2zzx.pw"; classtype:trojan-activity; sid:100002969; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"360down7.miiyun.cn"; classtype:trojan-activity; sid:100002970; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.222.98.51"; classtype:trojan-activity; sid:100002971; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.233.60.68"; classtype:trojan-activity; sid:100002972; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.34.179.221"; classtype:trojan-activity; sid:100002973; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.34.180.172"; classtype:trojan-activity; sid:100002974; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.44.238.35"; classtype:trojan-activity; sid:100002975; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.49.229.154"; classtype:trojan-activity; sid:100002976; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.49.230.152"; classtype:trojan-activity; sid:100002977; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.52.117.132"; classtype:trojan-activity; sid:100002978; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.54.14.36"; classtype:trojan-activity; sid:100002979; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"38.77.14.237"; classtype:trojan-activity; sid:100002980; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"38.81.149.108"; classtype:trojan-activity; sid:100002981; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.113.245.254"; classtype:trojan-activity; sid:100002982; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.113.98.136"; classtype:trojan-activity; sid:100002983; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.114.137.102"; classtype:trojan-activity; sid:100002984; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.117.31.162"; classtype:trojan-activity; sid:100002985; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.162.104.119"; classtype:trojan-activity; sid:100002986; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.64.28.214"; classtype:trojan-activity; sid:100002987; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.65.171.29"; classtype:trojan-activity; sid:100002988; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.65.196.34"; classtype:trojan-activity; sid:100002989; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.65.59.160"; classtype:trojan-activity; sid:100002990; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.66.129.163"; classtype:trojan-activity; sid:100002991; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.66.85.187"; classtype:trojan-activity; sid:100002992; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.104.83"; classtype:trojan-activity; sid:100002993; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.125.186"; classtype:trojan-activity; sid:100002994; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.146.60"; classtype:trojan-activity; sid:100002995; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.148.163"; classtype:trojan-activity; sid:100002996; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.92.131"; classtype:trojan-activity; sid:100002997; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.68.124.76"; classtype:trojan-activity; sid:100002998; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.68.249.255"; classtype:trojan-activity; sid:100002999; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.72.130.114"; classtype:trojan-activity; sid:100003000; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.72.167.202"; classtype:trojan-activity; sid:100003001; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.72.67.64"; classtype:trojan-activity; sid:100003002; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.10.198"; classtype:trojan-activity; sid:100003003; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.163.231"; classtype:trojan-activity; sid:100003004; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.183.14"; classtype:trojan-activity; sid:100003005; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.203.225"; classtype:trojan-activity; sid:100003006; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.74.104.228"; classtype:trojan-activity; sid:100003007; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.74.21.201"; classtype:trojan-activity; sid:100003008; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.74.28.89"; classtype:trojan-activity; sid:100003009; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.74.31.192"; classtype:trojan-activity; sid:100003010; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.74.68.182"; classtype:trojan-activity; sid:100003011; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.76.194.65"; classtype:trojan-activity; sid:100003012; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.76.79.43"; classtype:trojan-activity; sid:100003013; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.76.97.16"; classtype:trojan-activity; sid:100003014; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.113.201"; classtype:trojan-activity; sid:100003015; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.114.45"; classtype:trojan-activity; sid:100003016; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.136.47"; classtype:trojan-activity; sid:100003017; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.14.27"; classtype:trojan-activity; sid:100003018; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.150.203"; classtype:trojan-activity; sid:100003019; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.197.81"; classtype:trojan-activity; sid:100003020; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.209.209"; classtype:trojan-activity; sid:100003021; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.94.189"; classtype:trojan-activity; sid:100003022; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.95.50"; classtype:trojan-activity; sid:100003023; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.107.66"; classtype:trojan-activity; sid:100003024; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.166.31"; classtype:trojan-activity; sid:100003025; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.218.46"; classtype:trojan-activity; sid:100003026; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.62.43"; classtype:trojan-activity; sid:100003027; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.90.92"; classtype:trojan-activity; sid:100003028; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.91.244"; classtype:trojan-activity; sid:100003029; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.93.171"; classtype:trojan-activity; sid:100003030; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.127.214"; classtype:trojan-activity; sid:100003031; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.188.238"; classtype:trojan-activity; sid:100003032; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.191.137"; classtype:trojan-activity; sid:100003033; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.205.255"; classtype:trojan-activity; sid:100003034; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.24.54"; classtype:trojan-activity; sid:100003035; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.34.26"; classtype:trojan-activity; sid:100003036; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.36.151"; classtype:trojan-activity; sid:100003037; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.124.33"; classtype:trojan-activity; sid:100003038; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.130.19"; classtype:trojan-activity; sid:100003039; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.251.0"; classtype:trojan-activity; sid:100003040; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.27.15"; classtype:trojan-activity; sid:100003041; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.29.231"; classtype:trojan-activity; sid:100003042; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.82.86.105"; classtype:trojan-activity; sid:100003043; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.83.94.11"; classtype:trojan-activity; sid:100003044; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.84.157.52"; classtype:trojan-activity; sid:100003045; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.84.34.217"; classtype:trojan-activity; sid:100003046; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.84.95.200"; classtype:trojan-activity; sid:100003047; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.85.54.191"; classtype:trojan-activity; sid:100003048; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.129.233"; classtype:trojan-activity; sid:100003049; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.13.0"; classtype:trojan-activity; sid:100003050; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.170.209"; classtype:trojan-activity; sid:100003051; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.184.164"; classtype:trojan-activity; sid:100003052; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.211.20"; classtype:trojan-activity; sid:100003053; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.234.187"; classtype:trojan-activity; sid:100003054; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.248.91"; classtype:trojan-activity; sid:100003055; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.60.98"; classtype:trojan-activity; sid:100003056; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.66.24"; classtype:trojan-activity; sid:100003057; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.76.9"; classtype:trojan-activity; sid:100003058; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.78.228"; classtype:trojan-activity; sid:100003059; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.87.63.58"; classtype:trojan-activity; sid:100003060; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.87.93.109"; classtype:trojan-activity; sid:100003061; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.141.172"; classtype:trojan-activity; sid:100003062; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.155.96"; classtype:trojan-activity; sid:100003063; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.233.131"; classtype:trojan-activity; sid:100003064; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.39.222"; classtype:trojan-activity; sid:100003065; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.41.73"; classtype:trojan-activity; sid:100003066; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.67.238"; classtype:trojan-activity; sid:100003067; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.72.9"; classtype:trojan-activity; sid:100003068; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.146.198"; classtype:trojan-activity; sid:100003069; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.146.36"; classtype:trojan-activity; sid:100003070; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.157.140"; classtype:trojan-activity; sid:100003071; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.63.23"; classtype:trojan-activity; sid:100003072; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.90.86.212"; classtype:trojan-activity; sid:100003073; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.139.209.46"; classtype:trojan-activity; sid:100003074; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.165.130.43"; classtype:trojan-activity; sid:100003075; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.190.63.174"; classtype:trojan-activity; sid:100003076; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.193.192.100"; classtype:trojan-activity; sid:100003077; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.219.185.171"; classtype:trojan-activity; sid:100003078; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.230.31.58"; classtype:trojan-activity; sid:100003079; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.72.203.82"; classtype:trojan-activity; sid:100003080; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.76.157.2"; classtype:trojan-activity; sid:100003081; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.18.147"; classtype:trojan-activity; sid:100003082; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.18.148"; classtype:trojan-activity; sid:100003083; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.18.200"; classtype:trojan-activity; sid:100003084; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.18.71"; classtype:trojan-activity; sid:100003085; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.21.35"; classtype:trojan-activity; sid:100003086; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.21.40"; classtype:trojan-activity; sid:100003087; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.5.103"; classtype:trojan-activity; sid:100003088; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.5.104"; classtype:trojan-activity; sid:100003089; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.5.198"; classtype:trojan-activity; sid:100003090; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.5.237"; classtype:trojan-activity; sid:100003091; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.176.112.72"; classtype:trojan-activity; sid:100003092; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.202.101.147"; classtype:trojan-activity; sid:100003093; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.128.210"; classtype:trojan-activity; sid:100003094; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.168.142"; classtype:trojan-activity; sid:100003095; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.168.97"; classtype:trojan-activity; sid:100003096; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.170.140"; classtype:trojan-activity; sid:100003097; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.179.49"; classtype:trojan-activity; sid:100003098; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.181.121"; classtype:trojan-activity; sid:100003099; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.183.11"; classtype:trojan-activity; sid:100003100; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.209.156"; classtype:trojan-activity; sid:100003101; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.212.124"; classtype:trojan-activity; sid:100003102; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.218.16"; classtype:trojan-activity; sid:100003103; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.233.247"; classtype:trojan-activity; sid:100003104; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.235.4"; classtype:trojan-activity; sid:100003105; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.37.186"; classtype:trojan-activity; sid:100003106; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.37.44"; classtype:trojan-activity; sid:100003107; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.43.25"; classtype:trojan-activity; sid:100003108; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.64.34"; classtype:trojan-activity; sid:100003109; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.66.246"; classtype:trojan-activity; sid:100003110; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.70.213"; classtype:trojan-activity; sid:100003111; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.76.168"; classtype:trojan-activity; sid:100003112; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.76.198"; classtype:trojan-activity; sid:100003113; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.8.136"; classtype:trojan-activity; sid:100003114; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.91.8"; classtype:trojan-activity; sid:100003115; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.225.24.101"; classtype:trojan-activity; sid:100003116; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.225.240.244"; classtype:trojan-activity; sid:100003117; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.225.250.39"; classtype:trojan-activity; sid:100003118; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.226.76.62"; classtype:trojan-activity; sid:100003119; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.227.179.209"; classtype:trojan-activity; sid:100003120; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.227.204.4"; classtype:trojan-activity; sid:100003121; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.227.66.88"; classtype:trojan-activity; sid:100003122; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.198.102"; classtype:trojan-activity; sid:100003123; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.60.114"; classtype:trojan-activity; sid:100003124; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.65.201"; classtype:trojan-activity; sid:100003125; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.70.126"; classtype:trojan-activity; sid:100003126; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.70.231"; classtype:trojan-activity; sid:100003127; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.76.135"; classtype:trojan-activity; sid:100003128; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.230.100.114"; classtype:trojan-activity; sid:100003129; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.230.228.78"; classtype:trojan-activity; sid:100003130; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.230.57.145"; classtype:trojan-activity; sid:100003131; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.230.66.255"; classtype:trojan-activity; sid:100003132; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.230.82.44"; classtype:trojan-activity; sid:100003133; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.230.88.107"; classtype:trojan-activity; sid:100003134; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.230.93.169"; classtype:trojan-activity; sid:100003135; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.231.66.174"; classtype:trojan-activity; sid:100003136; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.232.102.163"; classtype:trojan-activity; sid:100003137; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.232.170.117"; classtype:trojan-activity; sid:100003138; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.232.226.16"; classtype:trojan-activity; sid:100003139; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.234.166.242"; classtype:trojan-activity; sid:100003140; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.234.180.136"; classtype:trojan-activity; sid:100003141; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.234.255.20"; classtype:trojan-activity; sid:100003142; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.235.124.55"; classtype:trojan-activity; sid:100003143; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.235.160.215"; classtype:trojan-activity; sid:100003144; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.235.169.85"; classtype:trojan-activity; sid:100003145; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.235.23.163"; classtype:trojan-activity; sid:100003146; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.235.66.249"; classtype:trojan-activity; sid:100003147; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.235.83.180"; classtype:trojan-activity; sid:100003148; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.236.148.201"; classtype:trojan-activity; sid:100003149; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.236.212.174"; classtype:trojan-activity; sid:100003150; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.236.212.83"; classtype:trojan-activity; sid:100003151; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.236.215.63"; classtype:trojan-activity; sid:100003152; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.236.236.179"; classtype:trojan-activity; sid:100003153; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.237.54.162"; classtype:trojan-activity; sid:100003154; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.238.175.61"; classtype:trojan-activity; sid:100003155; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.238.191.210"; classtype:trojan-activity; sid:100003156; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.238.241.239"; classtype:trojan-activity; sid:100003157; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.238.59.222"; classtype:trojan-activity; sid:100003158; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.239.192.128"; classtype:trojan-activity; sid:100003159; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.239.207.166"; classtype:trojan-activity; sid:100003160; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.239.42.135"; classtype:trojan-activity; sid:100003161; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.242.200.90"; classtype:trojan-activity; sid:100003162; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.52.180.36"; classtype:trojan-activity; sid:100003163; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.56.15.227"; classtype:trojan-activity; sid:100003164; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.61.99.155"; classtype:trojan-activity; sid:100003165; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.84.14.5"; classtype:trojan-activity; sid:100003166; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"43.230.156.44"; classtype:trojan-activity; sid:100003167; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"43.230.207.204"; classtype:trojan-activity; sid:100003168; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"43.241.106.183"; classtype:trojan-activity; sid:100003169; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"43.252.8.94"; classtype:trojan-activity; sid:100003170; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.112.203.218"; classtype:trojan-activity; sid:100003171; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.130.138.66"; classtype:trojan-activity; sid:100003172; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.133.1.137"; classtype:trojan-activity; sid:100003173; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.133.1.242"; classtype:trojan-activity; sid:100003174; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.133.203.192"; classtype:trojan-activity; sid:100003175; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.135.134.228"; classtype:trojan-activity; sid:100003176; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.14.149.182"; classtype:trojan-activity; sid:100003177; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.14.149.204"; classtype:trojan-activity; sid:100003178; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.14.149.244"; classtype:trojan-activity; sid:100003179; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.14.149.66"; classtype:trojan-activity; sid:100003180; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.141.84.182"; classtype:trojan-activity; sid:100003181; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.141.84.184"; classtype:trojan-activity; sid:100003182; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.65"; classtype:trojan-activity; sid:100003183; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.148.10.47"; classtype:trojan-activity; sid:100003184; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.15.143.158"; classtype:trojan-activity; sid:100003185; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.164.140.133"; classtype:trojan-activity; sid:100003186; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.165.215.19"; classtype:trojan-activity; sid:100003187; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.108.116"; classtype:trojan-activity; sid:100003188; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.108.248"; classtype:trojan-activity; sid:100003189; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.111.16"; classtype:trojan-activity; sid:100003190; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.178.101.22"; classtype:trojan-activity; sid:100003191; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.201.165.164"; classtype:trojan-activity; sid:100003192; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.22.209.58"; classtype:trojan-activity; sid:100003193; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.23.22.186"; classtype:trojan-activity; sid:100003194; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.27.253.137"; classtype:trojan-activity; sid:100003195; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.33.112.19"; classtype:trojan-activity; sid:100003196; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.51.104.59"; classtype:trojan-activity; sid:100003197; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.81.235.31"; classtype:trojan-activity; sid:100003198; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.9.148.37"; classtype:trojan-activity; sid:100003199; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.151.155.218"; classtype:trojan-activity; sid:100003200; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.172.75.231"; classtype:trojan-activity; sid:100003201; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.175.184.121"; classtype:trojan-activity; sid:100003202; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.182.173.246"; classtype:trojan-activity; sid:100003203; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.182.173.247"; classtype:trojan-activity; sid:100003204; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.20.63.218"; classtype:trojan-activity; sid:100003205; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.201.214.64"; classtype:trojan-activity; sid:100003206; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.201.38.162"; classtype:trojan-activity; sid:100003207; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.21.153.231"; classtype:trojan-activity; sid:100003208; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.214.27.4"; classtype:trojan-activity; sid:100003209; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.24.130.254"; classtype:trojan-activity; sid:100003210; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.243.179.115"; classtype:trojan-activity; sid:100003211; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.249.33.79"; classtype:trojan-activity; sid:100003212; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.25.242.211"; classtype:trojan-activity; sid:100003213; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.42.118.86"; classtype:trojan-activity; sid:100003214; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.42.86.128"; classtype:trojan-activity; sid:100003215; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.97.76.242"; classtype:trojan-activity; sid:100003216; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.145.152.26"; classtype:trojan-activity; sid:100003217; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.151.23.172"; classtype:trojan-activity; sid:100003218; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.157.97.71"; classtype:trojan-activity; sid:100003219; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.16.131.51"; classtype:trojan-activity; sid:100003220; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.197.0.119"; classtype:trojan-activity; sid:100003221; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.21.202.98"; classtype:trojan-activity; sid:100003222; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.223.167.153"; classtype:trojan-activity; sid:100003223; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.46.231.38"; classtype:trojan-activity; sid:100003224; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.142.162.113"; classtype:trojan-activity; sid:100003225; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.142.87.36"; classtype:trojan-activity; sid:100003226; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.143.43.93"; classtype:trojan-activity; sid:100003227; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.156.35.166"; classtype:trojan-activity; sid:100003228; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.158.201.200"; classtype:trojan-activity; sid:100003229; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.159.20.121"; classtype:trojan-activity; sid:100003230; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.159.21.3"; classtype:trojan-activity; sid:100003231; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.174.182.99"; classtype:trojan-activity; sid:100003232; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.213.170.49"; classtype:trojan-activity; sid:100003233; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.213.178.183"; classtype:trojan-activity; sid:100003234; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.213.179.129"; classtype:trojan-activity; sid:100003235; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.68.221.252"; classtype:trojan-activity; sid:100003236; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.68.249.121"; classtype:trojan-activity; sid:100003237; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.70.15.16"; classtype:trojan-activity; sid:100003238; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.70.2.100"; classtype:trojan-activity; sid:100003239; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.181.135.114"; classtype:trojan-activity; sid:100003240; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.2.70.50"; classtype:trojan-activity; sid:100003241; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.53.146.179"; classtype:trojan-activity; sid:100003242; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.8.10.62"; classtype:trojan-activity; sid:100003243; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.115.174.102"; classtype:trojan-activity; sid:100003244; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.121.91.255"; classtype:trojan-activity; sid:100003245; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.252.47.29"; classtype:trojan-activity; sid:100003246; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"51.171.146.13"; classtype:trojan-activity; sid:100003247; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"51.222.56.159"; classtype:trojan-activity; sid:100003248; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"54.253.194.14"; classtype:trojan-activity; sid:100003249; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"54.36.114.136"; classtype:trojan-activity; sid:100003250; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"54.36.180.122"; classtype:trojan-activity; sid:100003251; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"54.37.93.29"; classtype:trojan-activity; sid:100003252; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.114.246.26"; classtype:trojan-activity; sid:100003253; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.115.162.92"; classtype:trojan-activity; sid:100003254; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.115.174.4"; classtype:trojan-activity; sid:100003255; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.125.191.4"; classtype:trojan-activity; sid:100003256; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.126.247.118"; classtype:trojan-activity; sid:100003257; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.142.166.120"; classtype:trojan-activity; sid:100003258; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.142.200.124"; classtype:trojan-activity; sid:100003259; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.143.142.142"; classtype:trojan-activity; sid:100003260; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.18.103.109"; classtype:trojan-activity; sid:100003261; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.217.171.157"; classtype:trojan-activity; sid:100003262; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.218.67.253"; classtype:trojan-activity; sid:100003263; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.22.212.107"; classtype:trojan-activity; sid:100003264; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.226.129.29"; classtype:trojan-activity; sid:100003265; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.229.194.122"; classtype:trojan-activity; sid:100003266; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.23.245.24"; classtype:trojan-activity; sid:100003267; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.230.89.42"; classtype:trojan-activity; sid:100003268; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.232.155.37"; classtype:trojan-activity; sid:100003269; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.238.42.192"; classtype:trojan-activity; sid:100003270; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.240.147.97"; classtype:trojan-activity; sid:100003271; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.241.57.237"; classtype:trojan-activity; sid:100003272; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.241.78.55"; classtype:trojan-activity; sid:100003273; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.112.16"; classtype:trojan-activity; sid:100003274; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.116.2"; classtype:trojan-activity; sid:100003275; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.117.188"; classtype:trojan-activity; sid:100003276; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.140.132"; classtype:trojan-activity; sid:100003277; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.142.137"; classtype:trojan-activity; sid:100003278; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.142.174"; classtype:trojan-activity; sid:100003279; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.149.117"; classtype:trojan-activity; sid:100003280; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.150.204"; classtype:trojan-activity; sid:100003281; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.150.244"; classtype:trojan-activity; sid:100003282; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.153.194"; classtype:trojan-activity; sid:100003283; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.154.55"; classtype:trojan-activity; sid:100003284; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.154.66"; classtype:trojan-activity; sid:100003285; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.76.206"; classtype:trojan-activity; sid:100003286; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.79.25"; classtype:trojan-activity; sid:100003287; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.15.148"; classtype:trojan-activity; sid:100003288; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.18.244"; classtype:trojan-activity; sid:100003289; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.22.210"; classtype:trojan-activity; sid:100003290; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.72.121"; classtype:trojan-activity; sid:100003291; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.74.124"; classtype:trojan-activity; sid:100003292; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.74.248"; classtype:trojan-activity; sid:100003293; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.77.227"; classtype:trojan-activity; sid:100003294; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.79.134"; classtype:trojan-activity; sid:100003295; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.80.23"; classtype:trojan-activity; sid:100003296; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.86.85"; classtype:trojan-activity; sid:100003297; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.88.207"; classtype:trojan-activity; sid:100003298; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.252.177.212"; classtype:trojan-activity; sid:100003299; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.252.177.66"; classtype:trojan-activity; sid:100003300; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.252.178.167"; classtype:trojan-activity; sid:100003301; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.252.178.55"; classtype:trojan-activity; sid:100003302; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.253.14.46"; classtype:trojan-activity; sid:100003303; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.255.140.156"; classtype:trojan-activity; sid:100003304; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.255.43.163"; classtype:trojan-activity; sid:100003305; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.48.154.143"; classtype:trojan-activity; sid:100003306; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.50.178.137"; classtype:trojan-activity; sid:100003307; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.50.221.148"; classtype:trojan-activity; sid:100003308; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.72.165.153"; classtype:trojan-activity; sid:100003309; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.72.165.39"; classtype:trojan-activity; sid:100003310; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.76.151.51"; classtype:trojan-activity; sid:100003311; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.97.201.45"; classtype:trojan-activity; sid:100003312; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.97.206.33"; classtype:trojan-activity; sid:100003313; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.0.211.161"; classtype:trojan-activity; sid:100003314; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.102.168.189"; classtype:trojan-activity; sid:100003315; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.151.202.3"; classtype:trojan-activity; sid:100003316; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.151.214.4"; classtype:trojan-activity; sid:100003317; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.151.237.51"; classtype:trojan-activity; sid:100003318; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.151.246.125"; classtype:trojan-activity; sid:100003319; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.29.133.229"; classtype:trojan-activity; sid:100003320; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.30.12.254"; classtype:trojan-activity; sid:100003321; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.58.104.244"; classtype:trojan-activity; sid:100003322; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.58.117.226"; classtype:trojan-activity; sid:100003323; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.7.124.148"; classtype:trojan-activity; sid:100003324; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.8.35.22"; classtype:trojan-activity; sid:100003325; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.89.243.76"; classtype:trojan-activity; sid:100003326; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.92.176.136"; classtype:trojan-activity; sid:100003327; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.92.178.202"; classtype:trojan-activity; sid:100003328; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.92.18.175"; classtype:trojan-activity; sid:100003329; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.92.182.177"; classtype:trojan-activity; sid:100003330; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.92.216.255"; classtype:trojan-activity; sid:100003331; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.93.17.196"; classtype:trojan-activity; sid:100003332; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.93.17.204"; classtype:trojan-activity; sid:100003333; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.93.17.72"; classtype:trojan-activity; sid:100003334; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.93.19.11"; classtype:trojan-activity; sid:100003335; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.93.23.154"; classtype:trojan-activity; sid:100003336; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.93.23.215"; classtype:trojan-activity; sid:100003337; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.93.23.23"; classtype:trojan-activity; sid:100003338; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.93.23.7"; classtype:trojan-activity; sid:100003339; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.94.180.237"; classtype:trojan-activity; sid:100003340; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.96.36.131"; classtype:trojan-activity; sid:100003341; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.96.36.137"; classtype:trojan-activity; sid:100003342; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.96.39.91"; classtype:trojan-activity; sid:100003343; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.97.168.110"; classtype:trojan-activity; sid:100003344; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.97.170.16"; classtype:trojan-activity; sid:100003345; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.97.175.101"; classtype:trojan-activity; sid:100003346; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.97.175.96"; classtype:trojan-activity; sid:100003347; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.97.193.118"; classtype:trojan-activity; sid:100003348; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.99.137.46"; classtype:trojan-activity; sid:100003349; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.99.138.222"; classtype:trojan-activity; sid:100003350; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.99.139.252"; classtype:trojan-activity; sid:100003351; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.99.139.66"; classtype:trojan-activity; sid:100003352; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.99.141.103"; classtype:trojan-activity; sid:100003353; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.99.141.219"; classtype:trojan-activity; sid:100003354; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.99.142.43"; classtype:trojan-activity; sid:100003355; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.99.188.93"; classtype:trojan-activity; sid:100003356; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.99.41.26"; classtype:trojan-activity; sid:100003357; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.99.43.225"; classtype:trojan-activity; sid:100003358; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.99.46.7"; classtype:trojan-activity; sid:100003359; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.99.47.64"; classtype:trojan-activity; sid:100003360; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.13.61.12"; classtype:trojan-activity; sid:100003361; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.14.48.221"; classtype:trojan-activity; sid:100003362; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.162.122.36"; classtype:trojan-activity; sid:100003363; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.162.160.200"; classtype:trojan-activity; sid:100003364; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.164.130.220"; classtype:trojan-activity; sid:100003365; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.17.12.143"; classtype:trojan-activity; sid:100003366; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.176.249.56"; classtype:trojan-activity; sid:100003367; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.20.217.142"; classtype:trojan-activity; sid:100003368; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.208.135.42"; classtype:trojan-activity; sid:100003369; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.122.57"; classtype:trojan-activity; sid:100003370; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.186.185"; classtype:trojan-activity; sid:100003371; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.216.23"; classtype:trojan-activity; sid:100003372; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.33.5"; classtype:trojan-activity; sid:100003373; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.211.19.63"; classtype:trojan-activity; sid:100003374; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.211.6.112"; classtype:trojan-activity; sid:100003375; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.211.7.166"; classtype:trojan-activity; sid:100003376; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.100.83"; classtype:trojan-activity; sid:100003377; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.162.152"; classtype:trojan-activity; sid:100003378; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.206.246"; classtype:trojan-activity; sid:100003379; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.218.31"; classtype:trojan-activity; sid:100003380; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.220.167"; classtype:trojan-activity; sid:100003381; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.23.84"; classtype:trojan-activity; sid:100003382; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.254.178"; classtype:trojan-activity; sid:100003383; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.213.162.59"; classtype:trojan-activity; sid:100003384; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.213.58.188"; classtype:trojan-activity; sid:100003385; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.213.83.55"; classtype:trojan-activity; sid:100003386; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.214.93.166"; classtype:trojan-activity; sid:100003387; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.215.165.64"; classtype:trojan-activity; sid:100003388; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.215.195.111"; classtype:trojan-activity; sid:100003389; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.215.207.11"; classtype:trojan-activity; sid:100003390; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.215.219.108"; classtype:trojan-activity; sid:100003391; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.215.4.239"; classtype:trojan-activity; sid:100003392; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.216.95.211"; classtype:trojan-activity; sid:100003393; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.217.177.196"; classtype:trojan-activity; sid:100003394; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.217.86.208"; classtype:trojan-activity; sid:100003395; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.220.22.89"; classtype:trojan-activity; sid:100003396; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.25.115.48"; classtype:trojan-activity; sid:100003397; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.25.76.224"; classtype:trojan-activity; sid:100003398; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.15.104"; classtype:trojan-activity; sid:100003399; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.39.88"; classtype:trojan-activity; sid:100003400; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.42.72"; classtype:trojan-activity; sid:100003401; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.44.99"; classtype:trojan-activity; sid:100003402; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.51.127"; classtype:trojan-activity; sid:100003403; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.60.174"; classtype:trojan-activity; sid:100003404; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.8.81"; classtype:trojan-activity; sid:100003405; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.7.10.121"; classtype:trojan-activity; sid:100003406; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.7.136.8"; classtype:trojan-activity; sid:100003407; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.7.202.153"; classtype:trojan-activity; sid:100003408; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.7.99.254"; classtype:trojan-activity; sid:100003409; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.102.243.124"; classtype:trojan-activity; sid:100003410; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.162.169.210"; classtype:trojan-activity; sid:100003411; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.162.55.42"; classtype:trojan-activity; sid:100003412; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.163.129.97"; classtype:trojan-activity; sid:100003413; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.164.96.98"; classtype:trojan-activity; sid:100003414; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.167.211.218"; classtype:trojan-activity; sid:100003415; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.168.139.87"; classtype:trojan-activity; sid:100003416; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.179.171.60"; classtype:trojan-activity; sid:100003417; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.179.91.194"; classtype:trojan-activity; sid:100003418; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.179.91.230"; classtype:trojan-activity; sid:100003419; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.179.93.79"; classtype:trojan-activity; sid:100003420; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.18.112.48"; classtype:trojan-activity; sid:100003421; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.192.73.253"; classtype:trojan-activity; sid:100003422; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.213.118.28"; classtype:trojan-activity; sid:100003423; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.247.224.66"; classtype:trojan-activity; sid:100003424; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.253.94.230"; classtype:trojan-activity; sid:100003425; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.3.126.128"; classtype:trojan-activity; sid:100003426; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.3.144.90"; classtype:trojan-activity; sid:100003427; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.3.147.175"; classtype:trojan-activity; sid:100003428; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.47.220.169"; classtype:trojan-activity; sid:100003429; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.102.61"; classtype:trojan-activity; sid:100003430; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.103.144"; classtype:trojan-activity; sid:100003431; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.11.87"; classtype:trojan-activity; sid:100003432; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.157.4"; classtype:trojan-activity; sid:100003433; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.159.231"; classtype:trojan-activity; sid:100003434; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.195.226"; classtype:trojan-activity; sid:100003435; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.212.191"; classtype:trojan-activity; sid:100003436; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.243.169"; classtype:trojan-activity; sid:100003437; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.247.208"; classtype:trojan-activity; sid:100003438; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.30.49"; classtype:trojan-activity; sid:100003439; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.35.86"; classtype:trojan-activity; sid:100003440; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.43.174"; classtype:trojan-activity; sid:100003441; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.48.112"; classtype:trojan-activity; sid:100003442; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.9.166"; classtype:trojan-activity; sid:100003443; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.97.134"; classtype:trojan-activity; sid:100003444; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.99.183"; classtype:trojan-activity; sid:100003445; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.100.87"; classtype:trojan-activity; sid:100003446; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.121.19"; classtype:trojan-activity; sid:100003447; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.251.243"; classtype:trojan-activity; sid:100003448; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.62.169"; classtype:trojan-activity; sid:100003449; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.73.171"; classtype:trojan-activity; sid:100003450; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.74.27"; classtype:trojan-activity; sid:100003451; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.81.18"; classtype:trojan-activity; sid:100003452; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.83.14"; classtype:trojan-activity; sid:100003453; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.86.195"; classtype:trojan-activity; sid:100003454; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.172.248"; classtype:trojan-activity; sid:100003455; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.41.143"; classtype:trojan-activity; sid:100003456; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.64.104"; classtype:trojan-activity; sid:100003457; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.77.175"; classtype:trojan-activity; sid:100003458; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.56.180.67"; classtype:trojan-activity; sid:100003459; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.56.181.7"; classtype:trojan-activity; sid:100003460; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.57.96.116"; classtype:trojan-activity; sid:100003461; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.58.170.60"; classtype:trojan-activity; sid:100003462; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.58.73.220"; classtype:trojan-activity; sid:100003463; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.61.218.23"; classtype:trojan-activity; sid:100003464; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.65.172.121"; classtype:trojan-activity; sid:100003465; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.0.22"; classtype:trojan-activity; sid:100003466; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.104.46"; classtype:trojan-activity; sid:100003467; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.110.59"; classtype:trojan-activity; sid:100003468; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.132.195"; classtype:trojan-activity; sid:100003469; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.132.86"; classtype:trojan-activity; sid:100003470; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.255.60"; classtype:trojan-activity; sid:100003471; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.45.130"; classtype:trojan-activity; sid:100003472; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.98.144.75"; classtype:trojan-activity; sid:100003473; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.1.98.131"; classtype:trojan-activity; sid:100003474; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.117.124.114"; classtype:trojan-activity; sid:100003475; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.141.73.58"; classtype:trojan-activity; sid:100003476; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.219.131.205"; classtype:trojan-activity; sid:100003477; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.219.143.46"; classtype:trojan-activity; sid:100003478; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.219.227.31"; classtype:trojan-activity; sid:100003479; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.31.126.33"; classtype:trojan-activity; sid:100003480; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.38.149.66"; classtype:trojan-activity; sid:100003481; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.38.222.98"; classtype:trojan-activity; sid:100003482; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.43.207.148"; classtype:trojan-activity; sid:100003483; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.90.165.236"; classtype:trojan-activity; sid:100003484; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"63.245.122.93"; classtype:trojan-activity; sid:100003485; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"64.233.154.99"; classtype:trojan-activity; sid:100003486; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.125.128.196"; classtype:trojan-activity; sid:100003487; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.21.58.252"; classtype:trojan-activity; sid:100003488; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.26.155.131"; classtype:trojan-activity; sid:100003489; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.35.61.255"; classtype:trojan-activity; sid:100003490; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.153.233.87"; classtype:trojan-activity; sid:100003491; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.207.93.46"; classtype:trojan-activity; sid:100003492; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.229.214.115"; classtype:trojan-activity; sid:100003493; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.57.55.210"; classtype:trojan-activity; sid:100003494; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.74.7.197"; classtype:trojan-activity; sid:100003495; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.91.21.31"; classtype:trojan-activity; sid:100003496; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.97.181.196"; classtype:trojan-activity; sid:100003497; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.97.181.213"; classtype:trojan-activity; sid:100003498; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.221.107.75"; classtype:trojan-activity; sid:100003499; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.245.151.203"; classtype:trojan-activity; sid:100003500; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.3.169.223"; classtype:trojan-activity; sid:100003501; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.8.138.101"; classtype:trojan-activity; sid:100003502; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.81.98.111"; classtype:trojan-activity; sid:100003503; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.82.242.243"; classtype:trojan-activity; sid:100003504; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.83.49.234"; classtype:trojan-activity; sid:100003505; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.84.138.165"; classtype:trojan-activity; sid:100003506; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.148.103.248"; classtype:trojan-activity; sid:100003507; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.151.244.128"; classtype:trojan-activity; sid:100003508; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.174.182.226"; classtype:trojan-activity; sid:100003509; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.175.107.153"; classtype:trojan-activity; sid:100003510; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.188.144.143"; classtype:trojan-activity; sid:100003511; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.204.88.29"; classtype:trojan-activity; sid:100003512; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.205.106.84"; classtype:trojan-activity; sid:100003513; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.205.119.241"; classtype:trojan-activity; sid:100003514; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.78.33.33"; classtype:trojan-activity; sid:100003515; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.115.37.205"; classtype:trojan-activity; sid:100003516; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.120.237.255"; classtype:trojan-activity; sid:100003517; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.123.245.151"; classtype:trojan-activity; sid:100003518; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.124.231.110"; classtype:trojan-activity; sid:100003519; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.127.214.47"; classtype:trojan-activity; sid:100003520; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.146.232.34"; classtype:trojan-activity; sid:100003521; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.165.173.49"; classtype:trojan-activity; sid:100003522; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.196.158.227"; classtype:trojan-activity; sid:100003523; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.222.157.166"; classtype:trojan-activity; sid:100003524; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.229.0.133"; classtype:trojan-activity; sid:100003525; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.63.73.234"; classtype:trojan-activity; sid:100003526; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.75.115.194"; classtype:trojan-activity; sid:100003527; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.75.227.186"; classtype:trojan-activity; sid:100003528; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.76.240.206"; classtype:trojan-activity; sid:100003529; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.115.31.30"; classtype:trojan-activity; sid:100003530; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.118.240.88"; classtype:trojan-activity; sid:100003531; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.167.10.180"; classtype:trojan-activity; sid:100003532; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.236.190.250"; classtype:trojan-activity; sid:100003533; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.25.5.105"; classtype:trojan-activity; sid:100003534; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.33.144.248"; classtype:trojan-activity; sid:100003535; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.93.129.118"; classtype:trojan-activity; sid:100003536; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.127.148.69"; classtype:trojan-activity; sid:100003537; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.146.190.91"; classtype:trojan-activity; sid:100003538; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.204.63.239"; classtype:trojan-activity; sid:100003539; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.29.48.164"; classtype:trojan-activity; sid:100003540; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.34.191.213"; classtype:trojan-activity; sid:100003541; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.40.234.166"; classtype:trojan-activity; sid:100003542; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.43.2.122"; classtype:trojan-activity; sid:100003543; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.43.235.106"; classtype:trojan-activity; sid:100003544; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.47.133.58"; classtype:trojan-activity; sid:100003545; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.71.60.69"; classtype:trojan-activity; sid:100003546; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.85.106.211"; classtype:trojan-activity; sid:100003547; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.17.22.30"; classtype:trojan-activity; sid:100003548; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.186.139.38"; classtype:trojan-activity; sid:100003549; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.189.180.98"; classtype:trojan-activity; sid:100003550; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.214.69.226"; classtype:trojan-activity; sid:100003551; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.229.230.118"; classtype:trojan-activity; sid:100003552; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.229.35.40"; classtype:trojan-activity; sid:100003553; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.31.40.122"; classtype:trojan-activity; sid:100003554; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"73.204.216.103"; classtype:trojan-activity; sid:100003555; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.101.1.159"; classtype:trojan-activity; sid:100003556; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.108.224.112"; classtype:trojan-activity; sid:100003557; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.194.117.165"; classtype:trojan-activity; sid:100003558; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.195.115.176"; classtype:trojan-activity; sid:100003559; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.199.84.77"; classtype:trojan-activity; sid:100003560; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.75.165.81"; classtype:trojan-activity; sid:100003561; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"75.127.141.52"; classtype:trojan-activity; sid:100003562; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"75.176.213.114"; classtype:trojan-activity; sid:100003563; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"75.82.36.220"; classtype:trojan-activity; sid:100003564; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"75.83.102.27"; classtype:trojan-activity; sid:100003565; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"75.99.213.61"; classtype:trojan-activity; sid:100003566; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.108.199.153"; classtype:trojan-activity; sid:100003567; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.170.11.82"; classtype:trojan-activity; sid:100003568; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.178.22.145"; classtype:trojan-activity; sid:100003569; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.250.199.133"; classtype:trojan-activity; sid:100003570; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.254.129.227"; classtype:trojan-activity; sid:100003571; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.84.134.33"; classtype:trojan-activity; sid:100003572; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.95.12.137"; classtype:trojan-activity; sid:100003573; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.237.25.210"; classtype:trojan-activity; sid:100003574; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.71.50.153"; classtype:trojan-activity; sid:100003575; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.71.52.220"; classtype:trojan-activity; sid:100003576; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.79.191.32"; classtype:trojan-activity; sid:100003577; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.89.203.238"; classtype:trojan-activity; sid:100003578; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.179.225.254"; classtype:trojan-activity; sid:100003579; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.187.141.144"; classtype:trojan-activity; sid:100003580; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.187.240.125"; classtype:trojan-activity; sid:100003581; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.187.41.200"; classtype:trojan-activity; sid:100003582; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.188.168.64"; classtype:trojan-activity; sid:100003583; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.188.188.141"; classtype:trojan-activity; sid:100003584; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.189.104.157"; classtype:trojan-activity; sid:100003585; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.189.176.163"; classtype:trojan-activity; sid:100003586; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.23.172.81"; classtype:trojan-activity; sid:100003587; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.72.231.120"; classtype:trojan-activity; sid:100003588; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.8.225.77"; classtype:trojan-activity; sid:100003589; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.11.195.121"; classtype:trojan-activity; sid:100003590; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.13.49.221"; classtype:trojan-activity; sid:100003591; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.130.253.13"; classtype:trojan-activity; sid:100003592; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.147.123.48"; classtype:trojan-activity; sid:100003593; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.170.31.56"; classtype:trojan-activity; sid:100003594; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.175.42.244"; classtype:trojan-activity; sid:100003595; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.21.84.63"; classtype:trojan-activity; sid:100003596; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.22.176.145"; classtype:trojan-activity; sid:100003597; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.7.170.58"; classtype:trojan-activity; sid:100003598; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.79.58.94"; classtype:trojan-activity; sid:100003599; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.8.70.162"; classtype:trojan-activity; sid:100003600; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.9.88.185"; classtype:trojan-activity; sid:100003601; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.107.89.207"; classtype:trojan-activity; sid:100003602; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.19.101.218"; classtype:trojan-activity; sid:100003603; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.211.181.77"; classtype:trojan-activity; sid:100003604; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.217.12.7"; classtype:trojan-activity; sid:100003605; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.99.128.61"; classtype:trojan-activity; sid:100003606; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.136.146.213"; classtype:trojan-activity; sid:100003607; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.165.44.109"; classtype:trojan-activity; sid:100003608; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.191.40.58"; classtype:trojan-activity; sid:100003609; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.198.7.22"; classtype:trojan-activity; sid:100003610; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.213.111.60"; classtype:trojan-activity; sid:100003611; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.213.141.184"; classtype:trojan-activity; sid:100003612; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.213.166.175"; classtype:trojan-activity; sid:100003613; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.215.199.29"; classtype:trojan-activity; sid:100003614; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.218.187.113"; classtype:trojan-activity; sid:100003615; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.218.195.216"; classtype:trojan-activity; sid:100003616; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.237.128.200"; classtype:trojan-activity; sid:100003617; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.246.225.203"; classtype:trojan-activity; sid:100003618; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.92.36.96"; classtype:trojan-activity; sid:100003619; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.103.108.72"; classtype:trojan-activity; sid:100003620; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.135.196.130"; classtype:trojan-activity; sid:100003621; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.166.212.178"; classtype:trojan-activity; sid:100003622; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.166.85.112"; classtype:trojan-activity; sid:100003623; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.207.61.194"; classtype:trojan-activity; sid:100003624; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.209.250.155"; classtype:trojan-activity; sid:100003625; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.211.156.38"; classtype:trojan-activity; sid:100003626; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.62.110.252"; classtype:trojan-activity; sid:100003627; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.62.53.77"; classtype:trojan-activity; sid:100003628; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.138.72"; classtype:trojan-activity; sid:100003629; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.139.92"; classtype:trojan-activity; sid:100003630; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.154.214"; classtype:trojan-activity; sid:100003631; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.187.109"; classtype:trojan-activity; sid:100003632; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.100.54"; classtype:trojan-activity; sid:100003633; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.106.65"; classtype:trojan-activity; sid:100003634; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.108.172"; classtype:trojan-activity; sid:100003635; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.131.158"; classtype:trojan-activity; sid:100003636; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.19.42"; classtype:trojan-activity; sid:100003637; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.197.254"; classtype:trojan-activity; sid:100003638; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.215.149"; classtype:trojan-activity; sid:100003639; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.232.68"; classtype:trojan-activity; sid:100003640; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.234.195"; classtype:trojan-activity; sid:100003641; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.246.96"; classtype:trojan-activity; sid:100003642; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.28.57"; classtype:trojan-activity; sid:100003643; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.4.57"; classtype:trojan-activity; sid:100003644; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.55.84"; classtype:trojan-activity; sid:100003645; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.73.245"; classtype:trojan-activity; sid:100003646; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.9.62"; classtype:trojan-activity; sid:100003647; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.98.51"; classtype:trojan-activity; sid:100003648; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.165.237.163"; classtype:trojan-activity; sid:100003649; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.234.147.99"; classtype:trojan-activity; sid:100003650; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.234.218.42"; classtype:trojan-activity; sid:100003651; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.242.253.154"; classtype:trojan-activity; sid:100003652; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.252.9.37"; classtype:trojan-activity; sid:100003653; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.210.219.208"; classtype:trojan-activity; sid:100003654; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.210.219.213"; classtype:trojan-activity; sid:100003655; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.212.219.127"; classtype:trojan-activity; sid:100003656; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.214.103.73"; classtype:trojan-activity; sid:100003657; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.228.50.118"; classtype:trojan-activity; sid:100003658; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.228.95.204"; classtype:trojan-activity; sid:100003659; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.238.24.35"; classtype:trojan-activity; sid:100003660; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.247.83.74"; classtype:trojan-activity; sid:100003661; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.254.39.129"; classtype:trojan-activity; sid:100003662; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.33.111.227"; classtype:trojan-activity; sid:100003663; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.38.152.148"; classtype:trojan-activity; sid:100003664; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.40.127.242"; classtype:trojan-activity; sid:100003665; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.42.20.217"; classtype:trojan-activity; sid:100003666; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com"; classtype:trojan-activity; sid:100003667; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.11.216"; classtype:trojan-activity; sid:100003668; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.123.251"; classtype:trojan-activity; sid:100003669; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.135.187"; classtype:trojan-activity; sid:100003670; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.208.25"; classtype:trojan-activity; sid:100003671; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.224.141"; classtype:trojan-activity; sid:100003672; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.241.2"; classtype:trojan-activity; sid:100003673; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.214.149.236"; classtype:trojan-activity; sid:100003674; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.64.181.50"; classtype:trojan-activity; sid:100003675; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.74.215.180"; classtype:trojan-activity; sid:100003676; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.97.130.227"; classtype:trojan-activity; sid:100003677; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.97.195.129"; classtype:trojan-activity; sid:100003678; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.98.40.5"; classtype:trojan-activity; sid:100003679; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"86.35.43.220"; classtype:trojan-activity; sid:100003680; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"87.121.98.51"; classtype:trojan-activity; sid:100003681; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"87.61.89.40"; classtype:trojan-activity; sid:100003682; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.119.171.253"; classtype:trojan-activity; sid:100003683; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.2.208.71"; classtype:trojan-activity; sid:100003684; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.2.219.179"; classtype:trojan-activity; sid:100003685; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.225.222.128"; classtype:trojan-activity; sid:100003686; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.247.96.19"; classtype:trojan-activity; sid:100003687; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.248.136.231"; classtype:trojan-activity; sid:100003688; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.248.51.139"; classtype:trojan-activity; sid:100003689; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.249.244.180"; classtype:trojan-activity; sid:100003690; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.250.204.12"; classtype:trojan-activity; sid:100003691; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.250.226.26"; classtype:trojan-activity; sid:100003692; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.250.254.90"; classtype:trojan-activity; sid:100003693; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.37.171.141"; classtype:trojan-activity; sid:100003694; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.122.183.130"; classtype:trojan-activity; sid:100003695; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.136.197.170"; classtype:trojan-activity; sid:100003696; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.29.213.33"; classtype:trojan-activity; sid:100003697; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.35.62.96"; classtype:trojan-activity; sid:100003698; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.40.85.166"; classtype:trojan-activity; sid:100003699; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.40.87.5"; classtype:trojan-activity; sid:100003700; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"8poieq.bn.files.1drv.com"; classtype:trojan-activity; sid:100003701; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"90.152.144.139"; classtype:trojan-activity; sid:100003702; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.177.139.132"; classtype:trojan-activity; sid:100003703; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.187.103.32"; classtype:trojan-activity; sid:100003704; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.212.150.241"; classtype:trojan-activity; sid:100003705; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.212.150.243"; classtype:trojan-activity; sid:100003706; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.217.104.185"; classtype:trojan-activity; sid:100003707; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.233.112.188"; classtype:trojan-activity; sid:100003708; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.234.60.94"; classtype:trojan-activity; sid:100003709; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.239.168.83"; classtype:trojan-activity; sid:100003710; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.244.114.198"; classtype:trojan-activity; sid:100003711; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.244.169.139"; classtype:trojan-activity; sid:100003712; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.92.16.244"; classtype:trojan-activity; sid:100003713; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.98.4.181"; classtype:trojan-activity; sid:100003714; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.113.192.30"; classtype:trojan-activity; sid:100003715; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.113.195.115"; classtype:trojan-activity; sid:100003716; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.114.191.82"; classtype:trojan-activity; sid:100003717; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.241.78.114"; classtype:trojan-activity; sid:100003718; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.27.246.202"; classtype:trojan-activity; sid:100003719; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.85.18.138"; classtype:trojan-activity; sid:100003720; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.171.157.73"; classtype:trojan-activity; sid:100003721; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.21.224.154"; classtype:trojan-activity; sid:100003722; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.39.115.176"; classtype:trojan-activity; sid:100003723; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.41.137.16"; classtype:trojan-activity; sid:100003724; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.41.182.249"; classtype:trojan-activity; sid:100003725; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.41.206.56"; classtype:trojan-activity; sid:100003726; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.57.43.233"; classtype:trojan-activity; sid:100003727; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.73.99.102"; classtype:trojan-activity; sid:100003728; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.136.69.199"; classtype:trojan-activity; sid:100003729; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.143.53.34"; classtype:trojan-activity; sid:100003730; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.154.17.170"; classtype:trojan-activity; sid:100003731; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.154.82.190"; classtype:trojan-activity; sid:100003732; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.200.16.22"; classtype:trojan-activity; sid:100003733; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.224.83.208"; classtype:trojan-activity; sid:100003734; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.43.139.153"; classtype:trojan-activity; sid:100003735; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.53.120.109"; classtype:trojan-activity; sid:100003736; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.132.129.250"; classtype:trojan-activity; sid:100003737; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.154.20.231"; classtype:trojan-activity; sid:100003738; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.158.19.130"; classtype:trojan-activity; sid:100003739; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.170.113.52"; classtype:trojan-activity; sid:100003740; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.170.201.34"; classtype:trojan-activity; sid:100003741; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.181.155.112"; classtype:trojan-activity; sid:100003742; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.214.52.64"; classtype:trojan-activity; sid:100003743; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.53.229.84"; classtype:trojan-activity; sid:100003744; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.54.11.179"; classtype:trojan-activity; sid:100003745; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.60.146.134"; classtype:trojan-activity; sid:100003746; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.60.6.114"; classtype:trojan-activity; sid:100003747; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.66.196.63"; classtype:trojan-activity; sid:100003748; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.9.120.40"; classtype:trojan-activity; sid:100003749; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"96.239.73.246"; classtype:trojan-activity; sid:100003750; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"96.47.147.169"; classtype:trojan-activity; sid:100003751; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"97.68.140.254"; classtype:trojan-activity; sid:100003752; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"97.96.199.75"; classtype:trojan-activity; sid:100003753; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.0.210.218"; classtype:trojan-activity; sid:100003754; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.0.239.142"; classtype:trojan-activity; sid:100003755; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.113.239.207"; classtype:trojan-activity; sid:100003756; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.116.72.119"; classtype:trojan-activity; sid:100003757; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.128.147.115"; classtype:trojan-activity; sid:100003758; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.178.242.44"; classtype:trojan-activity; sid:100003759; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.249.236.11"; classtype:trojan-activity; sid:100003760; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.28.200.139"; classtype:trojan-activity; sid:100003761; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.30.24.54"; classtype:trojan-activity; sid:100003762; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"99.150.245.203"; classtype:trojan-activity; sid:100003763; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"99.33.195.164"; classtype:trojan-activity; sid:100003764; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"99centsdigitals.com"; classtype:trojan-activity; sid:100003765; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abcd.bg"; classtype:trojan-activity; sid:100003766; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abclicks.in"; classtype:trojan-activity; sid:100003767; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abissnet.net"; classtype:trojan-activity; sid:100003768; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aboveandbelow.com.au"; classtype:trojan-activity; sid:100003769; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"absoftechworld.com"; classtype:trojan-activity; sid:100003770; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"absupplies.co.uk"; classtype:trojan-activity; sid:100003771; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abyssos.eu"; classtype:trojan-activity; sid:100003772; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"acbick.com"; classtype:trojan-activity; sid:100003773; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"accounts.thesmarttechhub.com"; classtype:trojan-activity; sid:100003774; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aceeprc.com.aceeprc.com"; classtype:trojan-activity; sid:100003775; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"acellr.co.uk"; classtype:trojan-activity; sid:100003776; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aclassapart.in"; classtype:trojan-activity; sid:100003777; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"acteon.com.ar"; classtype:trojan-activity; sid:100003778; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"activateyourdiscount.com"; classtype:trojan-activity; sid:100003779; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"activecost.com.au"; classtype:trojan-activity; sid:100003780; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"adamorinmusic.com"; classtype:trojan-activity; sid:100003781; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"addahealingmusic.com"; classtype:trojan-activity; sid:100003782; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"adithimedia.com"; classtype:trojan-activity; sid:100003783; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"adithimedia.memengers.com"; classtype:trojan-activity; sid:100003784; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"admin.erapor.smk-alasror.net"; classtype:trojan-activity; sid:100003785; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"admin.gentbcn.org"; classtype:trojan-activity; sid:100003786; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"admin.grandoceanvilla.com"; classtype:trojan-activity; sid:100003787; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"adventureexplorer.in"; classtype:trojan-activity; sid:100003788; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aeropilates.cl"; classtype:trojan-activity; sid:100003789; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"afrimedspecialist.com"; classtype:trojan-activity; sid:100003790; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agemn.co.za"; classtype:trojan-activity; sid:100003791; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agenciadigitalwdys.com"; classtype:trojan-activity; sid:100003792; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agenciatabletshouse.com.br"; classtype:trojan-activity; sid:100003793; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agenda.gmelloinformatica.com.br"; classtype:trojan-activity; sid:100003794; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agentt.ac.ug"; classtype:trojan-activity; sid:100003795; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agile8studio.com"; classtype:trojan-activity; sid:100003796; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agmcarpetcare.co.uk"; classtype:trojan-activity; sid:100003797; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aiqtest.com"; classtype:trojan-activity; sid:100003798; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ajpharmaholding.com"; classtype:trojan-activity; sid:100003799; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ajstudiollc.com"; classtype:trojan-activity; sid:100003800; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aktyd05.top"; classtype:trojan-activity; sid:100003801; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"al-wahd.com"; classtype:trojan-activity; sid:100003802; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alasdemariposas.org"; classtype:trojan-activity; sid:100003803; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alemelektronik.com"; classtype:trojan-activity; sid:100003804; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alena1971.es"; classtype:trojan-activity; sid:100003805; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alertlauncher.fr"; classtype:trojan-activity; sid:100003806; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alexdubai.com.aldiabsteel.com"; classtype:trojan-activity; sid:100003807; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alka.institute"; classtype:trojan-activity; sid:100003808; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"allforcreative.com.au"; classtype:trojan-activity; sid:100003809; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alltheway.travel"; classtype:trojan-activity; sid:100003810; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alpaylar.com.tr"; classtype:trojan-activity; sid:100003811; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"am-concepts.ca"; classtype:trojan-activity; sid:100003812; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amamontajes.com"; classtype:trojan-activity; sid:100003813; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amarresdeamorymaestroshechiceros.com"; classtype:trojan-activity; sid:100003814; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amarteargentina.com.ar"; classtype:trojan-activity; sid:100003815; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amenyan.zouri.jp"; classtype:trojan-activity; sid:100003816; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amos524.org"; classtype:trojan-activity; sid:100003817; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anantam.net.in"; classtype:trojan-activity; sid:100003818; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andreelapeyre.com"; classtype:trojan-activity; sid:100003819; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andremaraisbeleggings.co.za"; classtype:trojan-activity; sid:100003820; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andres.ac.ug"; classtype:trojan-activity; sid:100003821; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andres.ug"; classtype:trojan-activity; sid:100003822; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andreshconcejal.solucioneslink.com"; classtype:trojan-activity; sid:100003823; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"angelazgheibld.com"; classtype:trojan-activity; sid:100003824; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"angelsdetour.com"; classtype:trojan-activity; sid:100003825; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"angloteste.bigprime.com.br"; classtype:trojan-activity; sid:100003826; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anhung1102.vn"; classtype:trojan-activity; sid:100003827; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anysbergbiltong.co.za"; classtype:trojan-activity; sid:100003828; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"apartamentoscitta.com"; classtype:trojan-activity; sid:100003829; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"api-ms.cobainaja.id"; classtype:trojan-activity; sid:100003830; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"api.cstdevs.com"; classtype:trojan-activity; sid:100003831; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"api.quocbao.biz"; classtype:trojan-activity; sid:100003832; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"api.sampy.io"; classtype:trojan-activity; sid:100003833; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aplicativoparasindicato.com.br"; classtype:trojan-activity; sid:100003834; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"apoolcondo.com"; classtype:trojan-activity; sid:100003835; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"app.adsensearticle.com"; classtype:trojan-activity; sid:100003836; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"app.explicitsurveys.co.uk"; classtype:trojan-activity; sid:100003837; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"app.prerana.info"; classtype:trojan-activity; sid:100003838; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"apps.saintsoporte.com"; classtype:trojan-activity; sid:100003839; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aras.iuc.ac"; classtype:trojan-activity; sid:100003840; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"areyoulivingwell.com"; classtype:trojan-activity; sid:100003841; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"arsapetrolab.com"; classtype:trojan-activity; sid:100003842; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"artedibujoyarquitectura.com"; classtype:trojan-activity; sid:100003843; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ask-regard.call-save.biz"; classtype:trojan-activity; sid:100003844; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"atfile.com"; classtype:trojan-activity; sid:100003845; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"athenacapsg.com"; classtype:trojan-activity; sid:100003846; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"atlasconcreteworks.com"; classtype:trojan-activity; sid:100003847; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"attach.66rpg.com"; classtype:trojan-activity; sid:100003848; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"atteuqpotentialunlimited.com"; classtype:trojan-activity; sid:100003849; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"augustair.com"; classtype:trojan-activity; sid:100003850; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aulist.com"; classtype:trojan-activity; sid:100003851; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"australiafashions.com"; classtype:trojan-activity; sid:100003852; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"automaticrefreshments.com"; classtype:trojan-activity; sid:100003853; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"avadhanagames.com"; classtype:trojan-activity; sid:100003854; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"avissrilanka.com"; classtype:trojan-activity; sid:100003855; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ayamallah.com"; classtype:trojan-activity; sid:100003856; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"azmeasurement.com"; classtype:trojan-activity; sid:100003857; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"azraktours.com"; classtype:trojan-activity; sid:100003858; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"b2b.toptanakaryakit.com.tr"; classtype:trojan-activity; sid:100003859; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"backgrounds.pk"; classtype:trojan-activity; sid:100003860; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"backup.agewsage.com"; classtype:trojan-activity; sid:100003861; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"badeggdesign.com"; classtype:trojan-activity; sid:100003862; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bangkok-orchids.com"; classtype:trojan-activity; sid:100003863; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bary.sz4h.com"; classtype:trojan-activity; sid:100003864; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"basma.com.kw"; classtype:trojan-activity; sid:100003865; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bausch.kr-atlas.monaxikoslykos@zytrox.tk"; classtype:trojan-activity; sid:100003866; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bavhome.com"; classtype:trojan-activity; sid:100003867; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bbia.co.uk"; classtype:trojan-activity; sid:100003868; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bcmt.elin.co.za"; classtype:trojan-activity; sid:100003869; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bcrg.co.za"; classtype:trojan-activity; sid:100003870; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bearcatpumps.com.cn"; classtype:trojan-activity; sid:100003871; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"beatyamerican.com"; classtype:trojan-activity; sid:100003872; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"beautincollagen.rs"; classtype:trojan-activity; sid:100003873; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bekape.co.id"; classtype:trojan-activity; sid:100003874; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bespokeweddings.ie"; classtype:trojan-activity; sid:100003875; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bestcarenepal.com"; classtype:trojan-activity; sid:100003876; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"betone.co.kr"; classtype:trojan-activity; sid:100003877; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"betycopaints.com"; classtype:trojan-activity; sid:100003878; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"beveragesmiami.solucioneslink.com"; classtype:trojan-activity; sid:100003879; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bilbosaquet.ug"; classtype:trojan-activity; sid:100003880; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bilhen.co.za"; classtype:trojan-activity; sid:100003881; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"billing.rahitechnosoft.com"; classtype:trojan-activity; sid:100003882; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"birdi.elin.co.za"; classtype:trojan-activity; sid:100003883; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"birminghamlink.org"; classtype:trojan-activity; sid:100003884; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.callensaxen.com"; classtype:trojan-activity; sid:100003885; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.oyinblogs.com"; classtype:trojan-activity; sid:100003886; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.takbelit.com"; classtype:trojan-activity; sid:100003887; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bmlifestyle.co.uk"; classtype:trojan-activity; sid:100003888; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bnrnews.id"; classtype:trojan-activity; sid:100003889; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bodenstein.co.za"; classtype:trojan-activity; sid:100003890; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bolnicaloznica.rs"; classtype:trojan-activity; sid:100003891; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"booksearch.com"; classtype:trojan-activity; sid:100003892; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bounces.mi-fs.com"; classtype:trojan-activity; sid:100003893; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bpo.correct.go.th"; classtype:trojan-activity; sid:100003894; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bradleyinstitute.co.za"; classtype:trojan-activity; sid:100003895; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brandtrust.com.pk"; classtype:trojan-activity; sid:100003896; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brendanquine.com"; classtype:trojan-activity; sid:100003897; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brideofmessiah.com"; classtype:trojan-activity; sid:100003898; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bridesofmaldives.com"; classtype:trojan-activity; sid:100003899; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brightmega.com"; classtype:trojan-activity; sid:100003900; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brightonrooms.co.uk"; classtype:trojan-activity; sid:100003901; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brightstarshop.com"; classtype:trojan-activity; sid:100003902; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"browardinsurancemiami.solucioneslink.com"; classtype:trojan-activity; sid:100003903; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bt2.elin.co.za"; classtype:trojan-activity; sid:100003904; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"btdapi.robotake.com"; classtype:trojan-activity; sid:100003905; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bucrinsuranlceonlines.com"; classtype:trojan-activity; sid:100003906; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"buenavista.co"; classtype:trojan-activity; sid:100003907; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"buigiaphat.com.vn"; classtype:trojan-activity; sid:100003908; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bullseyemedia.in"; classtype:trojan-activity; sid:100003909; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"busandvanrentalmalaysia.com"; classtype:trojan-activity; sid:100003910; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"buscascolegios.diit.cl"; classtype:trojan-activity; sid:100003911; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"business.softberg.ro"; classtype:trojan-activity; sid:100003912; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"buyingmusiconline.com"; classtype:trojan-activity; sid:100003913; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"buypropertyfast.com"; classtype:trojan-activity; sid:100003914; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bwsr.eu"; classtype:trojan-activity; sid:100003915; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"c.oooooooooo.ga"; classtype:trojan-activity; sid:100003916; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"c0140529.ferozo.com"; classtype:trojan-activity; sid:100003917; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cacapavaonline.sdserver144.com.br"; classtype:trojan-activity; sid:100003918; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"callbury.in"; classtype:trojan-activity; sid:100003919; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"camminachetipassa.it"; classtype:trojan-activity; sid:100003920; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"campusvirtual.cepsanjuanbosco.net.pe"; classtype:trojan-activity; sid:100003921; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cancer.educandome.co"; classtype:trojan-activity; sid:100003922; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"capitalgroup-kw.com"; classtype:trojan-activity; sid:100003923; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"capitalnewsagency.com"; classtype:trojan-activity; sid:100003924; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"capoeiraventrelivre.com"; classtype:trojan-activity; sid:100003925; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cashyinvestment.org"; classtype:trojan-activity; sid:100003926; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"casoauditores.com"; classtype:trojan-activity; sid:100003927; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"catchperch.com"; classtype:trojan-activity; sid:100003928; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"catchpoolshetlands.co.uk"; classtype:trojan-activity; sid:100003929; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cazyacustomfurniture.com"; classtype:trojan-activity; sid:100003930; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ccauthority.net"; classtype:trojan-activity; sid:100003931; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cdaonline.com.ar"; classtype:trojan-activity; sid:100003932; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cec.asso.ac-amiens.fr"; classtype:trojan-activity; sid:100003933; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cellas.sk"; classtype:trojan-activity; sid:100003934; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cendekiabinaaksara.com"; classtype:trojan-activity; sid:100003935; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cespol-bote.com.mx"; classtype:trojan-activity; sid:100003936; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cfs5.tistory.com"; classtype:trojan-activity; sid:100003937; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ch.rmu.ac.th"; classtype:trojan-activity; sid:100003938; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"changematterscounselling.com"; classtype:trojan-activity; sid:100003939; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chardhamdodham.com"; classtype:trojan-activity; sid:100003940; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cheacrilnsurances.com"; classtype:trojan-activity; sid:100003941; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chealablilitycarinsurances.com"; classtype:trojan-activity; sid:100003942; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chezalice.co.za"; classtype:trojan-activity; sid:100003943; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"childselect.com"; classtype:trojan-activity; sid:100003944; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chinhdropfile.myvnc.com"; classtype:trojan-activity; sid:100003945; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chinhdropfile80.myvnc.com"; classtype:trojan-activity; sid:100003946; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chipmania.it"; classtype:trojan-activity; sid:100003947; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cible-energy.com"; classtype:trojan-activity; sid:100003948; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cifeer.net"; classtype:trojan-activity; sid:100003949; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"citycapproperty.ru"; classtype:trojan-activity; sid:100003950; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cityglobalgospel.com"; classtype:trojan-activity; sid:100003951; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"civi.istmejia.com"; classtype:trojan-activity; sid:100003952; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cleanbydesignllc.com"; classtype:trojan-activity; sid:100003953; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"clim34000.fr"; classtype:trojan-activity; sid:100003954; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cloud.fc.co.mz"; classtype:trojan-activity; sid:100003955; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"codsambal.com"; classtype:trojan-activity; sid:100003956; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"colinde.pricesne.com"; classtype:trojan-activity; sid:100003957; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"colorpak.pl"; classtype:trojan-activity; sid:100003958; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"competancy.indigoconsult.net"; classtype:trojan-activity; sid:100003959; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"conceptimagine.ro"; classtype:trojan-activity; sid:100003960; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"config.cqhbkjzx.com"; classtype:trojan-activity; sid:100003961; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"constructoralyon.com"; classtype:trojan-activity; sid:100003962; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"consulateins.solucioneslink.com"; classtype:trojan-activity; sid:100003963; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"contributeindustry.com"; classtype:trojan-activity; sid:100003964; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"controladoradeplagasmm.com"; classtype:trojan-activity; sid:100003965; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"copelandscapes.com"; classtype:trojan-activity; sid:100003966; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"corporativos.com.co"; classtype:trojan-activity; sid:100003967; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"coulsongraphics.com"; classtype:trojan-activity; sid:100003968; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"coutler.newreadermedia.net"; classtype:trojan-activity; sid:100003969; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"covid19.cyberschool.or.id"; classtype:trojan-activity; sid:100003970; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cr-sq.com"; classtype:trojan-activity; sid:100003971; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crearechile.cl"; classtype:trojan-activity; sid:100003972; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"creationskateboards.com"; classtype:trojan-activity; sid:100003973; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crecerco.com"; classtype:trojan-activity; sid:100003974; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crittersbythebay.com"; classtype:trojan-activity; sid:100003975; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crm.notariavieitoyvelamazan.com"; classtype:trojan-activity; sid:100003976; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crmmanivela.net"; classtype:trojan-activity; sid:100003977; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crscorretordeimoveis.com.br"; classtype:trojan-activity; sid:100003978; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cse-engineer.com"; classtype:trojan-activity; sid:100003979; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"csnserver.com"; classtype:trojan-activity; sid:100003980; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cubescargoexpress.com"; classtype:trojan-activity; sid:100003981; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cubrebocasenpuebla.com.mx"; classtype:trojan-activity; sid:100003982; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"curasoles.co.za"; classtype:trojan-activity; sid:100003983; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"currantmedia.com"; classtype:trojan-activity; sid:100003984; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cwa.mx"; classtype:trojan-activity; sid:100003985; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cyber.searchkero.com"; classtype:trojan-activity; sid:100003986; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cyclomove.com"; classtype:trojan-activity; sid:100003987; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cynkon.kairoscs.net"; classtype:trojan-activity; sid:100003988; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"czas.dbstrony.pl"; classtype:trojan-activity; sid:100003989; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"czsl.91756.cn"; classtype:trojan-activity; sid:100003990; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"d.powerofwish.com"; classtype:trojan-activity; sid:100003991; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"d9.99ddd.com"; classtype:trojan-activity; sid:100003992; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"da.alibuf.com"; classtype:trojan-activity; sid:100003993; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"damagedessentialtelecommunications.testmail4.repl.co"; classtype:trojan-activity; sid:100003994; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dandyair.com"; classtype:trojan-activity; sid:100003995; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dannexgh.com"; classtype:trojan-activity; sid:100003996; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dartoonpictures.com"; classtype:trojan-activity; sid:100003997; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"data.cdevelop.org"; classtype:trojan-activity; sid:100003998; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"data.over-blog-kiwi.com"; classtype:trojan-activity; sid:100003999; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"datapolish.com"; classtype:trojan-activity; sid:100004000; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dating.khokhas.co.za"; classtype:trojan-activity; sid:100004001; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"datsom.vn"; classtype:trojan-activity; sid:100004002; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"daunhotq10.com"; classtype:trojan-activity; sid:100004003; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"davethompson.me.uk"; classtype:trojan-activity; sid:100004004; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"davidmcguinness.info"; classtype:trojan-activity; sid:100004005; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dayspringdaisies.com"; classtype:trojan-activity; sid:100004006; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dd.qiyuea.cn"; classtype:trojan-activity; sid:100004007; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"de.gsearch.com.de"; classtype:trojan-activity; sid:100004008; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"decifrar.com.br"; classtype:trojan-activity; sid:100004009; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"deigratia2.elin.co.za"; classtype:trojan-activity; sid:100004010; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dekovizyon.com"; classtype:trojan-activity; sid:100004011; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"demo-cliente.mindcreative.com.br"; classtype:trojan-activity; sid:100004012; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"demo6.hiites.com"; classtype:trojan-activity; sid:100004013; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dent-estet.com"; classtype:trojan-activity; sid:100004014; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dental.xiaoxiao.media"; classtype:trojan-activity; sid:100004015; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dentalalliance.se"; classtype:trojan-activity; sid:100004016; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"designerliving.co.za"; classtype:trojan-activity; sid:100004017; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"desiringhands.com"; classtype:trojan-activity; sid:100004018; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"despertaresi.com.br"; classtype:trojan-activity; sid:100004019; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"destinymc.co.za"; classtype:trojan-activity; sid:100004020; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"detorre.es"; classtype:trojan-activity; sid:100004021; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dev-interestingtech.pantheonsite.io"; classtype:trojan-activity; sid:100004022; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dev.sebpo.net"; classtype:trojan-activity; sid:100004023; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dezcom.com"; classtype:trojan-activity; sid:100004024; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dfcf.91756.cn"; classtype:trojan-activity; sid:100004025; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dfsfcsfcdsfsdvcfsvcscv.com"; classtype:trojan-activity; sid:100004026; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"diamantenegro.mi-fs.com"; classtype:trojan-activity; sid:100004027; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dienmayminhhung.com"; classtype:trojan-activity; sid:100004028; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"digilib.dianhusada.ac.id"; classtype:trojan-activity; sid:100004029; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"djking.f3322.net"; classtype:trojan-activity; sid:100004030; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.1003b.56a.com"; classtype:trojan-activity; sid:100004031; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.198424.com"; classtype:trojan-activity; sid:100004032; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.installcdn-aws.com"; classtype:trojan-activity; sid:100004033; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.packetstormsecurity.net"; classtype:trojan-activity; sid:100004034; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.rina-roleplay.com"; classtype:trojan-activity; sid:100004035; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.zkytech.com"; classtype:trojan-activity; sid:100004036; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dns.cyberium.cc"; classtype:trojan-activity; sid:100004037; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dockerupdate.anondns.net"; classtype:trojan-activity; sid:100004038; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"docman.orientalservices.in"; classtype:trojan-activity; sid:100004039; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dodsonimaging.com"; classtype:trojan-activity; sid:100004040; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dokan.blueberrytec.com"; classtype:trojan-activity; sid:100004041; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dom-chel74.ru"; classtype:trojan-activity; sid:100004042; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dom.daf.free.fr"; classtype:trojan-activity; sid:100004043; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"doncedyhall.com"; classtype:trojan-activity; sid:100004044; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"donghobinhminh.com"; classtype:trojan-activity; sid:100004045; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dongphuctop.com"; classtype:trojan-activity; sid:100004046; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"donwnloasecury.ath.cx"; classtype:trojan-activity; sid:100004047; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dosame.com"; classtype:trojan-activity; sid:100004048; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dosman.pl"; classtype:trojan-activity; sid:100004049; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dovberger.com"; classtype:trojan-activity; sid:100004050; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.flash-plays.com"; classtype:trojan-activity; sid:100004051; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.pcclear.com"; classtype:trojan-activity; sid:100004052; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.posti-fi-fsa.top"; classtype:trojan-activity; sid:100004053; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.posti-fi-fwa.top"; classtype:trojan-activity; sid:100004054; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.udashi.com"; classtype:trojan-activity; sid:100004055; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.webbora.com"; classtype:trojan-activity; sid:100004056; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down1.arpun.com"; classtype:trojan-activity; sid:100004057; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.caihong.com"; classtype:trojan-activity; sid:100004058; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.doumaibiji.cn"; classtype:trojan-activity; sid:100004059; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.exrnybuf.cn"; classtype:trojan-activity; sid:100004060; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.kaobeitu.com"; classtype:trojan-activity; sid:100004061; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.pdf00.cn"; classtype:trojan-activity; sid:100004062; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.rising.com.cn"; classtype:trojan-activity; sid:100004063; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.skycn.com"; classtype:trojan-activity; sid:100004064; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.zjsyawqj.cn"; classtype:trojan-activity; sid:100004065; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"downloads.jxtsteel.cn"; classtype:trojan-activity; sid:100004066; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dragonsknot.com"; classtype:trojan-activity; sid:100004067; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drbaby.com.sa"; classtype:trojan-activity; sid:100004068; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drohnen.ensenanzainteligente.com"; classtype:trojan-activity; sid:100004069; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drools-moved.46999.n3.nabble.com"; classtype:trojan-activity; sid:100004070; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drrohanfonseca.com"; classtype:trojan-activity; sid:100004071; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drsha.innovativesolutions.mobi"; classtype:trojan-activity; sid:100004072; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dsenterprize.co.za"; classtype:trojan-activity; sid:100004073; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dsspainting.com"; classtype:trojan-activity; sid:100004074; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"du-wizards.com"; classtype:trojan-activity; sid:100004075; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"duque.guantanameratravel.com"; classtype:trojan-activity; sid:100004076; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dutapp.wisolve.co.za"; classtype:trojan-activity; sid:100004077; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"duvalcharter.dekitout.com"; classtype:trojan-activity; sid:100004078; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dx.qqyewu.com"; classtype:trojan-activity; sid:100004079; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dzinestudio87.co.uk"; classtype:trojan-activity; sid:100004080; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"e-commerce.saleensuporte.com.br"; classtype:trojan-activity; sid:100004081; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"e.sldov.ru"; classtype:trojan-activity; sid:100004082; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ebruyatkin.com"; classtype:trojan-activity; sid:100004083; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"econews.treegle.org"; classtype:trojan-activity; sid:100004084; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"edelweissdecoration.com"; classtype:trojan-activity; sid:100004085; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"efficientegroup.com"; classtype:trojan-activity; sid:100004086; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"elliot.newreadermedia.net"; classtype:trojan-activity; sid:100004087; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"emaids.co.za"; classtype:trojan-activity; sid:100004088; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"en.baoend.com"; classtype:trojan-activity; sid:100004089; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"enc-tech.com"; classtype:trojan-activity; sid:100004090; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"endurotanzania.co.tz"; classtype:trojan-activity; sid:100004091; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"enkonooh.com"; classtype:trojan-activity; sid:100004092; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ennovate.elin.co.za"; classtype:trojan-activity; sid:100004093; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"enriquecendocomconsorcio.com.br"; classtype:trojan-activity; sid:100004094; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"envios.petpienso.cl"; classtype:trojan-activity; sid:100004095; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"equimination.ee"; classtype:trojan-activity; sid:100004096; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"es.paymelist.com"; classtype:trojan-activity; sid:100004097; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"escola.probommar.org.br"; classtype:trojan-activity; sid:100004098; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"esnconsultants.com"; classtype:trojan-activity; sid:100004099; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"essentia.org.br"; classtype:trojan-activity; sid:100004100; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"eubanks7.com"; classtype:trojan-activity; sid:100004101; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"evidencemarketing.ca"; classtype:trojan-activity; sid:100004102; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"exilum.com"; classtype:trojan-activity; sid:100004103; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"exitoalfaomega.co"; classtype:trojan-activity; sid:100004104; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"extrovertoffers.com"; classtype:trojan-activity; sid:100004105; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"f1sol.com"; classtype:trojan-activity; sid:100004106; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"familydentist.site"; classtype:trojan-activity; sid:100004107; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"farmaciasdrogaminas.com.br"; classtype:trojan-activity; sid:100004108; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"farmnatural.in"; classtype:trojan-activity; sid:100004109; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"faveraprojects.com"; classtype:trojan-activity; sid:100004110; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fc.co.mz"; classtype:trojan-activity; sid:100004111; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"felicienne.nl"; classtype:trojan-activity; sid:100004112; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fi.bonitastores.com"; classtype:trojan-activity; sid:100004113; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"files.martellexpress.us"; classtype:trojan-activity; sid:100004114; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"files6.uludagbilisim.com"; classtype:trojan-activity; sid:100004115; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"filmotainment.com"; classtype:trojan-activity; sid:100004116; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"final.makkahkmcc.com"; classtype:trojan-activity; sid:100004117; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fkd.derpcity.ru"; classtype:trojan-activity; sid:100004118; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"flintspin.com"; classtype:trojan-activity; sid:100004119; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"flyingbuddhadesign.com"; classtype:trojan-activity; sid:100004120; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fmjplastering.co.uk"; classtype:trojan-activity; sid:100004121; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fms.buladde.or.ug"; classtype:trojan-activity; sid:100004122; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"foothills.com.br"; classtype:trojan-activity; sid:100004123; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"footweardirect.elin.co.za"; classtype:trojan-activity; sid:100004124; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"formestore.evencsoft.co"; classtype:trojan-activity; sid:100004125; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"forum.mdb.nu"; classtype:trojan-activity; sid:100004126; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fotoobjetivo.com"; classtype:trojan-activity; sid:100004127; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"foundationrepairhoustontx.net"; classtype:trojan-activity; sid:100004128; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"foxeps.com.br"; classtype:trojan-activity; sid:100004129; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"freecnetdownload.com"; classtype:trojan-activity; sid:100004130; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"freedombookshop.tickme.lk"; classtype:trojan-activity; sid:100004131; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"freisites.com.br"; classtype:trojan-activity; sid:100004132; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ftp.n3twork30cm.ml"; classtype:trojan-activity; sid:100004133; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fullelectronica.com.ar"; classtype:trojan-activity; sid:100004134; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"funletters.net"; classtype:trojan-activity; sid:100004135; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fusionfiresolutions.com"; classtype:trojan-activity; sid:100004136; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"futuregraphics.com.ar"; classtype:trojan-activity; sid:100004137; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gahanassociates.com"; classtype:trojan-activity; sid:100004138; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gametwogame.com"; classtype:trojan-activity; sid:100004139; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"garayvidalabogados.com"; classtype:trojan-activity; sid:100004140; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"garciadogshow.com"; classtype:trojan-activity; sid:100004141; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"garenanow.myvnc.com"; classtype:trojan-activity; sid:100004142; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"garenanow4.myvnc.com"; classtype:trojan-activity; sid:100004143; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gbbulls.co.uk"; classtype:trojan-activity; sid:100004144; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gcpc.co.id.chronoscurtain.com"; classtype:trojan-activity; sid:100004145; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gcrcorporation.com"; classtype:trojan-activity; sid:100004146; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"generaldeviales.com"; classtype:trojan-activity; sid:100004147; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gfmodd1.webselffiles01.com"; classtype:trojan-activity; sid:100004148; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gfold1.webselffiles01.com"; classtype:trojan-activity; sid:100004149; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ghettohub.co.za"; classtype:trojan-activity; sid:100004150; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ghislain.dartois.pagesperso-orange.fr"; classtype:trojan-activity; sid:100004151; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"giadungg7.com"; classtype:trojan-activity; sid:100004152; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"giddos.ga"; classtype:trojan-activity; sid:100004153; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"giteletropical.com"; classtype:trojan-activity; sid:100004154; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"globaltask.ar"; classtype:trojan-activity; sid:100004155; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"glowinmedia.co.ke"; classtype:trojan-activity; sid:100004156; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gmtransformationacademy.com"; classtype:trojan-activity; sid:100004157; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gmvadmission.org"; classtype:trojan-activity; sid:100004158; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gnimelf.net"; classtype:trojan-activity; sid:100004159; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gnscrew.ro"; classtype:trojan-activity; sid:100004160; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gold.investforex.id"; classtype:trojan-activity; sid:100004161; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldcake.co.id"; classtype:trojan-activity; sid:100004162; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldcoastoffice365.com"; classtype:trojan-activity; sid:100004163; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldcoastoffice365.com.au"; classtype:trojan-activity; sid:100004164; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldcupmortgage.com"; classtype:trojan-activity; sid:100004165; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"golden-memories-funerals.yourpageserver.com"; classtype:trojan-activity; sid:100004166; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldmen.in"; classtype:trojan-activity; sid:100004167; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gracejukes.com"; classtype:trojan-activity; sid:100004168; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"grupoinmare.com"; classtype:trojan-activity; sid:100004169; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gruposelt.000webhostapp.com"; classtype:trojan-activity; sid:100004170; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gs.monerorx.com"; classtype:trojan-activity; sid:100004171; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gulfac-house.com"; classtype:trojan-activity; sid:100004172; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gvpcdpgc.edu.in"; classtype:trojan-activity; sid:100004173; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"habbotips.free.fr"; classtype:trojan-activity; sid:100004174; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hagebakken.no"; classtype:trojan-activity; sid:100004175; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"harrisauto.no"; classtype:trojan-activity; sid:100004176; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"harshraval.in"; classtype:trojan-activity; sid:100004177; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hd11315.com"; classtype:trojan-activity; sid:100004178; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hdkamera2003.hu"; classtype:trojan-activity; sid:100004179; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hdrest.fastlinktz.com"; classtype:trojan-activity; sid:100004180; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hds.sz4h.com"; classtype:trojan-activity; sid:100004181; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"healthy20.net"; classtype:trojan-activity; sid:100004182; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hechiceriadeamormaestrabelen.com.hechiceriadeamormaestrabelen.com"; classtype:trojan-activity; sid:100004183; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hellogorgeous.com.au"; classtype:trojan-activity; sid:100004184; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"help.hizuko.com"; classtype:trojan-activity; sid:100004185; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"herchinfitout.com.sg"; classtype:trojan-activity; sid:100004186; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hhaward.org"; classtype:trojan-activity; sid:100004187; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"highlandroadcoc.com"; classtype:trojan-activity; sid:100004188; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"highlandslasvegas.atakdev.com"; classtype:trojan-activity; sid:100004189; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hindi.factsriver.com"; classtype:trojan-activity; sid:100004190; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hiptool.net"; classtype:trojan-activity; sid:100004191; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hitpe.com"; classtype:trojan-activity; sid:100004192; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hitstation.nl"; classtype:trojan-activity; sid:100004193; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hmpmall.co.kr"; classtype:trojan-activity; sid:100004194; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hoagietesting10.com"; classtype:trojan-activity; sid:100004195; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hoayeuthuong-my.sharepoint.com"; classtype:trojan-activity; sid:100004196; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"homefindersolutions.com"; classtype:trojan-activity; sid:100004197; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hongluosi.com"; classtype:trojan-activity; sid:100004198; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hookedupboatclub.com"; classtype:trojan-activity; sid:100004199; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hostelkielce.com"; classtype:trojan-activity; sid:100004200; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hostzaa.com"; classtype:trojan-activity; sid:100004201; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"houstonshutters.site"; classtype:trojan-activity; sid:100004202; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hr2019.vrcom7.com"; classtype:trojan-activity; sid:100004203; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hseda.com"; classtype:trojan-activity; sid:100004204; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hsmwebapp.com"; classtype:trojan-activity; sid:100004205; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"htownbars.com"; classtype:trojan-activity; sid:100004206; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hubtech.co.za"; classtype:trojan-activity; sid:100004207; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"huequito.evencsoft.co"; classtype:trojan-activity; sid:100004208; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hunggiang.vn"; classtype:trojan-activity; sid:100004209; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"husamiyahschool.com"; classtype:trojan-activity; sid:100004210; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iam313.com"; classtype:trojan-activity; sid:100004211; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"icon.shatangmu.cn"; classtype:trojan-activity; sid:100004212; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idea-secure-login.com"; classtype:trojan-activity; sid:100004213; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idilsoft.com"; classtype:trojan-activity; sid:100004214; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idj.no"; classtype:trojan-activity; sid:100004215; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idvindia.com"; classtype:trojan-activity; sid:100004216; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iesanjosemonitos.edu.co"; classtype:trojan-activity; sid:100004217; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ikexpert.com"; classtype:trojan-activity; sid:100004218; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ilrafrica.com"; classtype:trojan-activity; sid:100004219; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"imbueautoworx.co.za"; classtype:trojan-activity; sid:100004220; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"imperiumtherapy.co.za"; classtype:trojan-activity; sid:100004221; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"in-tune2016.com"; classtype:trojan-activity; sid:100004222; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"incodimsa.com"; classtype:trojan-activity; sid:100004223; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"incrediblepixels.com"; classtype:trojan-activity; sid:100004224; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"incredicole.com"; classtype:trojan-activity; sid:100004225; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"industriasyuli.com"; classtype:trojan-activity; sid:100004226; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"infair.vn"; classtype:trojan-activity; sid:100004227; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"infovator.com"; classtype:trojan-activity; sid:100004228; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"innatosbrand.com"; classtype:trojan-activity; sid:100004229; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"inodesthetotaldesigners.com"; classtype:trojan-activity; sid:100004230; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"inovations.searchkero.com"; classtype:trojan-activity; sid:100004231; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"inrajahmundry.co.in"; classtype:trojan-activity; sid:100004232; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"insignificantfinecore.testmail4.repl.co"; classtype:trojan-activity; sid:100004233; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"instvisionmexico.edu.mx"; classtype:trojan-activity; sid:100004234; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"intellectsmart.in"; classtype:trojan-activity; sid:100004235; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"intersel-idf.org"; classtype:trojan-activity; sid:100004236; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"intuitiveideas.com.my"; classtype:trojan-activity; sid:100004237; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"inversiones.arrayanfinanciero.cl"; classtype:trojan-activity; sid:100004238; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"invest.xpcorporative.com.br"; classtype:trojan-activity; sid:100004239; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ipmes.ma"; classtype:trojan-activity; sid:100004240; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iremart.es"; classtype:trojan-activity; sid:100004241; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iris101.co.uk"; classtype:trojan-activity; sid:100004242; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iscamenabe.com"; classtype:trojan-activity; sid:100004243; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iso-dubai.net"; classtype:trojan-activity; sid:100004244; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"israrulhaq.me"; classtype:trojan-activity; sid:100004245; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"isrorg.com"; classtype:trojan-activity; sid:100004246; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"issmbour.falllo.com"; classtype:trojan-activity; sid:100004247; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"isso.ps"; classtype:trojan-activity; sid:100004248; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"it123.ru"; classtype:trojan-activity; sid:100004249; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"itc-demo.softgig.co.ke"; classtype:trojan-activity; sid:100004250; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"itconsultus.com.co"; classtype:trojan-activity; sid:100004251; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jamesjorgensen.newreadermedia.net"; classtype:trojan-activity; sid:100004252; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jamiekaylive.com"; classtype:trojan-activity; sid:100004253; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jamshed.pk"; classtype:trojan-activity; sid:100004254; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jansen-heesch.nl"; classtype:trojan-activity; sid:100004255; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jathra.co.uk"; classtype:trojan-activity; sid:100004256; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jay.diamondrelationscrm.us"; classtype:trojan-activity; sid:100004257; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jebs.net.au"; classtype:trojan-activity; sid:100004258; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jeffdahlke.com"; classtype:trojan-activity; sid:100004259; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jhayesconsulting.com"; classtype:trojan-activity; sid:100004260; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jiaoyuzixun.cn"; classtype:trojan-activity; sid:100004261; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jing-da.com.tw"; classtype:trojan-activity; sid:100004262; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jktnet.xyz"; classtype:trojan-activity; sid:100004263; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jmcomputacion.com.ar"; classtype:trojan-activity; sid:100004264; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jmtc.91756.cn"; classtype:trojan-activity; sid:100004265; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jnanbharati.com"; classtype:trojan-activity; sid:100004266; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jobs.thebeessolution.com"; classtype:trojan-activity; sid:100004267; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"joelbonissilver.com"; classtype:trojan-activity; sid:100004268; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"join.cl8movement.co.za"; classtype:trojan-activity; sid:100004269; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"josegene.com"; classtype:trojan-activity; sid:100004270; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"josuarochoa.com"; classtype:trojan-activity; sid:100004271; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jpwoodfordco.com"; classtype:trojan-activity; sid:100004272; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"julietlaser.site"; classtype:trojan-activity; sid:100004273; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jumpmanualjacobhiller.com"; classtype:trojan-activity; sid:100004274; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jumpnjamchicago.com"; classtype:trojan-activity; sid:100004275; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jupiter.toxsl.in"; classtype:trojan-activity; sid:100004276; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jurgensen.newreadermedia.net"; classtype:trojan-activity; sid:100004277; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"justinscott.com.au"; classtype:trojan-activity; sid:100004278; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kaizenjanitorial.com"; classtype:trojan-activity; sid:100004279; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kalawatihomes.com"; classtype:trojan-activity; sid:100004280; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kalpataru-elitus-mulund.thakkers.in"; classtype:trojan-activity; sid:100004281; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"karer.by"; classtype:trojan-activity; sid:100004282; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"katanvetov.co.il"; classtype:trojan-activity; sid:100004283; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kbdom.com"; classtype:trojan-activity; sid:100004284; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kensingtondriving.com"; classtype:trojan-activity; sid:100004285; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kevinjewelry.com.co"; classtype:trojan-activity; sid:100004286; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"keywatch.yourpageserver.com"; classtype:trojan-activity; sid:100004287; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kingssa.co.za"; classtype:trojan-activity; sid:100004288; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kjcpromo.com"; classtype:trojan-activity; sid:100004289; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kleinendeli.co.za"; classtype:trojan-activity; sid:100004290; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"korrectconceptservices.com"; classtype:trojan-activity; sid:100004291; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ktb.sch.id"; classtype:trojan-activity; sid:100004292; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kubatoglubaklava.com.tr"; classtype:trojan-activity; sid:100004293; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kumaralok.in"; classtype:trojan-activity; sid:100004294; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kwanfromhongkong.com"; classtype:trojan-activity; sid:100004295; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kz.sldov.ru"; classtype:trojan-activity; sid:100004296; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lacasadelosalebrijes.com"; classtype:trojan-activity; sid:100004297; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ladylabonde.com"; classtype:trojan-activity; sid:100004298; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lameguard.ru"; classtype:trojan-activity; sid:100004299; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"landing.yetiapp.ec"; classtype:trojan-activity; sid:100004300; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"laodongnhat.vn"; classtype:trojan-activity; sid:100004301; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"laravel.pointersoftwares.com.br"; classtype:trojan-activity; sid:100004302; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lasermobilesounds.co.uk"; classtype:trojan-activity; sid:100004303; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lauratomismith.com"; classtype:trojan-activity; sid:100004304; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lautarosanmiguel.com"; classtype:trojan-activity; sid:100004305; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lawforall.edu.lk"; classtype:trojan-activity; sid:100004306; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lceventos.net"; classtype:trojan-activity; sid:100004307; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ld.mediaget.com"; classtype:trojan-activity; sid:100004308; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ldgcorp.com"; classtype:trojan-activity; sid:100004309; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"learning.real-academy.net"; classtype:trojan-activity; sid:100004310; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"leasiacherise.com"; classtype:trojan-activity; sid:100004311; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"leczkregoslup.acelero.pl"; classtype:trojan-activity; sid:100004312; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"legend.nu"; classtype:trojan-activity; sid:100004313; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"leluibuffet.com.br"; classtype:trojan-activity; sid:100004314; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lestesteux.ca"; classtype:trojan-activity; sid:100004315; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"libantravel.pl"; classtype:trojan-activity; sid:100004316; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"library.arihantmbainstitute.ac.in"; classtype:trojan-activity; sid:100004317; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"library.uib.ac.id"; classtype:trojan-activity; sid:100004318; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lickmylash.com"; classtype:trojan-activity; sid:100004319; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lidoraggiodisole.it"; classtype:trojan-activity; sid:100004320; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lifebeam.elin.co.za"; classtype:trojan-activity; sid:100004321; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lindnerelektroanlagen.de"; classtype:trojan-activity; sid:100004322; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"linkintec.cn"; classtype:trojan-activity; sid:100004323; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"litroxlitro.com"; classtype:trojan-activity; sid:100004324; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"livetrack.in"; classtype:trojan-activity; sid:100004325; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lloydsindian.co.uk"; classtype:trojan-activity; sid:100004326; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lm.stagingarea.co.za"; classtype:trojan-activity; sid:100004327; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lmaancha.co.il"; classtype:trojan-activity; sid:100004328; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lms.cstdevs.com"; classtype:trojan-activity; sid:100004329; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lms.login2.in"; classtype:trojan-activity; sid:100004330; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lmvirtualbookkeeping.com"; classtype:trojan-activity; sid:100004331; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lnt-rejuve-360.thakkers.in"; classtype:trojan-activity; sid:100004332; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"location-voitures.ma"; classtype:trojan-activity; sid:100004333; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"login.trezor.com.stockfootagesindia.com"; classtype:trojan-activity; sid:100004334; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"logotypfabriken.se"; classtype:trojan-activity; sid:100004335; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lotix.de"; classtype:trojan-activity; sid:100004336; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lotusanddragonfly.com"; classtype:trojan-activity; sid:100004337; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lp.definerisco.com"; classtype:trojan-activity; sid:100004338; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lp.difusodesign.com"; classtype:trojan-activity; sid:100004339; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lp.juancamilogarciareyes.com"; classtype:trojan-activity; sid:100004340; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lp.tecnimasdecolombia.com.co"; classtype:trojan-activity; sid:100004341; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"luckybrownie.com"; classtype:trojan-activity; sid:100004342; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"luminouspneuma.com"; classtype:trojan-activity; sid:100004343; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"luxomodels.com"; classtype:trojan-activity; sid:100004344; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"m-technics.kz"; classtype:trojan-activity; sid:100004345; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"m.estudiomoros.com.ar"; classtype:trojan-activity; sid:100004346; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"madicon.co.za"; classtype:trojan-activity; sid:100004347; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"magianegramagiablancayamarres.com"; classtype:trojan-activity; sid:100004348; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mail.bs-eiendomme.co.za"; classtype:trojan-activity; sid:100004349; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mail.jeffsono.org"; classtype:trojan-activity; sid:100004350; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"maksi.feb.unib.ac.id"; classtype:trojan-activity; sid:100004351; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"malaya.tv"; classtype:trojan-activity; sid:100004352; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"malwarecoding.github.io"; classtype:trojan-activity; sid:100004353; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"managed.oss-cn-beijing.aliyuncs.com"; classtype:trojan-activity; sid:100004354; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"manantialesdelnorte.uy"; classtype:trojan-activity; sid:100004355; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"manivelasst.com"; classtype:trojan-activity; sid:100004356; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marcapinyo.ru"; classtype:trojan-activity; sid:100004357; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marcusthepoet.com"; classtype:trojan-activity; sid:100004358; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mario-sunjic.com"; classtype:trojan-activity; sid:100004359; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mariobrown.net"; classtype:trojan-activity; sid:100004360; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mariotessarollo.com"; classtype:trojan-activity; sid:100004361; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marketinfosales.com"; classtype:trojan-activity; sid:100004362; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marketing.enexusgroup.com.au"; classtype:trojan-activity; sid:100004363; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marksidfgs.ug"; classtype:trojan-activity; sid:100004364; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"masjidhabeebiyarazviya.mysunni.com"; classtype:trojan-activity; sid:100004365; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"materialescantu.com"; classtype:trojan-activity; sid:100004366; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"matinal-nominal.pt"; classtype:trojan-activity; sid:100004367; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"matruchhaya.co.in"; classtype:trojan-activity; sid:100004368; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mattysplayground.com"; classtype:trojan-activity; sid:100004369; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"maxtox.com.pk"; classtype:trojan-activity; sid:100004370; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mbgrm.com"; classtype:trojan-activity; sid:100004371; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mbsolutions.ge"; classtype:trojan-activity; sid:100004372; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mdasa.elin.co.za"; classtype:trojan-activity; sid:100004373; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"medevlb.org"; classtype:trojan-activity; sid:100004374; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"media-server.skyinternet.com.pk"; classtype:trojan-activity; sid:100004375; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mediamaster.co.za"; classtype:trojan-activity; sid:100004376; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"medianews.ge"; classtype:trojan-activity; sid:100004377; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"medistaffconsulting.com"; classtype:trojan-activity; sid:100004378; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"meeweb.com"; classtype:trojan-activity; sid:100004379; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"megamart.afnan-amc.com"; classtype:trojan-activity; sid:100004380; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"merbay.ru"; classtype:trojan-activity; sid:100004381; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"merkathink.com"; classtype:trojan-activity; sid:100004382; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mertlog.com"; classtype:trojan-activity; sid:100004383; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"metalin-cr.com"; classtype:trojan-activity; sid:100004384; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mettaanand.org"; classtype:trojan-activity; sid:100004385; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"meuoculosnanet.com.br"; classtype:trojan-activity; sid:100004386; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mfevr.com"; classtype:trojan-activity; sid:100004387; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mhkdhotbot.myvnc.com"; classtype:trojan-activity; sid:100004388; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mhkdhotbot80.myvnc.com"; classtype:trojan-activity; sid:100004389; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"micalle.com.au"; classtype:trojan-activity; sid:100004390; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"michaelphilip.com"; classtype:trojan-activity; sid:100004391; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"michimal2.000webhostapp.com"; classtype:trojan-activity; sid:100004392; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"microblading.mirliandias.com.br"; classtype:trojan-activity; sid:100004393; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"microcomm-group.com"; classtype:trojan-activity; sid:100004394; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"midlandtexasconstruction.com"; classtype:trojan-activity; sid:100004395; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mindfulbuildingandliving.com"; classtype:trojan-activity; sid:100004396; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mingguanwms.com"; classtype:trojan-activity; sid:100004397; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"minuevavida.org"; classtype:trojan-activity; sid:100004398; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mirror.mypage.sk"; classtype:trojan-activity; sid:100004399; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mis.nbcc.ac.th"; classtype:trojan-activity; sid:100004400; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"misterson.com"; classtype:trojan-activity; sid:100004401; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mixr.at"; classtype:trojan-activity; sid:100004402; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mkontakt.az"; classtype:trojan-activity; sid:100004403; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mktf.mx"; classtype:trojan-activity; sid:100004404; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mmogollon.com.mx"; classtype:trojan-activity; sid:100004405; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mncarteam.com"; classtype:trojan-activity; sid:100004406; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"modelhouseturkey.com"; classtype:trojan-activity; sid:100004407; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"modernmanna.org"; classtype:trojan-activity; sid:100004408; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"monetization.business"; classtype:trojan-activity; sid:100004409; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"moninediy.com"; classtype:trojan-activity; sid:100004410; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mopai.sg"; classtype:trojan-activity; sid:100004411; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"motorcomunicacion.com"; classtype:trojan-activity; sid:100004412; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mtspsmjeli.sch.id"; classtype:trojan-activity; sid:100004413; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"muzimbiti.xigubo.co.mz"; classtype:trojan-activity; sid:100004414; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mxpiqw.am.files.1drv.com"; classtype:trojan-activity; sid:100004415; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mydatebook.in"; classtype:trojan-activity; sid:100004416; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mymlql.com"; classtype:trojan-activity; sid:100004417; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"myritz.vettickal.com"; classtype:trojan-activity; sid:100004418; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"myscape.in"; classtype:trojan-activity; sid:100004419; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mysura.it"; classtype:trojan-activity; sid:100004420; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"namnyak.co.ke"; classtype:trojan-activity; sid:100004421; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nap.mgsservers.com"; classtype:trojan-activity; sid:100004422; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"navayurveda.in"; classtype:trojan-activity; sid:100004423; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nec-i.com"; classtype:trojan-activity; sid:100004424; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nelitrianggraeni.000webhostapp.com"; classtype:trojan-activity; sid:100004425; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nerve.untergrund.net"; classtype:trojan-activity; sid:100004426; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nettube.com.br"; classtype:trojan-activity; sid:100004427; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"networkwheels.co.za"; classtype:trojan-activity; sid:100004428; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"neuroenergy.fahadjutt.com"; classtype:trojan-activity; sid:100004429; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"neuromedic.com.br"; classtype:trojan-activity; sid:100004430; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"neverseenshop.com.mx"; classtype:trojan-activity; sid:100004431; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newinfinitysynergy.com"; classtype:trojan-activity; sid:100004432; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"news.dbstrony.pl"; classtype:trojan-activity; sid:100004433; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newtreedesign.co.uk"; classtype:trojan-activity; sid:100004434; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newtrendeg.com"; classtype:trojan-activity; sid:100004435; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newvisionopticallab.com"; classtype:trojan-activity; sid:100004436; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newxing.com"; classtype:trojan-activity; sid:100004437; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nextdigitalday.ru"; classtype:trojan-activity; sid:100004438; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ngdaycare.co.za"; classtype:trojan-activity; sid:100004439; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nguyenkekhuyen.com"; classtype:trojan-activity; sid:100004440; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nhorangtreem.com"; classtype:trojan-activity; sid:100004441; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nicolas.ug"; classtype:trojan-activity; sid:100004442; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nidhi.iexist.in"; classtype:trojan-activity; sid:100004443; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nikanpolimer.ir"; classtype:trojan-activity; sid:100004444; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nilinkeji.com"; classtype:trojan-activity; sid:100004445; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nisacooks.com"; classtype:trojan-activity; sid:100004446; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"njtiledesigncenter.com"; classtype:trojan-activity; sid:100004447; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nobius.org"; classtype:trojan-activity; sid:100004448; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nocalnoodle.elin.co.za"; classtype:trojan-activity; sid:100004449; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nomadicbees.com"; classtype:trojan-activity; sid:100004450; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nonnarina.ax"; classtype:trojan-activity; sid:100004451; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"notamuzikaletleri.com"; classtype:trojan-activity; sid:100004452; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"notif1.priruz.co.in"; classtype:trojan-activity; sid:100004453; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ns1.the-widyantos.com"; classtype:trojan-activity; sid:100004454; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nsb.org.uk"; classtype:trojan-activity; sid:100004455; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nsheldon.co.uk"; classtype:trojan-activity; sid:100004456; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nurmarkaz.org"; classtype:trojan-activity; sid:100004457; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nuthuassociates.com"; classtype:trojan-activity; sid:100004458; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nuwagi.com"; classtype:trojan-activity; sid:100004459; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nyeh2o.com.au"; classtype:trojan-activity; sid:100004460; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oakleyandfriends.co.uk"; classtype:trojan-activity; sid:100004461; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"obseques-conseils.com"; classtype:trojan-activity; sid:100004462; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ocean.tecnasulstore.com.br"; classtype:trojan-activity; sid:100004463; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ohsewgorgeous.co.uk"; classtype:trojan-activity; sid:100004464; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oleholeh.memangbeda.website"; classtype:trojan-activity; sid:100004465; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"olirecords.mixture.ltd"; classtype:trojan-activity; sid:100004466; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"olooom.com"; classtype:trojan-activity; sid:100004467; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omaromatic.com"; classtype:trojan-activity; sid:100004468; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omega.az"; classtype:trojan-activity; sid:100004469; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oms.pappai.com"; classtype:trojan-activity; sid:100004470; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omscoc.pappai.com"; classtype:trojan-activity; sid:100004471; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"onedigitalcard.granvizionnecorp.com"; classtype:trojan-activity; sid:100004472; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"onedrive.listifyapp.co"; classtype:trojan-activity; sid:100004473; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"online.creedglobal.in"; classtype:trojan-activity; sid:100004474; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"onlinestatis.bar"; classtype:trojan-activity; sid:100004475; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"open.warehousesaas.co.uk"; classtype:trojan-activity; sid:100004476; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"opolis.io"; classtype:trojan-activity; sid:100004477; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"optimus.com.sg"; classtype:trojan-activity; sid:100004478; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"optitechsa.co.za"; classtype:trojan-activity; sid:100004479; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"order.bizpeed.com"; classtype:trojan-activity; sid:100004480; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"orientgatewayltd.com"; classtype:trojan-activity; sid:100004481; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"orion445.com"; classtype:trojan-activity; sid:100004482; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ottimade.com"; classtype:trojan-activity; sid:100004483; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ourteam.searchkero.com"; classtype:trojan-activity; sid:100004484; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ozemag.com"; classtype:trojan-activity; sid:100004485; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"p1.lingpao8.com"; classtype:trojan-activity; sid:100004486; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"p3.zbjimg.com"; classtype:trojan-activity; sid:100004487; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"p6.zbjimg.com"; classtype:trojan-activity; sid:100004488; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pablobrothel.com.ar"; classtype:trojan-activity; sid:100004489; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pacificgroup.ws"; classtype:trojan-activity; sid:100004490; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pacwebdesigns.com"; classtype:trojan-activity; sid:100004491; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pagos.krayem.com.mx"; classtype:trojan-activity; sid:100004492; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"palochusvet.szm.com"; classtype:trojan-activity; sid:100004493; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"parallel.rockvideos.at"; classtype:trojan-activity; sid:100004494; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"parejasfelices.mi-fs.com"; classtype:trojan-activity; sid:100004495; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"parkhussion.com"; classtype:trojan-activity; sid:100004496; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pastorpaulocosta.com"; classtype:trojan-activity; sid:100004497; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"patch2.51lg.com"; classtype:trojan-activity; sid:100004498; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"patch2.99ddd.com"; classtype:trojan-activity; sid:100004499; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"patch3.99ddd.com"; classtype:trojan-activity; sid:100004500; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"paths.elin.co.za"; classtype:trojan-activity; sid:100004501; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"paulmercier.biz"; classtype:trojan-activity; sid:100004502; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"payerrealty.com"; classtype:trojan-activity; sid:100004503; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pcsoori.com"; classtype:trojan-activity; sid:100004504; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pd.oceaniarp.net"; classtype:trojan-activity; sid:100004505; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"perpus.onlineman7-jombang.sch.id"; classtype:trojan-activity; sid:100004506; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"perpustekim.untirta.ac.id"; classtype:trojan-activity; sid:100004507; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pestoclean.co.uk"; classtype:trojan-activity; sid:100004508; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"petercollie.com"; classtype:trojan-activity; sid:100004509; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ph4s.ru"; classtype:trojan-activity; sid:100004510; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"phenhuong.sanpham.online"; classtype:trojan-activity; sid:100004511; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"phittc.com"; classtype:trojan-activity; sid:100004512; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"photo360.kubooking.com"; classtype:trojan-activity; sid:100004513; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"photographytipsclub.com"; classtype:trojan-activity; sid:100004514; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pink99.com"; classtype:trojan-activity; sid:100004515; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"plasfan.ind.br"; classtype:trojan-activity; sid:100004516; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pmglance.startwriteup.com"; classtype:trojan-activity; sid:100004517; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pokojewewladyslawowie.pl"; classtype:trojan-activity; sid:100004518; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pole.com.vc"; classtype:trojan-activity; sid:100004519; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pool.phxdir.com"; classtype:trojan-activity; sid:100004520; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pooltablemoversdenver.net"; classtype:trojan-activity; sid:100004521; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"posmicrosystems.com"; classtype:trojan-activity; sid:100004522; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"poulman.panagiotopoulos-tours.gr"; classtype:trojan-activity; sid:100004523; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ppdb.smk-ciptaskill.sch.id"; classtype:trojan-activity; sid:100004524; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pptvideotemplates.com"; classtype:trojan-activity; sid:100004525; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prestasicash.com.ar"; classtype:trojan-activity; sid:100004526; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prestigehomeautomation.net"; classtype:trojan-activity; sid:100004527; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prishaartcreations.com"; classtype:trojan-activity; sid:100004528; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"production.sparshims.com"; classtype:trojan-activity; sid:100004529; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"productprecise.com"; classtype:trojan-activity; sid:100004530; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prof-dr-ahmedalmoatasem.com"; classtype:trojan-activity; sid:100004531; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"programaoperadoronline.com.br"; classtype:trojan-activity; sid:100004532; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"project.exquitec.com"; classtype:trojan-activity; sid:100004533; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"promotoradescomplica.com.br"; classtype:trojan-activity; sid:100004534; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"promoversdubai.com"; classtype:trojan-activity; sid:100004535; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"propertiq.elin.co.za"; classtype:trojan-activity; sid:100004536; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"propertiq2.elin.co.za"; classtype:trojan-activity; sid:100004537; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prosoc.nl"; classtype:trojan-activity; sid:100004538; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prostar.priruz.co.in"; classtype:trojan-activity; sid:100004539; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prosyarmakassar.com"; classtype:trojan-activity; sid:100004540; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"provence.elin.co.za"; classtype:trojan-activity; sid:100004541; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prueba.danielluza.com"; classtype:trojan-activity; sid:100004542; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pujashoppe.in"; classtype:trojan-activity; sid:100004543; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"punchdialogues.com"; classtype:trojan-activity; sid:100004544; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"punjabdevelopersassociation.com.pk"; classtype:trojan-activity; sid:100004545; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"purefoe.top"; classtype:trojan-activity; sid:100004546; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"qadir.tickfa.ir"; classtype:trojan-activity; sid:100004547; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"qatarglobalconsulting.com"; classtype:trojan-activity; sid:100004548; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"qmsled.com"; classtype:trojan-activity; sid:100004549; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"quartier-midi.be"; classtype:trojan-activity; sid:100004550; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"querocar.com"; classtype:trojan-activity; sid:100004551; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rachmat-assuhaimi.my.id"; classtype:trojan-activity; sid:100004552; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rainbowisp.info"; classtype:trojan-activity; sid:100004553; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"raodigitalmedia.com"; classtype:trojan-activity; sid:100004554; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rarlabarchiver.ac"; classtype:trojan-activity; sid:100004555; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rasadbar.ir"; classtype:trojan-activity; sid:100004556; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rashika.ascarvalho.co.za"; classtype:trojan-activity; sid:100004557; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ratemyfenancialadvisor.com"; classtype:trojan-activity; sid:100004558; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ravenproductionsltd.com"; classtype:trojan-activity; sid:100004559; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rc.ixiaoyang.cn"; classtype:trojan-activity; sid:100004560; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"readymmade.com"; classtype:trojan-activity; sid:100004561; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"realtheprocess.co"; classtype:trojan-activity; sid:100004562; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"redchillicrackers.com"; classtype:trojan-activity; sid:100004563; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"reifenquick.de"; classtype:trojan-activity; sid:100004564; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"relaxindulge.co.nz"; classtype:trojan-activity; sid:100004565; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"renehavis.com.ua"; classtype:trojan-activity; sid:100004566; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"repatriacioncolombia.com"; classtype:trojan-activity; sid:100004567; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"res.uf1.cn"; classtype:trojan-activity; sid:100004568; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"reseller.digimitra.in"; classtype:trojan-activity; sid:100004569; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"resuco.net"; classtype:trojan-activity; sid:100004570; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rezkabum.ru"; classtype:trojan-activity; sid:100004571; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rhema.com.sg"; classtype:trojan-activity; sid:100004572; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"richancyber.info"; classtype:trojan-activity; sid:100004573; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"richmondminerals.co.zm"; classtype:trojan-activity; sid:100004574; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rinaefoundation.org.za"; classtype:trojan-activity; sid:100004575; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rinkaisystem-ht.com"; classtype:trojan-activity; sid:100004576; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"riverfox.co.za"; classtype:trojan-activity; sid:100004577; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rkcable.co.in"; classtype:trojan-activity; sid:100004578; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rkverify.securestudies.com"; classtype:trojan-activity; sid:100004579; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"roadfurylifts.com"; classtype:trojan-activity; sid:100004580; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"robertmcardle.com"; classtype:trojan-activity; sid:100004581; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"robertsinclair.net"; classtype:trojan-activity; sid:100004582; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"robinhood-sports.com"; classtype:trojan-activity; sid:100004583; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"romanianpoints.com"; classtype:trojan-activity; sid:100004584; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ronnietucker.co.uk"; classtype:trojan-activity; sid:100004585; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"roomsvc.servegate.kr"; classtype:trojan-activity; sid:100004586; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"roshan.academy"; classtype:trojan-activity; sid:100004587; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"roshnijewellery.com"; classtype:trojan-activity; sid:100004588; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rs-toolkit.mikestclair.org"; classtype:trojan-activity; sid:100004589; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rsgym.net"; classtype:trojan-activity; sid:100004590; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rubazar.pro"; classtype:trojan-activity; sid:100004591; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rubycityvietnam.com"; classtype:trojan-activity; sid:100004592; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ruch.newreadermedia.net"; classtype:trojan-activity; sid:100004593; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ruisgood.ru"; classtype:trojan-activity; sid:100004594; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ruwadalkuwait.com"; classtype:trojan-activity; sid:100004595; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rzminc.com"; classtype:trojan-activity; sid:100004596; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"s.51shijuan.com"; classtype:trojan-activity; sid:100004597; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"s.thechinesemuslim.com"; classtype:trojan-activity; sid:100004598; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sacredscentsonline.com"; classtype:trojan-activity; sid:100004599; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"safcol-colors.com"; classtype:trojan-activity; sid:100004600; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"safehubsecurity.ca"; classtype:trojan-activity; sid:100004601; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"safety.nanotechproautocare.com"; classtype:trojan-activity; sid:100004602; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sahathaikasetpan.com"; classtype:trojan-activity; sid:100004603; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"saisoftwareinc.com"; classtype:trojan-activity; sid:100004604; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"salecorner.yourpageserver.com"; classtype:trojan-activity; sid:100004605; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sandovalgraphics.com"; classtype:trojan-activity; sid:100004606; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"santebarleyshop.jakewebtechs.ml"; classtype:trojan-activity; sid:100004607; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"santyago.org"; classtype:trojan-activity; sid:100004608; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sarakem.cl"; classtype:trojan-activity; sid:100004609; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sasystemsuk.com"; classtype:trojan-activity; sid:100004610; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"savasaachi.systems"; classtype:trojan-activity; sid:100004611; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"savingchintu.com"; classtype:trojan-activity; sid:100004612; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"scarfaceindustries.com"; classtype:trojan-activity; sid:100004613; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"scglobal.co.th"; classtype:trojan-activity; sid:100004614; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"schalke04rss.de"; classtype:trojan-activity; sid:100004615; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"scheff.com"; classtype:trojan-activity; sid:100004616; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"schoolbustracker.softgig.co.ke"; classtype:trojan-activity; sid:100004617; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sec-doc-w.com"; classtype:trojan-activity; sid:100004618; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"secure-doc-reader.com"; classtype:trojan-activity; sid:100004619; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sefp-boispro.fr"; classtype:trojan-activity; sid:100004620; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"segalsmetals.elin.co.za"; classtype:trojan-activity; sid:100004621; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sellmyphonela.com"; classtype:trojan-activity; sid:100004622; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"selltechtoday.com"; classtype:trojan-activity; sid:100004623; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"senbiaojita.com"; classtype:trojan-activity; sid:100004624; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sentierodelviandante.ml"; classtype:trojan-activity; sid:100004625; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"serendibsourcing.com"; classtype:trojan-activity; sid:100004626; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"servicemhkd.myvnc.com"; classtype:trojan-activity; sid:100004627; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"servicemhkd80.myvnc.com"; classtype:trojan-activity; sid:100004628; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"serviciovirtual.com.ar"; classtype:trojan-activity; sid:100004629; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"seyranikenger.com.tr"; classtype:trojan-activity; sid:100004630; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sgessy.com.br"; classtype:trojan-activity; sid:100004631; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shaheentbfoundation.com"; classtype:trojan-activity; sid:100004632; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shahikhana.cstdevs.com"; classtype:trojan-activity; sid:100004633; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sharkrigs.com"; classtype:trojan-activity; sid:100004634; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sharpelevators.in"; classtype:trojan-activity; sid:100004635; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shembefoundation.com"; classtype:trojan-activity; sid:100004636; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shivakunwar.com.np"; classtype:trojan-activity; sid:100004637; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shoblasaathitrust.org"; classtype:trojan-activity; sid:100004638; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shooka-co.com"; classtype:trojan-activity; sid:100004639; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shop.clarostudio.ro"; classtype:trojan-activity; sid:100004640; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shop.goldspot.agency"; classtype:trojan-activity; sid:100004641; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shopsofe.com"; classtype:trojan-activity; sid:100004642; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shrushtiinfotech.com"; classtype:trojan-activity; sid:100004643; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sibernetix.fr"; classtype:trojan-activity; sid:100004644; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"siddharthpanditpautra.com"; classtype:trojan-activity; sid:100004645; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sige.brisainformatica.com.br"; classtype:trojan-activity; sid:100004646; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"signatureads.co.in"; classtype:trojan-activity; sid:100004647; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"siili.net"; classtype:trojan-activity; sid:100004648; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"simoneporzi.it"; classtype:trojan-activity; sid:100004649; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"simplithy.co.uk"; classtype:trojan-activity; sid:100004650; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sindicato1ucm.cl"; classtype:trojan-activity; sid:100004651; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sinergidwireka.com"; classtype:trojan-activity; sid:100004652; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sipahielektrik.com"; classtype:trojan-activity; sid:100004653; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"siperb.in"; classtype:trojan-activity; sid:100004654; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sistelligent.com"; classtype:trojan-activity; sid:100004655; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"site.sjc.co.ke"; classtype:trojan-activity; sid:100004656; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"skkksolo.beweiretail.com"; classtype:trojan-activity; sid:100004657; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"skyflyfares.com"; classtype:trojan-activity; sid:100004658; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"skyscan.com"; classtype:trojan-activity; sid:100004659; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smarthouseforum.ru"; classtype:trojan-activity; sid:100004660; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smarts.tj"; classtype:trojan-activity; sid:100004661; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smartzedu.com"; classtype:trojan-activity; sid:100004662; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smokeandgrowrichtour.com"; classtype:trojan-activity; sid:100004663; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smokesolutionindia.com"; classtype:trojan-activity; sid:100004664; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sobethuacademy.com"; classtype:trojan-activity; sid:100004665; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"soft.110route.com"; classtype:trojan-activity; sid:100004666; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"soft.officelabo.net"; classtype:trojan-activity; sid:100004667; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sohs.conceptechs.info"; classtype:trojan-activity; sid:100004668; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"solar.amazingtribe.lk"; classtype:trojan-activity; sid:100004669; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"solo2.dbstrony.pl"; classtype:trojan-activity; sid:100004670; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"somcorbera.cat"; classtype:trojan-activity; sid:100004671; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"somir.com.mx"; classtype:trojan-activity; sid:100004672; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"soralapps.com"; classtype:trojan-activity; sid:100004673; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sorteio.orgaostalita.com.br"; classtype:trojan-activity; sid:100004674; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sota-france.fr"; classtype:trojan-activity; sid:100004675; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sowingminerals.cl"; classtype:trojan-activity; sid:100004676; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"space.proactint.org"; classtype:trojan-activity; sid:100004677; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spaceframe.mobi.space-frame.co.za"; classtype:trojan-activity; sid:100004678; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"specfloors.net"; classtype:trojan-activity; sid:100004679; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"special-key.cf"; classtype:trojan-activity; sid:100004680; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spent.com.pl"; classtype:trojan-activity; sid:100004681; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spetsesyachtcharter.gr"; classtype:trojan-activity; sid:100004682; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spititourism.com"; classtype:trojan-activity; sid:100004683; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spittinfire.com"; classtype:trojan-activity; sid:100004684; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sports-net.de"; classtype:trojan-activity; sid:100004685; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"src1.minibai.com"; classtype:trojan-activity; sid:100004686; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sreenivasapaintingworks.com"; classtype:trojan-activity; sid:100004687; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sriglobalit.com"; classtype:trojan-activity; sid:100004688; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"srvmanos.no-ip.info"; classtype:trojan-activity; sid:100004689; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ss.monita.co.id"; classtype:trojan-activity; sid:100004690; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"staging.apparelpunch.com"; classtype:trojan-activity; sid:100004691; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"starcountry.net"; classtype:trojan-activity; sid:100004692; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"static.3001.net"; classtype:trojan-activity; sid:100004693; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"statsres.com"; classtype:trojan-activity; sid:100004694; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"statssound.com"; classtype:trojan-activity; sid:100004695; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"statsspot.com"; classtype:trojan-activity; sid:100004696; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"statsvilla.com"; classtype:trojan-activity; sid:100004697; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stattilion.bar"; classtype:trojan-activity; sid:100004698; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stiepancasetia.ac.id"; classtype:trojan-activity; sid:100004699; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stott-thompson.co.uk"; classtype:trojan-activity; sid:100004700; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stratexec.co.za"; classtype:trojan-activity; sid:100004701; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"streetdemo.yourpageserver.com"; classtype:trojan-activity; sid:100004702; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"suboldesign.com"; classtype:trojan-activity; sid:100004703; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sumerians.org"; classtype:trojan-activity; sid:100004704; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sunbrero.com.au"; classtype:trojan-activity; sid:100004705; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sunmarkholidays.com"; classtype:trojan-activity; sid:100004706; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"supermercadostia.com"; classtype:trojan-activity; sid:100004707; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"support-4-free.com"; classtype:trojan-activity; sid:100004708; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"support.clz.kr"; classtype:trojan-activity; sid:100004709; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"supportit.online"; classtype:trojan-activity; sid:100004710; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sw.yourpageserver.com"; classtype:trojan-activity; sid:100004711; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sweaty.dk"; classtype:trojan-activity; sid:100004712; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sweet-diet.com"; classtype:trojan-activity; sid:100004713; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"swentsai.com"; classtype:trojan-activity; sid:100004714; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"swiftlogisticseg.com"; classtype:trojan-activity; sid:100004715; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"swwbia.com"; classtype:trojan-activity; sid:100004716; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"syedpro.dezinetimes.com"; classtype:trojan-activity; sid:100004717; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"syracusecoffee.com"; classtype:trojan-activity; sid:100004718; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sys.pbmadu.co.id"; classtype:trojan-activity; sid:100004719; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"systemsecuritylock.com"; classtype:trojan-activity; sid:100004720; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sytraders.co"; classtype:trojan-activity; sid:100004721; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"t.honker.info"; classtype:trojan-activity; sid:100004722; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tacticohosting.com"; classtype:trojan-activity; sid:100004723; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tadoo.ca"; classtype:trojan-activity; sid:100004724; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tafsantoursandtravels.com"; classtype:trojan-activity; sid:100004725; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tallyinvoicecustomization.com"; classtype:trojan-activity; sid:100004726; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"taltus.co.uk"; classtype:trojan-activity; sid:100004727; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tapalkoedacoffee.com"; classtype:trojan-activity; sid:100004728; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tarravalleyfoods.com.au"; classtype:trojan-activity; sid:100004729; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"taurus.ug"; classtype:trojan-activity; sid:100004730; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"taxicabsrilanka.com"; classtype:trojan-activity; sid:100004731; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"taxpos.com"; classtype:trojan-activity; sid:100004732; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tc.snpsresidential.com"; classtype:trojan-activity; sid:100004733; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tcy.198424.com"; classtype:trojan-activity; sid:100004734; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tdsp.yngw518.com"; classtype:trojan-activity; sid:100004735; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tech332.synology.me"; classtype:trojan-activity; sid:100004736; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"techgms.com"; classtype:trojan-activity; sid:100004737; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"technogreen.crmmanivela.com"; classtype:trojan-activity; sid:100004738; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"technohub.searchkero.com"; classtype:trojan-activity; sid:100004739; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tecnicaencolectores.com.mx"; classtype:trojan-activity; sid:100004740; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"teduae.com"; classtype:trojan-activity; sid:100004741; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"teleargentina.com"; classtype:trojan-activity; sid:100004742; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"telescopelms.com"; classtype:trojan-activity; sid:100004743; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"telmed.cl"; classtype:trojan-activity; sid:100004744; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"temptmag.com"; classtype:trojan-activity; sid:100004745; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tennisafrica.com"; classtype:trojan-activity; sid:100004746; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tentandoserfitness.000webhostapp.com"; classtype:trojan-activity; sid:100004747; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tepresto.net.pe"; classtype:trojan-activity; sid:100004748; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.adventser.com"; classtype:trojan-activity; sid:100004749; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.letraele.es"; classtype:trojan-activity; sid:100004750; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.wanepghana.org"; classtype:trojan-activity; sid:100004751; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test1.asistencia247.com"; classtype:trojan-activity; sid:100004752; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test1.milenial.id"; classtype:trojan-activity; sid:100004753; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test1.tenplusone.my"; classtype:trojan-activity; sid:100004754; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test2.basis-web.com"; classtype:trojan-activity; sid:100004755; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test2.marrenconstruction.ie"; classtype:trojan-activity; sid:100004756; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"testing.clickitsolutionsmw.com"; classtype:trojan-activity; sid:100004757; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"testing.thinkingcorp.in"; classtype:trojan-activity; sid:100004758; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"testnew.yourpageserver.com"; classtype:trojan-activity; sid:100004759; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"teteaffiche.stephanebillon.com"; classtype:trojan-activity; sid:100004760; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tewoerd.eu"; classtype:trojan-activity; sid:100004761; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"textile.softberg.ro"; classtype:trojan-activity; sid:100004762; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"texts.bfftexts.com"; classtype:trojan-activity; sid:100004763; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"texturesbyvinita.com"; classtype:trojan-activity; sid:100004764; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tharringtonsponsorship.com"; classtype:trojan-activity; sid:100004765; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thecleaningladiespdx.com"; classtype:trojan-activity; sid:100004766; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thecreativecafe.co.uk"; classtype:trojan-activity; sid:100004767; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thefuturelife.in"; classtype:trojan-activity; sid:100004768; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thehighlightinterior.com"; classtype:trojan-activity; sid:100004769; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thehouseofpragya.com"; classtype:trojan-activity; sid:100004770; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thekassia.co.uk"; classtype:trojan-activity; sid:100004771; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thelaunchpadteam.com"; classtype:trojan-activity; sid:100004772; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thelekhak.com"; classtype:trojan-activity; sid:100004773; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thelogicalgroup.co.uk"; classtype:trojan-activity; sid:100004774; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thesummitpc.net"; classtype:trojan-activity; sid:100004775; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"theurbantutors.com"; classtype:trojan-activity; sid:100004776; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thosewebbs.com"; classtype:trojan-activity; sid:100004777; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thriveink.com"; classtype:trojan-activity; sid:100004778; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tianangdep.com"; classtype:trojan-activity; sid:100004779; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tickfood.tickme.lk"; classtype:trojan-activity; sid:100004780; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tickjobs.tickme.lk"; classtype:trojan-activity; sid:100004781; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tickmart.tickme.lk"; classtype:trojan-activity; sid:100004782; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"timegonebuy.com"; classtype:trojan-activity; sid:100004783; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tksb.net"; classtype:trojan-activity; sid:100004784; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tlcc.com.gt"; classtype:trojan-activity; sid:100004785; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"todoapp.cstdevs.com"; classtype:trojan-activity; sid:100004786; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tonydong.com"; classtype:trojan-activity; sid:100004787; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tonyzone.com"; classtype:trojan-activity; sid:100004788; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tooba.tenplusone.my"; classtype:trojan-activity; sid:100004789; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"topcell9.com"; classtype:trojan-activity; sid:100004790; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"topicsnepal.com"; classtype:trojan-activity; sid:100004791; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"toplevel.com.br"; classtype:trojan-activity; sid:100004792; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"torresquinterocorp.com"; classtype:trojan-activity; sid:100004793; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"towme.services"; classtype:trojan-activity; sid:100004794; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"toyotacollege.ac.th"; classtype:trojan-activity; sid:100004795; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tpef.lsoftdemo.com"; classtype:trojan-activity; sid:100004796; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tpke.hu"; classtype:trojan-activity; sid:100004797; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tradezone.ejuicysolutions.com"; classtype:trojan-activity; sid:100004798; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"translaterjemah.com"; classtype:trojan-activity; sid:100004799; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"travel.travelwadi.com"; classtype:trojan-activity; sid:100004800; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"travelwithmanta.co.za"; classtype:trojan-activity; sid:100004801; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"trezors.io.mahlongwa.com"; classtype:trojan-activity; sid:100004802; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"triplonet.com.br"; classtype:trojan-activity; sid:100004803; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"troki.com.co"; classtype:trojan-activity; sid:100004804; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tropics.codeleek.net"; classtype:trojan-activity; sid:100004805; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"trudelfavreau.com"; classtype:trojan-activity; sid:100004806; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tsd.jxwan.com"; classtype:trojan-activity; sid:100004807; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tulli.info"; classtype:trojan-activity; sid:100004808; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tupperware.michaelroberge.ca"; classtype:trojan-activity; sid:100004809; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"turanggaresources.com"; classtype:trojan-activity; sid:100004810; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tushartyagiji.digitalswagger.in"; classtype:trojan-activity; sid:100004811; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uat.indianfilmzone.com"; classtype:trojan-activity; sid:100004812; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ublretailerdemo.cstdevs.com"; classtype:trojan-activity; sid:100004813; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"udesk.searchkero.com"; classtype:trojan-activity; sid:100004814; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ugprs-ubih.org"; classtype:trojan-activity; sid:100004815; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ultimate-24.de"; classtype:trojan-activity; sid:100004816; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"umwelt-kirchhof.de"; classtype:trojan-activity; sid:100004817; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"unicorpbrunei.com"; classtype:trojan-activity; sid:100004818; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uniengrisb.com"; classtype:trojan-activity; sid:100004819; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"unisoftcc.com"; classtype:trojan-activity; sid:100004820; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"unitedpestsolutionstx.com"; classtype:trojan-activity; sid:100004821; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"unyazitelecom.com"; classtype:trojan-activity; sid:100004822; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"upcbpta.com"; classtype:trojan-activity; sid:100004823; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"urbane.dezinetimes.com"; classtype:trojan-activity; sid:100004824; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"useformoney.000webhostapp.com"; classtype:trojan-activity; sid:100004825; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"usmadetshirts.com"; classtype:trojan-activity; sid:100004826; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uss.ac.th"; classtype:trojan-activity; sid:100004827; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uzzepay.com.br"; classtype:trojan-activity; sid:100004828; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vanzare.cabanabrazi2.ro"; classtype:trojan-activity; sid:100004829; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vbcargo.hu"; classtype:trojan-activity; sid:100004830; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vcah.co.uk"; classtype:trojan-activity; sid:100004831; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vegadelcasero.cl"; classtype:trojan-activity; sid:100004832; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vendas.lidiacarmeli.com.br"; classtype:trojan-activity; sid:100004833; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"verify.aicosoft.com"; classtype:trojan-activity; sid:100004834; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vfocus.net"; classtype:trojan-activity; sid:100004835; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vidmattic.com"; classtype:trojan-activity; sid:100004836; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vienen.gblix.srv.br"; classtype:trojan-activity; sid:100004837; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"villamarand.com"; classtype:trojan-activity; sid:100004838; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"villatera.com"; classtype:trojan-activity; sid:100004839; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"violinstop.com"; classtype:trojan-activity; sid:100004840; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"viraltalking.com"; classtype:trojan-activity; sid:100004841; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"visions.alnisamart.com"; classtype:trojan-activity; sid:100004842; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"visualhome.cl"; classtype:trojan-activity; sid:100004843; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vitoriamodaintima.com.br"; classtype:trojan-activity; sid:100004844; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vivationdesign.com"; classtype:trojan-activity; sid:100004845; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"viveirodoiscorregos.com.br"; classtype:trojan-activity; sid:100004846; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vksales.com"; classtype:trojan-activity; sid:100004847; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vokasi.ub.ac.id"; classtype:trojan-activity; sid:100004848; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vologroup.com.br"; classtype:trojan-activity; sid:100004849; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"voteyouramerica.dekitout.com"; classtype:trojan-activity; sid:100004850; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vstsample.com"; classtype:trojan-activity; sid:100004851; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vtube.fadlymotivator.com"; classtype:trojan-activity; sid:100004852; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vvsskmodinationalschool.com"; classtype:trojan-activity; sid:100004853; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wahrewah.nl"; classtype:trojan-activity; sid:100004854; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wanepliberia.org"; classtype:trojan-activity; sid:100004855; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wanepniger.org"; classtype:trojan-activity; sid:100004856; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"weareactum.com"; classtype:trojan-activity; sid:100004857; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.eng.ubu.ac.th"; classtype:trojan-activity; sid:100004858; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.geomegasoft.net"; classtype:trojan-activity; sid:100004859; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.newinnovationtechnology.com"; classtype:trojan-activity; sid:100004860; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.smarts-works.com"; classtype:trojan-activity; sid:100004861; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.thebeessolution.com"; classtype:trojan-activity; sid:100004862; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"webgis.perumdasolo.com"; classtype:trojan-activity; sid:100004863; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"webmailwindstreamnetmessagesecureapp1rqr.ga"; classtype:trojan-activity; sid:100004864; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"webpresario.com"; classtype:trojan-activity; sid:100004865; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"website-work.com"; classtype:trojan-activity; sid:100004866; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"weinsteincounseling.com"; classtype:trojan-activity; sid:100004867; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wexfashion.com"; classtype:trojan-activity; sid:100004868; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"whcms.yourpageserver.com"; classtype:trojan-activity; sid:100004869; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"whiteglovetailgate.com"; classtype:trojan-activity; sid:100004870; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"whiteresponse.com"; classtype:trojan-activity; sid:100004871; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wi522012.ferozo.com"; classtype:trojan-activity; sid:100004872; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wikalen.co.za"; classtype:trojan-activity; sid:100004873; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wildnights.co.uk"; classtype:trojan-activity; sid:100004874; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wildtrust.mediadevstaging.com"; classtype:trojan-activity; sid:100004875; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wimbamusica.com"; classtype:trojan-activity; sid:100004876; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"windcomtechnologies.com"; classtype:trojan-activity; sid:100004877; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"winnercircle.it"; classtype:trojan-activity; sid:100004878; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wishesconcierge.com"; classtype:trojan-activity; sid:100004879; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"woezon.agency"; classtype:trojan-activity; sid:100004880; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wolfgang-brodte.de"; classtype:trojan-activity; sid:100004881; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"woodsytech.com"; classtype:trojan-activity; sid:100004882; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wordpress.saleensuporte.com.br"; classtype:trojan-activity; sid:100004883; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wozata.000webhostapp.com"; classtype:trojan-activity; sid:100004884; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wp.readhere.in"; classtype:trojan-activity; sid:100004885; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wpdemo.101clients.com.au"; classtype:trojan-activity; sid:100004886; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"writtendeer.com"; classtype:trojan-activity; sid:100004887; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ws5588.f3322.net"; classtype:trojan-activity; sid:100004888; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wyklej.pl"; classtype:trojan-activity; sid:100004889; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"x2vn.com"; classtype:trojan-activity; sid:100004890; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xia.beihaixue.com"; classtype:trojan-activity; sid:100004891; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xixaoclothing.com"; classtype:trojan-activity; sid:100004892; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xk.996is.com"; classtype:trojan-activity; sid:100004893; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xmp.myracingaccounts.com"; classtype:trojan-activity; sid:100004894; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xn--80akinnkiib6h.xn--90ais"; classtype:trojan-activity; sid:100004895; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xn--polimerbizmimarlk-rvc.com"; classtype:trojan-activity; sid:100004896; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ybom.urbanolab.com"; classtype:trojan-activity; sid:100004897; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yeichner.com"; classtype:trojan-activity; sid:100004898; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ylfpremium.com"; classtype:trojan-activity; sid:100004899; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yoast.yourpageserver.com"; classtype:trojan-activity; sid:100004900; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"youtubetrainingacademy.com"; classtype:trojan-activity; sid:100004901; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yskadvisors.com"; classtype:trojan-activity; sid:100004902; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yummyyogaudaipur.com"; classtype:trojan-activity; sid:100004903; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yzkzixun.com"; classtype:trojan-activity; sid:100004904; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"zytrox.tk"; classtype:trojan-activity; sid:100004905; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"zz.690tx.com"; classtype:trojan-activity; sid:100004906; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/64.exe"; endswith; nocase; http.host; content:"2.indexsinas.me:811"; classtype:trojan-activity; sid:100004907; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/86.exe"; endswith; nocase; http.host; content:"2.indexsinas.me:811"; classtype:trojan-activity; sid:100004908; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c64.exe"; endswith; nocase; http.host; content:"2.indexsinas.me:811"; classtype:trojan-activity; sid:100004909; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/downfiles/file.exe"; endswith; nocase; http.host; content:"akwer03.top"; classtype:trojan-activity; sid:100004910; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe"; endswith; nocase; http.host; content:"amumufree.weebly.com"; classtype:trojan-activity; sid:100004911; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/proxyi.exe"; endswith; nocase; http.host; content:"analogx.com"; classtype:trojan-activity; sid:100004912; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004913; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/densjons/bro/downloads/rew.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004914; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dvdfv/anjj/downloads/jami.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004915; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jpavelski/chpock/downloads/4.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004916; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jpavelski/chpock/downloads/6.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004917; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/clr.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004918; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/clr3.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004919; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/instaler.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004920; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/installer.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004921; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/updatej.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004922; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/updatev.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004923; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/work.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004924; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player2012/rumpa1/downloads/component.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004925; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player2012/rumpa1/downloads/nordvpnsetup.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004926; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player2012/rumpa1/downloads/regsvc.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004927; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skygaming/updates/downloads/update.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004928; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/001.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004929; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1488.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004930; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1_cr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004931; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1cr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004932; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1fc2d.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004933; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/26a5.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004934; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/6e7_2021-01-19_18-04.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004935; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/abjects.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004936; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/attached.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004937; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/b7f2c.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004938; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/battletext.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004939; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/bkghj_nowin.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004940; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/bsdasdasd333.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004941; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004942; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build_makros.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004943; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build_silent.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004944; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build_sup.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004945; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildcmobiler.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004946; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildcmobiler.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004947; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildcr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004948; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildss.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004949; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/clientnik.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004950; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/clientrevers.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004951; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/dcrat.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004952; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/dllservices.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004953; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/dllservices2.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004954; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/exe_morris.mcdermott.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004955; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/hans.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004956; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/hulu.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004957; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelfive.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004958; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelfour.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004959; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelone.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004960; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelthree.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004961; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/inteltwo.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004962; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/jjuufksfn.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004963; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/kleiman.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004964; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/lucky_fixed.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004965; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/notepadplus.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004966; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/osiris_qqkz_nauto.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004967; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/out.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004968; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/out.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004969; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/pacbe_bin.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004970; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/putty.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004971; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/rockethcd.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004972; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/scvhost900.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004973; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/sessionwin.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004974; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/siliculose.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004975; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/statemobi.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004976; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/stealers.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004977; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/stealers2.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004978; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/stgedo.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004979; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/svcperf.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004980; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/symptomaticshon5.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004981; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/taurjok.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004982; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/taurusbabac.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004983; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/telekiller.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004984; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/updateanddr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004985; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/updateandr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004986; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/vhajeja.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004987; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/word.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004988; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/www.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004989; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/xlsd.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004990; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/teaserex/tease/downloads/b_kfmhkk172.bin"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004991; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/teaserex/tease/downloads/macro_xmprohiq27.bin"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004992; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hmatrix/data/hack1226.exe"; endswith; nocase; http.host; content:"cd.textfiles.com"; classtype:trojan-activity; sid:100004993; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100004994; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/816070119281131570/816070273254162442/all.txt"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100004995; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/823355293043261515/823692323514482788/inquiry_-_rfq_hmg_u66_sw5558_pdf.iso"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100004996; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/razor/rzr-winner_intro.zip"; endswith; nocase; http.host; content:"chiptune.com"; classtype:trojan-activity; sid:100004997; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz"; endswith; nocase; http.host; content:"cloudme.com"; classtype:trojan-activity; sid:100004998; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar"; endswith; nocase; http.host; content:"cloudme.com"; classtype:trojan-activity; sid:100004999; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/meteoradminz/hidden-tear/zip/master"; endswith; nocase; http.host; content:"codeload.github.com"; classtype:trojan-activity; sid:100005000; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/"; endswith; nocase; http.host; content:"colfincas.com"; classtype:trojan-activity; sid:100005001; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kr.bin"; endswith; nocase; http.host; content:"d.ttr3p.com"; classtype:trojan-activity; sid:100005002; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qz0h69.pdf"; endswith; nocase; http.host; content:"deepfreedom.org"; classtype:trojan-activity; sid:100005003; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/frm0reseen/prntscrnofamzorderid.jpg.exe"; endswith; nocase; http.host; content:"drive.google.com.it-barcelona.com"; classtype:trojan-activity; sid:100005004; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=0byfg0_4xbjgnwvuyev9ltuh4rmm"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005005; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=13vodfxml9fg8kcnexuafh64dzmnqv8ch"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005006; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=14l8sj2dqo04ozum88tvuy74yfcwk5fnf"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005007; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=15bd1dksg4pkrxehoczi7e0uok4vblz4e"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005008; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=167imxqgc8ehepa1gisxa6q6ifcjxceox"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005009; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=17xvn-rlhei5n9f6unuqqb_wh84u4w5cx"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005010; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1_vz7veeec-juwt23g9d9wjuid2kusew7"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005011; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1a-herfdxr6xamxeabcdao0mqw9bimrig"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005012; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1aphk_vq7gtn368zxpd5bg5rv8nk0bnhn"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005013; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1aqhdbelnscyjygigfopt7x_oafaqgwg1"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005014; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1cf8d3ljsfn3toddczqtkkbhrd5g00cjg"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005015; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005016; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1cynoc3t9rp-xvso3jcmx_prwppp8u-dv"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005017; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1d8fykmpewc_4yurihjh_cdehkdp_nuik"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005018; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1dgcin9vevl9f63cbhbkmc_gpa2b0zlrh"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005019; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1do7c-fjuscbueu0un2dbxe3-pnwdufb_"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005020; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1eqnvgn0qkunp7t6crk8oj7_e7rh5qxwi"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005021; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1f3kxfcvbpaaexgnchpvmyoxkcdmickjj"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005022; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1gsmk1t_yigh7jablxkuhbmmh93vwgikb"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005023; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1hmud67vsl-shqddzpxniqmyj92iynyis"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005024; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ik-x4_bsr5dbocs9j1ryg1ybw75fqu8t"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005025; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1in-rhdrss2qsjqj8xffb1hbwi9znp4je"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005026; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1iwc-lf99neesk6mvvo2al4futbmyoiev"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005027; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005028; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1jgykopezccdq3q5qprmkl1zdl1auymkq"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005029; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1lplk8rixxuboakkmut_qgzn92bkoulna"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005030; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1mug8m5o6kl_bx68x8cuxmzhn0gxnc7ki"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005031; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1n8o4hbvi7o9ks9jqhofny7okposfaz4y"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005032; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1nindqtjvyyzz-qk-hqa9gls5ccwhys-e"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005033; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1nio_cdsggt4zv1kdrpubrfpd0pzsyffd"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005034; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1nsyqwodoi1t9-i29arbxwe7fkafjydsz"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005035; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1nwctbvlr_1bewpvgdbmuhnny-zi6kp1l"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005036; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1o2dcrdwgu91moicmterbx9avcl9cavy1"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005037; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1o4lh97cmfnztr_hkocnwiucy5l6oskpy"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005038; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1oabvvnazifkxktvt-izbcdqpb7dm6nrw"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005039; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1oys1nkexzsuci6pfghowlbpwaw-_btxk"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005040; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1prxtn1juykhcr_9ilw-vtirv5anyeoej"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005041; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1pzywywxrwl2plk82nuodgvmcckpzrufb"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005042; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1q0uxhnzfs4j91rxz5x45iov8tjkomsgr"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005043; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1q9vzzhu-n9cu8ixdginpzaxxgvb1lrjv"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005044; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1qk8_jouqbnrfkky7x1aqunudfyl6fjii"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005045; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1qxv3i0dwy_cdx2bm1lqx6ef0qjwmhbpk"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005046; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1qzmi4jvter0_cwexcp4grjhxvr7lep5k"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005047; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1r-kstukxtxjqxlwypgd764dw-puj_7fz"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005048; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1r-zn6o95qzworq8e4fhz637bfuoxayby"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005049; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1rcykjynwhlc487sn1vwcsmjse_ctlrox"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005050; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1rdxnm_kxegbwlojlucu4qiff7kyax3oi"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005051; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1s9tu6akdxquy7cezquljtb2yarci99ab"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005052; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1serasql3bw7nc-sllzyrishnhodmefyf"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005053; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1shuxviwx167elbuz8mfcjc2bk99zzov_"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005054; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1sjzynfvpwdcwsr1p3w_q8-6ktsqiwadx"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005055; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1sogqqdapgyioillf7u62widsprhw3cjh"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005056; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1t1bd_itjnhsmozdl9was0gouehujm1fn"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005057; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1tfra7fzrjl2vdj73hcmcru5ynuqmz61g"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005058; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1tsmbsikhechaqedk6nktlfzasus_tghw"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005059; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ur9qebooqc-mjcdzn9wcbavocumdlosm"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005060; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1uvtmu3-hcryp3rskqnpkiodcjuchtz55"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005061; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1v4ima0sfnmboxmyoklp4g0_uehaj22x2"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005062; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1vevblftithattyguwyjot1p0wptg7l5t"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005063; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1vl9gje5llm7ja3dadct9okr6bzbmijc3"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005064; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1vvvujegfrgey39w6y3ybwpptl1guwf8a"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005065; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ws2ptumptku-imi9sv_k5g4fhsx30gnl"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005066; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1wtxdbb1fm9ozinx09a63-o-tn4ssgzpw"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005067; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1xbeqbw67xz4iqpu8dgmdrlkpa6kzotes"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005068; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1xdpxbb9gifdrugqxmg2_06xygbfq-x2k"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005069; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005070; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1xu9wvl5ktadwfxd94dicuej6y_j6kf8-"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005071; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1yawygcfjs9inzoiwagqfcn3utaywxmwi"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005072; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ycggxvacywdkt3jvqbpxpz9cyjcwvl_c"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005073; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1yhflwpk3yeyrdhlhanctlind-5j24iwv"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005074; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ys9rupdqvnhvrngizxfzstzcos0dlx-u"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005075; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1z6wmqtnaa-jtpm5bqkb3ebi_btjcvmat"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005076; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1zbclvhabervgfryoyqklo4_oe6icd8sr"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005077; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1zor7cinphnazfkldkthucb2h8jthlh9d"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005078; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1zsghzos5foggoqxq6w12xeqvanhccdyk"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005079; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=148pt6v0nlg8yoim7w6in7dpixkzaacbg&export=download&authuser=0"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005080; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/1zilg/"; endswith; nocase; http.host; content:"drpamelageorge.com"; classtype:trojan-activity; sid:100005081; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/qcgfmfvh/"; endswith; nocase; http.host; content:"drpamelageorge.com"; classtype:trojan-activity; sid:100005082; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/downloads/emclick.zip"; endswith; nocase; http.host; content:"e-mudhra.com"; classtype:trojan-activity; sid:100005083; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/informatica/informatica-actief/hoofdstuk1/extrasoftware/getallen.exe"; endswith; nocase; http.host; content:"evertkok.nl"; classtype:trojan-activity; sid:100005084; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/informatica/informatica-actief/hoofdstuk2/software/hksetup.exe"; endswith; nocase; http.host; content:"evertkok.nl"; classtype:trojan-activity; sid:100005085; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/register/phpcaptcha/images/19dnqhg1p/sbhvtqlysxhxn/"; endswith; nocase; http.host; content:"expeditionquest.com"; classtype:trojan-activity; sid:100005086; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/register/phpcaptcha/images/35egphpl5uzpvdmz9bncmvon3p/"; endswith; nocase; http.host; content:"expeditionquest.com"; classtype:trojan-activity; sid:100005087; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x/"; endswith; nocase; http.host; content:"expeditionquest.com"; classtype:trojan-activity; sid:100005088; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf/"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100005089; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf//"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100005090; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf///"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100005091; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf////"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100005092; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web1/m00/8f/36/o4ybafy-2m2aarfzaahkaiik5pi122.exe"; endswith; nocase; http.host; content:"file.elecfans.com"; classtype:trojan-activity; sid:100005093; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4cb7cebd101/e5fb4174-ab23-48e8-bf05-e80ec5fa2169.xls"; endswith; nocase; http.host; content:"files.constantcontact.com"; classtype:trojan-activity; sid:100005094; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ee304de9001/7e533e73-e272-4a44-9d9e-138cab64bf19.docx"; endswith; nocase; http.host; content:"files.constantcontact.com"; classtype:trojan-activity; sid:100005095; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe"; endswith; nocase; http.host; content:"gist.githubusercontent.com"; classtype:trojan-activity; sid:100005096; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/"; endswith; nocase; http.host; content:"hqdecig.com"; classtype:trojan-activity; sid:100005097; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/suy/"; endswith; nocase; http.host; content:"hsecaravans.co.uk"; classtype:trojan-activity; sid:100005098; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/19/items/startup_20210219/startup.txt"; endswith; nocase; http.host; content:"ia801802.us.archive.org"; classtype:trojan-activity; sid:100005099; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/online-timer-kvhxz/ilxl/"; endswith; nocase; http.host; content:"ie-best.net"; classtype:trojan-activity; sid:100005100; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/64.exe"; endswith; nocase; http.host; content:"indonesias.me:9998"; classtype:trojan-activity; sid:100005101; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c64.exe"; endswith; nocase; http.host; content:"indonesias.me:9998"; classtype:trojan-activity; sid:100005102; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ebook/cs17.exe"; endswith; nocase; http.host; content:"jcedu.org"; classtype:trojan-activity; sid:100005103; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/1"; endswith; nocase; http.host; content:"jointings.org"; classtype:trojan-activity; sid:100005104; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/2"; endswith; nocase; http.host; content:"jointings.org"; classtype:trojan-activity; sid:100005105; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/3"; endswith; nocase; http.host; content:"jointings.org"; classtype:trojan-activity; sid:100005106; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/3/2/8/8/3288864/karma_koin_codes.exe"; endswith; nocase; http.host; content:"karmakoincodes.weebly.com"; classtype:trojan-activity; sid:100005107; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dg/etrac/nf4emwz/"; endswith; nocase; http.host; content:"kotakwarna.co.id"; classtype:trojan-activity; sid:100005108; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/down/affiliate/kuaizip_setup_10029.exe"; endswith; nocase; http.host; content:"kuaizip.com"; classtype:trojan-activity; sid:100005109; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linuxforensicscode.zip"; endswith; nocase; http.host; content:"linuxforensicsbook.com.s3.amazonaws.com"; classtype:trojan-activity; sid:100005110; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/k/big5/1giof6/"; endswith; nocase; http.host; content:"minpic.de"; classtype:trojan-activity; sid:100005111; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v1/ws2/:gianni1962/:ie6setup/ie6setup.exe"; endswith; nocase; http.host; content:"my.cloudme.com"; classtype:trojan-activity; sid:100005112; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/components/aacenc.exe"; endswith; nocase; http.host; content:"nch.com.au"; classtype:trojan-activity; sid:100005113; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/components/doxillionsetup.exe"; endswith; nocase; http.host; content:"nch.com.au"; classtype:trojan-activity; sid:100005114; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/4/1/6/6/4166984/keygen.exe"; endswith; nocase; http.host; content:"newyarlfm.weebly.com"; classtype:trojan-activity; sid:100005115; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/efficiency-all-iuehb/bjug3jyhuyilwhcqs3ykssaqqw7tpyvmypb91wtzdbluio1ekope5vrbbcx8zhdar9yt/"; endswith; nocase; http.host; content:"nhipcauytevietnhat.com"; classtype:trojan-activity; sid:100005116; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yws/api/personal/file/web3a243b322cf83ca7cae587a92916bac7?method=download&inline=true&sharekey=649ac0bb5d5b13d15cbf50b2609e193a"; endswith; nocase; http.host; content:"note.youdao.com"; classtype:trojan-activity; sid:100005117; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spreadsheets/osv_stock_valuation-sample-dummy.exe"; endswith; nocase; http.host; content:"oldschoolvalue.s3.amazonaws.com"; classtype:trojan-activity; sid:100005118; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=81445407a9f44d37!197&authkey=apuz15kftzlrysa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005119; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=81445407a9f44d37!198&authkey=ags5rgb15_esaqq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005120; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=b4c15a27928f663b!229&authkey=aiarm61fwmd_npe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005121; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=b4c15a27928f663b!230&authkey=ancu1eabetiubzg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005122; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=b4c15a27928f663b!231&authkey=ai9h3sk_luxran0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005123; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=!aase4ma0-vo_cls&cid=4df11eda676a355f&resid=4df11eda676a355f!140"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005124; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=!akd6uxvljtlvpxu&cid=4df11eda676a355f&resid=4df11eda676a355f!130"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005125; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005126; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=adf5p_kn8rjf29y&cid=34224e3e49966a27&resid=34224e3e49966a27%211732"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005127; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=013413cfbbbcfae4&resid=13413cfbbbcfae4%211656&authkey=ai9wpcp_k9okgk4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005128; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c!111&authkey=aemrwamaaaiyyjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005129; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c%21111&authkey=aemrwamaaaiyyjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005130; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0175cdbe2d2944c5&resid=175cdbe2d2944c5%21107&authkey=al6uptubjmmugo0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005131; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!157&authkey=aagcsm7chqez6uu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005132; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!158&authkey=amsoii5nr6pomhc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005133; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21157&authkey=aagcsm7chqez6uu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005134; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21158&authkey=amsoii5nr6pomhc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005135; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=023f39d21b700310&resid=23f39d21b700310%211204&authkey=an2utsuaopn0fhc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005136; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211177&authkey=am0i98nwgvzgqvq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005137; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211183&authkey=anv33trmzmi5cko"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005138; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005139; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=03286724f74117f9&resid=3286724f74117f9!1179&authkey=acr-_rvrgp39kk4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005140; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=03286724f74117f9&resid=3286724f74117f9%211179&authkey=acr-_rvrgp39kk4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005141; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=032ce380af7ab389&resid=32ce380af7ab389!210&authkey=akcynbtc0h3ui7e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005142; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=032ce380af7ab389&resid=32ce380af7ab389%21210&authkey=akcynbtc0h3ui7e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005143; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005144; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005145; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005146; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005147; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005148; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!273&authkey=ae2m69e5nu3rrea"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005149; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21273&authkey=ae2m69e5nu3rrea"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005150; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21274&authkey=acqg0akutoxdpgo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005151; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0e26b39babdbf63c&resid=e26b39babdbf63c%21137&authkey=anshbgxg1_qa2h4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005152; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242!309&authkey=alfe36drai1zmwc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005153; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242%21309&authkey=alfe36drai1zmwc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005154; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21123&authkey=aco5hiwppfq8vrw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005155; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21124&authkey=ai6sfa2z-kqf6x0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005156; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=115bffdddaa40942&resid=115bffdddaa40942!540&authkey=aamhnqgfdtdsoxk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005157; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=115bffdddaa40942&resid=115bffdddaa40942%21540&authkey=aamhnqgfdtdsoxk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005158; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005159; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=13b301f1cb48f8cd&resid=13b301f1cb48f8cd%21106&authkey=aiae3olcs4lulz4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005160; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005161; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7%21118&authkey=antash3ig98aqte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005162; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e!348&authkey=ahnjoxa4ufoxa54"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005163; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e%21348&authkey=ahnjoxa4ufoxa54"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005164; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!126&authkey=ad4yflrisq6d82g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005165; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!129&authkey=apqoonsrce0ari4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005166; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21126&authkey=ad4yflrisq6d82g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005167; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21129&authkey=apqoonsrce0ari4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005168; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=196e83840ef8c152&resid=196e83840ef8c152%21107&authkey=ah2lhjyd0ukjcve"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005169; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1a162e8fcaaef5fa&resid=1a162e8fcaaef5fa%215495&authkey=aic7rmj1cm3rt2w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005170; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558!8182&authkey=aautw8tvzxr5v3a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005171; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558%218182&authkey=aautw8tvzxr5v3a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005172; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1cbd82dd55d70086&resid=1cbd82dd55d70086%212526&authkey=aogaboensav3jrg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005173; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1dbdf62bc3c2b05b&resid=1dbdf62bc3c2b05b!134&authkey=ape6bhxn7c89z60"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005174; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005175; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005176; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005177; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2184cd6093fdd997&resid=2184cd6093fdd997!136&authkey=agsnq9l7ncf4p-w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005178; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2184cd6093fdd997&resid=2184cd6093fdd997!137&authkey=aawcijw8fv4m-8g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005179; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2184cd6093fdd997&resid=2184cd6093fdd997%21136&authkey=agsnq9l7ncf4p-w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005180; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2184cd6093fdd997&resid=2184cd6093fdd997%21137&authkey=aawcijw8fv4m-8g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005181; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!123&authkey=am1rcmkppbht8v0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005182; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!124&authkey=am5sltharf-j_cc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005183; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!125&authkey=acgvgbbuowodg4c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005184; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21122&authkey=aa2f8su-5bfjlvs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005185; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005186; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0&c=3ii9gcd&r=7azia71ojgc8rxd0dmkukm&k=7s1&s=htgxfkpr86ttvokhkcn3enmimk12ewqfiglklz23spd"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005187; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21124&authkey=am5sltharf-j_cc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005188; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21125&authkey=acgvgbbuowodg4c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005189; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21154&authkey=alkjikpdfxvm8po"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005190; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21155&authkey=afu-yax_gxxddoe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005191; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21156&authkey=alqvv8nixrvsqrk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005192; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f!191&authkey=ajvumpkzpla_nca"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005193; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f%21191&authkey=ajvumpkzpla_nca"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005194; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=26bbd7d5ad88dd29&resid=26bbd7d5ad88dd29%21115&authkey=acipfa3gbiqqcvu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005195; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=26f87316a7e32bb5&resid=26f87316a7e32bb5%21106&authkey=aepqo5hlkxn1t1k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005196; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2831401bbac0235e&resid=2831401bbac0235e%211037&authkey=aagnkp6l76yhrlo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005197; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!182&authkey=apogh8yf-fj8xvk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005198; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!183&authkey=am4thhgmi0nlxei"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005199; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!185&authkey=akttgkvu39ugyte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005200; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21182&authkey=apogh8yf-fj8xvk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005201; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21183&authkey=am4thhgmi0nlxei"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005202; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21185&authkey=akttgkvu39ugyte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005203; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2894380eb084b79e&resid=2894380eb084b79e%21253&authkey=aimqerwvuylzjga"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005204; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2992e4d36c2a7dae&resid=2992e4d36c2a7dae%21132&authkey=af05vsjkocy8lly"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005205; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2b6e98d9e0cf1a17&resid=2b6e98d9e0cf1a17!2471&authkey=ai5r4hqy9i0g1qs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005206; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2b6e98d9e0cf1a17&resid=2b6e98d9e0cf1a17%212471&authkey=ai5r4hqy9i0g1qs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005207; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c1abc526306a6e1&resid=2c1abc526306a6e1%21106&authkey=adjthwhvjkbioc0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005208; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21109&authkey=aopcxq3owfiv620"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005209; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21114&authkey=ajzoj0ujggsnxlo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005210; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21115&authkey=aglznnsx71tbe9e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005211; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37!183&authkey=akon9i9zzhusiuk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005212; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37%21183&authkey=akon9i9zzhusiuk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005213; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f01a497b687285e&resid=2f01a497b687285e!734&authkey=aiumuxtp3phppy4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005214; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f01a497b687285e&resid=2f01a497b687285e%21734&authkey=aiumuxtp3phppy4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005215; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!116&authkey=!abwledjhfsqwap4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005216; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!121&authkey=!aa0qbuuss-wb13w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005217; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1!119&authkey=apmakx2cqb9rimu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005218; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21118&authkey=acrl2iiem-zjer8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005219; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21119&authkey=apmakx2cqb9rimu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005220; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2ffaa48ef4bec51a&resid=2ffaa48ef4bec51a%21107&authkey=aiohrvrc3uuo_cw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005221; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=30e33fc2c147c72f&resid=30e33fc2c147c72f!2742&authkey=ajviks-nvgb4gqs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005222; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=30e33fc2c147c72f&resid=30e33fc2c147c72f!2743&authkey=ao4um908kkhavqg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005223; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=30e33fc2c147c72f&resid=30e33fc2c147c72f%212742&authkey=ajviks-nvgb4gqs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005224; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=30e33fc2c147c72f&resid=30e33fc2c147c72f%212743&authkey=ao4um908kkhavqg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005225; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!320&authkey=aooujzuf408dclw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005226; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!321&authkey=almpxnbtsbzauna"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005227; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21320&authkey=aooujzuf408dclw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005228; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21321&authkey=almpxnbtsbzauna"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005229; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3164ddeba70d2263&resid=3164ddeba70d2263%21106&authkey=afkvqrm4zoor8qq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005230; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=31771958ea3373a1&resid=31771958ea3373a1%21108&authkey=aiofxduo9rdb_-o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005231; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=34207675f7506d94&resid=34207675f7506d94%21137&authkey=angxnhqpe2x5koc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005232; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005233; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005234; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005235; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c!139&authkey=ap4bbakgkikau-a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005236; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c%21139&authkey=ap4bbakgkikau-a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005237; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!198&authkey=acyz0gbpl6bp9mo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005238; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!199&authkey=admaszabh84m8ou"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005239; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e%21198&authkey=acyz0gbpl6bp9mo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005240; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e%21199&authkey=admaszabh84m8ou"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005241; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!152&authkey=am09sv26njxzyn0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005242; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!153&authkey=ajs0jkoeqkqjrze"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005243; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21152&authkey=am09sv26njxzyn0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005244; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21153&authkey=ajs0jkoeqkqjrze"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005245; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3a1715e2cb964f25&resid=3a1715e2cb964f25%213713&authkey=aortxmfnibnoqkk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005246; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237!963&authkey=aewqwrtr9szefem"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005247; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237!965&authkey=aaayllvoxl-rbdi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005248; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237!966&authkey=apsg26pur_hpk6k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005249; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237!971&authkey=amfm0a4mjjup0o8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005250; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237!973&authkey=acfwvefa0v7myb4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005251; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237!975&authkey=ajreyx8ik2l5uxm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005252; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237!976&authkey=alpmp7w4cfupsvu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005253; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237!977&authkey=adju1b_cnsxdxni"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005254; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21965&authkey=aaayllvoxl-rbdi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005255; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21966&authkey=apsg26pur_hpk6k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005256; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21971&authkey=amfm0a4mjjup0o8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005257; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21975&authkey=ajreyx8ik2l5uxm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005258; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21976&authkey=alpmp7w4cfupsvu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005259; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21977&authkey=adju1b_cnsxdxni"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005260; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21978&authkey=agg7tntwzgctq7s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005261; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21432&authkey=aa_npsupyqb2kge"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005262; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21435&authkey=admsjhgpkbtcqzs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005263; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005264; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f%21154&authkey=aasj15d0g_p2pog"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005265; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f!134&authkey=aaipzy8nllirlky"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005266; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f%21134&authkey=aaipzy8nllirlky"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005267; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=40cbf21d67b770f7&resid=40cbf21d67b770f7%21140&authkey=ah0uewz9k7-lzd0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005268; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2!106&authkey=aoigmqhuw6vqijm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005269; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2%21106&authkey=aoigmqhuw6vqijm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005270; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21108&authkey=akr9cesktucbqik"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005271; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21109&authkey=adzxmpjk-etbkjq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005272; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=45f0213456d899c0&resid=45f0213456d899c0%211133&authkey=alwgkm79xod8hpy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005273; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa!450&authkey=ahw0j-cme0jg6pw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005274; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa%21450&authkey=ahw0j-cme0jg6pw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005275; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=489dd700ea74963a&resid=489dd700ea74963a%21206&authkey=acgkmxuk000jse8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005276; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=489dd700ea74963a&resid=489dd700ea74963a%21210&authkey=aotjil_l-s-xh1c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005277; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ada4e22fff3e13&resid=48ada4e22fff3e13%21421&authkey=acd1sidm8c5fk0y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005278; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13805&authkey=ae-zbfo2uwln_gg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005279; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13806&authkey=aakiq-ymrjjodns"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005280; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113805&authkey=ae-zbfo2uwln_gg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005281; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113806&authkey=aakiq-ymrjjodns"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005282; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4ab7eafa48707b54&resid=4ab7eafa48707b54%21105&authkey=amb4gnkdn8igw8y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005283; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4b676ea3ff139b93&resid=4b676ea3ff139b93!133&authkey=amfix63glytflgo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005284; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21127&authkey=ablg20r-aat_ob4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005285; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21131&authkey=akbwlkrrtso_bqm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005286; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4df11eda676a355f&resid=4df11eda676a355f!130&authkey=!akd6uxvljtlvpxu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005287; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b!108&authkey=anbjpqxg-iwr4g8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005288; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b%21108&authkey=anbjpqxg-iwr4g8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005289; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005290; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005291; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21105&authkey=ajkwu0e9dzantl8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005292; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21107&authkey=apd9um4_12-kpe0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005293; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21116&authkey=anbj_rrcgyturjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005294; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21119&authkey=amrs3-3hsvcmtfs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005295; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21158&authkey=aodderdrnvhruts"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005296; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21161&authkey=agdsfxdnre82jjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005297; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21192&authkey=agn2xvrvup-xvtg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005298; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21206&authkey=ai1r52mhtbdnm2y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005299; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21247&authkey=ae6weny1fa4pday"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005300; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21252&authkey=aphl0oi4r6lrty0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005301; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21257&authkey=afnyvqwcghnyoas"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005302; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21265&authkey=abxqdhlwiurjvve"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005303; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21271&authkey=ae5qwlr5ceeptmy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005304; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21272&authkey=ahrqeoaynibwt14"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005305; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21275&authkey=af_sgsaxsmaxg7i"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005306; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21289&authkey=angyngbqixtrjaa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005307; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005308; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005309; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21306&authkey=ahpivoukyerzcjy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005310; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21314&authkey=aex2uv2-eiofr8q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005311; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21332&authkey=ad0jmjxgbaebvbm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005312; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21335&authkey=ah0vupcfbdfa6g4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005313; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21357&authkey=ap8sswuqjjjexho"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005314; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21366&authkey=aoblpmbmx7o_v18"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005315; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21379&authkey=air-bsjj46et47q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005316; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21389&authkey=aduenohuq_rbyhm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005317; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21391&authkey=aa15sw51njbn_na"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005318; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21392&authkey=abp0heeg6ybn0lk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005319; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21393&authkey=aa1pmur8sy8xtwe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005320; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212718&authkey=aie0v1d-cusuabi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005321; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212725&authkey=aanrz9et3bym3lc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005322; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212728&authkey=ahsmbkltfrwgqjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005323; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!395&authkey=alwvub_yhtogjxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005324; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!398&authkey=abaa_tjd7ohh4so"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005325; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!406&authkey=aarnp48wumgu6tq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005326; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!415&authkey=aglzsd6-g0nzj7s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005327; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!420&authkey=akk5droung_ecww"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005328; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!440&authkey=ai7-dpr11wnzyq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005329; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21395&authkey=alwvub_yhtogjxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005330; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21398&authkey=abaa_tjd7ohh4so"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005331; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21406&authkey=aarnp48wumgu6tq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005332; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21415&authkey=aglzsd6-g0nzj7s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005333; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21420&authkey=akk5droung_ecww"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005334; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21440&authkey=ai7-dpr11wnzyq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005335; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211121&authkey=al_fmezwfay4za4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005336; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211122&authkey=anz_q5njlanv2mu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005337; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21110&authkey=akars6koxqzdwgi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005338; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21112&authkey=aadare1gec7nzy8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005339; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005340; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8&em=2"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005341; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d%21109&authkey=adriswrtwdpbuc8&em=2"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005342; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53c5e6b8f6893887&resid=53c5e6b8f6893887!802&authkey=aapuufivkn2zwu8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005343; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!106&authkey=anzlf1ksptbqok8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005344; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!107&authkey=ag4dr58jrjuxfyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005345; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21106&authkey=anzlf1ksptbqok8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005346; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21107&authkey=ag4dr58jrjuxfyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005347; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005348; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005349; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5521b68dc17baf21&resid=5521b68dc17baf21%21129&authkey=ajdr2dbh-9h63wa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005350; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005351; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613!157&authkey=an55tjzt-9vbjfy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005352; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613%21156&authkey=agiuawekkbxb_4o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005353; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=55c9feaf3907aae5&resid=55c9feaf3907aae5%21208&authkey=adwuyrapfdzkyoa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005354; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950!280&authkey=advq4p3xhfhinq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005355; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950%21280&authkey=advq4p3xhfhinq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005356; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5629da828892367d&resid=5629da828892367d!803&authkey=aphjbq-bsg7ohpc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005357; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21383&authkey=adldpuaya7kj1dk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005358; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21384&authkey=alsuxvtsof32vea"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005359; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3599&authkey=am4yicme6lrjpki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005360; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3604&authkey=al6pb71mtq4jr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005361; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213599&authkey=am4yicme6lrjpki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005362; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213604&authkey=al6pb71mtq4jr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005363; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b!68197&authkey=aowpm7ocl_21-oc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005364; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b%2168197&authkey=aowpm7ocl_21-oc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005365; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=59389d626d829e8c&resid=59389d626d829e8c%212940&authkey=anx1ngd27vqeiwo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005366; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211568&authkey=aemrnwoi75oflva"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005367; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211572&authkey=aelz-gxlrxcwtnc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005368; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211573&authkey=ahksfdvda0doles"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005369; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005370; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005371; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!407&authkey=adnh8af-rvoxlcc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005372; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21406&authkey=aeyeq5j9zfepgai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005373; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21407&authkey=adnh8af-rvoxlcc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005374; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21892&authkey=apwphufzjdtsedw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005375; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005376; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21121&authkey=adjzlorvgx_ezhq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005377; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21123&authkey=ancfnepawtbmnug"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005378; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21124&authkey=ao7bknnuodxtfua"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005379; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21126&authkey=an6sswp8an1kfoe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005380; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6196314c52185efc&resid=6196314c52185efc%21106&authkey=ape4rx1hrtmrxxe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005381; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!490&authkey=aljraz5ktivqax4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005382; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!491&authkey=aopwdha2wyjx0aa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005383; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!492&authkey=akwg8p5adkpjm5w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005384; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!493&authkey=aeg__7wcf7esydo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005385; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21490&authkey=aljraz5ktivqax4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005386; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21491&authkey=aopwdha2wyjx0aa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005387; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21492&authkey=akwg8p5adkpjm5w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005388; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21493&authkey=aeg__7wcf7esydo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005389; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005390; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005391; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1094&authkey=anqjzd7pr18fu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005392; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211094&authkey=anqjzd7pr18fu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005393; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21129&authkey=ak5szbnikeklmzk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005394; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21132&authkey=ad3ia_1wkq0lyd4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005395; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6608a4dea9ff5918&resid=6608a4dea9ff5918%21399&authkey=aoya7flv_s9toxo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005396; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2%21505&authkey=ag7xi3lcnvi_hji"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005397; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad!1421&authkey=adixg2-asekemjw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005398; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad%211421&authkey=adixg2-asekemjw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005399; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213096&authkey=aob-cm9vv6erxqg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005400; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213097&authkey=abcuevfyu6pdw70"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005401; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=69b503a3f081a183&resid=69b503a3f081a183%21111&authkey=aazm9wlg1rvgzoc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005402; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!112&authkey=aasndgbcwol3mys"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005403; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!113&authkey=ak3tzu1lg4uuh5m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005404; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21112&authkey=aasndgbcwol3mys"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005405; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21113&authkey=ak3tzu1lg4uuh5m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005406; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21108&authkey=ameouv2jdxo5obw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005407; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21119&authkey=aazzzrl7mv2xbwq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005408; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a7b40a2bc530c6c&resid=6a7b40a2bc530c6c%21112&authkey=afuov36rbymlvxm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005409; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3!118&authkey=aepf8f3mfmlsng0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005410; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3%21118&authkey=aepf8f3mfmlsng0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005411; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b61e983f930f79f&resid=6b61e983f930f79f!540&authkey=ap2n5w41ifew0i8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005412; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7!1154&authkey=acnbdscb8-rbmcu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005413; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7%211154&authkey=acnbdscb8-rbmcu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005414; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21106&authkey=apvhok6edhtogfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005415; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21115&authkey=amc_k1nnlywdc4i"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005416; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=724b5c509337556e&resid=724b5c509337556e%21908&authkey=agcbb3nakpteyam"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005417; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7285f51e65036769&resid=7285f51e65036769%21264&authkey=akyjvrz006qlble"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005418; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21243&authkey=apivjmxivosek60"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005419; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21256&authkey=adljht0ogfq775k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005420; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21260&authkey=aig6cydr4_e-qj8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005421; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21262&authkey=ak4fiz1-a1ks8rg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005422; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21264&authkey=aizkjymvlgqwpte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005423; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=77518d098ad4dfb0&resid=77518d098ad4dfb0%21939&authkey=akzqobxxxn89z34"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005424; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005425; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005426; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21117&authkey=aivf1ddcvvu22em"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005427; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21210&authkey=agpl0pgvft8faaa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005428; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21211&authkey=anxavz-oaf9pv_c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005429; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005430; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005431; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005432; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21120&authkey=ajj7ueqjvobgfum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005433; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c1fc7da38ab958e&resid=7c1fc7da38ab958e!146&authkey=aktmjqz8n4s_sbm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005434; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125575&authkey=ahnmpmvzshrwoyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005435; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125579&authkey=amhnrbwecb4hp_k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005436; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5295&authkey=aasceqj1mdodeuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005437; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5296&authkey=ank3vz5syaf6bny"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005438; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5298&authkey=albzyizuqczfv9s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005439; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215295&authkey=aasceqj1mdodeuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005440; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215296&authkey=ank3vz5syaf6bny"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005441; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215298&authkey=albzyizuqczfv9s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005442; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7d109f249b512466&resid=7d109f249b512466!543&authkey=acqc4xjghclmwbs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005443; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b!183&authkey=aggjy50pjuecoli"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005444; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21181&authkey=ama3betib0dac18"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005445; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21183&authkey=aggjy50pjuecoli"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005446; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!443&authkey=abue79u9di9axjm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005447; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!444&authkey=abzxvycu0ggtmg8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005448; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0%21443&authkey=abue79u9di9axjm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005449; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0%21444&authkey=abzxvycu0ggtmg8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005450; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7e81645429ac5a22&resid=7e81645429ac5a22%21105&authkey=aa691jwf5wqi80c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005451; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7fed4fbea32e3c1e&resid=7fed4fbea32e3c1e%21107&authkey=aeoxfycpolifch0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005452; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=806bac90dc071edf&resid=806bac90dc071edf!105&authkey=!ao7jyz6-licb8hq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005453; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=81c2d8b116274e17&resid=81c2d8b116274e17%21107&authkey=aaqw-t4dx2sbvda"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005454; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=82977114b1af209d&resid=82977114b1af209d!220&authkey=abuin5vdedjughm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005455; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=860a0980486c93fa&resid=860a0980486c93fa!303&authkey=!agcmlab4r6syfvk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005456; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21164&authkey=agbeiinncf8ok_4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005457; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21165&authkey=aiof8rdvxglnm-c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005458; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4!2402&authkey=amigiam45mt6jia"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005459; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4%212402&authkey=amigiam45mt6jia"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005460; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=890837b4e4ca07c6&resid=890837b4e4ca07c6%21289&authkey=abujc0akmtbsxf4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005461; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8983011c6ecfb1d8&resid=8983011c6ecfb1d8%21132&authkey=ah0vja7wpyfjj84"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005462; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8a1574ed0cecd68a&resid=8a1574ed0cecd68a%21395&authkey=ane01evt0sz-1wk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005463; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8c77cee60e33a6b1&resid=8c77cee60e33a6b1%21106&authkey=af8h8jn801bjnbk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005464; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8ca507baa15fdb5c&resid=8ca507baa15fdb5c!213&authkey=acyrjlhflcrypae"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005465; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8ffd8cbd6540c065&resid=8ffd8cbd6540c065!822&authkey=acfj7bbrmktj1i0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005466; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!243&authkey=aeiqd4ihuqopwm8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005467; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21276&authkey=afig5wsljtdc33s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005468; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005469; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25!130&authkey=ais_g9dqoddonsc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005470; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005471; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21109&authkey=akr1n3qxtmnttuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005472; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21113&authkey=ajpvf1h89sqstti"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005473; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!289&authkey=aoiy68zx8ddnjhe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005474; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!290&authkey=afn1bhvmpaicari"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005475; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!291&authkey=aknqfhnxttsrvz4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005476; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!297&authkey=agy0f-5almc6_ia"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005477; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!298&authkey=ajiut2kebcaycok"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005478; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21288&authkey=ag9wi9pub-q4jly"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005479; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21289&authkey=aoiy68zx8ddnjhe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005480; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21290&authkey=afn1bhvmpaicari"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005481; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21291&authkey=aknqfhnxttsrvz4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005482; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21295&authkey=afvy6r0mspzeb6m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005483; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21297&authkey=agy0f-5almc6_ia"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005484; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21298&authkey=ajiut2kebcaycok"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005485; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21299&authkey=agmfs3scdvngolm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005486; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21105&authkey=ah9x7rn0p03kd_m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005487; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21110&authkey=ammswulpdsjeu4w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005488; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3!107&authkey=ac-m9dlvo5l7wfk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005489; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3%21107&authkey=ac-m9dlvo5l7wfk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005490; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=96a54b19ff5f6bab&resid=96a54b19ff5f6bab%21107&authkey=anxv07ez7s5sh_k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005491; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21410&authkey=acwug6bewxk0pli"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005492; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21411&authkey=aj8o1fcvfhibmlm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005493; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=96fd249b957988a2&resid=96fd249b957988a2%211303&authkey=ah_etf1fqofknue"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005494; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935!778&authkey=aaezyk4ypt-elma"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005495; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21772&authkey=akeozmv0aafqlbg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005496; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21774&authkey=aly_m3fnrvh6dfq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005497; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21775&authkey=abblpjxi4mwomgs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005498; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21777&authkey=ahmuwqi4jg8rvho"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005499; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=98103c88c2d68867&resid=98103c88c2d68867!773&authkey=akptbml43mi4ufc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005500; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211925&authkey=amhhfhcsigeue9w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005501; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211927&authkey=an_3paqpemptbvm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005502; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211953&authkey=abdfqiyruwplpo0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005503; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211954&authkey=aok-srkhxjazccy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005504; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21172&authkey=ahharhcv0fmn5fm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005505; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21173&authkey=aecb3qcquacvzhi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005506; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21174&authkey=afv7cprqwxezgsi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005507; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005508; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005509; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005510; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9fb622acb27482ef&resid=9fb622acb27482ef%211197&authkey=aeacibxy2zlyxro"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005511; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005512; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005513; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005514; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340!997&authkey=akw6btyej2zht08"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005515; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340%21997&authkey=akw6btyej2zht08"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005516; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a1c8c8055848b889&resid=a1c8c8055848b889!111&authkey=agzlftsgr4lspvo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005517; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a2cd2cdb93584d7e&resid=a2cd2cdb93584d7e%21106&authkey=aeifpqbwo1s3dyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005518; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211064&authkey=apebndb6tstxywi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005519; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211065&authkey=aca4_dggi5gbbfs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005520; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211067&authkey=ae-3ej9zzj4ibhw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005521; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211069&authkey=agx6b8qjt_clm-o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005522; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4acaf66051e469e&resid=a4acaf66051e469e!189&authkey=alnhzcg0wzhusdc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005523; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a502994ea313f5c7&resid=a502994ea313f5c7%21215&authkey=aiydvejv0l8stbs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005524; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21!6053&authkey=agfh0ahstj7rrki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005525; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21%216053&authkey=agfh0ahstj7rrki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005526; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005527; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a76c2c9b2bbef5ec&resid=a76c2c9b2bbef5ec%21141&authkey=akcfuxzfafd_c9c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005528; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21414&authkey=akf9uwwkitvhrvc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005529; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21415&authkey=ag_5kthuezprnoy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005530; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21416&authkey=airlma-pycgfkyc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005531; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21419&authkey=ab1-sgyv2gibyey"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005532; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21422&authkey=acphsmdy415izjg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005533; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21424&authkey=afvfwz5uvde1pui"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005534; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a819c72315838312&resid=a819c72315838312%21112&authkey=abl1vflnfw3nrgi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005535; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=aa4e252db942faec&resid=aa4e252db942faec%21168&authkey=anlnjo7xnwtswuk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005536; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ae28961c75435487&resid=ae28961c75435487%21106&authkey=alph5awcis8r9iw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005537; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992!113&authkey=agh9q_zzyjjcspc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005538; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992%21113&authkey=agh9q_zzyjjcspc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005539; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=af84ebf13dd5499c&resid=af84ebf13dd5499c!167&authkey=anqr_yvn_hdh2_e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005540; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308!2152&authkey=abutaac83l5utks"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005541; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308%212152&authkey=abutaac83l5utks"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005542; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b0fddd36b3843d3b&resid=b0fddd36b3843d3b!561&authkey=abhena0pdghcveu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005543; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b0fddd36b3843d3b&resid=b0fddd36b3843d3b%21561&authkey=abhena0pdghcveu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005544; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21650&authkey=aht-wbxsofyx33u"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005545; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21651&authkey=aebbyk6sevdmzgm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005546; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21652&authkey=afsw5wahxo5kwjy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005547; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1c3a5ef115e135c&resid=b1c3a5ef115e135c%216219&authkey=ahr7bklirbub0pc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005548; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b2289382b9cf7ba8&resid=b2289382b9cf7ba8%21106&authkey=ajwobaztcbbpxmy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005549; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21120&authkey=aozmspl2dqkgkgy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005550; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21123&authkey=aj18p0rtfbtwa84"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005551; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21139&authkey=ahwfjvw4zmjukeo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005552; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21140&authkey=aksvfpmrfqrrggw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005553; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21141&authkey=acznh6clby0qyww"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005554; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21142&authkey=ajf7j1rr3d7jcxy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005555; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21143&authkey=ahs21wnsqb_vu9w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005556; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b50c4248502103d0&resid=b50c4248502103d0%21107&authkey=alf1nley7ja4dbq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005557; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6!164&authkey=adfsfcdaw3biboy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005558; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6%21164&authkey=adfsfcdaw3biboy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005559; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b7cb31db66675eb4&resid=b7cb31db66675eb4%21922&authkey=aghayyucvwey7lg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005560; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b86046e8cbd4254b&resid=b86046e8cbd4254b%21115&authkey=agwstptwpaquleg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005561; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b!7521&authkey=ablt9zdyq2d4rb0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005562; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b%217521&authkey=ablt9zdyq2d4rb0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005563; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b90c1aa3b6cd0326&resid=b90c1aa3b6cd0326%21471&authkey=aoil8ra4oc4s_2m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005564; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b9690a1860a591d0&resid=b9690a1860a591d0%21161&authkey=aehawjpwf6tqtm8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005565; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b!246&authkey=afyrchdutalpu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005566; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b%21246&authkey=afyrchdutalpu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005567; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=bf83d9247c2329e0&resid=bf83d9247c2329e0%211108&authkey=absaw-bpqrc6mpq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005568; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214199&authkey=adgqe8qiyu92bqm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005569; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214200&authkey=adqtju8i3nmlgai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005570; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214201&authkey=ahqber27s7gg8kk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005571; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019!1251&authkey=act34eizpzjugfa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005572; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019%211251&authkey=act34eizpzjugfa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005573; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1337&authkey=afnvu1fsuczht5e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005574; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1338&authkey=ajngambosws75_c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005575; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1340&authkey=al1ay3fbtude6d8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005576; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1342&authkey=acpr_htn2jtaxfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005577; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1343&authkey=abodysrxu9l2xxu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005578; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1344&authkey=aozerppd6mnokwy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005579; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1345&authkey=aevvyhonxhtcdh0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005580; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1346&authkey=achrnf5vlov1gf4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005581; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1347&authkey=al-zge-ttvr921s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005582; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211337&authkey=afnvu1fsuczht5e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005583; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211338&authkey=ajngambosws75_c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005584; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211340&authkey=al1ay3fbtude6d8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005585; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211342&authkey=acpr_htn2jtaxfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005586; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211343&authkey=abodysrxu9l2xxu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005587; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211344&authkey=aozerppd6mnokwy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005588; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211345&authkey=aevvyhonxhtcdh0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005589; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211346&authkey=achrnf5vlov1gf4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005590; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211347&authkey=al-zge-ttvr921s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005591; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c701663053a57d59&resid=c701663053a57d59%211009&authkey=ahowgkak7j0p2q8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005592; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21486&authkey=amy4euf_rrlcykc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005593; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21489&authkey=ako3anwfnqfohnc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005594; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c7c32628aba70e70&resid=c7c32628aba70e70%21114&authkey=agdy8xpuh32sluw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005595; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c80630c4d385fb9d&resid=c80630c4d385fb9d%21286&authkey=amgaucv8bld_5qs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005596; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c8b0c7dc2b2570c5&resid=c8b0c7dc2b2570c5!122&authkey=aa4yfqt4cckzxhe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005597; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c8b0c7dc2b2570c5&resid=c8b0c7dc2b2570c5%21122&authkey=aa4yfqt4cckzxhe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005598; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21546&authkey=aa6q-ryiifnet5m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005599; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21547&authkey=aipm8qnwbgo4yga"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005600; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!355&authkey=aajjwf_sm4xdqdk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005601; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!357&authkey=alw3vqqxz6myrle"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005602; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21354&authkey=aa_ukeour7rex1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005603; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21355&authkey=aajjwf_sm4xdqdk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005604; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21357&authkey=alw3vqqxz6myrle"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005605; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca897bdd16fc7940&resid=ca897bdd16fc7940%21106&authkey=aniklpt8vtlahbg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005606; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2!109&authkey=ac4gxwjoopafr9a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005607; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2%21109&authkey=ac4gxwjoopafr9a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005608; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cbb66cac420484bc&resid=cbb66cac420484bc!10968&authkey=aj9bjkobu-rlnaw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005609; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!742&authkey=akbxju17f8g0r2s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005610; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!744&authkey=adak4zftd0yhhhs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005611; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21742&authkey=akbxju17f8g0r2s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005612; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21744&authkey=adak4zftd0yhhhs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005613; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!872&authkey=ap9hchztywo8zuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005614; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!874&authkey=alkzcbxz-dscgum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005615; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!875&authkey=aka55ybdhqnoc6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005616; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21872&authkey=ap9hchztywo8zuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005617; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21874&authkey=alkzcbxz-dscgum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005618; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21875&authkey=aka55ybdhqnoc6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005619; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d2f3748954f6f8a8&resid=d2f3748954f6f8a8%21119&authkey=aex5s9uoun2zps0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005620; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1029&authkey=ann3uz8huqi7ogw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005621; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1030&authkey=aeqnasuksxccax4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005622; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1031&authkey=acxtarrhbwrqt20"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005623; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1032&authkey=aemitbkn-vma9yk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005624; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1033&authkey=abiydifgst6musa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005625; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1035&authkey=ahd_ichsrf8ok_u"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005626; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1038&authkey=anxf-kuw1jn9-8y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005627; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211029&authkey=ann3uz8huqi7ogw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005628; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211030&authkey=aeqnasuksxccax4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005629; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211031&authkey=acxtarrhbwrqt20"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005630; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211032&authkey=aemitbkn-vma9yk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005631; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211035&authkey=ahd_ichsrf8ok_u"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005632; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!191&authkey=ajl2uegqunsgc3q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005633; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!192&authkey=acd_hx4bka3z0nw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005634; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21191&authkey=ajl2uegqunsgc3q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005635; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21192&authkey=acd_hx4bka3z0nw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005636; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005637; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21109&authkey=adnbm6mekgzvvh8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005638; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!141&authkey=alya4infudqs53o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005639; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!142&authkey=aiemnxi-s-5vrz0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005640; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21141&authkey=alya4infudqs53o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005641; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21142&authkey=aiemnxi-s-5vrz0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005642; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21142&authkey=aiemnxi-s-5vrz0&c=3ii9gcd&r=5onulz3wldybwlmup37su3&k=7s1&s=kzymn52eroemh1tamvmlsfsn9jtvwguukky5hlxcfgw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005643; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=db0fc77df51690e1&resid=db0fc77df51690e1%21802&authkey=apefr8w_rdk--pe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005644; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=db5548cd728f142b&resid=db5548cd728f142b%21187&authkey=aansxudby0o7uwq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005645; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=db62f747c6d887d0&resid=db62f747c6d887d0%21111&authkey=ai2guftczvfehs4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005646; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dcd65237fcd1a1a9&resid=dcd65237fcd1a1a9%21162&authkey=aprqs0hugnfo6uq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005647; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7527&authkey=aipybipwht56um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005648; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7530&authkey=am9p2ic6zdkgfmy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005649; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7532&authkey=aonjnubquvon_uk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005650; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217527&authkey=aipybipwht56um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005651; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217530&authkey=am9p2ic6zdkgfmy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005652; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217532&authkey=aonjnubquvon_uk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005653; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21107&authkey=akrabrcroiddkxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005654; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21115&authkey=ad1ncwtj_zcjsh0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005655; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21132&authkey=akpbxohbtjebyn4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005656; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21150&authkey=aevazjbqnu7cmjs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005657; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21160&authkey=aiendf-9lyln0x0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005658; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e1065ab3e86a5fc2&resid=e1065ab3e86a5fc2%211443&authkey=apybkcvf4iwxp_q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005659; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e3ddc3980f743711&resid=e3ddc3980f743711%21795&authkey=aptivsvyk2we5xc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005660; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21745&authkey=ah1i_jo73zgdxpc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005661; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21746&authkey=ag1mhwlznwdxpw0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005662; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e43694f4bd6f68d1&resid=e43694f4bd6f68d1!563&authkey=aj8ovsob9ll6r-c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005663; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!509&authkey=akmdyqkzcsuf_gg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005664; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!511&authkey=agfs0q7dz7os1lu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005665; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c%21511&authkey=agfs0q7dz7os1lu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005666; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e54ea4e0368d023b&resid=e54ea4e0368d023b%21106&authkey=aozas6g9pm0fzvq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005667; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21349&authkey=ae9ea8jdsa7vmom"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005668; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21350&authkey=ao-vuexoihzj7da"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005669; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2!142&authkey=ais88uad5aom6qu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005670; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2%21142&authkey=ais88uad5aom6qu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005671; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e86539a3497e46a2&resid=e86539a3497e46a2!120&authkey=amd6o5flalahjsy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005672; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e86539a3497e46a2&resid=e86539a3497e46a2%21120&authkey=amd6o5flalahjsy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005673; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e97110434470423e&resid=e97110434470423e%21113&authkey=afowclex54if0g0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005674; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005675; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005676; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211215&authkey=ac1jr_bieufz0ai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005677; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211219&authkey=akgo75rmvr4khlc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005678; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ebacca5dec27fd20&resid=ebacca5dec27fd20%2118735&authkey=ajfyl1mzidnylc8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005679; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21113&authkey=aovavpmokd2jrns"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005680; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21116&authkey=aadnj5xyfasugu8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005681; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ef04dd7f0a6a5f7c&resid=ef04dd7f0a6a5f7c%21142&authkey=aad-nuysvlhc-i4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005682; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!202&authkey=ah1gjq8j29darw4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005683; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!203&authkey=af8xr99mrqp8um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005684; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!204&authkey=ad0nbzlscbg-0sa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005685; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21202&authkey=ah1gjq8j29darw4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005686; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21203&authkey=af8xr99mrqp8um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005687; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21204&authkey=ad0nbzlscbg-0sa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005688; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21489&authkey=ads_gff3tjkd0w0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005689; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21490&authkey=aj_rld7xooge6aw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005690; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21492&authkey=ahdb75ptd1_uc8e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005691; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f06038a5f7dbd6d6&resid=f06038a5f7dbd6d6%215498&authkey=aiozi3z5qzdysmu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005692; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f293cebb54e5ea71&resid=f293cebb54e5ea71%21293&authkey=aha74rsqiuewnpq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005693; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21566&authkey=aevafh7rydhi19k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005694; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21581&authkey=agx0b8ho87w4uie"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005695; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21582&authkey=af-9_xwysl1o7-c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005696; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21598&authkey=ah-gkc-b7fa8h-g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005697; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21599&authkey=aajunhe1ex_-zta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005698; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!216&authkey=alslscyemd7hr_o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005699; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!223&authkey=ajbtso2laio00ao"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005700; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21216&authkey=alslscyemd7hr_o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005701; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f50a3aff00683adc&resid=f50a3aff00683adc%21108&authkey=ac44gtgp13l9xpw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005702; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f50a3aff00683adc&resid=f50a3aff00683adc%21139&authkey=aovmqh4ookdlkty"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005703; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f79e41c0e32d3314&resid=f79e41c0e32d3314%211182&authkey=aiqtptberyvlgqk&em=2%22"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005704; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806!1368&authkey=anphh1fijhvzv6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005705; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806%211368&authkey=anphh1fijhvzv6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005706; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382!159&authkey=ai4_8srrzf48hw0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005707; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382%21159&authkey=ai4_8srrzf48hw0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005708; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fb2177c192eed796&resid=fb2177c192eed796%21124&authkey=abotnmdhu_tg7bc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005709; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fd50774e5ce0e314&resid=fd50774e5ce0e314%21778&authkey=aoxb2vhhz3qodiu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005710; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fe85161c3947f2c1&resid=fe85161c3947f2c1%211441&authkey=agb6c1ecr91svrw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005711; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e!192&authkey=ab_lrrmyxmcfrjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005712; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e%21192&authkey=ab_lrrmyxmcfrjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005713; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!693&authkey=agcpkhnewfte_yc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005714; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!694&authkey=aa5jqzjsp0esr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005715; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21693&authkey=agcpkhnewfte_yc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005716; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21694&authkey=aa5jqzjsp0esr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005717; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!330&authkey=adxnzkb0a09pizw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005718; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!334&authkey=agsvox_t7qim4ta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005719; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!335&authkey=ach14e6omcghwgg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005720; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21330&authkey=adxnzkb0a09pizw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005721; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21333&authkey=aielwtaiuvcttlm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005722; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005723; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raw/yqvsvlvq"; endswith; nocase; http.host; content:"pastebin.com"; classtype:trojan-activity; sid:100005724; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/llc/mwcacs65xienqdp/"; endswith; nocase; http.host; content:"pierreconsulting.info"; classtype:trojan-activity; sid:100005725; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bayesian-forecasting-amj5e/s5hqmf6/"; endswith; nocase; http.host; content:"pioneiraagronegocio.com.br"; classtype:trojan-activity; sid:100005726; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/uploads/2020/10/skoda22.jpg"; endswith; nocase; http.host; content:"procrossover.ru"; classtype:trojan-activity; sid:100005727; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/uploads/2020/10/skodaqq.jpg"; endswith; nocase; http.host; content:"procrossover.ru"; classtype:trojan-activity; sid:100005728; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/zzcoiatsr5wujrwagsgbnm2wkjxldvgu/"; endswith; nocase; http.host; content:"qjbutterflyevents.co.za"; classtype:trojan-activity; sid:100005729; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/order+acknowledgement+bc202374++stock++20021+dem+p4.ace"; endswith; nocase; http.host; content:"quen.s3.us-east-2.amazonaws.com"; classtype:trojan-activity; sid:100005730; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/purchasing+ordersigned+contractinv-30067121.ace"; endswith; nocase; http.host; content:"quen.s3.us-east-2.amazonaws.com"; classtype:trojan-activity; sid:100005731; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arntsonl/calc_security_poc/master/dll/calc.dll"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005732; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bero1985/berotinypascal/e34bd4164f4b7c27e7cf667dffd9274d33d6dfbe/bin/btpc.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005733; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/evil-coder66/defendercontrol/main/defendercontrol.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005734; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fuzzbunch/fuzzbunch/master/payloads/doublepulsar-1.3.1.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005735; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005736; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/malwares/webshell/master/ajax_php%20command%20shell.rar"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005737; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/myqseeaccount/one/main/one.htm"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005738; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/realtek25556/rhti2/gh-pages/90hfnvo69vk2ot.bmp"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005739; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/secwiki/windows-kernel-exploits/master/ms15-076/binary/trebuchet.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005740; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/secwiki/windows-kernel-exploits/master/ms16-098/bfill.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005741; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tennc/webshell/master/other/small_shell.txt"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005742; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player/launch/2017/09/12/da5f9a1c23034353852750488feeaf36.exe"; endswith; nocase; http.host; content:"res.yeshen.com"; classtype:trojan-activity; sid:100005743; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pro/dl/q05z91"; endswith; nocase; http.host; content:"sendspace.com"; classtype:trojan-activity; sid:100005744; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ey4lpx8rx.zip"; endswith; nocase; http.host; content:"shribharatvatika.com"; classtype:trojan-activity; sid:100005745; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/site/stormqk/dn/stormagent.apk?attredirects=0"; endswith; nocase; http.host; content:"sites.google.com"; classtype:trojan-activity; sid:100005746; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6ca94027662tilxa4p/base.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005747; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005748; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6cd19c87f44r9fomit/base64jef.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005749; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6e2cbda22efxk3t7x2/base64.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005750; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6e2f6c8c5adup2yiwx/basejefin.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005751; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6eab37b8dadmy1gx7c/base3.5.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005752; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6eb2aa215a8cvwcf6s/fudjs.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005753; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aamus8/go.jpeg"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005754; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c7921a2cf26cunjcgvm/nanocoregomes.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005755; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005756; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a-nurse-ss8d9/z/"; endswith; nocase; http.host; content:"technologydistilled.com"; classtype:trojan-activity; sid:100005757; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/databases/merit.php"; endswith; nocase; http.host; content:"truemerit.io"; classtype:trojan-activity; sid:100005758; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/23.exe"; endswith; nocase; http.host; content:"tsrv4.ws"; classtype:trojan-activity; sid:100005759; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crisanar/defis/jek_crackme1.7.zip"; endswith; nocase; http.host; content:"users.skynet.be"; classtype:trojan-activity; sid:100005760; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gnuboard/data/scan/amowvegfrt9ja/"; endswith; nocase; http.host; content:"vniel.co.kr"; classtype:trojan-activity; sid:100005761; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gnuboard/data/scan/fu6jvxzzs46uqlp7l/"; endswith; nocase; http.host; content:"vniel.co.kr"; classtype:trojan-activity; sid:100005762; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kolya/.f/root/net.mit.edu/net/user/chris/winnt/mit_agenda2a.doc"; endswith; nocase; http.host; content:"web.mit.edu"; classtype:trojan-activity; sid:100005763; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kolya/.f/root/net.mit.edu/sipb/user/kolya/afs/root.afs/net/user/chris/winnt/mit_agenda2a.doc"; endswith; nocase; http.host; content:"web.mit.edu"; classtype:trojan-activity; sid:100005764; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/136_140/flt_shovemydiscoupyourarse.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100005765; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/136_140/kb%5efr_ouverture.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100005766; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/136_140/kb^fr_ouverture.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100005767; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/146_150/bc_memories_from_the_mcp.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100005768; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/151_155/tidex_-_short_stuff.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100005769; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syria-files/attach/222/222051_instruction.zip"; endswith; nocase; http.host; content:"wikileaks.org"; classtype:trojan-activity; sid:100005770; rev:1;)
-alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/common/yz.vbs"; endswith; nocase; http.host; content:"yp.hnggzyjy.cn"; classtype:trojan-activity; sid:100005771; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.225.24"; classtype:trojan-activity; sid:100000185; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.233.147"; classtype:trojan-activity; sid:100000186; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.235.57"; classtype:trojan-activity; sid:100000187; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.249.21"; classtype:trojan-activity; sid:100000188; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110.35.4.2"; classtype:trojan-activity; sid:100000189; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"110fss.net"; classtype:trojan-activity; sid:100000190; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.118.111.207"; classtype:trojan-activity; sid:100000191; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.118.41.173"; classtype:trojan-activity; sid:100000192; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.118.88.61"; classtype:trojan-activity; sid:100000193; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.119.245.114"; classtype:trojan-activity; sid:100000194; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.125.67.125"; classtype:trojan-activity; sid:100000195; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.160.112.142"; classtype:trojan-activity; sid:100000196; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.162.224.14"; classtype:trojan-activity; sid:100000197; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.163.50.120"; classtype:trojan-activity; sid:100000198; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.165.21.195"; classtype:trojan-activity; sid:100000199; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.165.28.234"; classtype:trojan-activity; sid:100000200; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.17.186.194"; classtype:trojan-activity; sid:100000201; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.170.84.182"; classtype:trojan-activity; sid:100000202; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.170.86.133"; classtype:trojan-activity; sid:100000203; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.172.164.104"; classtype:trojan-activity; sid:100000204; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.176.182.149"; classtype:trojan-activity; sid:100000205; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.179.153.69"; classtype:trojan-activity; sid:100000206; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.179.243.126"; classtype:trojan-activity; sid:100000207; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.182.232.18"; classtype:trojan-activity; sid:100000208; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.177.85"; classtype:trojan-activity; sid:100000209; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.23.84"; classtype:trojan-activity; sid:100000210; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.230.136"; classtype:trojan-activity; sid:100000211; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.27.9"; classtype:trojan-activity; sid:100000212; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.185.48.248"; classtype:trojan-activity; sid:100000213; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.103.114"; classtype:trojan-activity; sid:100000214; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.103.122"; classtype:trojan-activity; sid:100000215; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.103.13"; classtype:trojan-activity; sid:100000216; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.103.66"; classtype:trojan-activity; sid:100000217; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.104.141"; classtype:trojan-activity; sid:100000218; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.104.165"; classtype:trojan-activity; sid:100000219; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.106.128"; classtype:trojan-activity; sid:100000220; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.106.19"; classtype:trojan-activity; sid:100000221; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.106.48"; classtype:trojan-activity; sid:100000222; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.121.222"; classtype:trojan-activity; sid:100000223; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.121.223"; classtype:trojan-activity; sid:100000224; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.121.228"; classtype:trojan-activity; sid:100000225; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.123.18"; classtype:trojan-activity; sid:100000226; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.123.184"; classtype:trojan-activity; sid:100000227; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.123.197"; classtype:trojan-activity; sid:100000228; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.123.200"; classtype:trojan-activity; sid:100000229; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.123.23"; classtype:trojan-activity; sid:100000230; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.26.173"; classtype:trojan-activity; sid:100000231; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.26.243"; classtype:trojan-activity; sid:100000232; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.38.8.81"; classtype:trojan-activity; sid:100000233; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.61.52.53"; classtype:trojan-activity; sid:100000234; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.73.99.162"; classtype:trojan-activity; sid:100000235; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.91.185.131"; classtype:trojan-activity; sid:100000236; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.92.63.24"; classtype:trojan-activity; sid:100000237; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"111.93.169.90"; classtype:trojan-activity; sid:100000238; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.105.117.227"; classtype:trojan-activity; sid:100000239; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.111.100.236"; classtype:trojan-activity; sid:100000240; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.111.108.184"; classtype:trojan-activity; sid:100000241; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.111.31.175"; classtype:trojan-activity; sid:100000242; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.122.36.108"; classtype:trojan-activity; sid:100000243; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.123.200.47"; classtype:trojan-activity; sid:100000244; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.132.134.106"; classtype:trojan-activity; sid:100000245; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.159.108.96"; classtype:trojan-activity; sid:100000246; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.170.124.75"; classtype:trojan-activity; sid:100000247; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.170.233.9"; classtype:trojan-activity; sid:100000248; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.186.210.211"; classtype:trojan-activity; sid:100000249; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.186.96.252"; classtype:trojan-activity; sid:100000250; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.187.91.117"; classtype:trojan-activity; sid:100000251; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.214.127.42"; classtype:trojan-activity; sid:100000252; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.187.19"; classtype:trojan-activity; sid:100000253; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.236.77"; classtype:trojan-activity; sid:100000254; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.43.27"; classtype:trojan-activity; sid:100000255; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.52.145"; classtype:trojan-activity; sid:100000256; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.225.82.4"; classtype:trojan-activity; sid:100000257; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.118.229"; classtype:trojan-activity; sid:100000258; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.176.167"; classtype:trojan-activity; sid:100000259; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.195.104"; classtype:trojan-activity; sid:100000260; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.202.111"; classtype:trojan-activity; sid:100000261; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.205.96"; classtype:trojan-activity; sid:100000262; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.47.235"; classtype:trojan-activity; sid:100000263; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.67.193"; classtype:trojan-activity; sid:100000264; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.226.92.34"; classtype:trojan-activity; sid:100000265; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.228.100.15"; classtype:trojan-activity; sid:100000266; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.228.180.95"; classtype:trojan-activity; sid:100000267; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.228.79.114"; classtype:trojan-activity; sid:100000268; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.228.79.137"; classtype:trojan-activity; sid:100000269; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.229.178.109"; classtype:trojan-activity; sid:100000270; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.229.188.28"; classtype:trojan-activity; sid:100000271; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.229.199.19"; classtype:trojan-activity; sid:100000272; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.234.134.244"; classtype:trojan-activity; sid:100000273; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.234.16.252"; classtype:trojan-activity; sid:100000274; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.234.194.178"; classtype:trojan-activity; sid:100000275; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.234.216.151"; classtype:trojan-activity; sid:100000276; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.234.218.202"; classtype:trojan-activity; sid:100000277; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.235.149.73"; classtype:trojan-activity; sid:100000278; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.235.188.86"; classtype:trojan-activity; sid:100000279; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.236.126.177"; classtype:trojan-activity; sid:100000280; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.236.171.69"; classtype:trojan-activity; sid:100000281; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.236.228.21"; classtype:trojan-activity; sid:100000282; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.141.241"; classtype:trojan-activity; sid:100000283; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.144.226"; classtype:trojan-activity; sid:100000284; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.197.144"; classtype:trojan-activity; sid:100000285; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.230.192"; classtype:trojan-activity; sid:100000286; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.75.157"; classtype:trojan-activity; sid:100000287; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.237.89.82"; classtype:trojan-activity; sid:100000288; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.143.135"; classtype:trojan-activity; sid:100000289; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.17.120"; classtype:trojan-activity; sid:100000290; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.190.207"; classtype:trojan-activity; sid:100000291; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.194.18"; classtype:trojan-activity; sid:100000292; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.227.228"; classtype:trojan-activity; sid:100000293; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.238.73.181"; classtype:trojan-activity; sid:100000294; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.240.184.162"; classtype:trojan-activity; sid:100000295; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.240.216.17"; classtype:trojan-activity; sid:100000296; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.242.106.228"; classtype:trojan-activity; sid:100000297; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.242.18.128"; classtype:trojan-activity; sid:100000298; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.242.2.247"; classtype:trojan-activity; sid:100000299; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.243.115.183"; classtype:trojan-activity; sid:100000300; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.245.12.89"; classtype:trojan-activity; sid:100000301; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.245.5.141"; classtype:trojan-activity; sid:100000302; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.245.8.24"; classtype:trojan-activity; sid:100000303; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.246.162.50"; classtype:trojan-activity; sid:100000304; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.246.180.49"; classtype:trojan-activity; sid:100000305; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.100.14"; classtype:trojan-activity; sid:100000306; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.121.39"; classtype:trojan-activity; sid:100000307; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.14.135"; classtype:trojan-activity; sid:100000308; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.161.45"; classtype:trojan-activity; sid:100000309; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.191.118"; classtype:trojan-activity; sid:100000310; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.214.146"; classtype:trojan-activity; sid:100000311; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.240.226"; classtype:trojan-activity; sid:100000312; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.248.76"; classtype:trojan-activity; sid:100000313; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.81.173"; classtype:trojan-activity; sid:100000314; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.82.122"; classtype:trojan-activity; sid:100000315; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.247.89.81"; classtype:trojan-activity; sid:100000316; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.248.148.90"; classtype:trojan-activity; sid:100000317; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.248.197.164"; classtype:trojan-activity; sid:100000318; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.248.44.153"; classtype:trojan-activity; sid:100000319; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.109.217"; classtype:trojan-activity; sid:100000320; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.118.157"; classtype:trojan-activity; sid:100000321; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.206.69"; classtype:trojan-activity; sid:100000322; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.26.129"; classtype:trojan-activity; sid:100000323; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.41.142"; classtype:trojan-activity; sid:100000324; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.249.79.98"; classtype:trojan-activity; sid:100000325; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.250.102.173"; classtype:trojan-activity; sid:100000326; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.250.57.99"; classtype:trojan-activity; sid:100000327; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.251.17.5"; classtype:trojan-activity; sid:100000328; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.251.218.210"; classtype:trojan-activity; sid:100000329; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.251.23.55"; classtype:trojan-activity; sid:100000330; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.136.84"; classtype:trojan-activity; sid:100000331; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.199.150"; classtype:trojan-activity; sid:100000332; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.221.244"; classtype:trojan-activity; sid:100000333; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.236.40"; classtype:trojan-activity; sid:100000334; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.237.109"; classtype:trojan-activity; sid:100000335; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.239.103"; classtype:trojan-activity; sid:100000336; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.245.249"; classtype:trojan-activity; sid:100000337; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.252.46.212"; classtype:trojan-activity; sid:100000338; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.254.208.123"; classtype:trojan-activity; sid:100000339; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.255.38.10"; classtype:trojan-activity; sid:100000340; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.255.52.179"; classtype:trojan-activity; sid:100000341; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.255.8.235"; classtype:trojan-activity; sid:100000342; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.121.163"; classtype:trojan-activity; sid:100000343; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.123.174"; classtype:trojan-activity; sid:100000344; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.109"; classtype:trojan-activity; sid:100000345; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.110"; classtype:trojan-activity; sid:100000346; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.111"; classtype:trojan-activity; sid:100000347; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.112"; classtype:trojan-activity; sid:100000348; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.117"; classtype:trojan-activity; sid:100000349; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.119"; classtype:trojan-activity; sid:100000350; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.120"; classtype:trojan-activity; sid:100000351; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.122"; classtype:trojan-activity; sid:100000352; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.124"; classtype:trojan-activity; sid:100000353; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.127"; classtype:trojan-activity; sid:100000354; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.128"; classtype:trojan-activity; sid:100000355; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.130"; classtype:trojan-activity; sid:100000356; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.131"; classtype:trojan-activity; sid:100000357; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.132"; classtype:trojan-activity; sid:100000358; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.133"; classtype:trojan-activity; sid:100000359; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.136"; classtype:trojan-activity; sid:100000360; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.139"; classtype:trojan-activity; sid:100000361; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.140"; classtype:trojan-activity; sid:100000362; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.142"; classtype:trojan-activity; sid:100000363; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.143"; classtype:trojan-activity; sid:100000364; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.144"; classtype:trojan-activity; sid:100000365; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.146"; classtype:trojan-activity; sid:100000366; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.149"; classtype:trojan-activity; sid:100000367; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.150"; classtype:trojan-activity; sid:100000368; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.155"; classtype:trojan-activity; sid:100000369; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.158"; classtype:trojan-activity; sid:100000370; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.160"; classtype:trojan-activity; sid:100000371; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.162"; classtype:trojan-activity; sid:100000372; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.163"; classtype:trojan-activity; sid:100000373; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.165"; classtype:trojan-activity; sid:100000374; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.168"; classtype:trojan-activity; sid:100000375; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.171"; classtype:trojan-activity; sid:100000376; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.172"; classtype:trojan-activity; sid:100000377; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.175"; classtype:trojan-activity; sid:100000378; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.176"; classtype:trojan-activity; sid:100000379; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.178"; classtype:trojan-activity; sid:100000380; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.179"; classtype:trojan-activity; sid:100000381; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.124.71"; classtype:trojan-activity; sid:100000382; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.126.243"; classtype:trojan-activity; sid:100000383; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.127.155"; classtype:trojan-activity; sid:100000384; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.80.120"; classtype:trojan-activity; sid:100000385; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.80.121"; classtype:trojan-activity; sid:100000386; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.80.98"; classtype:trojan-activity; sid:100000387; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.82.29"; classtype:trojan-activity; sid:100000388; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.83.182"; classtype:trojan-activity; sid:100000389; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.83.23"; classtype:trojan-activity; sid:100000390; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.87.213"; classtype:trojan-activity; sid:100000391; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.88.116"; classtype:trojan-activity; sid:100000392; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.91.212"; classtype:trojan-activity; sid:100000393; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.27.91.247"; classtype:trojan-activity; sid:100000394; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.150"; classtype:trojan-activity; sid:100000395; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.158"; classtype:trojan-activity; sid:100000396; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.159"; classtype:trojan-activity; sid:100000397; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.168"; classtype:trojan-activity; sid:100000398; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.177"; classtype:trojan-activity; sid:100000399; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.178"; classtype:trojan-activity; sid:100000400; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.181"; classtype:trojan-activity; sid:100000401; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.188"; classtype:trojan-activity; sid:100000402; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.194"; classtype:trojan-activity; sid:100000403; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.197"; classtype:trojan-activity; sid:100000404; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.200"; classtype:trojan-activity; sid:100000405; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.211"; classtype:trojan-activity; sid:100000406; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.219"; classtype:trojan-activity; sid:100000407; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.229"; classtype:trojan-activity; sid:100000408; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.230"; classtype:trojan-activity; sid:100000409; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.245"; classtype:trojan-activity; sid:100000410; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.247"; classtype:trojan-activity; sid:100000411; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.54"; classtype:trojan-activity; sid:100000412; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.55"; classtype:trojan-activity; sid:100000413; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.57"; classtype:trojan-activity; sid:100000414; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.60"; classtype:trojan-activity; sid:100000415; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.90"; classtype:trojan-activity; sid:100000416; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.1.91"; classtype:trojan-activity; sid:100000417; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.100.228"; classtype:trojan-activity; sid:100000418; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.27"; classtype:trojan-activity; sid:100000419; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.30"; classtype:trojan-activity; sid:100000420; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.31"; classtype:trojan-activity; sid:100000421; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.32"; classtype:trojan-activity; sid:100000422; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.33"; classtype:trojan-activity; sid:100000423; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.37"; classtype:trojan-activity; sid:100000424; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.38"; classtype:trojan-activity; sid:100000425; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.41"; classtype:trojan-activity; sid:100000426; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.42"; classtype:trojan-activity; sid:100000427; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.43"; classtype:trojan-activity; sid:100000428; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.52"; classtype:trojan-activity; sid:100000429; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.55"; classtype:trojan-activity; sid:100000430; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.57"; classtype:trojan-activity; sid:100000431; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.58"; classtype:trojan-activity; sid:100000432; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.60"; classtype:trojan-activity; sid:100000433; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.62"; classtype:trojan-activity; sid:100000434; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.110.64"; classtype:trojan-activity; sid:100000435; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.35.237"; classtype:trojan-activity; sid:100000436; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.38.100"; classtype:trojan-activity; sid:100000437; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.38.19"; classtype:trojan-activity; sid:100000438; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.118"; classtype:trojan-activity; sid:100000439; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.119"; classtype:trojan-activity; sid:100000440; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.121"; classtype:trojan-activity; sid:100000441; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.136"; classtype:trojan-activity; sid:100000442; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.37"; classtype:trojan-activity; sid:100000443; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.52"; classtype:trojan-activity; sid:100000444; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.53"; classtype:trojan-activity; sid:100000445; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.73"; classtype:trojan-activity; sid:100000446; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.77"; classtype:trojan-activity; sid:100000447; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.30.4.90"; classtype:trojan-activity; sid:100000448; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.31.211.135"; classtype:trojan-activity; sid:100000449; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.53.224.79"; classtype:trojan-activity; sid:100000450; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.53.227.57"; classtype:trojan-activity; sid:100000451; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.53.227.66"; classtype:trojan-activity; sid:100000452; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.65.53.175"; classtype:trojan-activity; sid:100000453; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.153.37"; classtype:trojan-activity; sid:100000454; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.162.159"; classtype:trojan-activity; sid:100000455; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.162.49"; classtype:trojan-activity; sid:100000456; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.175.147"; classtype:trojan-activity; sid:100000457; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.176.112"; classtype:trojan-activity; sid:100000458; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.176.84"; classtype:trojan-activity; sid:100000459; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.72.226.202"; classtype:trojan-activity; sid:100000460; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.78.45.158"; classtype:trojan-activity; sid:100000461; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.80.118.16"; classtype:trojan-activity; sid:100000462; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.80.127.91"; classtype:trojan-activity; sid:100000463; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.80.215.101"; classtype:trojan-activity; sid:100000464; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.81.161.10"; classtype:trojan-activity; sid:100000465; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.81.199.218"; classtype:trojan-activity; sid:100000466; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.81.49.200"; classtype:trojan-activity; sid:100000467; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.131.124"; classtype:trojan-activity; sid:100000468; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.141.200"; classtype:trojan-activity; sid:100000469; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.146.253"; classtype:trojan-activity; sid:100000470; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.148.146"; classtype:trojan-activity; sid:100000471; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.18.255"; classtype:trojan-activity; sid:100000472; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.224.139"; classtype:trojan-activity; sid:100000473; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.227.41"; classtype:trojan-activity; sid:100000474; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.82.228.175"; classtype:trojan-activity; sid:100000475; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.86.133.125"; classtype:trojan-activity; sid:100000476; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.86.253.238"; classtype:trojan-activity; sid:100000477; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.9.140.247"; classtype:trojan-activity; sid:100000478; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.93.29.211"; classtype:trojan-activity; sid:100000479; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.95.22.17"; classtype:trojan-activity; sid:100000480; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"112.95.23.121"; classtype:trojan-activity; sid:100000481; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.103.10.209"; classtype:trojan-activity; sid:100000482; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.104.237.52"; classtype:trojan-activity; sid:100000483; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.105.71.239"; classtype:trojan-activity; sid:100000484; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.116.121.167"; classtype:trojan-activity; sid:100000485; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.116.149.83"; classtype:trojan-activity; sid:100000486; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.116.150.147"; classtype:trojan-activity; sid:100000487; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.116.246.109"; classtype:trojan-activity; sid:100000488; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.116.48.217"; classtype:trojan-activity; sid:100000489; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.118.195.247"; classtype:trojan-activity; sid:100000490; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.122.238.68"; classtype:trojan-activity; sid:100000491; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.122.59.84"; classtype:trojan-activity; sid:100000492; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.161.58.249"; classtype:trojan-activity; sid:100000493; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.172.250.35"; classtype:trojan-activity; sid:100000494; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.179.129.99"; classtype:trojan-activity; sid:100000495; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.194.133.9"; classtype:trojan-activity; sid:100000496; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.194.135.154"; classtype:trojan-activity; sid:100000497; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.195.163.26"; classtype:trojan-activity; sid:100000498; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.195.166.46"; classtype:trojan-activity; sid:100000499; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.201.24.26"; classtype:trojan-activity; sid:100000500; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.224.225.172"; classtype:trojan-activity; sid:100000501; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.226.42.250"; classtype:trojan-activity; sid:100000502; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.227.128.9"; classtype:trojan-activity; sid:100000503; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.227.169.170"; classtype:trojan-activity; sid:100000504; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.227.35.229"; classtype:trojan-activity; sid:100000505; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.231.211.131"; classtype:trojan-activity; sid:100000506; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.231.93.142"; classtype:trojan-activity; sid:100000507; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.232.141.23"; classtype:trojan-activity; sid:100000508; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.232.211.182"; classtype:trojan-activity; sid:100000509; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.234.224.130"; classtype:trojan-activity; sid:100000510; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.235.116.209"; classtype:trojan-activity; sid:100000511; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.237.129.7"; classtype:trojan-activity; sid:100000512; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.253.144.141"; classtype:trojan-activity; sid:100000513; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.254.169.251"; classtype:trojan-activity; sid:100000514; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.3.153.57"; classtype:trojan-activity; sid:100000515; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.3.155.199"; classtype:trojan-activity; sid:100000516; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.133.16"; classtype:trojan-activity; sid:100000517; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.59.154.21"; classtype:trojan-activity; sid:100000518; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.61.204.205"; classtype:trojan-activity; sid:100000519; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.81.112.35"; classtype:trojan-activity; sid:100000520; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.86.204.13"; classtype:trojan-activity; sid:100000521; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.87.175.112"; classtype:trojan-activity; sid:100000522; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.87.248.177"; classtype:trojan-activity; sid:100000523; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.88.100.120"; classtype:trojan-activity; sid:100000524; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.88.208.189"; classtype:trojan-activity; sid:100000525; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.88.232.36"; classtype:trojan-activity; sid:100000526; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.88.242.0"; classtype:trojan-activity; sid:100000527; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.88.38.232"; classtype:trojan-activity; sid:100000528; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.89.245.13"; classtype:trojan-activity; sid:100000529; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"113.89.41.51"; classtype:trojan-activity; sid:100000530; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.199.204.37"; classtype:trojan-activity; sid:100000531; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.226.100.56"; classtype:trojan-activity; sid:100000532; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.227.156.119"; classtype:trojan-activity; sid:100000533; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.228.205.101"; classtype:trojan-activity; sid:100000534; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.228.242.109"; classtype:trojan-activity; sid:100000535; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.229.165.194"; classtype:trojan-activity; sid:100000536; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.229.52.14"; classtype:trojan-activity; sid:100000537; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.235.115.236"; classtype:trojan-activity; sid:100000538; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.235.42.152"; classtype:trojan-activity; sid:100000539; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.79.161.94"; classtype:trojan-activity; sid:100000540; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"114.79.172.42"; classtype:trojan-activity; sid:100000541; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.165.216.112"; classtype:trojan-activity; sid:100000542; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.171.239.28"; classtype:trojan-activity; sid:100000543; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.193.130.126"; classtype:trojan-activity; sid:100000544; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.201.38.185"; classtype:trojan-activity; sid:100000545; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.208.101.195"; classtype:trojan-activity; sid:100000546; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.213.187.251"; classtype:trojan-activity; sid:100000547; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.223.159.80"; classtype:trojan-activity; sid:100000548; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.23.88.135"; classtype:trojan-activity; sid:100000549; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.42.47.36"; classtype:trojan-activity; sid:100000550; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.45.178.12"; classtype:trojan-activity; sid:100000551; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.48.130.181"; classtype:trojan-activity; sid:100000552; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.48.130.187"; classtype:trojan-activity; sid:100000553; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.48.135.151"; classtype:trojan-activity; sid:100000554; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.48.141.239"; classtype:trojan-activity; sid:100000555; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.48.198.142"; classtype:trojan-activity; sid:100000556; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.48.200.115"; classtype:trojan-activity; sid:100000557; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.48.22.130"; classtype:trojan-activity; sid:100000558; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.48.228.176"; classtype:trojan-activity; sid:100000559; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.48.9.246"; classtype:trojan-activity; sid:100000560; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.49.100.124"; classtype:trojan-activity; sid:100000561; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.49.152.10"; classtype:trojan-activity; sid:100000562; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.49.242.100"; classtype:trojan-activity; sid:100000563; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.49.60.231"; classtype:trojan-activity; sid:100000564; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.49.80.117"; classtype:trojan-activity; sid:100000565; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.49.96.88"; classtype:trojan-activity; sid:100000566; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.1.143"; classtype:trojan-activity; sid:100000567; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.158.223"; classtype:trojan-activity; sid:100000568; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.2.251"; classtype:trojan-activity; sid:100000569; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.202.11"; classtype:trojan-activity; sid:100000570; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.220.156"; classtype:trojan-activity; sid:100000571; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.239.222"; classtype:trojan-activity; sid:100000572; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.240.230"; classtype:trojan-activity; sid:100000573; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.61.247"; classtype:trojan-activity; sid:100000574; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.64.182"; classtype:trojan-activity; sid:100000575; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.50.81.194"; classtype:trojan-activity; sid:100000576; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.51.104.85"; classtype:trojan-activity; sid:100000577; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.51.107.18"; classtype:trojan-activity; sid:100000578; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.51.123.216"; classtype:trojan-activity; sid:100000579; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.51.93.76"; classtype:trojan-activity; sid:100000580; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.52.112.200"; classtype:trojan-activity; sid:100000581; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.52.17.196"; classtype:trojan-activity; sid:100000582; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.52.19.250"; classtype:trojan-activity; sid:100000583; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.52.200.245"; classtype:trojan-activity; sid:100000584; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.52.201.231"; classtype:trojan-activity; sid:100000585; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.52.21.5"; classtype:trojan-activity; sid:100000586; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.52.22.162"; classtype:trojan-activity; sid:100000587; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.54.160.25"; classtype:trojan-activity; sid:100000588; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.54.212.227"; classtype:trojan-activity; sid:100000589; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.54.236.22"; classtype:trojan-activity; sid:100000590; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.54.240.173"; classtype:trojan-activity; sid:100000591; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.54.241.122"; classtype:trojan-activity; sid:100000592; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.54.70.108"; classtype:trojan-activity; sid:100000593; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.54.73.162"; classtype:trojan-activity; sid:100000594; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.54.73.50"; classtype:trojan-activity; sid:100000595; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.144.146"; classtype:trojan-activity; sid:100000596; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.144.222"; classtype:trojan-activity; sid:100000597; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.144.42"; classtype:trojan-activity; sid:100000598; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.145.147"; classtype:trojan-activity; sid:100000599; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.149.30"; classtype:trojan-activity; sid:100000600; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.178.67"; classtype:trojan-activity; sid:100000601; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.198.209"; classtype:trojan-activity; sid:100000602; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.211.41"; classtype:trojan-activity; sid:100000603; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.211.86"; classtype:trojan-activity; sid:100000604; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.3.36"; classtype:trojan-activity; sid:100000605; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.42.200"; classtype:trojan-activity; sid:100000606; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.55.53.51"; classtype:trojan-activity; sid:100000607; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.134.116"; classtype:trojan-activity; sid:100000608; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.134.220"; classtype:trojan-activity; sid:100000609; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.136.144"; classtype:trojan-activity; sid:100000610; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.139.122"; classtype:trojan-activity; sid:100000611; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.142.251"; classtype:trojan-activity; sid:100000612; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.143.241"; classtype:trojan-activity; sid:100000613; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.148.22"; classtype:trojan-activity; sid:100000614; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.154.147"; classtype:trojan-activity; sid:100000615; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.155.72"; classtype:trojan-activity; sid:100000616; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.156.185"; classtype:trojan-activity; sid:100000617; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.156.54"; classtype:trojan-activity; sid:100000618; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.162.173"; classtype:trojan-activity; sid:100000619; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.177.202"; classtype:trojan-activity; sid:100000620; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.188.24"; classtype:trojan-activity; sid:100000621; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.31.54"; classtype:trojan-activity; sid:100000622; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.86.251"; classtype:trojan-activity; sid:100000623; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.87.42"; classtype:trojan-activity; sid:100000624; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.56.98.205"; classtype:trojan-activity; sid:100000625; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.111.222"; classtype:trojan-activity; sid:100000626; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.119.171"; classtype:trojan-activity; sid:100000627; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.132.199"; classtype:trojan-activity; sid:100000628; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.134.143"; classtype:trojan-activity; sid:100000629; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.141.177"; classtype:trojan-activity; sid:100000630; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.167.90"; classtype:trojan-activity; sid:100000631; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.20.186"; classtype:trojan-activity; sid:100000632; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.83.233"; classtype:trojan-activity; sid:100000633; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.88.163"; classtype:trojan-activity; sid:100000634; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.58.93.151"; classtype:trojan-activity; sid:100000635; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.197.123"; classtype:trojan-activity; sid:100000636; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.198.165"; classtype:trojan-activity; sid:100000637; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.198.200"; classtype:trojan-activity; sid:100000638; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.210.228"; classtype:trojan-activity; sid:100000639; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.215.96"; classtype:trojan-activity; sid:100000640; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.235.229"; classtype:trojan-activity; sid:100000641; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.253.202"; classtype:trojan-activity; sid:100000642; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.63.220"; classtype:trojan-activity; sid:100000643; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.59.95.247"; classtype:trojan-activity; sid:100000644; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.60.201.176"; classtype:trojan-activity; sid:100000645; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.107.203"; classtype:trojan-activity; sid:100000646; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.118.201"; classtype:trojan-activity; sid:100000647; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.119.187"; classtype:trojan-activity; sid:100000648; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.119.198"; classtype:trojan-activity; sid:100000649; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.119.77"; classtype:trojan-activity; sid:100000650; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.125.184"; classtype:trojan-activity; sid:100000651; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.180.193"; classtype:trojan-activity; sid:100000652; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.182.138"; classtype:trojan-activity; sid:100000653; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.185.246"; classtype:trojan-activity; sid:100000654; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.97.190"; classtype:trojan-activity; sid:100000655; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.61.97.55"; classtype:trojan-activity; sid:100000656; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.62.152.207"; classtype:trojan-activity; sid:100000657; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.62.26.39"; classtype:trojan-activity; sid:100000658; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.63.135.206"; classtype:trojan-activity; sid:100000659; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.63.140.242"; classtype:trojan-activity; sid:100000660; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.63.4.244"; classtype:trojan-activity; sid:100000661; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.63.56.176"; classtype:trojan-activity; sid:100000662; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.73.3.11"; classtype:trojan-activity; sid:100000663; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.74.217.2"; classtype:trojan-activity; sid:100000664; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.75.217.79"; classtype:trojan-activity; sid:100000665; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.78.133.146"; classtype:trojan-activity; sid:100000666; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"115.92.174.231"; classtype:trojan-activity; sid:100000667; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.124.219.2"; classtype:trojan-activity; sid:100000668; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.127.207.224"; classtype:trojan-activity; sid:100000669; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.149.119.185"; classtype:trojan-activity; sid:100000670; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.2.100.221"; classtype:trojan-activity; sid:100000671; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.2.66.3"; classtype:trojan-activity; sid:100000672; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.206.164.46"; classtype:trojan-activity; sid:100000673; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.211.100.26"; classtype:trojan-activity; sid:100000674; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.212.142.215"; classtype:trojan-activity; sid:100000675; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.24.153.40"; classtype:trojan-activity; sid:100000676; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.72.202.126"; classtype:trojan-activity; sid:100000677; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.72.202.87"; classtype:trojan-activity; sid:100000678; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.72.203.143"; classtype:trojan-activity; sid:100000679; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.74.84.65"; classtype:trojan-activity; sid:100000680; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.75.194.14"; classtype:trojan-activity; sid:100000681; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.76.114.71"; classtype:trojan-activity; sid:100000682; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"116.88.65.131"; classtype:trojan-activity; sid:100000683; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.11.234.35"; classtype:trojan-activity; sid:100000684; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.15.201.1"; classtype:trojan-activity; sid:100000685; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.156.69.22"; classtype:trojan-activity; sid:100000686; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.194.160.84"; classtype:trojan-activity; sid:100000687; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.194.161.143"; classtype:trojan-activity; sid:100000688; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.194.162.121"; classtype:trojan-activity; sid:100000689; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.196.48.216"; classtype:trojan-activity; sid:100000690; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.204.138"; classtype:trojan-activity; sid:100000691; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.204.5"; classtype:trojan-activity; sid:100000692; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.210.52"; classtype:trojan-activity; sid:100000693; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.220.126"; classtype:trojan-activity; sid:100000694; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.236.14"; classtype:trojan-activity; sid:100000695; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.20.243.40"; classtype:trojan-activity; sid:100000696; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.200.76.54"; classtype:trojan-activity; sid:100000697; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.200.76.60"; classtype:trojan-activity; sid:100000698; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.201.128.152"; classtype:trojan-activity; sid:100000699; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.202.66.177"; classtype:trojan-activity; sid:100000700; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.202.68.94"; classtype:trojan-activity; sid:100000701; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.208.133.121"; classtype:trojan-activity; sid:100000702; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.222.161.68"; classtype:trojan-activity; sid:100000703; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.222.162.144"; classtype:trojan-activity; sid:100000704; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.222.163.150"; classtype:trojan-activity; sid:100000705; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.222.165.31"; classtype:trojan-activity; sid:100000706; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.222.170.189"; classtype:trojan-activity; sid:100000707; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.222.171.68"; classtype:trojan-activity; sid:100000708; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.222.172.97"; classtype:trojan-activity; sid:100000709; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.241.66.200"; classtype:trojan-activity; sid:100000710; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.241.67.68"; classtype:trojan-activity; sid:100000711; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.242.210.69"; classtype:trojan-activity; sid:100000712; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.242.211.111"; classtype:trojan-activity; sid:100000713; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.242.211.98"; classtype:trojan-activity; sid:100000714; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.251.56.135"; classtype:trojan-activity; sid:100000715; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.251.59.242"; classtype:trojan-activity; sid:100000716; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.251.60.161"; classtype:trojan-activity; sid:100000717; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.251.60.69"; classtype:trojan-activity; sid:100000718; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.26.110.17"; classtype:trojan-activity; sid:100000719; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.26.235.164"; classtype:trojan-activity; sid:100000720; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.27.10.73"; classtype:trojan-activity; sid:100000721; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.63.113.146"; classtype:trojan-activity; sid:100000722; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.63.195.140"; classtype:trojan-activity; sid:100000723; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.63.252.82"; classtype:trojan-activity; sid:100000724; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.63.53.15"; classtype:trojan-activity; sid:100000725; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.63.56.81"; classtype:trojan-activity; sid:100000726; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.86.105.110"; classtype:trojan-activity; sid:100000727; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.87.170.32"; classtype:trojan-activity; sid:100000728; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.90.78.120"; classtype:trojan-activity; sid:100000729; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.91.240.50"; classtype:trojan-activity; sid:100000730; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.93.115.242"; classtype:trojan-activity; sid:100000731; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"117.93.79.40"; classtype:trojan-activity; sid:100000732; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.176.104.35"; classtype:trojan-activity; sid:100000733; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.176.157.64"; classtype:trojan-activity; sid:100000734; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.176.7.132"; classtype:trojan-activity; sid:100000735; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.211.38.112"; classtype:trojan-activity; sid:100000736; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.223.32.74"; classtype:trojan-activity; sid:100000737; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.223.5.149"; classtype:trojan-activity; sid:100000738; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.223.72.141"; classtype:trojan-activity; sid:100000739; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.128.147"; classtype:trojan-activity; sid:100000740; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.208.215"; classtype:trojan-activity; sid:100000741; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.209.108"; classtype:trojan-activity; sid:100000742; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.214.72"; classtype:trojan-activity; sid:100000743; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.88.146"; classtype:trojan-activity; sid:100000744; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.96.150"; classtype:trojan-activity; sid:100000745; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.232.96.6"; classtype:trojan-activity; sid:100000746; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.233.221.162"; classtype:trojan-activity; sid:100000747; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.233.63.194"; classtype:trojan-activity; sid:100000748; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.233.65.93"; classtype:trojan-activity; sid:100000749; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.249.136.112"; classtype:trojan-activity; sid:100000750; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.250.51.192"; classtype:trojan-activity; sid:100000751; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.42.125.246"; classtype:trojan-activity; sid:100000752; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.43.180.33"; classtype:trojan-activity; sid:100000753; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.68.245.69"; classtype:trojan-activity; sid:100000754; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.75.120.136"; classtype:trojan-activity; sid:100000755; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.75.240.239"; classtype:trojan-activity; sid:100000756; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.75.50.253"; classtype:trojan-activity; sid:100000757; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.75.70.70"; classtype:trojan-activity; sid:100000758; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.125.92"; classtype:trojan-activity; sid:100000759; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.164.102"; classtype:trojan-activity; sid:100000760; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.218.157"; classtype:trojan-activity; sid:100000761; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.50.203"; classtype:trojan-activity; sid:100000762; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.58.82"; classtype:trojan-activity; sid:100000763; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.79.73.123"; classtype:trojan-activity; sid:100000764; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.83.79.43"; classtype:trojan-activity; sid:100000765; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.99.179.164"; classtype:trojan-activity; sid:100000766; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.99.183.235"; classtype:trojan-activity; sid:100000767; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"118.99.239.217"; classtype:trojan-activity; sid:100000768; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.100.40.250"; classtype:trojan-activity; sid:100000769; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.108.188.238"; classtype:trojan-activity; sid:100000770; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.108.252.237"; classtype:trojan-activity; sid:100000771; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.109.34.245"; classtype:trojan-activity; sid:100000772; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.112.22.58"; classtype:trojan-activity; sid:100000773; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.118.251.73"; classtype:trojan-activity; sid:100000774; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.119.52.202"; classtype:trojan-activity; sid:100000775; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.123.175.133"; classtype:trojan-activity; sid:100000776; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.14.143.145"; classtype:trojan-activity; sid:100000777; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.147.213.57"; classtype:trojan-activity; sid:100000778; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.162.109.111"; classtype:trojan-activity; sid:100000779; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.163.144.208"; classtype:trojan-activity; sid:100000780; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.163.93.191"; classtype:trojan-activity; sid:100000781; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.164.18.235"; classtype:trojan-activity; sid:100000782; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.164.31.76"; classtype:trojan-activity; sid:100000783; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.164.74.153"; classtype:trojan-activity; sid:100000784; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.107.93"; classtype:trojan-activity; sid:100000785; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.163.220"; classtype:trojan-activity; sid:100000786; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.174.63"; classtype:trojan-activity; sid:100000787; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.208.73"; classtype:trojan-activity; sid:100000788; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.241.222"; classtype:trojan-activity; sid:100000789; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.27.77"; classtype:trojan-activity; sid:100000790; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.165.68.145"; classtype:trojan-activity; sid:100000791; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.166.170.241"; classtype:trojan-activity; sid:100000792; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.166.19.254"; classtype:trojan-activity; sid:100000793; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.166.97.6"; classtype:trojan-activity; sid:100000794; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.167.1.13"; classtype:trojan-activity; sid:100000795; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.167.2.214"; classtype:trojan-activity; sid:100000796; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.167.26.33"; classtype:trojan-activity; sid:100000797; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.167.63.195"; classtype:trojan-activity; sid:100000798; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.176.231.217"; classtype:trojan-activity; sid:100000799; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.178.201.188"; classtype:trojan-activity; sid:100000800; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.178.248.123"; classtype:trojan-activity; sid:100000801; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.178.249.140"; classtype:trojan-activity; sid:100000802; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.157.219"; classtype:trojan-activity; sid:100000803; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.16.149"; classtype:trojan-activity; sid:100000804; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.170.212"; classtype:trojan-activity; sid:100000805; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.27.213"; classtype:trojan-activity; sid:100000806; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.43.1"; classtype:trojan-activity; sid:100000807; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.44.141"; classtype:trojan-activity; sid:100000808; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.179.75.8"; classtype:trojan-activity; sid:100000809; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.18.38.144"; classtype:trojan-activity; sid:100000810; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.101.151"; classtype:trojan-activity; sid:100000811; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.106.217"; classtype:trojan-activity; sid:100000812; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.108.227"; classtype:trojan-activity; sid:100000813; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.108.79"; classtype:trojan-activity; sid:100000814; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.11.29"; classtype:trojan-activity; sid:100000815; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.231.79"; classtype:trojan-activity; sid:100000816; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.33.161"; classtype:trojan-activity; sid:100000817; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.80.69"; classtype:trojan-activity; sid:100000818; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.9.35"; classtype:trojan-activity; sid:100000819; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.180.94.80"; classtype:trojan-activity; sid:100000820; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.181.124.203"; classtype:trojan-activity; sid:100000821; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.181.43.18"; classtype:trojan-activity; sid:100000822; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.183.109.21"; classtype:trojan-activity; sid:100000823; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.183.115.103"; classtype:trojan-activity; sid:100000824; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.183.9.82"; classtype:trojan-activity; sid:100000825; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.184.14.112"; classtype:trojan-activity; sid:100000826; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.184.172.199"; classtype:trojan-activity; sid:100000827; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.184.172.53"; classtype:trojan-activity; sid:100000828; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.185.102.182"; classtype:trojan-activity; sid:100000829; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.185.237.89"; classtype:trojan-activity; sid:100000830; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.185.39.240"; classtype:trojan-activity; sid:100000831; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.185.43.193"; classtype:trojan-activity; sid:100000832; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.186.22.245"; classtype:trojan-activity; sid:100000833; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.187.195.161"; classtype:trojan-activity; sid:100000834; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.187.220.115"; classtype:trojan-activity; sid:100000835; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.187.62.80"; classtype:trojan-activity; sid:100000836; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.189.137.195"; classtype:trojan-activity; sid:100000837; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.189.227.244"; classtype:trojan-activity; sid:100000838; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.190.211.99"; classtype:trojan-activity; sid:100000839; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.190.240.238"; classtype:trojan-activity; sid:100000840; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.150.85"; classtype:trojan-activity; sid:100000841; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.187.206"; classtype:trojan-activity; sid:100000842; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.215.221"; classtype:trojan-activity; sid:100000843; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.191.253.206"; classtype:trojan-activity; sid:100000844; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.204.30.144"; classtype:trojan-activity; sid:100000845; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.250.129.231"; classtype:trojan-activity; sid:100000846; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.250.218.177"; classtype:trojan-activity; sid:100000847; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.251.105.221"; classtype:trojan-activity; sid:100000848; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.251.12.85"; classtype:trojan-activity; sid:100000849; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.251.14.251"; classtype:trojan-activity; sid:100000850; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.131.155"; classtype:trojan-activity; sid:100000851; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.143.46"; classtype:trojan-activity; sid:100000852; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.143.71"; classtype:trojan-activity; sid:100000853; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.144.75"; classtype:trojan-activity; sid:100000854; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.148.115"; classtype:trojan-activity; sid:100000855; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.155.57"; classtype:trojan-activity; sid:100000856; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.166.36"; classtype:trojan-activity; sid:100000857; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.172.28"; classtype:trojan-activity; sid:100000858; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.56.206.43"; classtype:trojan-activity; sid:100000859; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.96.37.55"; classtype:trojan-activity; sid:100000860; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.96.70.116"; classtype:trojan-activity; sid:100000861; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.99.188.187"; classtype:trojan-activity; sid:100000862; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.99.190.152"; classtype:trojan-activity; sid:100000863; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"119.99.232.62"; classtype:trojan-activity; sid:100000864; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.132.113.2"; classtype:trojan-activity; sid:100000865; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.15.69.83"; classtype:trojan-activity; sid:100000866; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.6"; classtype:trojan-activity; sid:100000867; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.7"; classtype:trojan-activity; sid:100000868; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.8"; classtype:trojan-activity; sid:100000869; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.178.187.9"; classtype:trojan-activity; sid:100000870; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"12.207.39.227"; classtype:trojan-activity; sid:100000871; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.12.144.232"; classtype:trojan-activity; sid:100000872; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.12.153.54"; classtype:trojan-activity; sid:100000873; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.12.212.5"; classtype:trojan-activity; sid:100000874; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.142.222.22"; classtype:trojan-activity; sid:100000875; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.150.213.110"; classtype:trojan-activity; sid:100000876; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.151.248.134"; classtype:trojan-activity; sid:100000877; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.177"; classtype:trojan-activity; sid:100000878; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.178"; classtype:trojan-activity; sid:100000879; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.180"; classtype:trojan-activity; sid:100000880; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.181"; classtype:trojan-activity; sid:100000881; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.183"; classtype:trojan-activity; sid:100000882; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.184"; classtype:trojan-activity; sid:100000883; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.185"; classtype:trojan-activity; sid:100000884; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.186"; classtype:trojan-activity; sid:100000885; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.188"; classtype:trojan-activity; sid:100000886; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.191"; classtype:trojan-activity; sid:100000887; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.193"; classtype:trojan-activity; sid:100000888; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.196"; classtype:trojan-activity; sid:100000889; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.197"; classtype:trojan-activity; sid:100000890; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.198"; classtype:trojan-activity; sid:100000891; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.199"; classtype:trojan-activity; sid:100000892; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.200"; classtype:trojan-activity; sid:100000893; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.201"; classtype:trojan-activity; sid:100000894; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.202"; classtype:trojan-activity; sid:100000895; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.203"; classtype:trojan-activity; sid:100000896; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.204"; classtype:trojan-activity; sid:100000897; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.207"; classtype:trojan-activity; sid:100000898; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.208"; classtype:trojan-activity; sid:100000899; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.209"; classtype:trojan-activity; sid:100000900; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.212"; classtype:trojan-activity; sid:100000901; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.213"; classtype:trojan-activity; sid:100000902; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.215"; classtype:trojan-activity; sid:100000903; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.91.233"; classtype:trojan-activity; sid:100000904; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.193.93.227"; classtype:trojan-activity; sid:100000905; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.121.243"; classtype:trojan-activity; sid:100000906; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.206"; classtype:trojan-activity; sid:100000907; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.214"; classtype:trojan-activity; sid:100000908; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.240"; classtype:trojan-activity; sid:100000909; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.243"; classtype:trojan-activity; sid:100000910; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.25"; classtype:trojan-activity; sid:100000911; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.126.60"; classtype:trojan-activity; sid:100000912; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.127.187"; classtype:trojan-activity; sid:100000913; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.209.99.127"; classtype:trojan-activity; sid:100000914; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.210.89.79"; classtype:trojan-activity; sid:100000915; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.43.54.218"; classtype:trojan-activity; sid:100000916; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.50.66.60"; classtype:trojan-activity; sid:100000917; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.50.93.115"; classtype:trojan-activity; sid:100000918; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.6.141.142"; classtype:trojan-activity; sid:100000919; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.6.8.11"; classtype:trojan-activity; sid:100000920; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.69.113.208"; classtype:trojan-activity; sid:100000921; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.69.131.51"; classtype:trojan-activity; sid:100000922; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.7.90.104"; classtype:trojan-activity; sid:100000923; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.165.141"; classtype:trojan-activity; sid:100000924; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.173.137"; classtype:trojan-activity; sid:100000925; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.174.165"; classtype:trojan-activity; sid:100000926; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.174.175"; classtype:trojan-activity; sid:100000927; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.174.39"; classtype:trojan-activity; sid:100000928; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.199.222"; classtype:trojan-activity; sid:100000929; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.212.45"; classtype:trojan-activity; sid:100000930; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.85.237.129"; classtype:trojan-activity; sid:100000931; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"120.9.32.51"; classtype:trojan-activity; sid:100000932; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.100.114.164"; classtype:trojan-activity; sid:100000933; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.100.96.8"; classtype:trojan-activity; sid:100000934; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.121.44.222"; classtype:trojan-activity; sid:100000935; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.123.53.25"; classtype:trojan-activity; sid:100000936; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.127.155.220"; classtype:trojan-activity; sid:100000937; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.141.11.56"; classtype:trojan-activity; sid:100000938; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.15.142.137"; classtype:trojan-activity; sid:100000939; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.151.78.190"; classtype:trojan-activity; sid:100000940; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.159.22.144"; classtype:trojan-activity; sid:100000941; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.16.155.206"; classtype:trojan-activity; sid:100000942; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.17.103.176"; classtype:trojan-activity; sid:100000943; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.170.234.142"; classtype:trojan-activity; sid:100000944; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.185.31.2"; classtype:trojan-activity; sid:100000945; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.190.36.8"; classtype:trojan-activity; sid:100000946; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.205.229.200"; classtype:trojan-activity; sid:100000947; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.225.11.163"; classtype:trojan-activity; sid:100000948; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.226.82.202"; classtype:trojan-activity; sid:100000949; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.23.18.18"; classtype:trojan-activity; sid:100000950; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.230.171.198"; classtype:trojan-activity; sid:100000951; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.231.103.95"; classtype:trojan-activity; sid:100000952; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.237.225.91"; classtype:trojan-activity; sid:100000953; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.238.175.87"; classtype:trojan-activity; sid:100000954; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.239.15.74"; classtype:trojan-activity; sid:100000955; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.24.116.173"; classtype:trojan-activity; sid:100000956; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.25.101.86"; classtype:trojan-activity; sid:100000957; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.254.43.215"; classtype:trojan-activity; sid:100000958; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.34.150.32"; classtype:trojan-activity; sid:100000959; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.61.101.93"; classtype:trojan-activity; sid:100000960; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.61.102.1"; classtype:trojan-activity; sid:100000961; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.61.107.189"; classtype:trojan-activity; sid:100000962; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.61.97.195"; classtype:trojan-activity; sid:100000963; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.61.98.151"; classtype:trojan-activity; sid:100000964; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"121.88.99.236"; classtype:trojan-activity; sid:100000965; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.100.150.204"; classtype:trojan-activity; sid:100000966; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.137.52.122"; classtype:trojan-activity; sid:100000967; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.160.147.53"; classtype:trojan-activity; sid:100000968; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.188.86.225"; classtype:trojan-activity; sid:100000969; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.190.19.204"; classtype:trojan-activity; sid:100000970; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.192.190.203"; classtype:trojan-activity; sid:100000971; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.194.191.57"; classtype:trojan-activity; sid:100000972; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.199.72.23"; classtype:trojan-activity; sid:100000973; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.199.79.27"; classtype:trojan-activity; sid:100000974; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.199.83.86"; classtype:trojan-activity; sid:100000975; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.202.37.85"; classtype:trojan-activity; sid:100000976; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.202.41.23"; classtype:trojan-activity; sid:100000977; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.252.250.22"; classtype:trojan-activity; sid:100000978; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.254.183.207"; classtype:trojan-activity; sid:100000979; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.254.29.37"; classtype:trojan-activity; sid:100000980; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"122.254.33.214"; classtype:trojan-activity; sid:100000981; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.0.240.58"; classtype:trojan-activity; sid:100000982; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.10.128.46"; classtype:trojan-activity; sid:100000983; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.10.131.225"; classtype:trojan-activity; sid:100000984; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.10.140.225"; classtype:trojan-activity; sid:100000985; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.10.209.95"; classtype:trojan-activity; sid:100000986; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.10.36.124"; classtype:trojan-activity; sid:100000987; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.10.41.32"; classtype:trojan-activity; sid:100000988; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.10.83.136"; classtype:trojan-activity; sid:100000989; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.124.238"; classtype:trojan-activity; sid:100000990; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.124.244"; classtype:trojan-activity; sid:100000991; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.170.237"; classtype:trojan-activity; sid:100000992; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.182.187"; classtype:trojan-activity; sid:100000993; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.19.248"; classtype:trojan-activity; sid:100000994; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.200.98"; classtype:trojan-activity; sid:100000995; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.110.238.188"; classtype:trojan-activity; sid:100000996; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.12.229.243"; classtype:trojan-activity; sid:100000997; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.12.3.58"; classtype:trojan-activity; sid:100000998; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.12.36.185"; classtype:trojan-activity; sid:100000999; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.128.128.205"; classtype:trojan-activity; sid:100001000; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.128.133.91"; classtype:trojan-activity; sid:100001001; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.129.84.36"; classtype:trojan-activity; sid:100001002; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.129.88.123"; classtype:trojan-activity; sid:100001003; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.13.101.56"; classtype:trojan-activity; sid:100001004; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.13.30.75"; classtype:trojan-activity; sid:100001005; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.208.52"; classtype:trojan-activity; sid:100001006; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.23.110"; classtype:trojan-activity; sid:100001007; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.37.182"; classtype:trojan-activity; sid:100001008; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.130.61.210"; classtype:trojan-activity; sid:100001009; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.131.186.250"; classtype:trojan-activity; sid:100001010; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.132.219.147"; classtype:trojan-activity; sid:100001011; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.133.125.77"; classtype:trojan-activity; sid:100001012; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.133.144.138"; classtype:trojan-activity; sid:100001013; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.133.98.135"; classtype:trojan-activity; sid:100001014; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.134.14.130"; classtype:trojan-activity; sid:100001015; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.134.50.186"; classtype:trojan-activity; sid:100001016; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.135.157.193"; classtype:trojan-activity; sid:100001017; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.135.39.36"; classtype:trojan-activity; sid:100001018; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.135.71.150"; classtype:trojan-activity; sid:100001019; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.101.111"; classtype:trojan-activity; sid:100001020; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.150.79"; classtype:trojan-activity; sid:100001021; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.205.23"; classtype:trojan-activity; sid:100001022; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.217.22"; classtype:trojan-activity; sid:100001023; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.235.65"; classtype:trojan-activity; sid:100001024; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.76.38"; classtype:trojan-activity; sid:100001025; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.14.88.195"; classtype:trojan-activity; sid:100001026; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.152.42.4"; classtype:trojan-activity; sid:100001027; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.152.43.21"; classtype:trojan-activity; sid:100001028; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.154.94.1"; classtype:trojan-activity; sid:100001029; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.155.118.36"; classtype:trojan-activity; sid:100001030; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.156.136.21"; classtype:trojan-activity; sid:100001031; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.159.137.101"; classtype:trojan-activity; sid:100001032; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.159.31.110"; classtype:trojan-activity; sid:100001033; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.159.8.100"; classtype:trojan-activity; sid:100001034; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.183.123.41"; classtype:trojan-activity; sid:100001035; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.191.173.88"; classtype:trojan-activity; sid:100001036; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.192.101.163"; classtype:trojan-activity; sid:100001037; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.192.194.233"; classtype:trojan-activity; sid:100001038; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.193.149.235"; classtype:trojan-activity; sid:100001039; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.193.53.237"; classtype:trojan-activity; sid:100001040; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.235.37"; classtype:trojan-activity; sid:100001041; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.35.146"; classtype:trojan-activity; sid:100001042; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.52.79"; classtype:trojan-activity; sid:100001043; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.194.60.238"; classtype:trojan-activity; sid:100001044; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.195.112.240"; classtype:trojan-activity; sid:100001045; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.195.184.191"; classtype:trojan-activity; sid:100001046; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.195.98.141"; classtype:trojan-activity; sid:100001047; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.212.29.154"; classtype:trojan-activity; sid:100001048; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.213.225.130"; classtype:trojan-activity; sid:100001049; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.233.130.162"; classtype:trojan-activity; sid:100001050; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.233.152.249"; classtype:trojan-activity; sid:100001051; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.234.100.219"; classtype:trojan-activity; sid:100001052; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.234.116.110"; classtype:trojan-activity; sid:100001053; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.234.184.57"; classtype:trojan-activity; sid:100001054; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.234.246.103"; classtype:trojan-activity; sid:100001055; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.240.103.89"; classtype:trojan-activity; sid:100001056; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.240.181.57"; classtype:trojan-activity; sid:100001057; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.240.79.61"; classtype:trojan-activity; sid:100001058; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.241.148.58"; classtype:trojan-activity; sid:100001059; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.241.184.124"; classtype:trojan-activity; sid:100001060; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.27.44.219"; classtype:trojan-activity; sid:100001061; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.28.217.23"; classtype:trojan-activity; sid:100001062; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.180.137"; classtype:trojan-activity; sid:100001063; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.185.137"; classtype:trojan-activity; sid:100001064; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.193.171"; classtype:trojan-activity; sid:100001065; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.44.217"; classtype:trojan-activity; sid:100001066; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.85.76"; classtype:trojan-activity; sid:100001067; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.4.92.3"; classtype:trojan-activity; sid:100001068; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.5.123.162"; classtype:trojan-activity; sid:100001069; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.5.178.213"; classtype:trojan-activity; sid:100001070; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.5.188.181"; classtype:trojan-activity; sid:100001071; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.5.22.220"; classtype:trojan-activity; sid:100001072; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.5.27.66"; classtype:trojan-activity; sid:100001073; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.8.183.194"; classtype:trojan-activity; sid:100001074; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.8.254.172"; classtype:trojan-activity; sid:100001075; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.8.40.20"; classtype:trojan-activity; sid:100001076; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.8.41.63"; classtype:trojan-activity; sid:100001077; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.8.62.165"; classtype:trojan-activity; sid:100001078; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"123.9.243.93"; classtype:trojan-activity; sid:100001079; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.105.105.222"; classtype:trojan-activity; sid:100001080; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.129.162.169"; classtype:trojan-activity; sid:100001081; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.129.221.150"; classtype:trojan-activity; sid:100001082; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.129.76.230"; classtype:trojan-activity; sid:100001083; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.130.167.20"; classtype:trojan-activity; sid:100001084; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.130.40.31"; classtype:trojan-activity; sid:100001085; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.104.82"; classtype:trojan-activity; sid:100001086; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.130.95"; classtype:trojan-activity; sid:100001087; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.136.75"; classtype:trojan-activity; sid:100001088; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.151.135"; classtype:trojan-activity; sid:100001089; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.21.39"; classtype:trojan-activity; sid:100001090; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.26.243"; classtype:trojan-activity; sid:100001091; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.26.78"; classtype:trojan-activity; sid:100001092; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.54.33"; classtype:trojan-activity; sid:100001093; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.70.49"; classtype:trojan-activity; sid:100001094; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.131.72.208"; classtype:trojan-activity; sid:100001095; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.132.110.150"; classtype:trojan-activity; sid:100001096; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.135.34.49"; classtype:trojan-activity; sid:100001097; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.153.136.175"; classtype:trojan-activity; sid:100001098; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.153.236.6"; classtype:trojan-activity; sid:100001099; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.160.126.238"; classtype:trojan-activity; sid:100001100; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.138.104"; classtype:trojan-activity; sid:100001101; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.167.54"; classtype:trojan-activity; sid:100001102; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.65.64"; classtype:trojan-activity; sid:100001103; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.72.102"; classtype:trojan-activity; sid:100001104; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.77.191"; classtype:trojan-activity; sid:100001105; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.163.90.243"; classtype:trojan-activity; sid:100001106; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.165.123.7"; classtype:trojan-activity; sid:100001107; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.167.186.211"; classtype:trojan-activity; sid:100001108; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.187.111.160"; classtype:trojan-activity; sid:100001109; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.199.56.198"; classtype:trojan-activity; sid:100001110; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.226.24.117"; classtype:trojan-activity; sid:100001111; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.230.174.233"; classtype:trojan-activity; sid:100001112; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.234.6.130"; classtype:trojan-activity; sid:100001113; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.5.92.20"; classtype:trojan-activity; sid:100001114; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.6.0.4"; classtype:trojan-activity; sid:100001115; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.7.254.85"; classtype:trojan-activity; sid:100001116; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.80.46.73"; classtype:trojan-activity; sid:100001117; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.92.148.218"; classtype:trojan-activity; sid:100001118; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"124.95.17.41"; classtype:trojan-activity; sid:100001119; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.106.125.119"; classtype:trojan-activity; sid:100001120; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.106.252.96"; classtype:trojan-activity; sid:100001121; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.126.69.95"; classtype:trojan-activity; sid:100001122; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.128.28.161"; classtype:trojan-activity; sid:100001123; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.142.93.34"; classtype:trojan-activity; sid:100001124; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.168.10.234"; classtype:trojan-activity; sid:100001125; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.191.113.212"; classtype:trojan-activity; sid:100001126; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.1.127"; classtype:trojan-activity; sid:100001127; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.107.252"; classtype:trojan-activity; sid:100001128; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.113.66"; classtype:trojan-activity; sid:100001129; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.136.25"; classtype:trojan-activity; sid:100001130; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.150.131"; classtype:trojan-activity; sid:100001131; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.16.231"; classtype:trojan-activity; sid:100001132; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.163.112"; classtype:trojan-activity; sid:100001133; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.237.130"; classtype:trojan-activity; sid:100001134; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.65.120"; classtype:trojan-activity; sid:100001135; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.73.6"; classtype:trojan-activity; sid:100001136; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.74.153"; classtype:trojan-activity; sid:100001137; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.40.75.22"; classtype:trojan-activity; sid:100001138; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.106.180"; classtype:trojan-activity; sid:100001139; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.138.208"; classtype:trojan-activity; sid:100001140; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.189.235"; classtype:trojan-activity; sid:100001141; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.191.183"; classtype:trojan-activity; sid:100001142; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.196.151"; classtype:trojan-activity; sid:100001143; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.200.189"; classtype:trojan-activity; sid:100001144; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.204.126"; classtype:trojan-activity; sid:100001145; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.205.197"; classtype:trojan-activity; sid:100001146; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.6.192"; classtype:trojan-activity; sid:100001147; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.7.204"; classtype:trojan-activity; sid:100001148; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.80.153"; classtype:trojan-activity; sid:100001149; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.86.72"; classtype:trojan-activity; sid:100001150; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.41.96.53"; classtype:trojan-activity; sid:100001151; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.42.124.114"; classtype:trojan-activity; sid:100001152; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.42.125.103"; classtype:trojan-activity; sid:100001153; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.42.234.197"; classtype:trojan-activity; sid:100001154; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.42.96.17"; classtype:trojan-activity; sid:100001155; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.42.98.24"; classtype:trojan-activity; sid:100001156; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.105.157"; classtype:trojan-activity; sid:100001157; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.106.162"; classtype:trojan-activity; sid:100001158; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.112.123"; classtype:trojan-activity; sid:100001159; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.126.184"; classtype:trojan-activity; sid:100001160; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.130.232"; classtype:trojan-activity; sid:100001161; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.136.23"; classtype:trojan-activity; sid:100001162; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.177.48"; classtype:trojan-activity; sid:100001163; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.21.157"; classtype:trojan-activity; sid:100001164; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.26.36"; classtype:trojan-activity; sid:100001165; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.34.132"; classtype:trojan-activity; sid:100001166; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.53.9"; classtype:trojan-activity; sid:100001167; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.43.73.19"; classtype:trojan-activity; sid:100001168; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.168.169"; classtype:trojan-activity; sid:100001169; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.212.107"; classtype:trojan-activity; sid:100001170; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.213.216"; classtype:trojan-activity; sid:100001171; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.230.191"; classtype:trojan-activity; sid:100001172; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.30.143"; classtype:trojan-activity; sid:100001173; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.31.79"; classtype:trojan-activity; sid:100001174; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.44.8.227"; classtype:trojan-activity; sid:100001175; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.45.57.249"; classtype:trojan-activity; sid:100001176; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.45.65.166"; classtype:trojan-activity; sid:100001177; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.45.90.158"; classtype:trojan-activity; sid:100001178; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.46.138.117"; classtype:trojan-activity; sid:100001179; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.46.184.28"; classtype:trojan-activity; sid:100001180; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.46.206.206"; classtype:trojan-activity; sid:100001181; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.193.134"; classtype:trojan-activity; sid:100001182; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.200.11"; classtype:trojan-activity; sid:100001183; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.209.166"; classtype:trojan-activity; sid:100001184; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.244.201"; classtype:trojan-activity; sid:100001185; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.252.106"; classtype:trojan-activity; sid:100001186; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.254.44"; classtype:trojan-activity; sid:100001187; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.28.217"; classtype:trojan-activity; sid:100001188; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.36.171"; classtype:trojan-activity; sid:100001189; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.45.218"; classtype:trojan-activity; sid:100001190; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.71.30"; classtype:trojan-activity; sid:100001191; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.90.82"; classtype:trojan-activity; sid:100001192; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.47.91.51"; classtype:trojan-activity; sid:100001193; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"125.99.220.202"; classtype:trojan-activity; sid:100001194; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"128.116.133.92"; classtype:trojan-activity; sid:100001195; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"130.255.159.133"; classtype:trojan-activity; sid:100001196; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"134.195.139.4"; classtype:trojan-activity; sid:100001197; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"138.99.204.224"; classtype:trojan-activity; sid:100001198; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.159.226.180"; classtype:trojan-activity; sid:100001199; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.170.173.198"; classtype:trojan-activity; sid:100001200; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.170.174.162"; classtype:trojan-activity; sid:100001201; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.170.228.166"; classtype:trojan-activity; sid:100001202; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.216.102.151"; classtype:trojan-activity; sid:100001203; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"139.227.46.137"; classtype:trojan-activity; sid:100001204; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.102.17.222"; classtype:trojan-activity; sid:100001205; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.136.80.242"; classtype:trojan-activity; sid:100001206; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.138.109.129"; classtype:trojan-activity; sid:100001207; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.138.109.26"; classtype:trojan-activity; sid:100001208; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.138.8.215"; classtype:trojan-activity; sid:100001209; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.138.8.51"; classtype:trojan-activity; sid:100001210; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.155.220.240"; classtype:trojan-activity; sid:100001211; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.155.223.79"; classtype:trojan-activity; sid:100001212; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.169.164.77"; classtype:trojan-activity; sid:100001213; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.189.247.118"; classtype:trojan-activity; sid:100001214; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.205.201.192"; classtype:trojan-activity; sid:100001215; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.37.222.190"; classtype:trojan-activity; sid:100001216; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.45.127.110"; classtype:trojan-activity; sid:100001217; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.46.25.17"; classtype:trojan-activity; sid:100001218; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.46.98.241"; classtype:trojan-activity; sid:100001219; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"14.55.29.2"; classtype:trojan-activity; sid:100001220; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"140.237.30.113"; classtype:trojan-activity; sid:100001221; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"140.237.5.43"; classtype:trojan-activity; sid:100001222; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"142.11.216.5"; classtype:trojan-activity; sid:100001223; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"142.177.56.127"; classtype:trojan-activity; sid:100001224; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"146.71.79.230"; classtype:trojan-activity; sid:100001225; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"148.69.108.177"; classtype:trojan-activity; sid:100001226; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.20.176.179"; classtype:trojan-activity; sid:100001227; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.180"; classtype:trojan-activity; sid:100001228; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.182"; classtype:trojan-activity; sid:100001229; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.191"; classtype:trojan-activity; sid:100001230; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.235"; classtype:trojan-activity; sid:100001231; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.255.15.87"; classtype:trojan-activity; sid:100001232; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"149.3.85.55"; classtype:trojan-activity; sid:100001233; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"150.116.207.99"; classtype:trojan-activity; sid:100001234; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"150.129.105.61"; classtype:trojan-activity; sid:100001235; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"151.177.163.87"; classtype:trojan-activity; sid:100001236; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"151.33.230.191"; classtype:trojan-activity; sid:100001237; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"151.51.158.195"; classtype:trojan-activity; sid:100001238; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"151.73.124.231"; classtype:trojan-activity; sid:100001239; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.101.225.96"; classtype:trojan-activity; sid:100001240; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.101.234.167"; classtype:trojan-activity; sid:100001241; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.3.123.47"; classtype:trojan-activity; sid:100001242; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.3.43.136"; classtype:trojan-activity; sid:100001243; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.3.44.44"; classtype:trojan-activity; sid:100001244; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.34.135.92"; classtype:trojan-activity; sid:100001245; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.34.23.76"; classtype:trojan-activity; sid:100001246; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.34.29.28"; classtype:trojan-activity; sid:100001247; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.35.111.46"; classtype:trojan-activity; sid:100001248; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.35.27.49"; classtype:trojan-activity; sid:100001249; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"153.36.126.35"; classtype:trojan-activity; sid:100001250; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"154.126.178.16"; classtype:trojan-activity; sid:100001251; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"154.91.1.27"; classtype:trojan-activity; sid:100001252; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"157.122.105.142"; classtype:trojan-activity; sid:100001253; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"158.101.165.14"; classtype:trojan-activity; sid:100001254; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"158.174.213.128"; classtype:trojan-activity; sid:100001255; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"158.51.125.115"; classtype:trojan-activity; sid:100001256; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"159.224.74.112"; classtype:trojan-activity; sid:100001257; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.191.165.238"; classtype:trojan-activity; sid:100001258; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.191.205.175"; classtype:trojan-activity; sid:100001259; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.191.249.195"; classtype:trojan-activity; sid:100001260; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.194.28.60"; classtype:trojan-activity; sid:100001261; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"162.209.98.174"; classtype:trojan-activity; sid:100001262; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.183.111"; classtype:trojan-activity; sid:100001263; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.195.108"; classtype:trojan-activity; sid:100001264; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.200.72"; classtype:trojan-activity; sid:100001265; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.200.73"; classtype:trojan-activity; sid:100001266; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.202.174"; classtype:trojan-activity; sid:100001267; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.202.74"; classtype:trojan-activity; sid:100001268; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.203.179"; classtype:trojan-activity; sid:100001269; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.207.125"; classtype:trojan-activity; sid:100001270; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.250.202"; classtype:trojan-activity; sid:100001271; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.125.68.29"; classtype:trojan-activity; sid:100001272; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"163.53.206.228"; classtype:trojan-activity; sid:100001273; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"165.90.16.5"; classtype:trojan-activity; sid:100001274; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"170.78.39.3"; classtype:trojan-activity; sid:100001275; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"170.81.238.178"; classtype:trojan-activity; sid:100001276; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.118.18.184"; classtype:trojan-activity; sid:100001277; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.118.210.67"; classtype:trojan-activity; sid:100001278; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.119.217.149"; classtype:trojan-activity; sid:100001279; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.119.218.208"; classtype:trojan-activity; sid:100001280; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.119.219.150"; classtype:trojan-activity; sid:100001281; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.119.255.96"; classtype:trojan-activity; sid:100001282; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.120.125.147"; classtype:trojan-activity; sid:100001283; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.121.6.162"; classtype:trojan-activity; sid:100001284; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.123.189.154"; classtype:trojan-activity; sid:100001285; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.125.30.233"; classtype:trojan-activity; sid:100001286; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.125.30.93"; classtype:trojan-activity; sid:100001287; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.125.64.223"; classtype:trojan-activity; sid:100001288; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.125.65.22"; classtype:trojan-activity; sid:100001289; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.126.109.145"; classtype:trojan-activity; sid:100001290; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.34.112.42"; classtype:trojan-activity; sid:100001291; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.34.114.181"; classtype:trojan-activity; sid:100001292; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.34.179.178"; classtype:trojan-activity; sid:100001293; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.35.161.234"; classtype:trojan-activity; sid:100001294; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.35.162.156"; classtype:trojan-activity; sid:100001295; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.35.173.151"; classtype:trojan-activity; sid:100001296; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.35.174.198"; classtype:trojan-activity; sid:100001297; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.36.42.154"; classtype:trojan-activity; sid:100001298; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.38.219.189"; classtype:trojan-activity; sid:100001299; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"171.44.254.4"; classtype:trojan-activity; sid:100001300; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.105.36.168"; classtype:trojan-activity; sid:100001301; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.114.244.127"; classtype:trojan-activity; sid:100001302; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.245.5.185"; classtype:trojan-activity; sid:100001303; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"172.245.5.190"; classtype:trojan-activity; sid:100001304; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.167.85.89"; classtype:trojan-activity; sid:100001305; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.169.46.85"; classtype:trojan-activity; sid:100001306; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.19.58.108"; classtype:trojan-activity; sid:100001307; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.220.222.227"; classtype:trojan-activity; sid:100001308; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.233.85.171"; classtype:trojan-activity; sid:100001309; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.235.209.70"; classtype:trojan-activity; sid:100001310; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.25.113.8"; classtype:trojan-activity; sid:100001311; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.52.95.134"; classtype:trojan-activity; sid:100001312; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.52.97.25"; classtype:trojan-activity; sid:100001313; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.56.119.108"; classtype:trojan-activity; sid:100001314; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"173.56.92.166"; classtype:trojan-activity; sid:100001315; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.106.33.85"; classtype:trojan-activity; sid:100001316; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.48.181.23"; classtype:trojan-activity; sid:100001317; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.73.246.193"; classtype:trojan-activity; sid:100001318; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.81.78.7"; classtype:trojan-activity; sid:100001319; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.84.148.29"; classtype:trojan-activity; sid:100001320; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"174.96.30.156"; classtype:trojan-activity; sid:100001321; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.10.147.167"; classtype:trojan-activity; sid:100001322; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.11.193.66"; classtype:trojan-activity; sid:100001323; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.115.241.87"; classtype:trojan-activity; sid:100001324; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.117.66.74"; classtype:trojan-activity; sid:100001325; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.145.200.216"; classtype:trojan-activity; sid:100001326; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.146.17.227"; classtype:trojan-activity; sid:100001327; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.153.144.2"; classtype:trojan-activity; sid:100001328; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.162.69.13"; classtype:trojan-activity; sid:100001329; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.169.172.216"; classtype:trojan-activity; sid:100001330; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.173.196.162"; classtype:trojan-activity; sid:100001331; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.174.93.57"; classtype:trojan-activity; sid:100001332; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.199.33.139"; classtype:trojan-activity; sid:100001333; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.201.104.192"; classtype:trojan-activity; sid:100001334; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.208.230.8"; classtype:trojan-activity; sid:100001335; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.212.6.169"; classtype:trojan-activity; sid:100001336; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.42.46.118"; classtype:trojan-activity; sid:100001337; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"175.9.24.110"; classtype:trojan-activity; sid:100001338; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.14"; classtype:trojan-activity; sid:100001339; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.35"; classtype:trojan-activity; sid:100001340; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.63"; classtype:trojan-activity; sid:100001341; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.66"; classtype:trojan-activity; sid:100001342; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.111.174.67"; classtype:trojan-activity; sid:100001343; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.101"; classtype:trojan-activity; sid:100001344; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.104"; classtype:trojan-activity; sid:100001345; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.113"; classtype:trojan-activity; sid:100001346; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.120"; classtype:trojan-activity; sid:100001347; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.128"; classtype:trojan-activity; sid:100001348; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.138"; classtype:trojan-activity; sid:100001349; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.59"; classtype:trojan-activity; sid:100001350; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.60"; classtype:trojan-activity; sid:100001351; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.65"; classtype:trojan-activity; sid:100001352; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.66"; classtype:trojan-activity; sid:100001353; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.84"; classtype:trojan-activity; sid:100001354; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.88"; classtype:trojan-activity; sid:100001355; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.91"; classtype:trojan-activity; sid:100001356; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.161.93"; classtype:trojan-activity; sid:100001357; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.113.174.139"; classtype:trojan-activity; sid:100001358; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.12.117.70"; classtype:trojan-activity; sid:100001359; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.123.4.115"; classtype:trojan-activity; sid:100001360; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.123.7.115"; classtype:trojan-activity; sid:100001361; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.123.7.127"; classtype:trojan-activity; sid:100001362; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.123.9.243"; classtype:trojan-activity; sid:100001363; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.124.7.225"; classtype:trojan-activity; sid:100001364; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.221.251.147"; classtype:trojan-activity; sid:100001365; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.240.40.142"; classtype:trojan-activity; sid:100001366; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.240.84.106"; classtype:trojan-activity; sid:100001367; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"176.32.151.180"; classtype:trojan-activity; sid:100001368; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.229.64.218"; classtype:trojan-activity; sid:100001369; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.44.61.243"; classtype:trojan-activity; sid:100001370; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.54.82.154"; classtype:trojan-activity; sid:100001371; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"177.86.235.143"; classtype:trojan-activity; sid:100001372; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.124.182.187"; classtype:trojan-activity; sid:100001373; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.134.185.112"; classtype:trojan-activity; sid:100001374; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.141.161.129"; classtype:trojan-activity; sid:100001375; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.141.25.82"; classtype:trojan-activity; sid:100001376; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.141.57.166"; classtype:trojan-activity; sid:100001377; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.150.174.65"; classtype:trojan-activity; sid:100001378; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.165.122.141"; classtype:trojan-activity; sid:100001379; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.0.140"; classtype:trojan-activity; sid:100001380; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.0.232"; classtype:trojan-activity; sid:100001381; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.247"; classtype:trojan-activity; sid:100001382; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.250"; classtype:trojan-activity; sid:100001383; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.252"; classtype:trojan-activity; sid:100001384; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.1.80"; classtype:trojan-activity; sid:100001385; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.10.108"; classtype:trojan-activity; sid:100001386; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.10.156"; classtype:trojan-activity; sid:100001387; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.10.26"; classtype:trojan-activity; sid:100001388; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.10.34"; classtype:trojan-activity; sid:100001389; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.10.42"; classtype:trojan-activity; sid:100001390; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.129"; classtype:trojan-activity; sid:100001391; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.180"; classtype:trojan-activity; sid:100001392; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.190"; classtype:trojan-activity; sid:100001393; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.223"; classtype:trojan-activity; sid:100001394; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.4"; classtype:trojan-activity; sid:100001395; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.100.87"; classtype:trojan-activity; sid:100001396; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.101.110"; classtype:trojan-activity; sid:100001397; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.101.207"; classtype:trojan-activity; sid:100001398; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.134"; classtype:trojan-activity; sid:100001399; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.136"; classtype:trojan-activity; sid:100001400; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.152"; classtype:trojan-activity; sid:100001401; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.221"; classtype:trojan-activity; sid:100001402; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.228"; classtype:trojan-activity; sid:100001403; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.102.245"; classtype:trojan-activity; sid:100001404; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.103.172"; classtype:trojan-activity; sid:100001405; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.103.195"; classtype:trojan-activity; sid:100001406; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.103.91"; classtype:trojan-activity; sid:100001407; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.106"; classtype:trojan-activity; sid:100001408; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.110"; classtype:trojan-activity; sid:100001409; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.120"; classtype:trojan-activity; sid:100001410; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.128"; classtype:trojan-activity; sid:100001411; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.153"; classtype:trojan-activity; sid:100001412; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.155"; classtype:trojan-activity; sid:100001413; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.16"; classtype:trojan-activity; sid:100001414; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.169"; classtype:trojan-activity; sid:100001415; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.183"; classtype:trojan-activity; sid:100001416; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.206"; classtype:trojan-activity; sid:100001417; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.49"; classtype:trojan-activity; sid:100001418; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.64"; classtype:trojan-activity; sid:100001419; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.104.80"; classtype:trojan-activity; sid:100001420; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.111"; classtype:trojan-activity; sid:100001421; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.125"; classtype:trojan-activity; sid:100001422; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.146"; classtype:trojan-activity; sid:100001423; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.177"; classtype:trojan-activity; sid:100001424; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.217"; classtype:trojan-activity; sid:100001425; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.245"; classtype:trojan-activity; sid:100001426; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.247"; classtype:trojan-activity; sid:100001427; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.27"; classtype:trojan-activity; sid:100001428; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.28"; classtype:trojan-activity; sid:100001429; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.49"; classtype:trojan-activity; sid:100001430; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.105.94"; classtype:trojan-activity; sid:100001431; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.118"; classtype:trojan-activity; sid:100001432; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.18"; classtype:trojan-activity; sid:100001433; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.193"; classtype:trojan-activity; sid:100001434; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.219"; classtype:trojan-activity; sid:100001435; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.253"; classtype:trojan-activity; sid:100001436; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.37"; classtype:trojan-activity; sid:100001437; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.77"; classtype:trojan-activity; sid:100001438; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.106.87"; classtype:trojan-activity; sid:100001439; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.0"; classtype:trojan-activity; sid:100001440; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.133"; classtype:trojan-activity; sid:100001441; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.245"; classtype:trojan-activity; sid:100001442; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.83"; classtype:trojan-activity; sid:100001443; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.107.86"; classtype:trojan-activity; sid:100001444; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.116"; classtype:trojan-activity; sid:100001445; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.145"; classtype:trojan-activity; sid:100001446; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.148"; classtype:trojan-activity; sid:100001447; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.179"; classtype:trojan-activity; sid:100001448; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.232"; classtype:trojan-activity; sid:100001449; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.67"; classtype:trojan-activity; sid:100001450; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.87"; classtype:trojan-activity; sid:100001451; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.108.94"; classtype:trojan-activity; sid:100001452; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.109.1"; classtype:trojan-activity; sid:100001453; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.109.127"; classtype:trojan-activity; sid:100001454; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.109.193"; classtype:trojan-activity; sid:100001455; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.109.37"; classtype:trojan-activity; sid:100001456; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.109.77"; classtype:trojan-activity; sid:100001457; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.109.78"; classtype:trojan-activity; sid:100001458; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.176"; classtype:trojan-activity; sid:100001459; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.184"; classtype:trojan-activity; sid:100001460; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.204"; classtype:trojan-activity; sid:100001461; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.11.57"; classtype:trojan-activity; sid:100001462; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.150"; classtype:trojan-activity; sid:100001463; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.155"; classtype:trojan-activity; sid:100001464; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.214"; classtype:trojan-activity; sid:100001465; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.221"; classtype:trojan-activity; sid:100001466; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.90"; classtype:trojan-activity; sid:100001467; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.110.97"; classtype:trojan-activity; sid:100001468; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.105"; classtype:trojan-activity; sid:100001469; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.157"; classtype:trojan-activity; sid:100001470; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.190"; classtype:trojan-activity; sid:100001471; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.206"; classtype:trojan-activity; sid:100001472; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.36"; classtype:trojan-activity; sid:100001473; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.111.84"; classtype:trojan-activity; sid:100001474; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.159"; classtype:trojan-activity; sid:100001475; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.26"; classtype:trojan-activity; sid:100001476; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.4"; classtype:trojan-activity; sid:100001477; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.112.79"; classtype:trojan-activity; sid:100001478; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.113.0"; classtype:trojan-activity; sid:100001479; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.113.171"; classtype:trojan-activity; sid:100001480; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.113.174"; classtype:trojan-activity; sid:100001481; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.113.35"; classtype:trojan-activity; sid:100001482; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.113.64"; classtype:trojan-activity; sid:100001483; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.113.85"; classtype:trojan-activity; sid:100001484; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.107"; classtype:trojan-activity; sid:100001485; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.215"; classtype:trojan-activity; sid:100001486; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.234"; classtype:trojan-activity; sid:100001487; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.238"; classtype:trojan-activity; sid:100001488; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.241"; classtype:trojan-activity; sid:100001489; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.247"; classtype:trojan-activity; sid:100001490; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.254"; classtype:trojan-activity; sid:100001491; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.5"; classtype:trojan-activity; sid:100001492; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.55"; classtype:trojan-activity; sid:100001493; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.63"; classtype:trojan-activity; sid:100001494; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.82"; classtype:trojan-activity; sid:100001495; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.90"; classtype:trojan-activity; sid:100001496; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.114.99"; classtype:trojan-activity; sid:100001497; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.1"; classtype:trojan-activity; sid:100001498; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.12"; classtype:trojan-activity; sid:100001499; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.13"; classtype:trojan-activity; sid:100001500; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.142"; classtype:trojan-activity; sid:100001501; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.143"; classtype:trojan-activity; sid:100001502; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.19"; classtype:trojan-activity; sid:100001503; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.206"; classtype:trojan-activity; sid:100001504; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.208"; classtype:trojan-activity; sid:100001505; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.221"; classtype:trojan-activity; sid:100001506; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.242"; classtype:trojan-activity; sid:100001507; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.35"; classtype:trojan-activity; sid:100001508; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.115.40"; classtype:trojan-activity; sid:100001509; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.116.15"; classtype:trojan-activity; sid:100001510; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.116.236"; classtype:trojan-activity; sid:100001511; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.116.48"; classtype:trojan-activity; sid:100001512; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.116.64"; classtype:trojan-activity; sid:100001513; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.116.87"; classtype:trojan-activity; sid:100001514; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.117.215"; classtype:trojan-activity; sid:100001515; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.117.32"; classtype:trojan-activity; sid:100001516; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.117.51"; classtype:trojan-activity; sid:100001517; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.117.63"; classtype:trojan-activity; sid:100001518; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.117.84"; classtype:trojan-activity; sid:100001519; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.112"; classtype:trojan-activity; sid:100001520; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.139"; classtype:trojan-activity; sid:100001521; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.192"; classtype:trojan-activity; sid:100001522; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.225"; classtype:trojan-activity; sid:100001523; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.118.60"; classtype:trojan-activity; sid:100001524; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.205"; classtype:trojan-activity; sid:100001525; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.209"; classtype:trojan-activity; sid:100001526; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.26"; classtype:trojan-activity; sid:100001527; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.86"; classtype:trojan-activity; sid:100001528; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.119.88"; classtype:trojan-activity; sid:100001529; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.114"; classtype:trojan-activity; sid:100001530; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.252"; classtype:trojan-activity; sid:100001531; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.53"; classtype:trojan-activity; sid:100001532; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.12.97"; classtype:trojan-activity; sid:100001533; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.120.133"; classtype:trojan-activity; sid:100001534; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.120.184"; classtype:trojan-activity; sid:100001535; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.120.196"; classtype:trojan-activity; sid:100001536; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.120.203"; classtype:trojan-activity; sid:100001537; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.120.251"; classtype:trojan-activity; sid:100001538; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.123"; classtype:trojan-activity; sid:100001539; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.155"; classtype:trojan-activity; sid:100001540; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.55"; classtype:trojan-activity; sid:100001541; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.62"; classtype:trojan-activity; sid:100001542; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.63"; classtype:trojan-activity; sid:100001543; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.68"; classtype:trojan-activity; sid:100001544; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.121.99"; classtype:trojan-activity; sid:100001545; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.172"; classtype:trojan-activity; sid:100001546; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.245"; classtype:trojan-activity; sid:100001547; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.26"; classtype:trojan-activity; sid:100001548; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.122.28"; classtype:trojan-activity; sid:100001549; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.113"; classtype:trojan-activity; sid:100001550; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.2"; classtype:trojan-activity; sid:100001551; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.20"; classtype:trojan-activity; sid:100001552; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.30"; classtype:trojan-activity; sid:100001553; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.56"; classtype:trojan-activity; sid:100001554; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.123.60"; classtype:trojan-activity; sid:100001555; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.109"; classtype:trojan-activity; sid:100001556; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.122"; classtype:trojan-activity; sid:100001557; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.131"; classtype:trojan-activity; sid:100001558; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.141"; classtype:trojan-activity; sid:100001559; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.211"; classtype:trojan-activity; sid:100001560; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.4"; classtype:trojan-activity; sid:100001561; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.79"; classtype:trojan-activity; sid:100001562; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.124.89"; classtype:trojan-activity; sid:100001563; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.118"; classtype:trojan-activity; sid:100001564; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.14"; classtype:trojan-activity; sid:100001565; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.153"; classtype:trojan-activity; sid:100001566; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.156"; classtype:trojan-activity; sid:100001567; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.174"; classtype:trojan-activity; sid:100001568; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.219"; classtype:trojan-activity; sid:100001569; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.125.39"; classtype:trojan-activity; sid:100001570; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.124"; classtype:trojan-activity; sid:100001571; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.131"; classtype:trojan-activity; sid:100001572; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.141"; classtype:trojan-activity; sid:100001573; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.167"; classtype:trojan-activity; sid:100001574; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.220"; classtype:trojan-activity; sid:100001575; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.222"; classtype:trojan-activity; sid:100001576; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.237"; classtype:trojan-activity; sid:100001577; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.126.83"; classtype:trojan-activity; sid:100001578; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.10"; classtype:trojan-activity; sid:100001579; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.109"; classtype:trojan-activity; sid:100001580; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.116"; classtype:trojan-activity; sid:100001581; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.129"; classtype:trojan-activity; sid:100001582; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.142"; classtype:trojan-activity; sid:100001583; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.15"; classtype:trojan-activity; sid:100001584; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.182"; classtype:trojan-activity; sid:100001585; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.230"; classtype:trojan-activity; sid:100001586; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.231"; classtype:trojan-activity; sid:100001587; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.236"; classtype:trojan-activity; sid:100001588; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.238"; classtype:trojan-activity; sid:100001589; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.63"; classtype:trojan-activity; sid:100001590; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.127.75"; classtype:trojan-activity; sid:100001591; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.13.237"; classtype:trojan-activity; sid:100001592; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.14.106"; classtype:trojan-activity; sid:100001593; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.14.185"; classtype:trojan-activity; sid:100001594; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.14.246"; classtype:trojan-activity; sid:100001595; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.14.60"; classtype:trojan-activity; sid:100001596; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.17"; classtype:trojan-activity; sid:100001597; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.217"; classtype:trojan-activity; sid:100001598; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.232"; classtype:trojan-activity; sid:100001599; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.246"; classtype:trojan-activity; sid:100001600; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.252"; classtype:trojan-activity; sid:100001601; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.35"; classtype:trojan-activity; sid:100001602; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.44"; classtype:trojan-activity; sid:100001603; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.45"; classtype:trojan-activity; sid:100001604; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.15.85"; classtype:trojan-activity; sid:100001605; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.1"; classtype:trojan-activity; sid:100001606; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.108"; classtype:trojan-activity; sid:100001607; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.114"; classtype:trojan-activity; sid:100001608; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.17"; classtype:trojan-activity; sid:100001609; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.179"; classtype:trojan-activity; sid:100001610; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.193"; classtype:trojan-activity; sid:100001611; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.208"; classtype:trojan-activity; sid:100001612; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.73"; classtype:trojan-activity; sid:100001613; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.16.97"; classtype:trojan-activity; sid:100001614; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.17.176"; classtype:trojan-activity; sid:100001615; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.17.245"; classtype:trojan-activity; sid:100001616; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.18.238"; classtype:trojan-activity; sid:100001617; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.18.27"; classtype:trojan-activity; sid:100001618; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.18.93"; classtype:trojan-activity; sid:100001619; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.144"; classtype:trojan-activity; sid:100001620; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.150"; classtype:trojan-activity; sid:100001621; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.163"; classtype:trojan-activity; sid:100001622; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.174"; classtype:trojan-activity; sid:100001623; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.229"; classtype:trojan-activity; sid:100001624; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.242"; classtype:trojan-activity; sid:100001625; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.44"; classtype:trojan-activity; sid:100001626; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.19.47"; classtype:trojan-activity; sid:100001627; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.110"; classtype:trojan-activity; sid:100001628; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.237"; classtype:trojan-activity; sid:100001629; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.41"; classtype:trojan-activity; sid:100001630; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.2.5"; classtype:trojan-activity; sid:100001631; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.117"; classtype:trojan-activity; sid:100001632; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.145"; classtype:trojan-activity; sid:100001633; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.170"; classtype:trojan-activity; sid:100001634; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.21"; classtype:trojan-activity; sid:100001635; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.225"; classtype:trojan-activity; sid:100001636; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.237"; classtype:trojan-activity; sid:100001637; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.238"; classtype:trojan-activity; sid:100001638; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.24"; classtype:trojan-activity; sid:100001639; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.38"; classtype:trojan-activity; sid:100001640; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.20.70"; classtype:trojan-activity; sid:100001641; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.149"; classtype:trojan-activity; sid:100001642; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.184"; classtype:trojan-activity; sid:100001643; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.238"; classtype:trojan-activity; sid:100001644; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.21.76"; classtype:trojan-activity; sid:100001645; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.22.207"; classtype:trojan-activity; sid:100001646; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.22.248"; classtype:trojan-activity; sid:100001647; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.23.102"; classtype:trojan-activity; sid:100001648; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.23.156"; classtype:trojan-activity; sid:100001649; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.23.250"; classtype:trojan-activity; sid:100001650; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.23.6"; classtype:trojan-activity; sid:100001651; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.13"; classtype:trojan-activity; sid:100001652; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.138"; classtype:trojan-activity; sid:100001653; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.15"; classtype:trojan-activity; sid:100001654; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.171"; classtype:trojan-activity; sid:100001655; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.227"; classtype:trojan-activity; sid:100001656; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.24.230"; classtype:trojan-activity; sid:100001657; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.117"; classtype:trojan-activity; sid:100001658; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.169"; classtype:trojan-activity; sid:100001659; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.244"; classtype:trojan-activity; sid:100001660; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.28"; classtype:trojan-activity; sid:100001661; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.56"; classtype:trojan-activity; sid:100001662; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.64"; classtype:trojan-activity; sid:100001663; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.25.77"; classtype:trojan-activity; sid:100001664; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.134"; classtype:trojan-activity; sid:100001665; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.164"; classtype:trojan-activity; sid:100001666; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.165"; classtype:trojan-activity; sid:100001667; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.215"; classtype:trojan-activity; sid:100001668; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.219"; classtype:trojan-activity; sid:100001669; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.224"; classtype:trojan-activity; sid:100001670; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.246"; classtype:trojan-activity; sid:100001671; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.26.34"; classtype:trojan-activity; sid:100001672; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.122"; classtype:trojan-activity; sid:100001673; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.138"; classtype:trojan-activity; sid:100001674; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.14"; classtype:trojan-activity; sid:100001675; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.167"; classtype:trojan-activity; sid:100001676; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.179"; classtype:trojan-activity; sid:100001677; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.199"; classtype:trojan-activity; sid:100001678; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.202"; classtype:trojan-activity; sid:100001679; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.215"; classtype:trojan-activity; sid:100001680; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.225"; classtype:trojan-activity; sid:100001681; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.233"; classtype:trojan-activity; sid:100001682; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.239"; classtype:trojan-activity; sid:100001683; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.32"; classtype:trojan-activity; sid:100001684; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.48"; classtype:trojan-activity; sid:100001685; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.68"; classtype:trojan-activity; sid:100001686; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.69"; classtype:trojan-activity; sid:100001687; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.27.84"; classtype:trojan-activity; sid:100001688; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.28.124"; classtype:trojan-activity; sid:100001689; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.28.168"; classtype:trojan-activity; sid:100001690; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.28.75"; classtype:trojan-activity; sid:100001691; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.28.8"; classtype:trojan-activity; sid:100001692; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.12"; classtype:trojan-activity; sid:100001693; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.16"; classtype:trojan-activity; sid:100001694; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.173"; classtype:trojan-activity; sid:100001695; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.174"; classtype:trojan-activity; sid:100001696; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.29.207"; classtype:trojan-activity; sid:100001697; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.116"; classtype:trojan-activity; sid:100001698; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.123"; classtype:trojan-activity; sid:100001699; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.130"; classtype:trojan-activity; sid:100001700; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.172"; classtype:trojan-activity; sid:100001701; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.190"; classtype:trojan-activity; sid:100001702; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.194"; classtype:trojan-activity; sid:100001703; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.196"; classtype:trojan-activity; sid:100001704; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.214"; classtype:trojan-activity; sid:100001705; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.56"; classtype:trojan-activity; sid:100001706; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.3.81"; classtype:trojan-activity; sid:100001707; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.0"; classtype:trojan-activity; sid:100001708; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.30.77"; classtype:trojan-activity; sid:100001709; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.31.211"; classtype:trojan-activity; sid:100001710; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.31.232"; classtype:trojan-activity; sid:100001711; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.31.249"; classtype:trojan-activity; sid:100001712; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.31.251"; classtype:trojan-activity; sid:100001713; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.0"; classtype:trojan-activity; sid:100001714; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.172"; classtype:trojan-activity; sid:100001715; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.198"; classtype:trojan-activity; sid:100001716; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.208"; classtype:trojan-activity; sid:100001717; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.211"; classtype:trojan-activity; sid:100001718; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.229"; classtype:trojan-activity; sid:100001719; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.243"; classtype:trojan-activity; sid:100001720; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.255"; classtype:trojan-activity; sid:100001721; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.42"; classtype:trojan-activity; sid:100001722; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.32.89"; classtype:trojan-activity; sid:100001723; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.112"; classtype:trojan-activity; sid:100001724; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.155"; classtype:trojan-activity; sid:100001725; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.161"; classtype:trojan-activity; sid:100001726; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.162"; classtype:trojan-activity; sid:100001727; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.170"; classtype:trojan-activity; sid:100001728; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.173"; classtype:trojan-activity; sid:100001729; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.174"; classtype:trojan-activity; sid:100001730; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.181"; classtype:trojan-activity; sid:100001731; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.2"; classtype:trojan-activity; sid:100001732; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.205"; classtype:trojan-activity; sid:100001733; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.216"; classtype:trojan-activity; sid:100001734; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.234"; classtype:trojan-activity; sid:100001735; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.236"; classtype:trojan-activity; sid:100001736; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.33.26"; classtype:trojan-activity; sid:100001737; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.34.219"; classtype:trojan-activity; sid:100001738; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.34.5"; classtype:trojan-activity; sid:100001739; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.34.56"; classtype:trojan-activity; sid:100001740; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.34.96"; classtype:trojan-activity; sid:100001741; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.35.21"; classtype:trojan-activity; sid:100001742; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.35.215"; classtype:trojan-activity; sid:100001743; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.35.38"; classtype:trojan-activity; sid:100001744; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.35.83"; classtype:trojan-activity; sid:100001745; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.35.89"; classtype:trojan-activity; sid:100001746; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.0"; classtype:trojan-activity; sid:100001747; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.1"; classtype:trojan-activity; sid:100001748; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.102"; classtype:trojan-activity; sid:100001749; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.112"; classtype:trojan-activity; sid:100001750; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.12"; classtype:trojan-activity; sid:100001751; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.127"; classtype:trojan-activity; sid:100001752; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.176"; classtype:trojan-activity; sid:100001753; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.19"; classtype:trojan-activity; sid:100001754; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.199"; classtype:trojan-activity; sid:100001755; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.218"; classtype:trojan-activity; sid:100001756; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.22"; classtype:trojan-activity; sid:100001757; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.223"; classtype:trojan-activity; sid:100001758; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.33"; classtype:trojan-activity; sid:100001759; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.36.78"; classtype:trojan-activity; sid:100001760; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.121"; classtype:trojan-activity; sid:100001761; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.135"; classtype:trojan-activity; sid:100001762; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.159"; classtype:trojan-activity; sid:100001763; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.37.6"; classtype:trojan-activity; sid:100001764; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.1"; classtype:trojan-activity; sid:100001765; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.132"; classtype:trojan-activity; sid:100001766; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.162"; classtype:trojan-activity; sid:100001767; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.165"; classtype:trojan-activity; sid:100001768; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.191"; classtype:trojan-activity; sid:100001769; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.200"; classtype:trojan-activity; sid:100001770; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.53"; classtype:trojan-activity; sid:100001771; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.38.98"; classtype:trojan-activity; sid:100001772; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.39.167"; classtype:trojan-activity; sid:100001773; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.39.176"; classtype:trojan-activity; sid:100001774; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.39.245"; classtype:trojan-activity; sid:100001775; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.39.61"; classtype:trojan-activity; sid:100001776; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.219"; classtype:trojan-activity; sid:100001777; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.222"; classtype:trojan-activity; sid:100001778; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.42"; classtype:trojan-activity; sid:100001779; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.4.95"; classtype:trojan-activity; sid:100001780; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.1"; classtype:trojan-activity; sid:100001781; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.145"; classtype:trojan-activity; sid:100001782; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.151"; classtype:trojan-activity; sid:100001783; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.166"; classtype:trojan-activity; sid:100001784; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.199"; classtype:trojan-activity; sid:100001785; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.226"; classtype:trojan-activity; sid:100001786; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.41"; classtype:trojan-activity; sid:100001787; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.5"; classtype:trojan-activity; sid:100001788; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.67"; classtype:trojan-activity; sid:100001789; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.70"; classtype:trojan-activity; sid:100001790; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.71"; classtype:trojan-activity; sid:100001791; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.40.82"; classtype:trojan-activity; sid:100001792; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.165"; classtype:trojan-activity; sid:100001793; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.178"; classtype:trojan-activity; sid:100001794; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.200"; classtype:trojan-activity; sid:100001795; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.203"; classtype:trojan-activity; sid:100001796; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.210"; classtype:trojan-activity; sid:100001797; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.216"; classtype:trojan-activity; sid:100001798; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.246"; classtype:trojan-activity; sid:100001799; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.41.34"; classtype:trojan-activity; sid:100001800; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.162"; classtype:trojan-activity; sid:100001801; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.166"; classtype:trojan-activity; sid:100001802; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.200"; classtype:trojan-activity; sid:100001803; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.211"; classtype:trojan-activity; sid:100001804; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.221"; classtype:trojan-activity; sid:100001805; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.27"; classtype:trojan-activity; sid:100001806; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.42.31"; classtype:trojan-activity; sid:100001807; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.1"; classtype:trojan-activity; sid:100001808; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.121"; classtype:trojan-activity; sid:100001809; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.125"; classtype:trojan-activity; sid:100001810; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.147"; classtype:trojan-activity; sid:100001811; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.16"; classtype:trojan-activity; sid:100001812; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.33"; classtype:trojan-activity; sid:100001813; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.43.34"; classtype:trojan-activity; sid:100001814; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.0"; classtype:trojan-activity; sid:100001815; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.134"; classtype:trojan-activity; sid:100001816; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.143"; classtype:trojan-activity; sid:100001817; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.155"; classtype:trojan-activity; sid:100001818; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.197"; classtype:trojan-activity; sid:100001819; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.209"; classtype:trojan-activity; sid:100001820; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.218"; classtype:trojan-activity; sid:100001821; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.219"; classtype:trojan-activity; sid:100001822; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.22"; classtype:trojan-activity; sid:100001823; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.241"; classtype:trojan-activity; sid:100001824; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.70"; classtype:trojan-activity; sid:100001825; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.89"; classtype:trojan-activity; sid:100001826; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.90"; classtype:trojan-activity; sid:100001827; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.44.95"; classtype:trojan-activity; sid:100001828; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.45.205"; classtype:trojan-activity; sid:100001829; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.45.221"; classtype:trojan-activity; sid:100001830; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.45.224"; classtype:trojan-activity; sid:100001831; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.45.230"; classtype:trojan-activity; sid:100001832; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.119"; classtype:trojan-activity; sid:100001833; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.132"; classtype:trojan-activity; sid:100001834; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.151"; classtype:trojan-activity; sid:100001835; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.46.187"; classtype:trojan-activity; sid:100001836; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.141"; classtype:trojan-activity; sid:100001837; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.47.151"; classtype:trojan-activity; sid:100001838; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.48.121"; classtype:trojan-activity; sid:100001839; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.48.195"; classtype:trojan-activity; sid:100001840; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.48.243"; classtype:trojan-activity; sid:100001841; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.48.76"; classtype:trojan-activity; sid:100001842; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.100"; classtype:trojan-activity; sid:100001843; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.107"; classtype:trojan-activity; sid:100001844; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.129"; classtype:trojan-activity; sid:100001845; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.138"; classtype:trojan-activity; sid:100001846; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.188"; classtype:trojan-activity; sid:100001847; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.247"; classtype:trojan-activity; sid:100001848; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.49.3"; classtype:trojan-activity; sid:100001849; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.5.247"; classtype:trojan-activity; sid:100001850; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.5.251"; classtype:trojan-activity; sid:100001851; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.5.70"; classtype:trojan-activity; sid:100001852; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.131"; classtype:trojan-activity; sid:100001853; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.177"; classtype:trojan-activity; sid:100001854; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.196"; classtype:trojan-activity; sid:100001855; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.201"; classtype:trojan-activity; sid:100001856; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.218"; classtype:trojan-activity; sid:100001857; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.236"; classtype:trojan-activity; sid:100001858; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.50.237"; classtype:trojan-activity; sid:100001859; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.51.197"; classtype:trojan-activity; sid:100001860; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.51.202"; classtype:trojan-activity; sid:100001861; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.51.223"; classtype:trojan-activity; sid:100001862; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.51.66"; classtype:trojan-activity; sid:100001863; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.149"; classtype:trojan-activity; sid:100001864; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.52.161"; classtype:trojan-activity; sid:100001865; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.103"; classtype:trojan-activity; sid:100001866; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.186"; classtype:trojan-activity; sid:100001867; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.20"; classtype:trojan-activity; sid:100001868; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.228"; classtype:trojan-activity; sid:100001869; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.4"; classtype:trojan-activity; sid:100001870; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.5"; classtype:trojan-activity; sid:100001871; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.53.79"; classtype:trojan-activity; sid:100001872; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.105"; classtype:trojan-activity; sid:100001873; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.205"; classtype:trojan-activity; sid:100001874; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.214"; classtype:trojan-activity; sid:100001875; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.35"; classtype:trojan-activity; sid:100001876; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.54.72"; classtype:trojan-activity; sid:100001877; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.101"; classtype:trojan-activity; sid:100001878; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.163"; classtype:trojan-activity; sid:100001879; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.170"; classtype:trojan-activity; sid:100001880; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.216"; classtype:trojan-activity; sid:100001881; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.248"; classtype:trojan-activity; sid:100001882; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.29"; classtype:trojan-activity; sid:100001883; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.41"; classtype:trojan-activity; sid:100001884; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.77"; classtype:trojan-activity; sid:100001885; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.55.85"; classtype:trojan-activity; sid:100001886; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.103"; classtype:trojan-activity; sid:100001887; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.196"; classtype:trojan-activity; sid:100001888; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.33"; classtype:trojan-activity; sid:100001889; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.75"; classtype:trojan-activity; sid:100001890; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.56.94"; classtype:trojan-activity; sid:100001891; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.57.141"; classtype:trojan-activity; sid:100001892; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.57.178"; classtype:trojan-activity; sid:100001893; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.57.192"; classtype:trojan-activity; sid:100001894; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.58.141"; classtype:trojan-activity; sid:100001895; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.58.42"; classtype:trojan-activity; sid:100001896; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.142"; classtype:trojan-activity; sid:100001897; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.161"; classtype:trojan-activity; sid:100001898; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.229"; classtype:trojan-activity; sid:100001899; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.33"; classtype:trojan-activity; sid:100001900; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.46"; classtype:trojan-activity; sid:100001901; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.54"; classtype:trojan-activity; sid:100001902; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.59.91"; classtype:trojan-activity; sid:100001903; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.134"; classtype:trojan-activity; sid:100001904; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.151"; classtype:trojan-activity; sid:100001905; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.162"; classtype:trojan-activity; sid:100001906; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.6.72"; classtype:trojan-activity; sid:100001907; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.60.181"; classtype:trojan-activity; sid:100001908; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.60.209"; classtype:trojan-activity; sid:100001909; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.117"; classtype:trojan-activity; sid:100001910; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.156"; classtype:trojan-activity; sid:100001911; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.219"; classtype:trojan-activity; sid:100001912; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.229"; classtype:trojan-activity; sid:100001913; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.234"; classtype:trojan-activity; sid:100001914; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.253"; classtype:trojan-activity; sid:100001915; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.40"; classtype:trojan-activity; sid:100001916; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.42"; classtype:trojan-activity; sid:100001917; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.61.82"; classtype:trojan-activity; sid:100001918; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.110"; classtype:trojan-activity; sid:100001919; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.115"; classtype:trojan-activity; sid:100001920; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.168"; classtype:trojan-activity; sid:100001921; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.216"; classtype:trojan-activity; sid:100001922; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.43"; classtype:trojan-activity; sid:100001923; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.44"; classtype:trojan-activity; sid:100001924; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.62.70"; classtype:trojan-activity; sid:100001925; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.63.194"; classtype:trojan-activity; sid:100001926; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.63.21"; classtype:trojan-activity; sid:100001927; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.63.218"; classtype:trojan-activity; sid:100001928; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.116"; classtype:trojan-activity; sid:100001929; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.12"; classtype:trojan-activity; sid:100001930; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.142"; classtype:trojan-activity; sid:100001931; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.158"; classtype:trojan-activity; sid:100001932; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.219"; classtype:trojan-activity; sid:100001933; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.30"; classtype:trojan-activity; sid:100001934; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.64.66"; classtype:trojan-activity; sid:100001935; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.65.115"; classtype:trojan-activity; sid:100001936; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.65.171"; classtype:trojan-activity; sid:100001937; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.65.223"; classtype:trojan-activity; sid:100001938; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.65.44"; classtype:trojan-activity; sid:100001939; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.65.70"; classtype:trojan-activity; sid:100001940; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.65.95"; classtype:trojan-activity; sid:100001941; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.65.96"; classtype:trojan-activity; sid:100001942; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.105"; classtype:trojan-activity; sid:100001943; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.170"; classtype:trojan-activity; sid:100001944; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.177"; classtype:trojan-activity; sid:100001945; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.186"; classtype:trojan-activity; sid:100001946; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.199"; classtype:trojan-activity; sid:100001947; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.211"; classtype:trojan-activity; sid:100001948; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.228"; classtype:trojan-activity; sid:100001949; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.66.93"; classtype:trojan-activity; sid:100001950; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.0"; classtype:trojan-activity; sid:100001951; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.184"; classtype:trojan-activity; sid:100001952; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.201"; classtype:trojan-activity; sid:100001953; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.254"; classtype:trojan-activity; sid:100001954; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.67.83"; classtype:trojan-activity; sid:100001955; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.1"; classtype:trojan-activity; sid:100001956; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.109"; classtype:trojan-activity; sid:100001957; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.126"; classtype:trojan-activity; sid:100001958; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.170"; classtype:trojan-activity; sid:100001959; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.227"; classtype:trojan-activity; sid:100001960; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.232"; classtype:trojan-activity; sid:100001961; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.29"; classtype:trojan-activity; sid:100001962; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.44"; classtype:trojan-activity; sid:100001963; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.66"; classtype:trojan-activity; sid:100001964; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.68.83"; classtype:trojan-activity; sid:100001965; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.111"; classtype:trojan-activity; sid:100001966; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.112"; classtype:trojan-activity; sid:100001967; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.119"; classtype:trojan-activity; sid:100001968; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.128"; classtype:trojan-activity; sid:100001969; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.138"; classtype:trojan-activity; sid:100001970; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.148"; classtype:trojan-activity; sid:100001971; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.149"; classtype:trojan-activity; sid:100001972; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.173"; classtype:trojan-activity; sid:100001973; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.188"; classtype:trojan-activity; sid:100001974; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.69.77"; classtype:trojan-activity; sid:100001975; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.7.163"; classtype:trojan-activity; sid:100001976; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.119"; classtype:trojan-activity; sid:100001977; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.12"; classtype:trojan-activity; sid:100001978; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.147"; classtype:trojan-activity; sid:100001979; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.18"; classtype:trojan-activity; sid:100001980; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.200"; classtype:trojan-activity; sid:100001981; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.38"; classtype:trojan-activity; sid:100001982; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.53"; classtype:trojan-activity; sid:100001983; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.70.54"; classtype:trojan-activity; sid:100001984; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.148"; classtype:trojan-activity; sid:100001985; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.153"; classtype:trojan-activity; sid:100001986; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.185"; classtype:trojan-activity; sid:100001987; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.22"; classtype:trojan-activity; sid:100001988; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.240"; classtype:trojan-activity; sid:100001989; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.55"; classtype:trojan-activity; sid:100001990; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.63"; classtype:trojan-activity; sid:100001991; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.64"; classtype:trojan-activity; sid:100001992; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.71.84"; classtype:trojan-activity; sid:100001993; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.13"; classtype:trojan-activity; sid:100001994; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.164"; classtype:trojan-activity; sid:100001995; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.196"; classtype:trojan-activity; sid:100001996; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.72.222"; classtype:trojan-activity; sid:100001997; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.73.211"; classtype:trojan-activity; sid:100001998; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.73.71"; classtype:trojan-activity; sid:100001999; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.74.182"; classtype:trojan-activity; sid:100002000; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.74.48"; classtype:trojan-activity; sid:100002001; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.74.77"; classtype:trojan-activity; sid:100002002; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.75.181"; classtype:trojan-activity; sid:100002003; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.75.19"; classtype:trojan-activity; sid:100002004; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.75.209"; classtype:trojan-activity; sid:100002005; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.75.84"; classtype:trojan-activity; sid:100002006; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.75.87"; classtype:trojan-activity; sid:100002007; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.109"; classtype:trojan-activity; sid:100002008; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.121"; classtype:trojan-activity; sid:100002009; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.167"; classtype:trojan-activity; sid:100002010; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.187"; classtype:trojan-activity; sid:100002011; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.214"; classtype:trojan-activity; sid:100002012; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.215"; classtype:trojan-activity; sid:100002013; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.217"; classtype:trojan-activity; sid:100002014; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.76.24"; classtype:trojan-activity; sid:100002015; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.77.46"; classtype:trojan-activity; sid:100002016; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.77.47"; classtype:trojan-activity; sid:100002017; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.77.95"; classtype:trojan-activity; sid:100002018; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.106"; classtype:trojan-activity; sid:100002019; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.118"; classtype:trojan-activity; sid:100002020; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.233"; classtype:trojan-activity; sid:100002021; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.46"; classtype:trojan-activity; sid:100002022; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.76"; classtype:trojan-activity; sid:100002023; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.78.97"; classtype:trojan-activity; sid:100002024; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.79.156"; classtype:trojan-activity; sid:100002025; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.79.227"; classtype:trojan-activity; sid:100002026; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.79.247"; classtype:trojan-activity; sid:100002027; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.79.45"; classtype:trojan-activity; sid:100002028; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.79.77"; classtype:trojan-activity; sid:100002029; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.8.100"; classtype:trojan-activity; sid:100002030; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.8.199"; classtype:trojan-activity; sid:100002031; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.8.217"; classtype:trojan-activity; sid:100002032; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.8.254"; classtype:trojan-activity; sid:100002033; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.8.97"; classtype:trojan-activity; sid:100002034; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.100"; classtype:trojan-activity; sid:100002035; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.136"; classtype:trojan-activity; sid:100002036; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.237"; classtype:trojan-activity; sid:100002037; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.41"; classtype:trojan-activity; sid:100002038; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.79"; classtype:trojan-activity; sid:100002039; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.80.86"; classtype:trojan-activity; sid:100002040; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.1"; classtype:trojan-activity; sid:100002041; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.141"; classtype:trojan-activity; sid:100002042; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.15"; classtype:trojan-activity; sid:100002043; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.152"; classtype:trojan-activity; sid:100002044; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.17"; classtype:trojan-activity; sid:100002045; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.194"; classtype:trojan-activity; sid:100002046; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.226"; classtype:trojan-activity; sid:100002047; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.244"; classtype:trojan-activity; sid:100002048; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.32"; classtype:trojan-activity; sid:100002049; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.50"; classtype:trojan-activity; sid:100002050; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.81.8"; classtype:trojan-activity; sid:100002051; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.82.120"; classtype:trojan-activity; sid:100002052; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.82.61"; classtype:trojan-activity; sid:100002053; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.83.147"; classtype:trojan-activity; sid:100002054; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.83.196"; classtype:trojan-activity; sid:100002055; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.83.247"; classtype:trojan-activity; sid:100002056; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.102"; classtype:trojan-activity; sid:100002057; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.109"; classtype:trojan-activity; sid:100002058; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.148"; classtype:trojan-activity; sid:100002059; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.158"; classtype:trojan-activity; sid:100002060; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.159"; classtype:trojan-activity; sid:100002061; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.215"; classtype:trojan-activity; sid:100002062; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.84.42"; classtype:trojan-activity; sid:100002063; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.153"; classtype:trojan-activity; sid:100002064; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.183"; classtype:trojan-activity; sid:100002065; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.190"; classtype:trojan-activity; sid:100002066; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.23"; classtype:trojan-activity; sid:100002067; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.81"; classtype:trojan-activity; sid:100002068; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.85.87"; classtype:trojan-activity; sid:100002069; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.86.119"; classtype:trojan-activity; sid:100002070; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.86.159"; classtype:trojan-activity; sid:100002071; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.86.166"; classtype:trojan-activity; sid:100002072; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.108"; classtype:trojan-activity; sid:100002073; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.123"; classtype:trojan-activity; sid:100002074; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.162"; classtype:trojan-activity; sid:100002075; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.87.253"; classtype:trojan-activity; sid:100002076; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.180"; classtype:trojan-activity; sid:100002077; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.88.181"; classtype:trojan-activity; sid:100002078; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.89.130"; classtype:trojan-activity; sid:100002079; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.89.157"; classtype:trojan-activity; sid:100002080; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.89.160"; classtype:trojan-activity; sid:100002081; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.89.169"; classtype:trojan-activity; sid:100002082; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.89.37"; classtype:trojan-activity; sid:100002083; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.106"; classtype:trojan-activity; sid:100002084; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.139"; classtype:trojan-activity; sid:100002085; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.183"; classtype:trojan-activity; sid:100002086; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.210"; classtype:trojan-activity; sid:100002087; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.215"; classtype:trojan-activity; sid:100002088; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.217"; classtype:trojan-activity; sid:100002089; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.245"; classtype:trojan-activity; sid:100002090; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.45"; classtype:trojan-activity; sid:100002091; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.80"; classtype:trojan-activity; sid:100002092; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.84"; classtype:trojan-activity; sid:100002093; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.9.95"; classtype:trojan-activity; sid:100002094; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.104"; classtype:trojan-activity; sid:100002095; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.122"; classtype:trojan-activity; sid:100002096; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.178"; classtype:trojan-activity; sid:100002097; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.187"; classtype:trojan-activity; sid:100002098; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.21"; classtype:trojan-activity; sid:100002099; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.212"; classtype:trojan-activity; sid:100002100; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.4"; classtype:trojan-activity; sid:100002101; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.90.8"; classtype:trojan-activity; sid:100002102; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.15"; classtype:trojan-activity; sid:100002103; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.165"; classtype:trojan-activity; sid:100002104; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.172"; classtype:trojan-activity; sid:100002105; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.191"; classtype:trojan-activity; sid:100002106; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.223"; classtype:trojan-activity; sid:100002107; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.230"; classtype:trojan-activity; sid:100002108; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.253"; classtype:trojan-activity; sid:100002109; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.58"; classtype:trojan-activity; sid:100002110; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.91.96"; classtype:trojan-activity; sid:100002111; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.132"; classtype:trojan-activity; sid:100002112; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.186"; classtype:trojan-activity; sid:100002113; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.201"; classtype:trojan-activity; sid:100002114; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.208"; classtype:trojan-activity; sid:100002115; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.215"; classtype:trojan-activity; sid:100002116; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.231"; classtype:trojan-activity; sid:100002117; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.248"; classtype:trojan-activity; sid:100002118; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.92.45"; classtype:trojan-activity; sid:100002119; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.143"; classtype:trojan-activity; sid:100002120; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.148"; classtype:trojan-activity; sid:100002121; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.150"; classtype:trojan-activity; sid:100002122; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.155"; classtype:trojan-activity; sid:100002123; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.171"; classtype:trojan-activity; sid:100002124; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.198"; classtype:trojan-activity; sid:100002125; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.224"; classtype:trojan-activity; sid:100002126; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.225"; classtype:trojan-activity; sid:100002127; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.31"; classtype:trojan-activity; sid:100002128; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.34"; classtype:trojan-activity; sid:100002129; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.4"; classtype:trojan-activity; sid:100002130; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.45"; classtype:trojan-activity; sid:100002131; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.6"; classtype:trojan-activity; sid:100002132; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.93.90"; classtype:trojan-activity; sid:100002133; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.116"; classtype:trojan-activity; sid:100002134; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.195"; classtype:trojan-activity; sid:100002135; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.238"; classtype:trojan-activity; sid:100002136; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.248"; classtype:trojan-activity; sid:100002137; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.94.40"; classtype:trojan-activity; sid:100002138; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.111"; classtype:trojan-activity; sid:100002139; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.132"; classtype:trojan-activity; sid:100002140; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.147"; classtype:trojan-activity; sid:100002141; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.227"; classtype:trojan-activity; sid:100002142; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.237"; classtype:trojan-activity; sid:100002143; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.244"; classtype:trojan-activity; sid:100002144; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.4"; classtype:trojan-activity; sid:100002145; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.7"; classtype:trojan-activity; sid:100002146; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.95.89"; classtype:trojan-activity; sid:100002147; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.96.13"; classtype:trojan-activity; sid:100002148; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.96.195"; classtype:trojan-activity; sid:100002149; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.96.6"; classtype:trojan-activity; sid:100002150; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.97.1"; classtype:trojan-activity; sid:100002151; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.97.128"; classtype:trojan-activity; sid:100002152; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.97.135"; classtype:trojan-activity; sid:100002153; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.97.162"; classtype:trojan-activity; sid:100002154; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.97.17"; classtype:trojan-activity; sid:100002155; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.97.208"; classtype:trojan-activity; sid:100002156; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.98.228"; classtype:trojan-activity; sid:100002157; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.98.254"; classtype:trojan-activity; sid:100002158; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.98.50"; classtype:trojan-activity; sid:100002159; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.98.68"; classtype:trojan-activity; sid:100002160; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.123"; classtype:trojan-activity; sid:100002161; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.130"; classtype:trojan-activity; sid:100002162; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.22"; classtype:trojan-activity; sid:100002163; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.45"; classtype:trojan-activity; sid:100002164; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.8"; classtype:trojan-activity; sid:100002165; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.175.99.91"; classtype:trojan-activity; sid:100002166; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.19.183.14"; classtype:trojan-activity; sid:100002167; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.21.164.68"; classtype:trojan-activity; sid:100002168; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.217.8.194"; classtype:trojan-activity; sid:100002169; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.22.117.102"; classtype:trojan-activity; sid:100002170; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.222.252.130"; classtype:trojan-activity; sid:100002171; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.34.183.30"; classtype:trojan-activity; sid:100002172; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.92.246.246"; classtype:trojan-activity; sid:100002173; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"178.95.115.33"; classtype:trojan-activity; sid:100002174; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.159.58.134"; classtype:trojan-activity; sid:100002175; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.4.187.39"; classtype:trojan-activity; sid:100002176; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.48.156.252"; classtype:trojan-activity; sid:100002177; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.60.84.7"; classtype:trojan-activity; sid:100002178; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"179.99.210.161"; classtype:trojan-activity; sid:100002179; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.109.36.244"; classtype:trojan-activity; sid:100002180; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.111.101.141"; classtype:trojan-activity; sid:100002181; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.114.111.153"; classtype:trojan-activity; sid:100002182; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.116.203.220"; classtype:trojan-activity; sid:100002183; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.120.149.106"; classtype:trojan-activity; sid:100002184; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.122.13.227"; classtype:trojan-activity; sid:100002185; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.125.44.194"; classtype:trojan-activity; sid:100002186; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.157.66.204"; classtype:trojan-activity; sid:100002187; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.175.93.52"; classtype:trojan-activity; sid:100002188; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.105.41"; classtype:trojan-activity; sid:100002189; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.110.243"; classtype:trojan-activity; sid:100002190; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.165.230"; classtype:trojan-activity; sid:100002191; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.214.171"; classtype:trojan-activity; sid:100002192; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.34.51"; classtype:trojan-activity; sid:100002193; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.176.96.248"; classtype:trojan-activity; sid:100002194; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.177.104.65"; classtype:trojan-activity; sid:100002195; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.177.242.73"; classtype:trojan-activity; sid:100002196; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.218.5.171"; classtype:trojan-activity; sid:100002197; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.248.80.38"; classtype:trojan-activity; sid:100002198; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.66.111.36"; classtype:trojan-activity; sid:100002199; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.66.53.93"; classtype:trojan-activity; sid:100002200; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"180.94.170.166"; classtype:trojan-activity; sid:100002201; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.112.138.154"; classtype:trojan-activity; sid:100002202; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.112.218.238"; classtype:trojan-activity; sid:100002203; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.112.218.6"; classtype:trojan-activity; sid:100002204; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.143.60.163"; classtype:trojan-activity; sid:100002205; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.193.107.10"; classtype:trojan-activity; sid:100002206; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.199.170.210"; classtype:trojan-activity; sid:100002207; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.199.170.222"; classtype:trojan-activity; sid:100002208; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.199.170.230"; classtype:trojan-activity; sid:100002209; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.199.170.240"; classtype:trojan-activity; sid:100002210; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.210.45.42"; classtype:trojan-activity; sid:100002211; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.215.47.82"; classtype:trojan-activity; sid:100002212; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.224.242.131"; classtype:trojan-activity; sid:100002213; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.49.236.4"; classtype:trojan-activity; sid:100002214; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"181.49.59.162"; classtype:trojan-activity; sid:100002215; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.112.0.33"; classtype:trojan-activity; sid:100002216; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.112.15.49"; classtype:trojan-activity; sid:100002217; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.112.39.201"; classtype:trojan-activity; sid:100002218; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.112.52.131"; classtype:trojan-activity; sid:100002219; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.113.0.79"; classtype:trojan-activity; sid:100002220; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.113.222.154"; classtype:trojan-activity; sid:100002221; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.113.233.129"; classtype:trojan-activity; sid:100002222; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.113.24.21"; classtype:trojan-activity; sid:100002223; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.106.207"; classtype:trojan-activity; sid:100002224; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.202.186"; classtype:trojan-activity; sid:100002225; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.114.64.27"; classtype:trojan-activity; sid:100002226; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.101.82"; classtype:trojan-activity; sid:100002227; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.103.81"; classtype:trojan-activity; sid:100002228; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.108.180"; classtype:trojan-activity; sid:100002229; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.108.244"; classtype:trojan-activity; sid:100002230; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.110.31"; classtype:trojan-activity; sid:100002231; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.119.129"; classtype:trojan-activity; sid:100002232; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.60.73"; classtype:trojan-activity; sid:100002233; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.61.252"; classtype:trojan-activity; sid:100002234; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.65.157"; classtype:trojan-activity; sid:100002235; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.65.245"; classtype:trojan-activity; sid:100002236; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.68.40"; classtype:trojan-activity; sid:100002237; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.69.37"; classtype:trojan-activity; sid:100002238; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.94.196"; classtype:trojan-activity; sid:100002239; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.99.150"; classtype:trojan-activity; sid:100002240; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.116.99.17"; classtype:trojan-activity; sid:100002241; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.155.204"; classtype:trojan-activity; sid:100002242; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.25.120"; classtype:trojan-activity; sid:100002243; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.26.235"; classtype:trojan-activity; sid:100002244; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.29.220"; classtype:trojan-activity; sid:100002245; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.29.74"; classtype:trojan-activity; sid:100002246; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.117.43.27"; classtype:trojan-activity; sid:100002247; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.118.140.117"; classtype:trojan-activity; sid:100002248; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.100.228"; classtype:trojan-activity; sid:100002249; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.13.141"; classtype:trojan-activity; sid:100002250; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.14.252"; classtype:trojan-activity; sid:100002251; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.166.208"; classtype:trojan-activity; sid:100002252; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.196.182"; classtype:trojan-activity; sid:100002253; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.211.69"; classtype:trojan-activity; sid:100002254; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.220.48"; classtype:trojan-activity; sid:100002255; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.236.21"; classtype:trojan-activity; sid:100002256; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.49.17"; classtype:trojan-activity; sid:100002257; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.50.155"; classtype:trojan-activity; sid:100002258; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.7.54"; classtype:trojan-activity; sid:100002259; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.119.81.33"; classtype:trojan-activity; sid:100002260; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.10.21"; classtype:trojan-activity; sid:100002261; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.16.22"; classtype:trojan-activity; sid:100002262; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.16.46"; classtype:trojan-activity; sid:100002263; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.37.251"; classtype:trojan-activity; sid:100002264; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.43.0"; classtype:trojan-activity; sid:100002265; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.120.86.248"; classtype:trojan-activity; sid:100002266; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.101.100"; classtype:trojan-activity; sid:100002267; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.109.190"; classtype:trojan-activity; sid:100002268; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.12.128"; classtype:trojan-activity; sid:100002269; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.125.170"; classtype:trojan-activity; sid:100002270; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.129.232"; classtype:trojan-activity; sid:100002271; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.133.200"; classtype:trojan-activity; sid:100002272; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.133.46"; classtype:trojan-activity; sid:100002273; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.134.73"; classtype:trojan-activity; sid:100002274; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.148.236"; classtype:trojan-activity; sid:100002275; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.157.221"; classtype:trojan-activity; sid:100002276; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.165.217"; classtype:trojan-activity; sid:100002277; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.205.118"; classtype:trojan-activity; sid:100002278; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.206.132"; classtype:trojan-activity; sid:100002279; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.219.239"; classtype:trojan-activity; sid:100002280; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.233.191"; classtype:trojan-activity; sid:100002281; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.249.26"; classtype:trojan-activity; sid:100002282; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.50.111"; classtype:trojan-activity; sid:100002283; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.78.29"; classtype:trojan-activity; sid:100002284; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.81.241"; classtype:trojan-activity; sid:100002285; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.92.113"; classtype:trojan-activity; sid:100002286; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.93.174"; classtype:trojan-activity; sid:100002287; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.121.98.21"; classtype:trojan-activity; sid:100002288; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.122.170.19"; classtype:trojan-activity; sid:100002289; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.122.202.37"; classtype:trojan-activity; sid:100002290; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.122.220.203"; classtype:trojan-activity; sid:100002291; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.122.229.102"; classtype:trojan-activity; sid:100002292; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.122.245.2"; classtype:trojan-activity; sid:100002293; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.122.246.187"; classtype:trojan-activity; sid:100002294; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.122.249.24"; classtype:trojan-activity; sid:100002295; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.122.251.141"; classtype:trojan-activity; sid:100002296; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.124.134.80"; classtype:trojan-activity; sid:100002297; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.124.15.108"; classtype:trojan-activity; sid:100002298; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.124.166.57"; classtype:trojan-activity; sid:100002299; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.124.188.23"; classtype:trojan-activity; sid:100002300; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.124.95.139"; classtype:trojan-activity; sid:100002301; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.113.127"; classtype:trojan-activity; sid:100002302; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.117.41"; classtype:trojan-activity; sid:100002303; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.124.47"; classtype:trojan-activity; sid:100002304; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.126.203"; classtype:trojan-activity; sid:100002305; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.127.40"; classtype:trojan-activity; sid:100002306; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.139.193"; classtype:trojan-activity; sid:100002307; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.139.66"; classtype:trojan-activity; sid:100002308; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.140.30"; classtype:trojan-activity; sid:100002309; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.178.187"; classtype:trojan-activity; sid:100002310; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.181.121"; classtype:trojan-activity; sid:100002311; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.241.7"; classtype:trojan-activity; sid:100002312; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.52.233"; classtype:trojan-activity; sid:100002313; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.82.29"; classtype:trojan-activity; sid:100002314; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.83.79"; classtype:trojan-activity; sid:100002315; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.87.207"; classtype:trojan-activity; sid:100002316; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.126.95.209"; classtype:trojan-activity; sid:100002317; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.155.157"; classtype:trojan-activity; sid:100002318; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.166.232"; classtype:trojan-activity; sid:100002319; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.210.107"; classtype:trojan-activity; sid:100002320; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.6.12"; classtype:trojan-activity; sid:100002321; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.70.195"; classtype:trojan-activity; sid:100002322; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.78.61"; classtype:trojan-activity; sid:100002323; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.91.161"; classtype:trojan-activity; sid:100002324; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.127.96.120"; classtype:trojan-activity; sid:100002325; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.172.36.164"; classtype:trojan-activity; sid:100002326; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.233.0.252"; classtype:trojan-activity; sid:100002327; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.235.252.31"; classtype:trojan-activity; sid:100002328; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.53.197.62"; classtype:trojan-activity; sid:100002329; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.58.160.0"; classtype:trojan-activity; sid:100002330; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.59.227.125"; classtype:trojan-activity; sid:100002331; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"182.88.235.221"; classtype:trojan-activity; sid:100002332; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.105.104.83"; classtype:trojan-activity; sid:100002333; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.105.225.154"; classtype:trojan-activity; sid:100002334; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.109.169.45"; classtype:trojan-activity; sid:100002335; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.11.238.228"; classtype:trojan-activity; sid:100002336; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.136.252.233"; classtype:trojan-activity; sid:100002337; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.150.138.131"; classtype:trojan-activity; sid:100002338; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.16.208.172"; classtype:trojan-activity; sid:100002339; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.187.163.176"; classtype:trojan-activity; sid:100002340; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.188.151.225"; classtype:trojan-activity; sid:100002341; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.188.180.116"; classtype:trojan-activity; sid:100002342; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.188.180.68"; classtype:trojan-activity; sid:100002343; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.188.188.186"; classtype:trojan-activity; sid:100002344; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.191.162.120"; classtype:trojan-activity; sid:100002345; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.83.105.21"; classtype:trojan-activity; sid:100002346; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.83.14.35"; classtype:trojan-activity; sid:100002347; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.83.15.116"; classtype:trojan-activity; sid:100002348; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.83.23.138"; classtype:trojan-activity; sid:100002349; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.83.99.36"; classtype:trojan-activity; sid:100002350; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.92.195.140"; classtype:trojan-activity; sid:100002351; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.95.147.102"; classtype:trojan-activity; sid:100002352; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"183.97.22.14"; classtype:trojan-activity; sid:100002353; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"184.164.185.41"; classtype:trojan-activity; sid:100002354; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"184.175.115.10"; classtype:trojan-activity; sid:100002355; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"184.74.149.230"; classtype:trojan-activity; sid:100002356; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.106.209.68"; classtype:trojan-activity; sid:100002357; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.107.3.8"; classtype:trojan-activity; sid:100002358; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.172.110.235"; classtype:trojan-activity; sid:100002359; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.181.10.234"; classtype:trojan-activity; sid:100002360; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.200.241.196"; classtype:trojan-activity; sid:100002361; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.112"; classtype:trojan-activity; sid:100002362; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.54"; classtype:trojan-activity; sid:100002363; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.77"; classtype:trojan-activity; sid:100002364; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.215.113.93"; classtype:trojan-activity; sid:100002365; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.219.133.122"; classtype:trojan-activity; sid:100002366; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.221.3.244"; classtype:trojan-activity; sid:100002367; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.228.141.74"; classtype:trojan-activity; sid:100002368; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.239.243.77"; classtype:trojan-activity; sid:100002369; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.26.113.95"; classtype:trojan-activity; sid:100002370; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.43.19.151"; classtype:trojan-activity; sid:100002371; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.55.1.182"; classtype:trojan-activity; sid:100002372; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.68.230.207"; classtype:trojan-activity; sid:100002373; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.81.157.186"; classtype:trojan-activity; sid:100002374; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.217.185"; classtype:trojan-activity; sid:100002375; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.160"; classtype:trojan-activity; sid:100002376; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.161"; classtype:trojan-activity; sid:100002377; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.82.219.219"; classtype:trojan-activity; sid:100002378; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"185.90.166.56"; classtype:trojan-activity; sid:100002379; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.151.144.85"; classtype:trojan-activity; sid:100002380; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.219.164"; classtype:trojan-activity; sid:100002381; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.243.112"; classtype:trojan-activity; sid:100002382; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.243.77"; classtype:trojan-activity; sid:100002383; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.243.91"; classtype:trojan-activity; sid:100002384; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.179.253.150"; classtype:trojan-activity; sid:100002385; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.225.120.173"; classtype:trojan-activity; sid:100002386; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.227.148.107"; classtype:trojan-activity; sid:100002387; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.232.44.86"; classtype:trojan-activity; sid:100002388; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.28.60.184"; classtype:trojan-activity; sid:100002389; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.33.112.28"; classtype:trojan-activity; sid:100002390; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"186.73.188.132"; classtype:trojan-activity; sid:100002391; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.12.10.98"; classtype:trojan-activity; sid:100002392; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.188.124.229"; classtype:trojan-activity; sid:100002393; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"187.212.200.162"; classtype:trojan-activity; sid:100002394; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.10.21.14"; classtype:trojan-activity; sid:100002395; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.10.231.246"; classtype:trojan-activity; sid:100002396; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.113.102.18"; classtype:trojan-activity; sid:100002397; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.113.81.17"; classtype:trojan-activity; sid:100002398; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.127.224.61"; classtype:trojan-activity; sid:100002399; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.127.227.173"; classtype:trojan-activity; sid:100002400; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.127.227.99"; classtype:trojan-activity; sid:100002401; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.127.231.226"; classtype:trojan-activity; sid:100002402; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.127.231.55"; classtype:trojan-activity; sid:100002403; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.127.235.232"; classtype:trojan-activity; sid:100002404; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.127.235.244"; classtype:trojan-activity; sid:100002405; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.127.235.71"; classtype:trojan-activity; sid:100002406; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.127.237.152"; classtype:trojan-activity; sid:100002407; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.127.254.114"; classtype:trojan-activity; sid:100002408; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.13.179.87"; classtype:trojan-activity; sid:100002409; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.138.200.32"; classtype:trojan-activity; sid:100002410; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.152.41.141"; classtype:trojan-activity; sid:100002411; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.169.178.50"; classtype:trojan-activity; sid:100002412; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.169.30.30"; classtype:trojan-activity; sid:100002413; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.169.36.163"; classtype:trojan-activity; sid:100002414; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.242.167.159"; classtype:trojan-activity; sid:100002415; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.242.242.144"; classtype:trojan-activity; sid:100002416; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.83.202.25"; classtype:trojan-activity; sid:100002417; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"188.93.233.223"; classtype:trojan-activity; sid:100002418; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"189.222.157.241"; classtype:trojan-activity; sid:100002419; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"19.dbstrony.pl"; classtype:trojan-activity; sid:100002420; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.0.42.106"; classtype:trojan-activity; sid:100002421; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.110.161.252"; classtype:trojan-activity; sid:100002422; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.111.151.164"; classtype:trojan-activity; sid:100002423; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.119.207.58"; classtype:trojan-activity; sid:100002424; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.12.99.194"; classtype:trojan-activity; sid:100002425; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.121.194.18"; classtype:trojan-activity; sid:100002426; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.160"; classtype:trojan-activity; sid:100002427; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.3"; classtype:trojan-activity; sid:100002428; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.37"; classtype:trojan-activity; sid:100002429; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.41"; classtype:trojan-activity; sid:100002430; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.122.112.42"; classtype:trojan-activity; sid:100002431; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.130.15.212"; classtype:trojan-activity; sid:100002432; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.130.20.14"; classtype:trojan-activity; sid:100002433; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.141.117.41"; classtype:trojan-activity; sid:100002434; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.159.240.9"; classtype:trojan-activity; sid:100002435; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.187.55.150"; classtype:trojan-activity; sid:100002436; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.210.214.130"; classtype:trojan-activity; sid:100002437; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.213.177.39"; classtype:trojan-activity; sid:100002438; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.213.226.63"; classtype:trojan-activity; sid:100002439; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.213.49.207"; classtype:trojan-activity; sid:100002440; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.216.140.123"; classtype:trojan-activity; sid:100002441; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.35.225.36"; classtype:trojan-activity; sid:100002442; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.65.206.162"; classtype:trojan-activity; sid:100002443; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.92.4.231"; classtype:trojan-activity; sid:100002444; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.98.37.135"; classtype:trojan-activity; sid:100002445; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.98.37.200"; classtype:trojan-activity; sid:100002446; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"190.98.41.33"; classtype:trojan-activity; sid:100002447; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"191.255.248.220"; classtype:trojan-activity; sid:100002448; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.210.175.130"; classtype:trojan-activity; sid:100002449; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.210.241.200"; classtype:trojan-activity; sid:100002450; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.185.106"; classtype:trojan-activity; sid:100002451; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.209.27"; classtype:trojan-activity; sid:100002452; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.227.228.67"; classtype:trojan-activity; sid:100002453; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.3.152.166"; classtype:trojan-activity; sid:100002454; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.3.73.205"; classtype:trojan-activity; sid:100002455; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"192.99.240.77"; classtype:trojan-activity; sid:100002456; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"193.142.146.25"; classtype:trojan-activity; sid:100002457; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"193.228.135.144"; classtype:trojan-activity; sid:100002458; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"193.91.131.237"; classtype:trojan-activity; sid:100002459; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.15.36.167"; classtype:trojan-activity; sid:100002460; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.15.36.202"; classtype:trojan-activity; sid:100002461; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.152.35.139"; classtype:trojan-activity; sid:100002462; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.38.20.199"; classtype:trojan-activity; sid:100002463; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"194.87.139.10"; classtype:trojan-activity; sid:100002464; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.123.213.154"; classtype:trojan-activity; sid:100002465; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.139.126.51"; classtype:trojan-activity; sid:100002466; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.228.231.218"; classtype:trojan-activity; sid:100002467; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.24.94.187"; classtype:trojan-activity; sid:100002468; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"195.64.163.103"; classtype:trojan-activity; sid:100002469; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.202.26.182"; classtype:trojan-activity; sid:100002470; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.218.48.82"; classtype:trojan-activity; sid:100002471; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.221.148.90"; classtype:trojan-activity; sid:100002472; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"196.221.166.203"; classtype:trojan-activity; sid:100002473; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"197.159.2.106"; classtype:trojan-activity; sid:100002474; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"197.50.27.115"; classtype:trojan-activity; sid:100002475; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.133.218"; classtype:trojan-activity; sid:100002476; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.207.121"; classtype:trojan-activity; sid:100002477; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.213.57"; classtype:trojan-activity; sid:100002478; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.23.251.105"; classtype:trojan-activity; sid:100002479; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.46.201.76"; classtype:trojan-activity; sid:100002480; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"198.46.202.7"; classtype:trojan-activity; sid:100002481; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"1am.co.nz"; classtype:trojan-activity; sid:100002482; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.229.89.119"; classtype:trojan-activity; sid:100002483; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.249.161.188"; classtype:trojan-activity; sid:100002484; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.45.111.158"; classtype:trojan-activity; sid:100002485; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.45.4.24"; classtype:trojan-activity; sid:100002486; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.55.125.182"; classtype:trojan-activity; sid:100002487; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.55.92.184"; classtype:trojan-activity; sid:100002488; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"2.83.152.16"; classtype:trojan-activity; sid:100002489; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"20.dbstrony.pl"; classtype:trojan-activity; sid:100002490; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.105.167.98"; classtype:trojan-activity; sid:100002491; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.111.189.70"; classtype:trojan-activity; sid:100002492; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.194.4.24"; classtype:trojan-activity; sid:100002493; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.2.161.171"; classtype:trojan-activity; sid:100002494; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"200.30.132.50"; classtype:trojan-activity; sid:100002495; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.142.147.89"; classtype:trojan-activity; sid:100002496; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.184.163.170"; classtype:trojan-activity; sid:100002497; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.184.248.190"; classtype:trojan-activity; sid:100002498; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.187.102.73"; classtype:trojan-activity; sid:100002499; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.200.254.86"; classtype:trojan-activity; sid:100002500; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.203.221.20"; classtype:trojan-activity; sid:100002501; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.208.139.84"; classtype:trojan-activity; sid:100002502; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.215.84.97"; classtype:trojan-activity; sid:100002503; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"201.218.97.142"; classtype:trojan-activity; sid:100002504; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.107.233.41"; classtype:trojan-activity; sid:100002505; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.111.131.91"; classtype:trojan-activity; sid:100002506; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.164.150.115"; classtype:trojan-activity; sid:100002507; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.166.217.54"; classtype:trojan-activity; sid:100002508; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.169.234.22"; classtype:trojan-activity; sid:100002509; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.169.234.47"; classtype:trojan-activity; sid:100002510; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.169.234.52"; classtype:trojan-activity; sid:100002511; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.169.234.56"; classtype:trojan-activity; sid:100002512; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.169.234.9"; classtype:trojan-activity; sid:100002513; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.29.95.12"; classtype:trojan-activity; sid:100002514; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.4.124.58"; classtype:trojan-activity; sid:100002515; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.51.176.114"; classtype:trojan-activity; sid:100002516; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.51.191.174"; classtype:trojan-activity; sid:100002517; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"202.74.236.9"; classtype:trojan-activity; sid:100002518; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.109.201.243"; classtype:trojan-activity; sid:100002519; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.170.115.82"; classtype:trojan-activity; sid:100002520; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.189.156.107"; classtype:trojan-activity; sid:100002521; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.202.248.237"; classtype:trojan-activity; sid:100002522; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.204.232.18"; classtype:trojan-activity; sid:100002523; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.229.21.56"; classtype:trojan-activity; sid:100002524; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.236.190.28"; classtype:trojan-activity; sid:100002525; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.238.86.202"; classtype:trojan-activity; sid:100002526; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.70.166.107"; classtype:trojan-activity; sid:100002527; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.77.80.159"; classtype:trojan-activity; sid:100002528; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.80.119.166"; classtype:trojan-activity; sid:100002529; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.80.171.138"; classtype:trojan-activity; sid:100002530; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.82.36.34"; classtype:trojan-activity; sid:100002531; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"203.93.6.28"; classtype:trojan-activity; sid:100002532; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"204.195.116.171"; classtype:trojan-activity; sid:100002533; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"205.185.123.217"; classtype:trojan-activity; sid:100002534; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"206.248.137.132"; classtype:trojan-activity; sid:100002535; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"206.47.41.166"; classtype:trojan-activity; sid:100002536; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"207.200.247.187"; classtype:trojan-activity; sid:100002537; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"207.44.28.234"; classtype:trojan-activity; sid:100002538; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"207.5.32.6"; classtype:trojan-activity; sid:100002539; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"208.163.58.18"; classtype:trojan-activity; sid:100002540; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.141.39.50"; classtype:trojan-activity; sid:100002541; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.141.40.190"; classtype:trojan-activity; sid:100002542; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"209.145.60.38"; classtype:trojan-activity; sid:100002543; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.102.196.200"; classtype:trojan-activity; sid:100002544; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.124.149.19"; classtype:trojan-activity; sid:100002545; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.216.152.122"; classtype:trojan-activity; sid:100002546; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.216.153.142"; classtype:trojan-activity; sid:100002547; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.57.237.70"; classtype:trojan-activity; sid:100002548; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.57.245.109"; classtype:trojan-activity; sid:100002549; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.68.242.114"; classtype:trojan-activity; sid:100002550; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"210.96.116.236"; classtype:trojan-activity; sid:100002551; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.172.11.169"; classtype:trojan-activity; sid:100002552; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.187.132.204"; classtype:trojan-activity; sid:100002553; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.187.75.220"; classtype:trojan-activity; sid:100002554; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.204.215.157"; classtype:trojan-activity; sid:100002555; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.210.66.179"; classtype:trojan-activity; sid:100002556; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.210.93.93"; classtype:trojan-activity; sid:100002557; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.216.66.105"; classtype:trojan-activity; sid:100002558; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.237.114.96"; classtype:trojan-activity; sid:100002559; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.237.120.13"; classtype:trojan-activity; sid:100002560; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.238.83.238"; classtype:trojan-activity; sid:100002561; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.247.113.49"; classtype:trojan-activity; sid:100002562; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.247.5.96"; classtype:trojan-activity; sid:100002563; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.36.174.137"; classtype:trojan-activity; sid:100002564; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.41.197.30"; classtype:trojan-activity; sid:100002565; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.47.102.51"; classtype:trojan-activity; sid:100002566; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"211.51.174.149"; classtype:trojan-activity; sid:100002567; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.122.86.105"; classtype:trojan-activity; sid:100002568; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.143.227.22"; classtype:trojan-activity; sid:100002569; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.156.215.178"; classtype:trojan-activity; sid:100002570; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.46.197.114"; classtype:trojan-activity; sid:100002571; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"212.56.197.230"; classtype:trojan-activity; sid:100002572; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.119.74.202"; classtype:trojan-activity; sid:100002573; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.123.206.197"; classtype:trojan-activity; sid:100002574; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.135.178.253"; classtype:trojan-activity; sid:100002575; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.14.173.117"; classtype:trojan-activity; sid:100002576; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.149.182.113"; classtype:trojan-activity; sid:100002577; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.149.190.193"; classtype:trojan-activity; sid:100002578; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.104.10"; classtype:trojan-activity; sid:100002579; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.104.12"; classtype:trojan-activity; sid:100002580; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.104.20"; classtype:trojan-activity; sid:100002581; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.104.99"; classtype:trojan-activity; sid:100002582; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.100"; classtype:trojan-activity; sid:100002583; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.199"; classtype:trojan-activity; sid:100002584; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.225"; classtype:trojan-activity; sid:100002585; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.51"; classtype:trojan-activity; sid:100002586; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.113.79"; classtype:trojan-activity; sid:100002587; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.114.80"; classtype:trojan-activity; sid:100002588; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.11"; classtype:trojan-activity; sid:100002589; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.15"; classtype:trojan-activity; sid:100002590; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.26"; classtype:trojan-activity; sid:100002591; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.33"; classtype:trojan-activity; sid:100002592; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.115.71"; classtype:trojan-activity; sid:100002593; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.116.132"; classtype:trojan-activity; sid:100002594; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.116.164"; classtype:trojan-activity; sid:100002595; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.116.203"; classtype:trojan-activity; sid:100002596; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.116.249"; classtype:trojan-activity; sid:100002597; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.116.33"; classtype:trojan-activity; sid:100002598; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.116.85"; classtype:trojan-activity; sid:100002599; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.117.97"; classtype:trojan-activity; sid:100002600; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.118.10"; classtype:trojan-activity; sid:100002601; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.118.144"; classtype:trojan-activity; sid:100002602; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.118.238"; classtype:trojan-activity; sid:100002603; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.119.24"; classtype:trojan-activity; sid:100002604; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.131"; classtype:trojan-activity; sid:100002605; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.243"; classtype:trojan-activity; sid:100002606; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.60"; classtype:trojan-activity; sid:100002607; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.7"; classtype:trojan-activity; sid:100002608; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.126.71"; classtype:trojan-activity; sid:100002609; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.127.217"; classtype:trojan-activity; sid:100002610; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.163.127.46"; classtype:trojan-activity; sid:100002611; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.189.178.163"; classtype:trojan-activity; sid:100002612; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.240.218.15"; classtype:trojan-activity; sid:100002613; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.249.156.189"; classtype:trojan-activity; sid:100002614; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.27.8.6"; classtype:trojan-activity; sid:100002615; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.80.44.17"; classtype:trojan-activity; sid:100002616; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.92.254.52"; classtype:trojan-activity; sid:100002617; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.92.255.36"; classtype:trojan-activity; sid:100002618; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"213.92.255.84"; classtype:trojan-activity; sid:100002619; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.12.93.132"; classtype:trojan-activity; sid:100002620; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.127.185.150"; classtype:trojan-activity; sid:100002621; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.170.240.98"; classtype:trojan-activity; sid:100002622; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.183.54.169"; classtype:trojan-activity; sid:100002623; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.24.72.12"; classtype:trojan-activity; sid:100002624; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"216.36.12.98"; classtype:trojan-activity; sid:100002625; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"217.11.75.162"; classtype:trojan-activity; sid:100002626; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"217.127.133.214"; classtype:trojan-activity; sid:100002627; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.103.180.199"; classtype:trojan-activity; sid:100002628; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.215.243.65"; classtype:trojan-activity; sid:100002629; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.238.246.3"; classtype:trojan-activity; sid:100002630; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.28.160.174"; classtype:trojan-activity; sid:100002631; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.207.119"; classtype:trojan-activity; sid:100002632; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.227.133"; classtype:trojan-activity; sid:100002633; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.68.35"; classtype:trojan-activity; sid:100002634; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.35.81.81"; classtype:trojan-activity; sid:100002635; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.48.135.50"; classtype:trojan-activity; sid:100002636; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.56.93.129"; classtype:trojan-activity; sid:100002637; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.57.53.55"; classtype:trojan-activity; sid:100002638; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.59.116.203"; classtype:trojan-activity; sid:100002639; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.72.198.15"; classtype:trojan-activity; sid:100002640; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"218.79.103.159"; classtype:trojan-activity; sid:100002641; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.104.209"; classtype:trojan-activity; sid:100002642; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.119.145"; classtype:trojan-activity; sid:100002643; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.141.222"; classtype:trojan-activity; sid:100002644; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.154.182.197"; classtype:trojan-activity; sid:100002645; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.102.14"; classtype:trojan-activity; sid:100002646; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.12.221"; classtype:trojan-activity; sid:100002647; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.14.17"; classtype:trojan-activity; sid:100002648; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.170.22"; classtype:trojan-activity; sid:100002649; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.208.188"; classtype:trojan-activity; sid:100002650; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.24.246"; classtype:trojan-activity; sid:100002651; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.241.135"; classtype:trojan-activity; sid:100002652; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.26.37"; classtype:trojan-activity; sid:100002653; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.31.15"; classtype:trojan-activity; sid:100002654; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.31.67"; classtype:trojan-activity; sid:100002655; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.37.97"; classtype:trojan-activity; sid:100002656; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.155.9.202"; classtype:trojan-activity; sid:100002657; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.156.103.248"; classtype:trojan-activity; sid:100002658; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.156.21.73"; classtype:trojan-activity; sid:100002659; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.156.23.29"; classtype:trojan-activity; sid:100002660; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.156.60.224"; classtype:trojan-activity; sid:100002661; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.156.9.32"; classtype:trojan-activity; sid:100002662; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.146.200"; classtype:trojan-activity; sid:100002663; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.150.91"; classtype:trojan-activity; sid:100002664; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.162.205"; classtype:trojan-activity; sid:100002665; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.17.8"; classtype:trojan-activity; sid:100002666; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.178.201"; classtype:trojan-activity; sid:100002667; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.183.29"; classtype:trojan-activity; sid:100002668; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.202.66"; classtype:trojan-activity; sid:100002669; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.220.170"; classtype:trojan-activity; sid:100002670; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.221.133"; classtype:trojan-activity; sid:100002671; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.223.245"; classtype:trojan-activity; sid:100002672; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.244.33"; classtype:trojan-activity; sid:100002673; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.32.244"; classtype:trojan-activity; sid:100002674; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.50.211"; classtype:trojan-activity; sid:100002675; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.54.158"; classtype:trojan-activity; sid:100002676; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.157.56.46"; classtype:trojan-activity; sid:100002677; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.241.6.180"; classtype:trojan-activity; sid:100002678; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.1.148"; classtype:trojan-activity; sid:100002679; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.1.84"; classtype:trojan-activity; sid:100002680; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.163.7"; classtype:trojan-activity; sid:100002681; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.171.144"; classtype:trojan-activity; sid:100002682; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.245.63"; classtype:trojan-activity; sid:100002683; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.251.32"; classtype:trojan-activity; sid:100002684; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.68.5.140"; classtype:trojan-activity; sid:100002685; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.69.71.186"; classtype:trojan-activity; sid:100002686; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.80.217.209"; classtype:trojan-activity; sid:100002687; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"219.85.145.194"; classtype:trojan-activity; sid:100002688; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"21robo.com"; classtype:trojan-activity; sid:100002689; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.118.168.155"; classtype:trojan-activity; sid:100002690; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.126.237.74"; classtype:trojan-activity; sid:100002691; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.173.160.53"; classtype:trojan-activity; sid:100002692; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.200.22.163"; classtype:trojan-activity; sid:100002693; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.71.239.115"; classtype:trojan-activity; sid:100002694; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"220.90.159.188"; classtype:trojan-activity; sid:100002695; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.0.16.221"; classtype:trojan-activity; sid:100002696; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.1.162.82"; classtype:trojan-activity; sid:100002697; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.124.78.15"; classtype:trojan-activity; sid:100002698; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.14.122.127"; classtype:trojan-activity; sid:100002699; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.14.182.157"; classtype:trojan-activity; sid:100002700; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.14.46.33"; classtype:trojan-activity; sid:100002701; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.14.58.5"; classtype:trojan-activity; sid:100002702; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.14.58.84"; classtype:trojan-activity; sid:100002703; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.147.220"; classtype:trojan-activity; sid:100002704; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.153.17"; classtype:trojan-activity; sid:100002705; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.218.173"; classtype:trojan-activity; sid:100002706; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.234.159"; classtype:trojan-activity; sid:100002707; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.234.175"; classtype:trojan-activity; sid:100002708; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.237.107"; classtype:trojan-activity; sid:100002709; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.54.237"; classtype:trojan-activity; sid:100002710; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.15.7.202"; classtype:trojan-activity; sid:100002711; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.157.191.178"; classtype:trojan-activity; sid:100002712; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.160.136.213"; classtype:trojan-activity; sid:100002713; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.160.177.104"; classtype:trojan-activity; sid:100002714; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.160.177.107"; classtype:trojan-activity; sid:100002715; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.160.177.224"; classtype:trojan-activity; sid:100002716; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.196.12.96"; classtype:trojan-activity; sid:100002717; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.214.130.147"; classtype:trojan-activity; sid:100002718; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.214.162.109"; classtype:trojan-activity; sid:100002719; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.214.224.184"; classtype:trojan-activity; sid:100002720; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.116.167"; classtype:trojan-activity; sid:100002721; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.172.207"; classtype:trojan-activity; sid:100002722; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.184.31"; classtype:trojan-activity; sid:100002723; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.237.220"; classtype:trojan-activity; sid:100002724; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.239.162"; classtype:trojan-activity; sid:100002725; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.252.64"; classtype:trojan-activity; sid:100002726; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.215.8.64"; classtype:trojan-activity; sid:100002727; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.232.1.82"; classtype:trojan-activity; sid:100002728; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.232.179.70"; classtype:trojan-activity; sid:100002729; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.235.137.36"; classtype:trojan-activity; sid:100002730; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.235.142.206"; classtype:trojan-activity; sid:100002731; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.112.125"; classtype:trojan-activity; sid:100002732; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.32.88"; classtype:trojan-activity; sid:100002733; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.34.43"; classtype:trojan-activity; sid:100002734; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.43.223"; classtype:trojan-activity; sid:100002735; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.3.68.16"; classtype:trojan-activity; sid:100002736; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"221.5.30.118"; classtype:trojan-activity; sid:100002737; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.108.17.64"; classtype:trojan-activity; sid:100002738; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.119.65.145"; classtype:trojan-activity; sid:100002739; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.132.125.138"; classtype:trojan-activity; sid:100002740; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.133.102.202"; classtype:trojan-activity; sid:100002741; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.133.103.120"; classtype:trojan-activity; sid:100002742; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.133.105.87"; classtype:trojan-activity; sid:100002743; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.135.113.41"; classtype:trojan-activity; sid:100002744; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.135.219.29"; classtype:trojan-activity; sid:100002745; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.135.26.161"; classtype:trojan-activity; sid:100002746; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.136.231.197"; classtype:trojan-activity; sid:100002747; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.136.49.252"; classtype:trojan-activity; sid:100002748; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.101.251"; classtype:trojan-activity; sid:100002749; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.113.184"; classtype:trojan-activity; sid:100002750; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.121.127"; classtype:trojan-activity; sid:100002751; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.136.241"; classtype:trojan-activity; sid:100002752; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.137.5"; classtype:trojan-activity; sid:100002753; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.137.94"; classtype:trojan-activity; sid:100002754; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.138.252"; classtype:trojan-activity; sid:100002755; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.139.170"; classtype:trojan-activity; sid:100002756; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.148.192"; classtype:trojan-activity; sid:100002757; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.152.35"; classtype:trojan-activity; sid:100002758; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.172.250"; classtype:trojan-activity; sid:100002759; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.175.242"; classtype:trojan-activity; sid:100002760; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.186.150"; classtype:trojan-activity; sid:100002761; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.22.79"; classtype:trojan-activity; sid:100002762; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.220.94"; classtype:trojan-activity; sid:100002763; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.221.128"; classtype:trojan-activity; sid:100002764; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.49.4"; classtype:trojan-activity; sid:100002765; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.5.150"; classtype:trojan-activity; sid:100002766; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.72.146"; classtype:trojan-activity; sid:100002767; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.81.67"; classtype:trojan-activity; sid:100002768; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.137.83.53"; classtype:trojan-activity; sid:100002769; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.137.188"; classtype:trojan-activity; sid:100002770; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.143.84"; classtype:trojan-activity; sid:100002771; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.189.88"; classtype:trojan-activity; sid:100002772; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.203.22"; classtype:trojan-activity; sid:100002773; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.215.161"; classtype:trojan-activity; sid:100002774; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.232.159"; classtype:trojan-activity; sid:100002775; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.232.84"; classtype:trojan-activity; sid:100002776; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.49.93"; classtype:trojan-activity; sid:100002777; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.138.96.79"; classtype:trojan-activity; sid:100002778; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.139.16.229"; classtype:trojan-activity; sid:100002779; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.139.59.63"; classtype:trojan-activity; sid:100002780; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.112.150"; classtype:trojan-activity; sid:100002781; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.117.221"; classtype:trojan-activity; sid:100002782; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.161.11"; classtype:trojan-activity; sid:100002783; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.163.112"; classtype:trojan-activity; sid:100002784; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.17.245"; classtype:trojan-activity; sid:100002785; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.209.222"; classtype:trojan-activity; sid:100002786; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.219.212"; classtype:trojan-activity; sid:100002787; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.140.39.66"; classtype:trojan-activity; sid:100002788; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.150.38"; classtype:trojan-activity; sid:100002789; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.165.180"; classtype:trojan-activity; sid:100002790; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.244.231"; classtype:trojan-activity; sid:100002791; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.40.136"; classtype:trojan-activity; sid:100002792; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.41.155"; classtype:trojan-activity; sid:100002793; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.44.36"; classtype:trojan-activity; sid:100002794; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.45.153"; classtype:trojan-activity; sid:100002795; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.60.251"; classtype:trojan-activity; sid:100002796; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.73.249"; classtype:trojan-activity; sid:100002797; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.141.85.128"; classtype:trojan-activity; sid:100002798; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.142.162.164"; classtype:trojan-activity; sid:100002799; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.142.192.66"; classtype:trojan-activity; sid:100002800; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.142.209.7"; classtype:trojan-activity; sid:100002801; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.142.65.30"; classtype:trojan-activity; sid:100002802; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.179.215.189"; classtype:trojan-activity; sid:100002803; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.185.116.233"; classtype:trojan-activity; sid:100002804; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.187.9.178"; classtype:trojan-activity; sid:100002805; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.211.72.66"; classtype:trojan-activity; sid:100002806; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.214.54.208"; classtype:trojan-activity; sid:100002807; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.218.220.219"; classtype:trojan-activity; sid:100002808; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.238.230.7"; classtype:trojan-activity; sid:100002809; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.239.83.232"; classtype:trojan-activity; sid:100002810; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.248.64.253"; classtype:trojan-activity; sid:100002811; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.64.16.239"; classtype:trojan-activity; sid:100002812; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.83.150.240"; classtype:trojan-activity; sid:100002813; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.92.9.126"; classtype:trojan-activity; sid:100002814; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"222.99.171.192"; classtype:trojan-activity; sid:100002815; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.166.117.210"; classtype:trojan-activity; sid:100002816; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.167.118.17"; classtype:trojan-activity; sid:100002817; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.212.225.68"; classtype:trojan-activity; sid:100002818; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.212.234.84"; classtype:trojan-activity; sid:100002819; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.212.252.180"; classtype:trojan-activity; sid:100002820; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.212.5.29"; classtype:trojan-activity; sid:100002821; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"223.212.73.175"; classtype:trojan-activity; sid:100002822; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.125.186.135"; classtype:trojan-activity; sid:100002823; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.126.120.25"; classtype:trojan-activity; sid:100002824; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.228.143.58"; classtype:trojan-activity; sid:100002825; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.24.213.121"; classtype:trojan-activity; sid:100002826; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.243.149.13"; classtype:trojan-activity; sid:100002827; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.243.21.167"; classtype:trojan-activity; sid:100002828; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"23.95.89.21"; classtype:trojan-activity; sid:100002829; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.103.74.180"; classtype:trojan-activity; sid:100002830; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.11.141.134"; classtype:trojan-activity; sid:100002831; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.119.158.74"; classtype:trojan-activity; sid:100002832; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.137.147.95"; classtype:trojan-activity; sid:100002833; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.152.235.88"; classtype:trojan-activity; sid:100002834; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.158.25.98"; classtype:trojan-activity; sid:100002835; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.176.206.12"; classtype:trojan-activity; sid:100002836; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.184.1.41"; classtype:trojan-activity; sid:100002837; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.192.191.109"; classtype:trojan-activity; sid:100002838; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.225.114.161"; classtype:trojan-activity; sid:100002839; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.227.190.78"; classtype:trojan-activity; sid:100002840; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.35.245.52"; classtype:trojan-activity; sid:100002841; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.39.181.18"; classtype:trojan-activity; sid:100002842; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.39.34.242"; classtype:trojan-activity; sid:100002843; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.42.229.143"; classtype:trojan-activity; sid:100002844; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.45.4.1"; classtype:trojan-activity; sid:100002845; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.51.91.113"; classtype:trojan-activity; sid:100002846; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.53.163.10"; classtype:trojan-activity; sid:100002847; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.53.163.9"; classtype:trojan-activity; sid:100002848; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"24.dbstrony.pl"; classtype:trojan-activity; sid:100002849; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.1.245.16"; classtype:trojan-activity; sid:100002850; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.1.245.7"; classtype:trojan-activity; sid:100002851; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.105.106.201"; classtype:trojan-activity; sid:100002852; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.105.152.107"; classtype:trojan-activity; sid:100002853; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.116.84.57"; classtype:trojan-activity; sid:100002854; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.12.234.4"; classtype:trojan-activity; sid:100002855; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.12.245.238"; classtype:trojan-activity; sid:100002856; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.13.83.77"; classtype:trojan-activity; sid:100002857; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.14.211.219"; classtype:trojan-activity; sid:100002858; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.141.218.17"; classtype:trojan-activity; sid:100002859; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.147.29.52"; classtype:trojan-activity; sid:100002860; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.147.40.128"; classtype:trojan-activity; sid:100002861; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.153.132.82"; classtype:trojan-activity; sid:100002862; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.153.207.1"; classtype:trojan-activity; sid:100002863; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.184.244.14"; classtype:trojan-activity; sid:100002864; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.184.54.199"; classtype:trojan-activity; sid:100002865; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.187.248.22"; classtype:trojan-activity; sid:100002866; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.193.196.190"; classtype:trojan-activity; sid:100002867; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.193.217.210"; classtype:trojan-activity; sid:100002868; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.194.149.142"; classtype:trojan-activity; sid:100002869; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.194.158.229"; classtype:trojan-activity; sid:100002870; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.194.192.66"; classtype:trojan-activity; sid:100002871; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.194.210.20"; classtype:trojan-activity; sid:100002872; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.194.224.96"; classtype:trojan-activity; sid:100002873; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.197.17.88"; classtype:trojan-activity; sid:100002874; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.197.22.217"; classtype:trojan-activity; sid:100002875; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.197.23.215"; classtype:trojan-activity; sid:100002876; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.197.24.175"; classtype:trojan-activity; sid:100002877; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.199.232.65"; classtype:trojan-activity; sid:100002878; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.199.3.194"; classtype:trojan-activity; sid:100002879; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.199.34.48"; classtype:trojan-activity; sid:100002880; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.200.140.229"; classtype:trojan-activity; sid:100002881; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.200.23.62"; classtype:trojan-activity; sid:100002882; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.200.32.146"; classtype:trojan-activity; sid:100002883; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.202.182.201"; classtype:trojan-activity; sid:100002884; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.202.21.57"; classtype:trojan-activity; sid:100002885; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.202.66.46"; classtype:trojan-activity; sid:100002886; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.102.12"; classtype:trojan-activity; sid:100002887; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.126.194"; classtype:trojan-activity; sid:100002888; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.154.105"; classtype:trojan-activity; sid:100002889; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.165.138"; classtype:trojan-activity; sid:100002890; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.185.42"; classtype:trojan-activity; sid:100002891; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.185.48"; classtype:trojan-activity; sid:100002892; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.213.79"; classtype:trojan-activity; sid:100002893; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.234.76"; classtype:trojan-activity; sid:100002894; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.246.96"; classtype:trojan-activity; sid:100002895; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.255.42"; classtype:trojan-activity; sid:100002896; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.28.115"; classtype:trojan-activity; sid:100002897; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.4.188"; classtype:trojan-activity; sid:100002898; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.54.217"; classtype:trojan-activity; sid:100002899; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.87.75"; classtype:trojan-activity; sid:100002900; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.203.94.134"; classtype:trojan-activity; sid:100002901; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.204.253.74"; classtype:trojan-activity; sid:100002902; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.205.178.110"; classtype:trojan-activity; sid:100002903; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.136.101"; classtype:trojan-activity; sid:100002904; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.14.137"; classtype:trojan-activity; sid:100002905; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.148.106"; classtype:trojan-activity; sid:100002906; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.154.122"; classtype:trojan-activity; sid:100002907; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.185.118"; classtype:trojan-activity; sid:100002908; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.26.218"; classtype:trojan-activity; sid:100002909; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.81.66"; classtype:trojan-activity; sid:100002910; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.83.48"; classtype:trojan-activity; sid:100002911; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.206.97.81"; classtype:trojan-activity; sid:100002912; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.207.155.31"; classtype:trojan-activity; sid:100002913; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.207.194.254"; classtype:trojan-activity; sid:100002914; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.207.199.162"; classtype:trojan-activity; sid:100002915; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.152.10"; classtype:trojan-activity; sid:100002916; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.160.177"; classtype:trojan-activity; sid:100002917; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.164.18"; classtype:trojan-activity; sid:100002918; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.166.13"; classtype:trojan-activity; sid:100002919; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.201.212"; classtype:trojan-activity; sid:100002920; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.247.130"; classtype:trojan-activity; sid:100002921; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.25.59"; classtype:trojan-activity; sid:100002922; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.34.2"; classtype:trojan-activity; sid:100002923; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.208.92.64"; classtype:trojan-activity; sid:100002924; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.209.160.222"; classtype:trojan-activity; sid:100002925; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.209.231.15"; classtype:trojan-activity; sid:100002926; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.209.60.21"; classtype:trojan-activity; sid:100002927; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.107.125"; classtype:trojan-activity; sid:100002928; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.127.11"; classtype:trojan-activity; sid:100002929; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.146.61"; classtype:trojan-activity; sid:100002930; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.172.245"; classtype:trojan-activity; sid:100002931; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.234.28"; classtype:trojan-activity; sid:100002932; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.236.134"; classtype:trojan-activity; sid:100002933; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.210.63.243"; classtype:trojan-activity; sid:100002934; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.211.251.162"; classtype:trojan-activity; sid:100002935; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.104.201"; classtype:trojan-activity; sid:100002936; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.109.105"; classtype:trojan-activity; sid:100002937; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.109.58"; classtype:trojan-activity; sid:100002938; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.145.221"; classtype:trojan-activity; sid:100002939; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.167.175"; classtype:trojan-activity; sid:100002940; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.175.208"; classtype:trojan-activity; sid:100002941; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.220.5"; classtype:trojan-activity; sid:100002942; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.255.202"; classtype:trojan-activity; sid:100002943; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.255.6"; classtype:trojan-activity; sid:100002944; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.213.84.74"; classtype:trojan-activity; sid:100002945; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.214.37.129"; classtype:trojan-activity; sid:100002946; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.139.242"; classtype:trojan-activity; sid:100002947; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.190.172"; classtype:trojan-activity; sid:100002948; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.212.209"; classtype:trojan-activity; sid:100002949; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.253.149"; classtype:trojan-activity; sid:100002950; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.34.242"; classtype:trojan-activity; sid:100002951; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.38.166"; classtype:trojan-activity; sid:100002952; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.71.243"; classtype:trojan-activity; sid:100002953; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.215.98.242"; classtype:trojan-activity; sid:100002954; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.131.66"; classtype:trojan-activity; sid:100002955; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.144.66"; classtype:trojan-activity; sid:100002956; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.193.217"; classtype:trojan-activity; sid:100002957; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.197.193"; classtype:trojan-activity; sid:100002958; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.225.28"; classtype:trojan-activity; sid:100002959; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.234.98"; classtype:trojan-activity; sid:100002960; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.46.85"; classtype:trojan-activity; sid:100002961; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.58.120"; classtype:trojan-activity; sid:100002962; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.216.95.56"; classtype:trojan-activity; sid:100002963; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.217.120.226"; classtype:trojan-activity; sid:100002964; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.217.133.53"; classtype:trojan-activity; sid:100002965; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.217.155.141"; classtype:trojan-activity; sid:100002966; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.217.191.58"; classtype:trojan-activity; sid:100002967; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.217.31.245"; classtype:trojan-activity; sid:100002968; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.217.76.48"; classtype:trojan-activity; sid:100002969; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.218.180.172"; classtype:trojan-activity; sid:100002970; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.218.219.228"; classtype:trojan-activity; sid:100002971; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.218.248.121"; classtype:trojan-activity; sid:100002972; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.132.71"; classtype:trojan-activity; sid:100002973; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.151.83"; classtype:trojan-activity; sid:100002974; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.160.112"; classtype:trojan-activity; sid:100002975; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.172.175"; classtype:trojan-activity; sid:100002976; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.173.180"; classtype:trojan-activity; sid:100002977; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.176.72"; classtype:trojan-activity; sid:100002978; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.184.94"; classtype:trojan-activity; sid:100002979; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.192.223"; classtype:trojan-activity; sid:100002980; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.219.83.244"; classtype:trojan-activity; sid:100002981; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.220.40.189"; classtype:trojan-activity; sid:100002982; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.220.85.168"; classtype:trojan-activity; sid:100002983; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.221.239.223"; classtype:trojan-activity; sid:100002984; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.222.241.223"; classtype:trojan-activity; sid:100002985; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.222.249.105"; classtype:trojan-activity; sid:100002986; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.222.249.210"; classtype:trojan-activity; sid:100002987; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.222.42.189"; classtype:trojan-activity; sid:100002988; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.222.50.170"; classtype:trojan-activity; sid:100002989; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.223.242.164"; classtype:trojan-activity; sid:100002990; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.223.44.106"; classtype:trojan-activity; sid:100002991; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.24.28.134"; classtype:trojan-activity; sid:100002992; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.129.198"; classtype:trojan-activity; sid:100002993; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.154.13"; classtype:trojan-activity; sid:100002994; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.16.145"; classtype:trojan-activity; sid:100002995; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.2.30"; classtype:trojan-activity; sid:100002996; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.212.124"; classtype:trojan-activity; sid:100002997; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.35.58.5"; classtype:trojan-activity; sid:100002998; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.41.153.66"; classtype:trojan-activity; sid:100002999; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.41.154.31"; classtype:trojan-activity; sid:100003000; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.43.82.210"; classtype:trojan-activity; sid:100003001; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.46.45.248"; classtype:trojan-activity; sid:100003002; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.46.47.74"; classtype:trojan-activity; sid:100003003; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.5.16.243"; classtype:trojan-activity; sid:100003004; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.5.26.105"; classtype:trojan-activity; sid:100003005; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.5.26.4"; classtype:trojan-activity; sid:100003006; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.5.27.1"; classtype:trojan-activity; sid:100003007; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"27.5.35.127"; classtype:trojan-activity; sid:100003008; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.0.98.131"; classtype:trojan-activity; sid:100003009; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.11.51.57"; classtype:trojan-activity; sid:100003010; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.13.23.180"; classtype:trojan-activity; sid:100003011; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.154.234.3"; classtype:trojan-activity; sid:100003012; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.163.191.11"; classtype:trojan-activity; sid:100003013; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.124.130"; classtype:trojan-activity; sid:100003014; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.179.83"; classtype:trojan-activity; sid:100003015; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.184.59"; classtype:trojan-activity; sid:100003016; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.191.243"; classtype:trojan-activity; sid:100003017; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.194.67"; classtype:trojan-activity; sid:100003018; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.216.132"; classtype:trojan-activity; sid:100003019; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.219.28"; classtype:trojan-activity; sid:100003020; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.24.115"; classtype:trojan-activity; sid:100003021; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.30.65"; classtype:trojan-activity; sid:100003022; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.60.234"; classtype:trojan-activity; sid:100003023; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.63.203"; classtype:trojan-activity; sid:100003024; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.65.233"; classtype:trojan-activity; sid:100003025; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.168.94.16"; classtype:trojan-activity; sid:100003026; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.179.201.26"; classtype:trojan-activity; sid:100003027; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.195.84.250"; classtype:trojan-activity; sid:100003028; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.204.174.180"; classtype:trojan-activity; sid:100003029; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.210.20.138"; classtype:trojan-activity; sid:100003030; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.210.20.177"; classtype:trojan-activity; sid:100003031; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.210.20.227"; classtype:trojan-activity; sid:100003032; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.28.7.159"; classtype:trojan-activity; sid:100003033; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.30.119.23"; classtype:trojan-activity; sid:100003034; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"31.62.255.3"; classtype:trojan-activity; sid:100003035; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"32.208.157.193"; classtype:trojan-activity; sid:100003036; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"32792.prolocksmithwinterpark.com"; classtype:trojan-activity; sid:100003037; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"35.184.169.169"; classtype:trojan-activity; sid:100003038; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.108.231.218"; classtype:trojan-activity; sid:100003039; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.109.132.50"; classtype:trojan-activity; sid:100003040; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.250.203.246"; classtype:trojan-activity; sid:100003041; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.157.225"; classtype:trojan-activity; sid:100003042; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.18.18"; classtype:trojan-activity; sid:100003043; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.19.88"; classtype:trojan-activity; sid:100003044; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.251.51.244"; classtype:trojan-activity; sid:100003045; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.255.90.219"; classtype:trojan-activity; sid:100003046; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.33.128.60"; classtype:trojan-activity; sid:100003047; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.33.160.167"; classtype:trojan-activity; sid:100003048; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.36.243.67"; classtype:trojan-activity; sid:100003049; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.66.105.159"; classtype:trojan-activity; sid:100003050; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.66.111.203"; classtype:trojan-activity; sid:100003051; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.66.133.125"; classtype:trojan-activity; sid:100003052; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.66.139.36"; classtype:trojan-activity; sid:100003053; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.67.152.161"; classtype:trojan-activity; sid:100003054; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.89.18.133"; classtype:trojan-activity; sid:100003055; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"36.96.187.93"; classtype:trojan-activity; sid:100003056; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"360.lcy2zzx.pw"; classtype:trojan-activity; sid:100003057; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"360down7.miiyun.cn"; classtype:trojan-activity; sid:100003058; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.222.98.51"; classtype:trojan-activity; sid:100003059; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.233.60.68"; classtype:trojan-activity; sid:100003060; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.34.179.221"; classtype:trojan-activity; sid:100003061; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.34.180.172"; classtype:trojan-activity; sid:100003062; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.44.238.35"; classtype:trojan-activity; sid:100003063; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.49.229.154"; classtype:trojan-activity; sid:100003064; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.49.230.152"; classtype:trojan-activity; sid:100003065; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.52.117.132"; classtype:trojan-activity; sid:100003066; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"37.54.14.36"; classtype:trojan-activity; sid:100003067; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"38.77.14.237"; classtype:trojan-activity; sid:100003068; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"38.81.149.108"; classtype:trojan-activity; sid:100003069; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.113.245.254"; classtype:trojan-activity; sid:100003070; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.113.98.136"; classtype:trojan-activity; sid:100003071; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.114.137.102"; classtype:trojan-activity; sid:100003072; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.117.31.162"; classtype:trojan-activity; sid:100003073; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.162.104.119"; classtype:trojan-activity; sid:100003074; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.64.28.214"; classtype:trojan-activity; sid:100003075; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.65.171.29"; classtype:trojan-activity; sid:100003076; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.65.196.34"; classtype:trojan-activity; sid:100003077; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.65.59.160"; classtype:trojan-activity; sid:100003078; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.66.129.163"; classtype:trojan-activity; sid:100003079; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.66.85.187"; classtype:trojan-activity; sid:100003080; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.104.83"; classtype:trojan-activity; sid:100003081; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.125.186"; classtype:trojan-activity; sid:100003082; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.146.60"; classtype:trojan-activity; sid:100003083; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.148.163"; classtype:trojan-activity; sid:100003084; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.67.92.131"; classtype:trojan-activity; sid:100003085; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.68.124.76"; classtype:trojan-activity; sid:100003086; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.68.249.255"; classtype:trojan-activity; sid:100003087; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.72.130.114"; classtype:trojan-activity; sid:100003088; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.72.167.202"; classtype:trojan-activity; sid:100003089; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.72.67.64"; classtype:trojan-activity; sid:100003090; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.10.198"; classtype:trojan-activity; sid:100003091; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.163.231"; classtype:trojan-activity; sid:100003092; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.203.225"; classtype:trojan-activity; sid:100003093; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.73.44.17"; classtype:trojan-activity; sid:100003094; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.74.104.228"; classtype:trojan-activity; sid:100003095; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.74.21.201"; classtype:trojan-activity; sid:100003096; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.74.28.89"; classtype:trojan-activity; sid:100003097; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.74.31.192"; classtype:trojan-activity; sid:100003098; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.74.68.182"; classtype:trojan-activity; sid:100003099; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.76.194.65"; classtype:trojan-activity; sid:100003100; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.76.79.43"; classtype:trojan-activity; sid:100003101; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.76.97.16"; classtype:trojan-activity; sid:100003102; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.113.201"; classtype:trojan-activity; sid:100003103; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.114.45"; classtype:trojan-activity; sid:100003104; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.136.47"; classtype:trojan-activity; sid:100003105; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.14.27"; classtype:trojan-activity; sid:100003106; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.150.203"; classtype:trojan-activity; sid:100003107; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.197.81"; classtype:trojan-activity; sid:100003108; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.209.209"; classtype:trojan-activity; sid:100003109; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.94.189"; classtype:trojan-activity; sid:100003110; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.77.95.50"; classtype:trojan-activity; sid:100003111; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.107.66"; classtype:trojan-activity; sid:100003112; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.166.31"; classtype:trojan-activity; sid:100003113; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.218.46"; classtype:trojan-activity; sid:100003114; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.62.43"; classtype:trojan-activity; sid:100003115; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.90.92"; classtype:trojan-activity; sid:100003116; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.91.244"; classtype:trojan-activity; sid:100003117; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.79.93.171"; classtype:trojan-activity; sid:100003118; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.127.214"; classtype:trojan-activity; sid:100003119; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.191.137"; classtype:trojan-activity; sid:100003120; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.205.255"; classtype:trojan-activity; sid:100003121; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.24.54"; classtype:trojan-activity; sid:100003122; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.34.26"; classtype:trojan-activity; sid:100003123; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.80.36.151"; classtype:trojan-activity; sid:100003124; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.124.33"; classtype:trojan-activity; sid:100003125; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.130.19"; classtype:trojan-activity; sid:100003126; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.251.0"; classtype:trojan-activity; sid:100003127; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.27.15"; classtype:trojan-activity; sid:100003128; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.81.29.231"; classtype:trojan-activity; sid:100003129; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.82.86.105"; classtype:trojan-activity; sid:100003130; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.83.94.11"; classtype:trojan-activity; sid:100003131; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.84.157.52"; classtype:trojan-activity; sid:100003132; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.84.34.217"; classtype:trojan-activity; sid:100003133; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.84.95.200"; classtype:trojan-activity; sid:100003134; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.85.54.191"; classtype:trojan-activity; sid:100003135; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.85.54.4"; classtype:trojan-activity; sid:100003136; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.129.233"; classtype:trojan-activity; sid:100003137; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.13.0"; classtype:trojan-activity; sid:100003138; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.151.49"; classtype:trojan-activity; sid:100003139; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.170.209"; classtype:trojan-activity; sid:100003140; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.184.164"; classtype:trojan-activity; sid:100003141; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.211.20"; classtype:trojan-activity; sid:100003142; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.234.187"; classtype:trojan-activity; sid:100003143; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.248.91"; classtype:trojan-activity; sid:100003144; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.60.98"; classtype:trojan-activity; sid:100003145; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.66.24"; classtype:trojan-activity; sid:100003146; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.76.9"; classtype:trojan-activity; sid:100003147; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.86.78.228"; classtype:trojan-activity; sid:100003148; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.87.63.58"; classtype:trojan-activity; sid:100003149; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.87.90.210"; classtype:trojan-activity; sid:100003150; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.87.93.109"; classtype:trojan-activity; sid:100003151; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.141.172"; classtype:trojan-activity; sid:100003152; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.155.96"; classtype:trojan-activity; sid:100003153; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.233.131"; classtype:trojan-activity; sid:100003154; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.39.222"; classtype:trojan-activity; sid:100003155; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.41.73"; classtype:trojan-activity; sid:100003156; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.67.238"; classtype:trojan-activity; sid:100003157; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.88.72.9"; classtype:trojan-activity; sid:100003158; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.146.198"; classtype:trojan-activity; sid:100003159; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.146.36"; classtype:trojan-activity; sid:100003160; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.157.140"; classtype:trojan-activity; sid:100003161; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.89.63.23"; classtype:trojan-activity; sid:100003162; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"39.90.86.212"; classtype:trojan-activity; sid:100003163; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.139.209.46"; classtype:trojan-activity; sid:100003164; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.165.130.43"; classtype:trojan-activity; sid:100003165; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.190.63.174"; classtype:trojan-activity; sid:100003166; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.193.192.100"; classtype:trojan-activity; sid:100003167; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.219.185.171"; classtype:trojan-activity; sid:100003168; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.230.31.58"; classtype:trojan-activity; sid:100003169; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.72.203.82"; classtype:trojan-activity; sid:100003170; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.18.133"; classtype:trojan-activity; sid:100003171; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.18.147"; classtype:trojan-activity; sid:100003172; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.18.148"; classtype:trojan-activity; sid:100003173; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.18.165"; classtype:trojan-activity; sid:100003174; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.18.200"; classtype:trojan-activity; sid:100003175; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.18.71"; classtype:trojan-activity; sid:100003176; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.21.28"; classtype:trojan-activity; sid:100003177; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.21.5"; classtype:trojan-activity; sid:100003178; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.21.62"; classtype:trojan-activity; sid:100003179; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"41.86.5.103"; classtype:trojan-activity; sid:100003180; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.176.112.72"; classtype:trojan-activity; sid:100003181; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.202.101.147"; classtype:trojan-activity; sid:100003182; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.122.39"; classtype:trojan-activity; sid:100003183; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.128.210"; classtype:trojan-activity; sid:100003184; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.168.142"; classtype:trojan-activity; sid:100003185; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.168.97"; classtype:trojan-activity; sid:100003186; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.176.214"; classtype:trojan-activity; sid:100003187; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.179.49"; classtype:trojan-activity; sid:100003188; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.209.156"; classtype:trojan-activity; sid:100003189; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.212.124"; classtype:trojan-activity; sid:100003190; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.218.16"; classtype:trojan-activity; sid:100003191; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.233.247"; classtype:trojan-activity; sid:100003192; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.235.4"; classtype:trojan-activity; sid:100003193; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.249.8"; classtype:trojan-activity; sid:100003194; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.37.186"; classtype:trojan-activity; sid:100003195; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.37.44"; classtype:trojan-activity; sid:100003196; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.43.25"; classtype:trojan-activity; sid:100003197; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.64.34"; classtype:trojan-activity; sid:100003198; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.70.213"; classtype:trojan-activity; sid:100003199; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.76.168"; classtype:trojan-activity; sid:100003200; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.76.198"; classtype:trojan-activity; sid:100003201; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.8.136"; classtype:trojan-activity; sid:100003202; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.90.17"; classtype:trojan-activity; sid:100003203; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.224.91.8"; classtype:trojan-activity; sid:100003204; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.225.240.244"; classtype:trojan-activity; sid:100003205; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.225.250.39"; classtype:trojan-activity; sid:100003206; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.225.33.31"; classtype:trojan-activity; sid:100003207; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.226.89.25"; classtype:trojan-activity; sid:100003208; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.227.179.209"; classtype:trojan-activity; sid:100003209; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.227.66.88"; classtype:trojan-activity; sid:100003210; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.198.102"; classtype:trojan-activity; sid:100003211; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.60.114"; classtype:trojan-activity; sid:100003212; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.65.201"; classtype:trojan-activity; sid:100003213; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.70.126"; classtype:trojan-activity; sid:100003214; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.70.231"; classtype:trojan-activity; sid:100003215; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.75.7"; classtype:trojan-activity; sid:100003216; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.228.76.135"; classtype:trojan-activity; sid:100003217; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.230.100.114"; classtype:trojan-activity; sid:100003218; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.230.174.125"; classtype:trojan-activity; sid:100003219; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.230.219.243"; classtype:trojan-activity; sid:100003220; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.230.228.78"; classtype:trojan-activity; sid:100003221; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.230.66.255"; classtype:trojan-activity; sid:100003222; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.230.82.44"; classtype:trojan-activity; sid:100003223; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.230.88.107"; classtype:trojan-activity; sid:100003224; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.230.93.169"; classtype:trojan-activity; sid:100003225; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.231.223.215"; classtype:trojan-activity; sid:100003226; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.231.244.80"; classtype:trojan-activity; sid:100003227; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.231.66.174"; classtype:trojan-activity; sid:100003228; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.231.95.195"; classtype:trojan-activity; sid:100003229; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.232.102.163"; classtype:trojan-activity; sid:100003230; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.232.170.117"; classtype:trojan-activity; sid:100003231; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.232.226.16"; classtype:trojan-activity; sid:100003232; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.233.90.183"; classtype:trojan-activity; sid:100003233; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.234.105.6"; classtype:trojan-activity; sid:100003234; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.234.162.44"; classtype:trojan-activity; sid:100003235; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.234.166.242"; classtype:trojan-activity; sid:100003236; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.234.255.20"; classtype:trojan-activity; sid:100003237; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.235.124.55"; classtype:trojan-activity; sid:100003238; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.235.169.85"; classtype:trojan-activity; sid:100003239; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.235.23.163"; classtype:trojan-activity; sid:100003240; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.235.66.249"; classtype:trojan-activity; sid:100003241; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.235.90.32"; classtype:trojan-activity; sid:100003242; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.235.92.111"; classtype:trojan-activity; sid:100003243; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.236.148.201"; classtype:trojan-activity; sid:100003244; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.236.212.174"; classtype:trojan-activity; sid:100003245; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.236.212.83"; classtype:trojan-activity; sid:100003246; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.236.215.63"; classtype:trojan-activity; sid:100003247; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.236.236.179"; classtype:trojan-activity; sid:100003248; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.237.45.223"; classtype:trojan-activity; sid:100003249; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.237.54.162"; classtype:trojan-activity; sid:100003250; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.238.175.32"; classtype:trojan-activity; sid:100003251; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.238.191.210"; classtype:trojan-activity; sid:100003252; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.238.241.239"; classtype:trojan-activity; sid:100003253; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.238.59.222"; classtype:trojan-activity; sid:100003254; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.239.192.128"; classtype:trojan-activity; sid:100003255; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.242.200.90"; classtype:trojan-activity; sid:100003256; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.52.180.36"; classtype:trojan-activity; sid:100003257; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.56.15.227"; classtype:trojan-activity; sid:100003258; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.61.99.155"; classtype:trojan-activity; sid:100003259; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.82.217.241"; classtype:trojan-activity; sid:100003260; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"42.84.14.5"; classtype:trojan-activity; sid:100003261; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"43.230.156.44"; classtype:trojan-activity; sid:100003262; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"43.241.106.183"; classtype:trojan-activity; sid:100003263; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"43.241.106.234"; classtype:trojan-activity; sid:100003264; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"43.252.8.94"; classtype:trojan-activity; sid:100003265; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.112.203.218"; classtype:trojan-activity; sid:100003266; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.130.138.66"; classtype:trojan-activity; sid:100003267; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.133.1.137"; classtype:trojan-activity; sid:100003268; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.133.1.242"; classtype:trojan-activity; sid:100003269; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.133.203.192"; classtype:trojan-activity; sid:100003270; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.135.134.228"; classtype:trojan-activity; sid:100003271; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.14.149.182"; classtype:trojan-activity; sid:100003272; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.14.149.204"; classtype:trojan-activity; sid:100003273; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.14.149.244"; classtype:trojan-activity; sid:100003274; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.14.149.66"; classtype:trojan-activity; sid:100003275; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.141.84.184"; classtype:trojan-activity; sid:100003276; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.142"; classtype:trojan-activity; sid:100003277; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.213"; classtype:trojan-activity; sid:100003278; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.144.225.65"; classtype:trojan-activity; sid:100003279; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.148.10.47"; classtype:trojan-activity; sid:100003280; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.15.143.158"; classtype:trojan-activity; sid:100003281; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.164.140.133"; classtype:trojan-activity; sid:100003282; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.108.116"; classtype:trojan-activity; sid:100003283; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.108.248"; classtype:trojan-activity; sid:100003284; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.110.99"; classtype:trojan-activity; sid:100003285; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.111.154"; classtype:trojan-activity; sid:100003286; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.111.16"; classtype:trojan-activity; sid:100003287; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.111.202"; classtype:trojan-activity; sid:100003288; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.176.111.84"; classtype:trojan-activity; sid:100003289; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.178.101.22"; classtype:trojan-activity; sid:100003290; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.201.165.164"; classtype:trojan-activity; sid:100003291; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.22.209.58"; classtype:trojan-activity; sid:100003292; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.23.22.186"; classtype:trojan-activity; sid:100003293; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.27.253.137"; classtype:trojan-activity; sid:100003294; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.33.112.19"; classtype:trojan-activity; sid:100003295; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.51.104.59"; classtype:trojan-activity; sid:100003296; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.81.235.31"; classtype:trojan-activity; sid:100003297; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"45.9.148.37"; classtype:trojan-activity; sid:100003298; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.151.155.218"; classtype:trojan-activity; sid:100003299; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.172.75.231"; classtype:trojan-activity; sid:100003300; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.175.184.121"; classtype:trojan-activity; sid:100003301; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.182.173.246"; classtype:trojan-activity; sid:100003302; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.20.63.218"; classtype:trojan-activity; sid:100003303; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.201.214.64"; classtype:trojan-activity; sid:100003304; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.21.153.231"; classtype:trojan-activity; sid:100003305; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.214.27.4"; classtype:trojan-activity; sid:100003306; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.24.130.254"; classtype:trojan-activity; sid:100003307; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.243.179.115"; classtype:trojan-activity; sid:100003308; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.249.33.79"; classtype:trojan-activity; sid:100003309; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.25.242.211"; classtype:trojan-activity; sid:100003310; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.42.118.86"; classtype:trojan-activity; sid:100003311; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.42.86.128"; classtype:trojan-activity; sid:100003312; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"46.97.76.242"; classtype:trojan-activity; sid:100003313; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.145.152.26"; classtype:trojan-activity; sid:100003314; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.151.23.172"; classtype:trojan-activity; sid:100003315; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.157.97.71"; classtype:trojan-activity; sid:100003316; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.16.131.51"; classtype:trojan-activity; sid:100003317; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.197.0.119"; classtype:trojan-activity; sid:100003318; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.21.202.98"; classtype:trojan-activity; sid:100003319; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.223.167.153"; classtype:trojan-activity; sid:100003320; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"47.46.231.38"; classtype:trojan-activity; sid:100003321; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.142.162.113"; classtype:trojan-activity; sid:100003322; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.142.87.36"; classtype:trojan-activity; sid:100003323; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.143.43.93"; classtype:trojan-activity; sid:100003324; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.156.35.166"; classtype:trojan-activity; sid:100003325; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.158.201.200"; classtype:trojan-activity; sid:100003326; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.159.20.121"; classtype:trojan-activity; sid:100003327; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.159.21.3"; classtype:trojan-activity; sid:100003328; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.174.182.99"; classtype:trojan-activity; sid:100003329; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.213.170.49"; classtype:trojan-activity; sid:100003330; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.213.178.183"; classtype:trojan-activity; sid:100003331; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.213.179.129"; classtype:trojan-activity; sid:100003332; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.68.221.252"; classtype:trojan-activity; sid:100003333; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.68.249.121"; classtype:trojan-activity; sid:100003334; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"49.70.15.16"; classtype:trojan-activity; sid:100003335; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.181.135.114"; classtype:trojan-activity; sid:100003336; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.2.70.50"; classtype:trojan-activity; sid:100003337; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.53.146.179"; classtype:trojan-activity; sid:100003338; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"5.8.10.62"; classtype:trojan-activity; sid:100003339; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.115.174.102"; classtype:trojan-activity; sid:100003340; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.121.91.255"; classtype:trojan-activity; sid:100003341; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"50.252.47.29"; classtype:trojan-activity; sid:100003342; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"51.171.146.13"; classtype:trojan-activity; sid:100003343; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"51.222.56.159"; classtype:trojan-activity; sid:100003344; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"54.180.158.181"; classtype:trojan-activity; sid:100003345; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"54.253.194.14"; classtype:trojan-activity; sid:100003346; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"54.36.114.136"; classtype:trojan-activity; sid:100003347; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"54.36.180.122"; classtype:trojan-activity; sid:100003348; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"54.37.93.29"; classtype:trojan-activity; sid:100003349; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.114.246.26"; classtype:trojan-activity; sid:100003350; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.115.162.92"; classtype:trojan-activity; sid:100003351; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.115.174.4"; classtype:trojan-activity; sid:100003352; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.125.191.4"; classtype:trojan-activity; sid:100003353; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.126.247.118"; classtype:trojan-activity; sid:100003354; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.142.166.120"; classtype:trojan-activity; sid:100003355; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.142.200.124"; classtype:trojan-activity; sid:100003356; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.143.142.142"; classtype:trojan-activity; sid:100003357; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.143.189.75"; classtype:trojan-activity; sid:100003358; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.18.103.109"; classtype:trojan-activity; sid:100003359; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.19.249.50"; classtype:trojan-activity; sid:100003360; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.217.171.157"; classtype:trojan-activity; sid:100003361; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.22.212.107"; classtype:trojan-activity; sid:100003362; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.226.129.29"; classtype:trojan-activity; sid:100003363; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.229.194.122"; classtype:trojan-activity; sid:100003364; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.23.245.24"; classtype:trojan-activity; sid:100003365; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.230.89.42"; classtype:trojan-activity; sid:100003366; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.232.155.37"; classtype:trojan-activity; sid:100003367; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.238.42.192"; classtype:trojan-activity; sid:100003368; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.240.147.97"; classtype:trojan-activity; sid:100003369; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.241.57.237"; classtype:trojan-activity; sid:100003370; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.241.78.55"; classtype:trojan-activity; sid:100003371; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.117.188"; classtype:trojan-activity; sid:100003372; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.143.173"; classtype:trojan-activity; sid:100003373; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.144.97"; classtype:trojan-activity; sid:100003374; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.149.117"; classtype:trojan-activity; sid:100003375; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.149.226"; classtype:trojan-activity; sid:100003376; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.154.55"; classtype:trojan-activity; sid:100003377; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.154.66"; classtype:trojan-activity; sid:100003378; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.76.206"; classtype:trojan-activity; sid:100003379; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.248.79.25"; classtype:trojan-activity; sid:100003380; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.18.244"; classtype:trojan-activity; sid:100003381; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.74.104"; classtype:trojan-activity; sid:100003382; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.74.124"; classtype:trojan-activity; sid:100003383; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.74.248"; classtype:trojan-activity; sid:100003384; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.77.227"; classtype:trojan-activity; sid:100003385; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.78.155"; classtype:trojan-activity; sid:100003386; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.80.23"; classtype:trojan-activity; sid:100003387; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.80.46"; classtype:trojan-activity; sid:100003388; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.86.85"; classtype:trojan-activity; sid:100003389; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.87.248"; classtype:trojan-activity; sid:100003390; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.89.210"; classtype:trojan-activity; sid:100003391; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.90.206"; classtype:trojan-activity; sid:100003392; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.249.90.86"; classtype:trojan-activity; sid:100003393; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.252.176.107"; classtype:trojan-activity; sid:100003394; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.252.177.66"; classtype:trojan-activity; sid:100003395; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.255.43.163"; classtype:trojan-activity; sid:100003396; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.48.154.143"; classtype:trojan-activity; sid:100003397; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.50.178.137"; classtype:trojan-activity; sid:100003398; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.50.221.148"; classtype:trojan-activity; sid:100003399; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.72.165.153"; classtype:trojan-activity; sid:100003400; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.72.165.39"; classtype:trojan-activity; sid:100003401; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.97.201.45"; classtype:trojan-activity; sid:100003402; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"58.97.206.33"; classtype:trojan-activity; sid:100003403; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.0.211.161"; classtype:trojan-activity; sid:100003404; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.102.168.189"; classtype:trojan-activity; sid:100003405; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.151.202.3"; classtype:trojan-activity; sid:100003406; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.151.214.4"; classtype:trojan-activity; sid:100003407; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.151.237.51"; classtype:trojan-activity; sid:100003408; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.29.133.229"; classtype:trojan-activity; sid:100003409; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.30.12.254"; classtype:trojan-activity; sid:100003410; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.32.97.190"; classtype:trojan-activity; sid:100003411; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.58.104.244"; classtype:trojan-activity; sid:100003412; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.58.117.226"; classtype:trojan-activity; sid:100003413; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.7.124.148"; classtype:trojan-activity; sid:100003414; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.8.35.22"; classtype:trojan-activity; sid:100003415; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.92.182.72"; classtype:trojan-activity; sid:100003416; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.92.218.77"; classtype:trojan-activity; sid:100003417; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.92.219.28"; classtype:trojan-activity; sid:100003418; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.97.174.85"; classtype:trojan-activity; sid:100003419; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"59.99.47.93"; classtype:trojan-activity; sid:100003420; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.13.61.12"; classtype:trojan-activity; sid:100003421; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.14.48.221"; classtype:trojan-activity; sid:100003422; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.162.122.36"; classtype:trojan-activity; sid:100003423; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.162.160.200"; classtype:trojan-activity; sid:100003424; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.164.130.220"; classtype:trojan-activity; sid:100003425; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.17.12.143"; classtype:trojan-activity; sid:100003426; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.176.249.56"; classtype:trojan-activity; sid:100003427; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.20.217.142"; classtype:trojan-activity; sid:100003428; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.208.135.42"; classtype:trojan-activity; sid:100003429; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.122.57"; classtype:trojan-activity; sid:100003430; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.186.185"; classtype:trojan-activity; sid:100003431; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.216.23"; classtype:trojan-activity; sid:100003432; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.209.33.5"; classtype:trojan-activity; sid:100003433; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.211.19.63"; classtype:trojan-activity; sid:100003434; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.211.6.112"; classtype:trojan-activity; sid:100003435; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.211.7.166"; classtype:trojan-activity; sid:100003436; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.100.83"; classtype:trojan-activity; sid:100003437; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.162.152"; classtype:trojan-activity; sid:100003438; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.206.246"; classtype:trojan-activity; sid:100003439; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.218.31"; classtype:trojan-activity; sid:100003440; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.220.167"; classtype:trojan-activity; sid:100003441; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.23.84"; classtype:trojan-activity; sid:100003442; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.212.254.178"; classtype:trojan-activity; sid:100003443; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.213.162.59"; classtype:trojan-activity; sid:100003444; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.213.58.188"; classtype:trojan-activity; sid:100003445; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.213.83.55"; classtype:trojan-activity; sid:100003446; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.214.93.166"; classtype:trojan-activity; sid:100003447; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.215.165.64"; classtype:trojan-activity; sid:100003448; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.215.195.111"; classtype:trojan-activity; sid:100003449; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.215.207.11"; classtype:trojan-activity; sid:100003450; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.215.219.108"; classtype:trojan-activity; sid:100003451; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.215.4.239"; classtype:trojan-activity; sid:100003452; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.216.95.211"; classtype:trojan-activity; sid:100003453; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.217.177.196"; classtype:trojan-activity; sid:100003454; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.217.86.208"; classtype:trojan-activity; sid:100003455; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.220.22.89"; classtype:trojan-activity; sid:100003456; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.25.115.48"; classtype:trojan-activity; sid:100003457; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.25.76.224"; classtype:trojan-activity; sid:100003458; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.4.72"; classtype:trojan-activity; sid:100003459; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.42.72"; classtype:trojan-activity; sid:100003460; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.51.127"; classtype:trojan-activity; sid:100003461; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.60.174"; classtype:trojan-activity; sid:100003462; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.8.36"; classtype:trojan-activity; sid:100003463; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.253.8.81"; classtype:trojan-activity; sid:100003464; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.254.49.59"; classtype:trojan-activity; sid:100003465; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.7.10.121"; classtype:trojan-activity; sid:100003466; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.7.136.8"; classtype:trojan-activity; sid:100003467; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.7.202.153"; classtype:trojan-activity; sid:100003468; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.7.8.43"; classtype:trojan-activity; sid:100003469; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"60.7.99.254"; classtype:trojan-activity; sid:100003470; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.102.243.124"; classtype:trojan-activity; sid:100003471; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.109.164.140"; classtype:trojan-activity; sid:100003472; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.141.124.123"; classtype:trojan-activity; sid:100003473; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.162.169.210"; classtype:trojan-activity; sid:100003474; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.162.55.42"; classtype:trojan-activity; sid:100003475; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.164.96.98"; classtype:trojan-activity; sid:100003476; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.179.171.60"; classtype:trojan-activity; sid:100003477; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.179.91.194"; classtype:trojan-activity; sid:100003478; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.179.91.230"; classtype:trojan-activity; sid:100003479; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.179.93.79"; classtype:trojan-activity; sid:100003480; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.18.112.48"; classtype:trojan-activity; sid:100003481; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.192.73.253"; classtype:trojan-activity; sid:100003482; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.213.118.28"; classtype:trojan-activity; sid:100003483; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.247.224.66"; classtype:trojan-activity; sid:100003484; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.253.94.230"; classtype:trojan-activity; sid:100003485; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.3.124.3"; classtype:trojan-activity; sid:100003486; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.3.124.51"; classtype:trojan-activity; sid:100003487; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.47.220.169"; classtype:trojan-activity; sid:100003488; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.102.61"; classtype:trojan-activity; sid:100003489; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.103.144"; classtype:trojan-activity; sid:100003490; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.11.87"; classtype:trojan-activity; sid:100003491; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.135.192"; classtype:trojan-activity; sid:100003492; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.157.4"; classtype:trojan-activity; sid:100003493; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.159.231"; classtype:trojan-activity; sid:100003494; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.195.226"; classtype:trojan-activity; sid:100003495; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.212.191"; classtype:trojan-activity; sid:100003496; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.212.250"; classtype:trojan-activity; sid:100003497; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.243.169"; classtype:trojan-activity; sid:100003498; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.247.208"; classtype:trojan-activity; sid:100003499; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.35.86"; classtype:trojan-activity; sid:100003500; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.39.119"; classtype:trojan-activity; sid:100003501; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.43.174"; classtype:trojan-activity; sid:100003502; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.48.112"; classtype:trojan-activity; sid:100003503; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.5.217"; classtype:trojan-activity; sid:100003504; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.63.119"; classtype:trojan-activity; sid:100003505; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.76.72"; classtype:trojan-activity; sid:100003506; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.9.166"; classtype:trojan-activity; sid:100003507; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.52.99.183"; classtype:trojan-activity; sid:100003508; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.100.87"; classtype:trojan-activity; sid:100003509; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.123.162"; classtype:trojan-activity; sid:100003510; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.125.182"; classtype:trojan-activity; sid:100003511; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.251.243"; classtype:trojan-activity; sid:100003512; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.62.169"; classtype:trojan-activity; sid:100003513; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.73.171"; classtype:trojan-activity; sid:100003514; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.81.18"; classtype:trojan-activity; sid:100003515; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.53.83.14"; classtype:trojan-activity; sid:100003516; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.172.248"; classtype:trojan-activity; sid:100003517; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.240.20"; classtype:trojan-activity; sid:100003518; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.58.190"; classtype:trojan-activity; sid:100003519; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.58.20"; classtype:trojan-activity; sid:100003520; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.61.18"; classtype:trojan-activity; sid:100003521; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.64.104"; classtype:trojan-activity; sid:100003522; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.54.77.175"; classtype:trojan-activity; sid:100003523; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.56.180.67"; classtype:trojan-activity; sid:100003524; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.56.181.7"; classtype:trojan-activity; sid:100003525; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.57.96.116"; classtype:trojan-activity; sid:100003526; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.58.170.60"; classtype:trojan-activity; sid:100003527; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.58.73.220"; classtype:trojan-activity; sid:100003528; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.61.218.23"; classtype:trojan-activity; sid:100003529; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.65.172.121"; classtype:trojan-activity; sid:100003530; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.0.22"; classtype:trojan-activity; sid:100003531; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.104.46"; classtype:trojan-activity; sid:100003532; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.110.59"; classtype:trojan-activity; sid:100003533; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.132.195"; classtype:trojan-activity; sid:100003534; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.132.86"; classtype:trojan-activity; sid:100003535; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.255.60"; classtype:trojan-activity; sid:100003536; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.70.45.130"; classtype:trojan-activity; sid:100003537; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"61.98.144.75"; classtype:trojan-activity; sid:100003538; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.1.98.131"; classtype:trojan-activity; sid:100003539; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.117.124.114"; classtype:trojan-activity; sid:100003540; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.141.73.58"; classtype:trojan-activity; sid:100003541; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.219.131.205"; classtype:trojan-activity; sid:100003542; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.219.143.46"; classtype:trojan-activity; sid:100003543; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.219.155.61"; classtype:trojan-activity; sid:100003544; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.219.227.31"; classtype:trojan-activity; sid:100003545; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.31.126.33"; classtype:trojan-activity; sid:100003546; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.38.149.66"; classtype:trojan-activity; sid:100003547; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.38.222.98"; classtype:trojan-activity; sid:100003548; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.43.207.148"; classtype:trojan-activity; sid:100003549; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"62.90.165.236"; classtype:trojan-activity; sid:100003550; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"63.245.122.93"; classtype:trojan-activity; sid:100003551; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"64.233.154.99"; classtype:trojan-activity; sid:100003552; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.125.128.196"; classtype:trojan-activity; sid:100003553; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.21.58.252"; classtype:trojan-activity; sid:100003554; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"65.26.155.131"; classtype:trojan-activity; sid:100003555; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.153.233.87"; classtype:trojan-activity; sid:100003556; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.229.214.115"; classtype:trojan-activity; sid:100003557; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.57.55.210"; classtype:trojan-activity; sid:100003558; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.74.7.197"; classtype:trojan-activity; sid:100003559; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.91.21.31"; classtype:trojan-activity; sid:100003560; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.97.181.196"; classtype:trojan-activity; sid:100003561; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"66.97.181.213"; classtype:trojan-activity; sid:100003562; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.245.151.203"; classtype:trojan-activity; sid:100003563; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.3.169.223"; classtype:trojan-activity; sid:100003564; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.8.138.101"; classtype:trojan-activity; sid:100003565; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.81.98.111"; classtype:trojan-activity; sid:100003566; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.82.242.243"; classtype:trojan-activity; sid:100003567; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.83.49.234"; classtype:trojan-activity; sid:100003568; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"67.84.138.165"; classtype:trojan-activity; sid:100003569; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.148.103.248"; classtype:trojan-activity; sid:100003570; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.151.244.128"; classtype:trojan-activity; sid:100003571; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.174.182.226"; classtype:trojan-activity; sid:100003572; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.175.107.153"; classtype:trojan-activity; sid:100003573; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.188.144.143"; classtype:trojan-activity; sid:100003574; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.204.88.29"; classtype:trojan-activity; sid:100003575; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.205.106.84"; classtype:trojan-activity; sid:100003576; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.205.119.241"; classtype:trojan-activity; sid:100003577; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"68.78.33.33"; classtype:trojan-activity; sid:100003578; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.115.37.205"; classtype:trojan-activity; sid:100003579; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.120.237.255"; classtype:trojan-activity; sid:100003580; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.123.245.151"; classtype:trojan-activity; sid:100003581; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.124.231.110"; classtype:trojan-activity; sid:100003582; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.127.214.47"; classtype:trojan-activity; sid:100003583; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.146.232.34"; classtype:trojan-activity; sid:100003584; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.165.173.49"; classtype:trojan-activity; sid:100003585; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.196.158.227"; classtype:trojan-activity; sid:100003586; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.222.157.166"; classtype:trojan-activity; sid:100003587; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.229.0.133"; classtype:trojan-activity; sid:100003588; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.63.73.234"; classtype:trojan-activity; sid:100003589; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.75.115.194"; classtype:trojan-activity; sid:100003590; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.75.227.186"; classtype:trojan-activity; sid:100003591; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"69.76.240.206"; classtype:trojan-activity; sid:100003592; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.115.31.30"; classtype:trojan-activity; sid:100003593; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.118.240.88"; classtype:trojan-activity; sid:100003594; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.167.10.180"; classtype:trojan-activity; sid:100003595; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.236.190.250"; classtype:trojan-activity; sid:100003596; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.25.5.105"; classtype:trojan-activity; sid:100003597; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.33.144.248"; classtype:trojan-activity; sid:100003598; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"70.93.129.118"; classtype:trojan-activity; sid:100003599; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.127.148.69"; classtype:trojan-activity; sid:100003600; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.19.150.93"; classtype:trojan-activity; sid:100003601; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.204.63.239"; classtype:trojan-activity; sid:100003602; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.29.48.164"; classtype:trojan-activity; sid:100003603; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.34.191.213"; classtype:trojan-activity; sid:100003604; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.40.234.166"; classtype:trojan-activity; sid:100003605; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.43.2.122"; classtype:trojan-activity; sid:100003606; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.43.235.106"; classtype:trojan-activity; sid:100003607; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.47.133.58"; classtype:trojan-activity; sid:100003608; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.71.60.69"; classtype:trojan-activity; sid:100003609; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"71.85.106.211"; classtype:trojan-activity; sid:100003610; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.17.22.30"; classtype:trojan-activity; sid:100003611; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.186.139.38"; classtype:trojan-activity; sid:100003612; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.189.180.98"; classtype:trojan-activity; sid:100003613; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.214.69.226"; classtype:trojan-activity; sid:100003614; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.229.230.118"; classtype:trojan-activity; sid:100003615; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.229.35.40"; classtype:trojan-activity; sid:100003616; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"72.31.40.122"; classtype:trojan-activity; sid:100003617; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"73.204.216.103"; classtype:trojan-activity; sid:100003618; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.101.1.159"; classtype:trojan-activity; sid:100003619; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.108.224.112"; classtype:trojan-activity; sid:100003620; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.194.117.165"; classtype:trojan-activity; sid:100003621; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.195.115.176"; classtype:trojan-activity; sid:100003622; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.199.84.77"; classtype:trojan-activity; sid:100003623; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"74.75.165.81"; classtype:trojan-activity; sid:100003624; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"75.127.141.52"; classtype:trojan-activity; sid:100003625; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"75.82.36.220"; classtype:trojan-activity; sid:100003626; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"75.83.102.27"; classtype:trojan-activity; sid:100003627; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"75.99.213.61"; classtype:trojan-activity; sid:100003628; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.108.199.153"; classtype:trojan-activity; sid:100003629; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.170.11.82"; classtype:trojan-activity; sid:100003630; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.178.22.145"; classtype:trojan-activity; sid:100003631; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.250.199.133"; classtype:trojan-activity; sid:100003632; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.254.129.227"; classtype:trojan-activity; sid:100003633; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.84.134.33"; classtype:trojan-activity; sid:100003634; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"76.95.12.137"; classtype:trojan-activity; sid:100003635; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.237.25.210"; classtype:trojan-activity; sid:100003636; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.45.183.39"; classtype:trojan-activity; sid:100003637; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.71.50.153"; classtype:trojan-activity; sid:100003638; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.71.52.220"; classtype:trojan-activity; sid:100003639; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.79.191.32"; classtype:trojan-activity; sid:100003640; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"77.89.203.238"; classtype:trojan-activity; sid:100003641; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.179.225.254"; classtype:trojan-activity; sid:100003642; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.186.155.18"; classtype:trojan-activity; sid:100003643; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.187.141.144"; classtype:trojan-activity; sid:100003644; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.187.240.125"; classtype:trojan-activity; sid:100003645; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.187.41.200"; classtype:trojan-activity; sid:100003646; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.188.168.64"; classtype:trojan-activity; sid:100003647; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.188.188.141"; classtype:trojan-activity; sid:100003648; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.189.104.157"; classtype:trojan-activity; sid:100003649; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.189.176.163"; classtype:trojan-activity; sid:100003650; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.23.172.81"; classtype:trojan-activity; sid:100003651; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.72.231.120"; classtype:trojan-activity; sid:100003652; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"78.8.225.77"; classtype:trojan-activity; sid:100003653; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.11.195.121"; classtype:trojan-activity; sid:100003654; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.13.49.221"; classtype:trojan-activity; sid:100003655; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.130.253.13"; classtype:trojan-activity; sid:100003656; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.147.123.48"; classtype:trojan-activity; sid:100003657; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.170.31.56"; classtype:trojan-activity; sid:100003658; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.175.42.244"; classtype:trojan-activity; sid:100003659; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.21.84.63"; classtype:trojan-activity; sid:100003660; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.7.170.58"; classtype:trojan-activity; sid:100003661; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.79.58.94"; classtype:trojan-activity; sid:100003662; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.8.70.162"; classtype:trojan-activity; sid:100003663; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"79.9.88.185"; classtype:trojan-activity; sid:100003664; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.107.89.207"; classtype:trojan-activity; sid:100003665; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.19.101.218"; classtype:trojan-activity; sid:100003666; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.211.181.77"; classtype:trojan-activity; sid:100003667; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.217.12.7"; classtype:trojan-activity; sid:100003668; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"80.99.128.61"; classtype:trojan-activity; sid:100003669; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.136.146.213"; classtype:trojan-activity; sid:100003670; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.165.44.109"; classtype:trojan-activity; sid:100003671; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.191.40.58"; classtype:trojan-activity; sid:100003672; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.198.7.22"; classtype:trojan-activity; sid:100003673; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.213.111.60"; classtype:trojan-activity; sid:100003674; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.213.141.184"; classtype:trojan-activity; sid:100003675; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.215.199.29"; classtype:trojan-activity; sid:100003676; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.218.187.113"; classtype:trojan-activity; sid:100003677; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.218.195.216"; classtype:trojan-activity; sid:100003678; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.237.128.200"; classtype:trojan-activity; sid:100003679; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.246.225.203"; classtype:trojan-activity; sid:100003680; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"81.92.36.96"; classtype:trojan-activity; sid:100003681; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.103.108.72"; classtype:trojan-activity; sid:100003682; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.135.196.130"; classtype:trojan-activity; sid:100003683; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.166.212.178"; classtype:trojan-activity; sid:100003684; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.166.85.112"; classtype:trojan-activity; sid:100003685; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.207.61.194"; classtype:trojan-activity; sid:100003686; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.209.250.155"; classtype:trojan-activity; sid:100003687; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.211.156.38"; classtype:trojan-activity; sid:100003688; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.62.110.252"; classtype:trojan-activity; sid:100003689; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.62.53.77"; classtype:trojan-activity; sid:100003690; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.138.72"; classtype:trojan-activity; sid:100003691; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.139.92"; classtype:trojan-activity; sid:100003692; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.154.214"; classtype:trojan-activity; sid:100003693; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.80.187.109"; classtype:trojan-activity; sid:100003694; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.100.54"; classtype:trojan-activity; sid:100003695; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.106.65"; classtype:trojan-activity; sid:100003696; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.108.172"; classtype:trojan-activity; sid:100003697; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.131.158"; classtype:trojan-activity; sid:100003698; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.19.42"; classtype:trojan-activity; sid:100003699; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.197.254"; classtype:trojan-activity; sid:100003700; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.215.149"; classtype:trojan-activity; sid:100003701; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.232.68"; classtype:trojan-activity; sid:100003702; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.234.195"; classtype:trojan-activity; sid:100003703; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.246.96"; classtype:trojan-activity; sid:100003704; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.28.57"; classtype:trojan-activity; sid:100003705; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.4.57"; classtype:trojan-activity; sid:100003706; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.55.84"; classtype:trojan-activity; sid:100003707; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.73.245"; classtype:trojan-activity; sid:100003708; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.9.62"; classtype:trojan-activity; sid:100003709; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"82.81.98.51"; classtype:trojan-activity; sid:100003710; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.165.237.163"; classtype:trojan-activity; sid:100003711; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.234.147.99"; classtype:trojan-activity; sid:100003712; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.234.218.42"; classtype:trojan-activity; sid:100003713; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.242.253.154"; classtype:trojan-activity; sid:100003714; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"83.252.9.37"; classtype:trojan-activity; sid:100003715; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.210.219.208"; classtype:trojan-activity; sid:100003716; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.210.219.213"; classtype:trojan-activity; sid:100003717; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.212.219.127"; classtype:trojan-activity; sid:100003718; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.224.162.170"; classtype:trojan-activity; sid:100003719; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.228.50.118"; classtype:trojan-activity; sid:100003720; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.228.95.204"; classtype:trojan-activity; sid:100003721; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.238.24.35"; classtype:trojan-activity; sid:100003722; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.247.83.74"; classtype:trojan-activity; sid:100003723; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.254.39.129"; classtype:trojan-activity; sid:100003724; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.33.111.227"; classtype:trojan-activity; sid:100003725; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.38.152.148"; classtype:trojan-activity; sid:100003726; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.40.127.242"; classtype:trojan-activity; sid:100003727; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"84.42.20.217"; classtype:trojan-activity; sid:100003728; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com"; classtype:trojan-activity; sid:100003729; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.11.216"; classtype:trojan-activity; sid:100003730; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.123.251"; classtype:trojan-activity; sid:100003731; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.135.187"; classtype:trojan-activity; sid:100003732; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.208.25"; classtype:trojan-activity; sid:100003733; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.224.141"; classtype:trojan-activity; sid:100003734; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.241.2"; classtype:trojan-activity; sid:100003735; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.105.9.152"; classtype:trojan-activity; sid:100003736; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.214.149.236"; classtype:trojan-activity; sid:100003737; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.64.181.50"; classtype:trojan-activity; sid:100003738; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.74.215.180"; classtype:trojan-activity; sid:100003739; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.97.130.227"; classtype:trojan-activity; sid:100003740; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"85.97.195.129"; classtype:trojan-activity; sid:100003741; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"86.35.43.220"; classtype:trojan-activity; sid:100003742; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"87.121.98.51"; classtype:trojan-activity; sid:100003743; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"87.61.89.40"; classtype:trojan-activity; sid:100003744; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.119.171.253"; classtype:trojan-activity; sid:100003745; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.2.208.71"; classtype:trojan-activity; sid:100003746; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.2.219.179"; classtype:trojan-activity; sid:100003747; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.225.222.128"; classtype:trojan-activity; sid:100003748; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.247.96.19"; classtype:trojan-activity; sid:100003749; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.248.136.231"; classtype:trojan-activity; sid:100003750; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.248.51.139"; classtype:trojan-activity; sid:100003751; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.249.244.180"; classtype:trojan-activity; sid:100003752; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.250.204.12"; classtype:trojan-activity; sid:100003753; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.250.226.26"; classtype:trojan-activity; sid:100003754; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"88.250.254.90"; classtype:trojan-activity; sid:100003755; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.122.183.130"; classtype:trojan-activity; sid:100003756; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.136.197.170"; classtype:trojan-activity; sid:100003757; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.29.213.33"; classtype:trojan-activity; sid:100003758; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.35.62.96"; classtype:trojan-activity; sid:100003759; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.40.85.166"; classtype:trojan-activity; sid:100003760; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"89.40.87.5"; classtype:trojan-activity; sid:100003761; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"8poieq.bn.files.1drv.com"; classtype:trojan-activity; sid:100003762; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"90.152.144.139"; classtype:trojan-activity; sid:100003763; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.177.139.132"; classtype:trojan-activity; sid:100003764; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.187.103.32"; classtype:trojan-activity; sid:100003765; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.212.150.241"; classtype:trojan-activity; sid:100003766; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.212.150.243"; classtype:trojan-activity; sid:100003767; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.217.104.185"; classtype:trojan-activity; sid:100003768; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.233.112.188"; classtype:trojan-activity; sid:100003769; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.234.60.94"; classtype:trojan-activity; sid:100003770; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.239.168.83"; classtype:trojan-activity; sid:100003771; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.244.114.198"; classtype:trojan-activity; sid:100003772; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.244.169.139"; classtype:trojan-activity; sid:100003773; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.92.16.244"; classtype:trojan-activity; sid:100003774; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"91.98.4.181"; classtype:trojan-activity; sid:100003775; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.114.191.82"; classtype:trojan-activity; sid:100003776; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.241.78.114"; classtype:trojan-activity; sid:100003777; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.27.246.202"; classtype:trojan-activity; sid:100003778; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.54.237.237"; classtype:trojan-activity; sid:100003779; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"92.85.18.138"; classtype:trojan-activity; sid:100003780; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.171.157.73"; classtype:trojan-activity; sid:100003781; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.21.224.154"; classtype:trojan-activity; sid:100003782; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.39.115.176"; classtype:trojan-activity; sid:100003783; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.41.137.16"; classtype:trojan-activity; sid:100003784; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.41.182.249"; classtype:trojan-activity; sid:100003785; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.41.206.56"; classtype:trojan-activity; sid:100003786; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.57.43.233"; classtype:trojan-activity; sid:100003787; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"93.73.99.102"; classtype:trojan-activity; sid:100003788; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.136.69.199"; classtype:trojan-activity; sid:100003789; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.143.53.34"; classtype:trojan-activity; sid:100003790; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.154.17.170"; classtype:trojan-activity; sid:100003791; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.154.82.190"; classtype:trojan-activity; sid:100003792; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.200.16.22"; classtype:trojan-activity; sid:100003793; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.224.83.208"; classtype:trojan-activity; sid:100003794; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.43.139.153"; classtype:trojan-activity; sid:100003795; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"94.53.120.109"; classtype:trojan-activity; sid:100003796; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.132.129.250"; classtype:trojan-activity; sid:100003797; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.154.20.231"; classtype:trojan-activity; sid:100003798; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.158.19.130"; classtype:trojan-activity; sid:100003799; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.170.113.52"; classtype:trojan-activity; sid:100003800; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.170.201.34"; classtype:trojan-activity; sid:100003801; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.181.155.112"; classtype:trojan-activity; sid:100003802; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.214.52.64"; classtype:trojan-activity; sid:100003803; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.54.11.179"; classtype:trojan-activity; sid:100003804; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.60.146.134"; classtype:trojan-activity; sid:100003805; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.60.6.114"; classtype:trojan-activity; sid:100003806; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.66.196.63"; classtype:trojan-activity; sid:100003807; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"95.9.120.40"; classtype:trojan-activity; sid:100003808; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"96.239.73.246"; classtype:trojan-activity; sid:100003809; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"96.47.147.169"; classtype:trojan-activity; sid:100003810; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"97.68.140.254"; classtype:trojan-activity; sid:100003811; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"97.96.199.75"; classtype:trojan-activity; sid:100003812; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.0.210.218"; classtype:trojan-activity; sid:100003813; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.0.239.142"; classtype:trojan-activity; sid:100003814; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.113.239.207"; classtype:trojan-activity; sid:100003815; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.116.72.119"; classtype:trojan-activity; sid:100003816; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.128.147.115"; classtype:trojan-activity; sid:100003817; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.178.242.44"; classtype:trojan-activity; sid:100003818; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.249.236.11"; classtype:trojan-activity; sid:100003819; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.28.200.139"; classtype:trojan-activity; sid:100003820; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"98.30.24.54"; classtype:trojan-activity; sid:100003821; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"99.150.245.203"; classtype:trojan-activity; sid:100003822; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"99.33.195.164"; classtype:trojan-activity; sid:100003823; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abcd.bg"; classtype:trojan-activity; sid:100003824; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abclicks.in"; classtype:trojan-activity; sid:100003825; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abissnet.net"; classtype:trojan-activity; sid:100003826; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aboveandbelow.com.au"; classtype:trojan-activity; sid:100003827; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"absoftechworld.com"; classtype:trojan-activity; sid:100003828; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"absupplies.co.uk"; classtype:trojan-activity; sid:100003829; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"abyssos.eu"; classtype:trojan-activity; sid:100003830; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"academyshademani.com"; classtype:trojan-activity; sid:100003831; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"acbick.com"; classtype:trojan-activity; sid:100003832; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"accounts.thesmarttechhub.com"; classtype:trojan-activity; sid:100003833; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aceeprc.com.aceeprc.com"; classtype:trojan-activity; sid:100003834; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"acellr.co.uk"; classtype:trojan-activity; sid:100003835; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aciabogados.com"; classtype:trojan-activity; sid:100003836; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"acteon.com.ar"; classtype:trojan-activity; sid:100003837; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"activateyourdiscount.com"; classtype:trojan-activity; sid:100003838; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"activecost.com.au"; classtype:trojan-activity; sid:100003839; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"adamorinmusic.com"; classtype:trojan-activity; sid:100003840; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"addahealingmusic.com"; classtype:trojan-activity; sid:100003841; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"adithimedia.com"; classtype:trojan-activity; sid:100003842; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"adithimedia.memengers.com"; classtype:trojan-activity; sid:100003843; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"admin.erapor.smk-alasror.net"; classtype:trojan-activity; sid:100003844; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"admin.gentbcn.org"; classtype:trojan-activity; sid:100003845; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"admin.grandoceanvilla.com"; classtype:trojan-activity; sid:100003846; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"adventureexplorer.in"; classtype:trojan-activity; sid:100003847; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aeropilates.cl"; classtype:trojan-activity; sid:100003848; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"afrimedspecialist.com"; classtype:trojan-activity; sid:100003849; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agemn.co.za"; classtype:trojan-activity; sid:100003850; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agenciadigitalwdys.com"; classtype:trojan-activity; sid:100003851; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agenciatabletshouse.com.br"; classtype:trojan-activity; sid:100003852; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agenda.gmelloinformatica.com.br"; classtype:trojan-activity; sid:100003853; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agenmovie.xyz"; classtype:trojan-activity; sid:100003854; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agentt.ac.ug"; classtype:trojan-activity; sid:100003855; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agile8studio.com"; classtype:trojan-activity; sid:100003856; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"agmcarpetcare.co.uk"; classtype:trojan-activity; sid:100003857; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aiqtest.com"; classtype:trojan-activity; sid:100003858; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ajpharmaholding.com"; classtype:trojan-activity; sid:100003859; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ajstudiollc.com"; classtype:trojan-activity; sid:100003860; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aktyd05.top"; classtype:trojan-activity; sid:100003861; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"al-wahd.com"; classtype:trojan-activity; sid:100003862; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alasdemariposas.org"; classtype:trojan-activity; sid:100003863; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alemelektronik.com"; classtype:trojan-activity; sid:100003864; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alena1971.es"; classtype:trojan-activity; sid:100003865; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alexdubai.com.aldiabsteel.com"; classtype:trojan-activity; sid:100003866; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alka.institute"; classtype:trojan-activity; sid:100003867; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"allforcreative.com.au"; classtype:trojan-activity; sid:100003868; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alltheway.travel"; classtype:trojan-activity; sid:100003869; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"alpaylar.com.tr"; classtype:trojan-activity; sid:100003870; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"am-concepts.ca"; classtype:trojan-activity; sid:100003871; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amamontajes.com"; classtype:trojan-activity; sid:100003872; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amarresdeamorymaestroshechiceros.com"; classtype:trojan-activity; sid:100003873; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amarteargentina.com.ar"; classtype:trojan-activity; sid:100003874; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amenyan.zouri.jp"; classtype:trojan-activity; sid:100003875; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"amos524.org"; classtype:trojan-activity; sid:100003876; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ams.alvinasschools.org.ng"; classtype:trojan-activity; sid:100003877; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anantam.net.in"; classtype:trojan-activity; sid:100003878; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andreelapeyre.com"; classtype:trojan-activity; sid:100003879; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andremaraisbeleggings.co.za"; classtype:trojan-activity; sid:100003880; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andres.ac.ug"; classtype:trojan-activity; sid:100003881; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andres.ug"; classtype:trojan-activity; sid:100003882; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"andreshconcejal.solucioneslink.com"; classtype:trojan-activity; sid:100003883; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"angelazgheibld.com"; classtype:trojan-activity; sid:100003884; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"angelsdetour.com"; classtype:trojan-activity; sid:100003885; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"angloteste.bigprime.com.br"; classtype:trojan-activity; sid:100003886; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anhung1102.vn"; classtype:trojan-activity; sid:100003887; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"anysbergbiltong.co.za"; classtype:trojan-activity; sid:100003888; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"apartamentoscitta.com"; classtype:trojan-activity; sid:100003889; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"api-ms.cobainaja.id"; classtype:trojan-activity; sid:100003890; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"api.cstdevs.com"; classtype:trojan-activity; sid:100003891; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"api.quocbao.biz"; classtype:trojan-activity; sid:100003892; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"api.sampy.io"; classtype:trojan-activity; sid:100003893; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aplicativoparasindicato.com.br"; classtype:trojan-activity; sid:100003894; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"apoolcondo.com"; classtype:trojan-activity; sid:100003895; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"app.adsensearticle.com"; classtype:trojan-activity; sid:100003896; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"app.prerana.info"; classtype:trojan-activity; sid:100003897; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"apps.saintsoporte.com"; classtype:trojan-activity; sid:100003898; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aqv.news"; classtype:trojan-activity; sid:100003899; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"areyoulivingwell.com"; classtype:trojan-activity; sid:100003900; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"arsapetrolab.com"; classtype:trojan-activity; sid:100003901; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"artedibujoyarquitectura.com"; classtype:trojan-activity; sid:100003902; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ask-regard.call-save.biz"; classtype:trojan-activity; sid:100003903; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"atfile.com"; classtype:trojan-activity; sid:100003904; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"athenacapsg.com"; classtype:trojan-activity; sid:100003905; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"atlasconcreteworks.com"; classtype:trojan-activity; sid:100003906; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"attach.66rpg.com"; classtype:trojan-activity; sid:100003907; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"atteuqpotentialunlimited.com"; classtype:trojan-activity; sid:100003908; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"augustair.com"; classtype:trojan-activity; sid:100003909; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"aulist.com"; classtype:trojan-activity; sid:100003910; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"australiafashions.com"; classtype:trojan-activity; sid:100003911; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"automaticrefreshments.com"; classtype:trojan-activity; sid:100003912; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"avadhanagames.com"; classtype:trojan-activity; sid:100003913; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"avissrilanka.com"; classtype:trojan-activity; sid:100003914; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ayamallah.com"; classtype:trojan-activity; sid:100003915; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"azmeasurement.com"; classtype:trojan-activity; sid:100003916; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"azraktours.com"; classtype:trojan-activity; sid:100003917; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"backgrounds.pk"; classtype:trojan-activity; sid:100003918; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"backup.agewsage.com"; classtype:trojan-activity; sid:100003919; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"badeggdesign.com"; classtype:trojan-activity; sid:100003920; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"balealgodon.mx"; classtype:trojan-activity; sid:100003921; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bangkok-orchids.com"; classtype:trojan-activity; sid:100003922; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"barcionstw.eastus.cloudapp.azure.com"; classtype:trojan-activity; sid:100003923; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bary.sz4h.com"; classtype:trojan-activity; sid:100003924; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"basma.com.kw"; classtype:trojan-activity; sid:100003925; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bausch.kr-atlas.monaxikoslykos@zytrox.tk"; classtype:trojan-activity; sid:100003926; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bavhome.com"; classtype:trojan-activity; sid:100003927; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bbia.co.uk"; classtype:trojan-activity; sid:100003928; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bcmt.elin.co.za"; classtype:trojan-activity; sid:100003929; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bcrg.co.za"; classtype:trojan-activity; sid:100003930; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bearcatpumps.com.cn"; classtype:trojan-activity; sid:100003931; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"beautincollagen.rs"; classtype:trojan-activity; sid:100003932; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bekape.co.id"; classtype:trojan-activity; sid:100003933; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bespokeweddings.ie"; classtype:trojan-activity; sid:100003934; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bestcarenepal.com"; classtype:trojan-activity; sid:100003935; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"betone.co.kr"; classtype:trojan-activity; sid:100003936; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"betycopaints.com"; classtype:trojan-activity; sid:100003937; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"beveragesmiami.solucioneslink.com"; classtype:trojan-activity; sid:100003938; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bhavaniengineering.com"; classtype:trojan-activity; sid:100003939; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bigbag.wootraining.certificacion.cl"; classtype:trojan-activity; sid:100003940; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bilbosaquet.ug"; classtype:trojan-activity; sid:100003941; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bilhen.co.za"; classtype:trojan-activity; sid:100003942; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"billing.rahitechnosoft.com"; classtype:trojan-activity; sid:100003943; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"birdi.elin.co.za"; classtype:trojan-activity; sid:100003944; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"birminghamlink.org"; classtype:trojan-activity; sid:100003945; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.callensaxen.com"; classtype:trojan-activity; sid:100003946; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"blog.oyinblogs.com"; classtype:trojan-activity; sid:100003947; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bmlifestyle.co.uk"; classtype:trojan-activity; sid:100003948; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bnrbook.com"; classtype:trojan-activity; sid:100003949; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bnrnews.id"; classtype:trojan-activity; sid:100003950; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bodenstein.co.za"; classtype:trojan-activity; sid:100003951; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"booksearch.com"; classtype:trojan-activity; sid:100003952; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bounces.mi-fs.com"; classtype:trojan-activity; sid:100003953; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bpo.correct.go.th"; classtype:trojan-activity; sid:100003954; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bradleyinstitute.co.za"; classtype:trojan-activity; sid:100003955; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brandtrust.com.pk"; classtype:trojan-activity; sid:100003956; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brendanquine.com"; classtype:trojan-activity; sid:100003957; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brideofmessiah.com"; classtype:trojan-activity; sid:100003958; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bridesofmaldives.com"; classtype:trojan-activity; sid:100003959; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brightmega.com"; classtype:trojan-activity; sid:100003960; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brightonrooms.co.uk"; classtype:trojan-activity; sid:100003961; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"brightstarshop.com"; classtype:trojan-activity; sid:100003962; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"browardinsurancemiami.solucioneslink.com"; classtype:trojan-activity; sid:100003963; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bt2.elin.co.za"; classtype:trojan-activity; sid:100003964; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bucrinsuranlceonlines.com"; classtype:trojan-activity; sid:100003965; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"buenavista.co"; classtype:trojan-activity; sid:100003966; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bullseyemedia.in"; classtype:trojan-activity; sid:100003967; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"busandvanrentalmalaysia.com"; classtype:trojan-activity; sid:100003968; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"buscascolegios.diit.cl"; classtype:trojan-activity; sid:100003969; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"business.softberg.ro"; classtype:trojan-activity; sid:100003970; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"buyingmusiconline.com"; classtype:trojan-activity; sid:100003971; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"bwsr.eu"; classtype:trojan-activity; sid:100003972; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"c.oooooooooo.ga"; classtype:trojan-activity; sid:100003973; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"c0140529.ferozo.com"; classtype:trojan-activity; sid:100003974; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"caballo.com.au"; classtype:trojan-activity; sid:100003975; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cacapavaonline.sdserver144.com.br"; classtype:trojan-activity; sid:100003976; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"calgaryautorepairservice.com"; classtype:trojan-activity; sid:100003977; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"callbury.in"; classtype:trojan-activity; sid:100003978; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"camminachetipassa.it"; classtype:trojan-activity; sid:100003979; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cancer.educandome.co"; classtype:trojan-activity; sid:100003980; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"capitalgroup-kw.com"; classtype:trojan-activity; sid:100003981; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"capitalnewsagency.com"; classtype:trojan-activity; sid:100003982; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"capoeiraventrelivre.com"; classtype:trojan-activity; sid:100003983; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cashyinvestment.org"; classtype:trojan-activity; sid:100003984; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"casoauditores.com"; classtype:trojan-activity; sid:100003985; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"catchperch.com"; classtype:trojan-activity; sid:100003986; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"catchpoolshetlands.co.uk"; classtype:trojan-activity; sid:100003987; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cazyacustomfurniture.com"; classtype:trojan-activity; sid:100003988; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ccauthority.net"; classtype:trojan-activity; sid:100003989; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cdaonline.com.ar"; classtype:trojan-activity; sid:100003990; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cec.asso.ac-amiens.fr"; classtype:trojan-activity; sid:100003991; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cendekiabinaaksara.com"; classtype:trojan-activity; sid:100003992; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cespol-bote.com.mx"; classtype:trojan-activity; sid:100003993; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cfs5.tistory.com"; classtype:trojan-activity; sid:100003994; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ch.rmu.ac.th"; classtype:trojan-activity; sid:100003995; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chardhamdodham.com"; classtype:trojan-activity; sid:100003996; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cheacrilnsurances.com"; classtype:trojan-activity; sid:100003997; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chealablilitycarinsurances.com"; classtype:trojan-activity; sid:100003998; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chezalice.co.za"; classtype:trojan-activity; sid:100003999; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"childselect.com"; classtype:trojan-activity; sid:100004000; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chinhdropfile.myvnc.com"; classtype:trojan-activity; sid:100004001; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"chinhdropfile80.myvnc.com"; classtype:trojan-activity; sid:100004002; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cible-energy.com"; classtype:trojan-activity; sid:100004003; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cifeer.net"; classtype:trojan-activity; sid:100004004; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"citycapproperty.ru"; classtype:trojan-activity; sid:100004005; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cityglobalgospel.com"; classtype:trojan-activity; sid:100004006; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"civi.istmejia.com"; classtype:trojan-activity; sid:100004007; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cleanbydesignllc.com"; classtype:trojan-activity; sid:100004008; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cloud.fc.co.mz"; classtype:trojan-activity; sid:100004009; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"clurbgolf.com"; classtype:trojan-activity; sid:100004010; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"codsambal.com"; classtype:trojan-activity; sid:100004011; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"colinde.pricesne.com"; classtype:trojan-activity; sid:100004012; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"colorpak.pl"; classtype:trojan-activity; sid:100004013; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"competancy.indigoconsult.net"; classtype:trojan-activity; sid:100004014; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"conceptimagine.ro"; classtype:trojan-activity; sid:100004015; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"config.cqhbkjzx.com"; classtype:trojan-activity; sid:100004016; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"constructoralyon.com"; classtype:trojan-activity; sid:100004017; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"consulateins.solucioneslink.com"; classtype:trojan-activity; sid:100004018; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"contributeindustry.com"; classtype:trojan-activity; sid:100004019; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"controladoradeplagasmm.com"; classtype:trojan-activity; sid:100004020; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"copelandscapes.com"; classtype:trojan-activity; sid:100004021; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"corporativos.com.co"; classtype:trojan-activity; sid:100004022; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"coulsongraphics.com"; classtype:trojan-activity; sid:100004023; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"coutler.newreadermedia.net"; classtype:trojan-activity; sid:100004024; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"covid19.cyberschool.or.id"; classtype:trojan-activity; sid:100004025; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cr-sq.com"; classtype:trojan-activity; sid:100004026; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crearechile.cl"; classtype:trojan-activity; sid:100004027; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"creationskateboards.com"; classtype:trojan-activity; sid:100004028; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crecerco.com"; classtype:trojan-activity; sid:100004029; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crittersbythebay.com"; classtype:trojan-activity; sid:100004030; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crm.notariavieitoyvelamazan.com"; classtype:trojan-activity; sid:100004031; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"crscorretordeimoveis.com.br"; classtype:trojan-activity; sid:100004032; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cse-engineer.com"; classtype:trojan-activity; sid:100004033; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"csnserver.com"; classtype:trojan-activity; sid:100004034; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cubescargoexpress.com"; classtype:trojan-activity; sid:100004035; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cubrebocasenpuebla.com.mx"; classtype:trojan-activity; sid:100004036; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"curasoles.co.za"; classtype:trojan-activity; sid:100004037; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"currantmedia.com"; classtype:trojan-activity; sid:100004038; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cwa.mx"; classtype:trojan-activity; sid:100004039; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cyber.searchkero.com"; classtype:trojan-activity; sid:100004040; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cyclomove.com"; classtype:trojan-activity; sid:100004041; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"cynkon.kairoscs.net"; classtype:trojan-activity; sid:100004042; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"czas.dbstrony.pl"; classtype:trojan-activity; sid:100004043; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"czsl.91756.cn"; classtype:trojan-activity; sid:100004044; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"d.powerofwish.com"; classtype:trojan-activity; sid:100004045; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"d9.99ddd.com"; classtype:trojan-activity; sid:100004046; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"da.alibuf.com"; classtype:trojan-activity; sid:100004047; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"damagedessentialtelecommunications.testmail4.repl.co"; classtype:trojan-activity; sid:100004048; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dandyair.com"; classtype:trojan-activity; sid:100004049; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dannexgh.com"; classtype:trojan-activity; sid:100004050; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dartoonpictures.com"; classtype:trojan-activity; sid:100004051; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"data.cdevelop.org"; classtype:trojan-activity; sid:100004052; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"data.over-blog-kiwi.com"; classtype:trojan-activity; sid:100004053; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"datapolish.com"; classtype:trojan-activity; sid:100004054; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dating.khokhas.co.za"; classtype:trojan-activity; sid:100004055; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"datsom.vn"; classtype:trojan-activity; sid:100004056; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"daunhotq10.com"; classtype:trojan-activity; sid:100004057; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"davethompson.me.uk"; classtype:trojan-activity; sid:100004058; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"davidmcguinness.info"; classtype:trojan-activity; sid:100004059; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dayspringdaisies.com"; classtype:trojan-activity; sid:100004060; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dd.qiyuea.cn"; classtype:trojan-activity; sid:100004061; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"de.gsearch.com.de"; classtype:trojan-activity; sid:100004062; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"decifrar.com.br"; classtype:trojan-activity; sid:100004063; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"deigratia2.elin.co.za"; classtype:trojan-activity; sid:100004064; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dekovizyon.com"; classtype:trojan-activity; sid:100004065; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"demo-cliente.mindcreative.com.br"; classtype:trojan-activity; sid:100004066; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"demo6.hiites.com"; classtype:trojan-activity; sid:100004067; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dent-estet.com"; classtype:trojan-activity; sid:100004068; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dental.xiaoxiao.media"; classtype:trojan-activity; sid:100004069; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dentalalliance.se"; classtype:trojan-activity; sid:100004070; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"designerliving.co.za"; classtype:trojan-activity; sid:100004071; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"desiringhands.com"; classtype:trojan-activity; sid:100004072; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"despertaresi.com.br"; classtype:trojan-activity; sid:100004073; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"destinymc.co.za"; classtype:trojan-activity; sid:100004074; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"detorre.es"; classtype:trojan-activity; sid:100004075; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dev-interestingtech.pantheonsite.io"; classtype:trojan-activity; sid:100004076; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dev.sebpo.net"; classtype:trojan-activity; sid:100004077; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dfcf.91756.cn"; classtype:trojan-activity; sid:100004078; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dfsfcsfcdsfsdvcfsvcscv.com"; classtype:trojan-activity; sid:100004079; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"diamantenegro.mi-fs.com"; classtype:trojan-activity; sid:100004080; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dienmayminhhung.com"; classtype:trojan-activity; sid:100004081; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"digilib.dianhusada.ac.id"; classtype:trojan-activity; sid:100004082; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"djking.f3322.net"; classtype:trojan-activity; sid:100004083; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.1003b.56a.com"; classtype:trojan-activity; sid:100004084; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.198424.com"; classtype:trojan-activity; sid:100004085; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.installcdn-aws.com"; classtype:trojan-activity; sid:100004086; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.packetstormsecurity.net"; classtype:trojan-activity; sid:100004087; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.rina-roleplay.com"; classtype:trojan-activity; sid:100004088; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dl.zkytech.com"; classtype:trojan-activity; sid:100004089; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dns.cyberium.cc"; classtype:trojan-activity; sid:100004090; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dockerupdate.anondns.net"; classtype:trojan-activity; sid:100004091; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"docman.orientalservices.in"; classtype:trojan-activity; sid:100004092; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dodsonimaging.com"; classtype:trojan-activity; sid:100004093; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dokan.blueberrytec.com"; classtype:trojan-activity; sid:100004094; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dom-chel74.ru"; classtype:trojan-activity; sid:100004095; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dom.daf.free.fr"; classtype:trojan-activity; sid:100004096; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"doncedyhall.com"; classtype:trojan-activity; sid:100004097; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"donghobinhminh.com"; classtype:trojan-activity; sid:100004098; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dongphuctop.com"; classtype:trojan-activity; sid:100004099; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dosame.com"; classtype:trojan-activity; sid:100004100; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dosman.pl"; classtype:trojan-activity; sid:100004101; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dovberger.com"; classtype:trojan-activity; sid:100004102; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.flash-plays.com"; classtype:trojan-activity; sid:100004103; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.pcclear.com"; classtype:trojan-activity; sid:100004104; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.posti-fi-fsa.top"; classtype:trojan-activity; sid:100004105; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.posti-fi-fwa.top"; classtype:trojan-activity; sid:100004106; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.posti-fi-ij.top"; classtype:trojan-activity; sid:100004107; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.posti-fi-in.top"; classtype:trojan-activity; sid:100004108; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.posti-fi-iz.top"; classtype:trojan-activity; sid:100004109; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.udashi.com"; classtype:trojan-activity; sid:100004110; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down.webbora.com"; classtype:trojan-activity; sid:100004111; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"down1.arpun.com"; classtype:trojan-activity; sid:100004112; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.caihong.com"; classtype:trojan-activity; sid:100004113; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.doumaibiji.cn"; classtype:trojan-activity; sid:100004114; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.exrnybuf.cn"; classtype:trojan-activity; sid:100004115; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.kaobeitu.com"; classtype:trojan-activity; sid:100004116; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.pdf00.cn"; classtype:trojan-activity; sid:100004117; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.rising.com.cn"; classtype:trojan-activity; sid:100004118; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.skycn.com"; classtype:trojan-activity; sid:100004119; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"download.zjsyawqj.cn"; classtype:trojan-activity; sid:100004120; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"downloads.jxtsteel.cn"; classtype:trojan-activity; sid:100004121; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dragonsknot.com"; classtype:trojan-activity; sid:100004122; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drbaby.com.sa"; classtype:trojan-activity; sid:100004123; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drohnen.ensenanzainteligente.com"; classtype:trojan-activity; sid:100004124; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drools-moved.46999.n3.nabble.com"; classtype:trojan-activity; sid:100004125; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"drsha.innovativesolutions.mobi"; classtype:trojan-activity; sid:100004126; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dsenterprize.co.za"; classtype:trojan-activity; sid:100004127; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dsspainting.com"; classtype:trojan-activity; sid:100004128; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"du-wizards.com"; classtype:trojan-activity; sid:100004129; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"duque.guantanameratravel.com"; classtype:trojan-activity; sid:100004130; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dutapp.wisolve.co.za"; classtype:trojan-activity; sid:100004131; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"duvalcharter.dekitout.com"; classtype:trojan-activity; sid:100004132; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dx.qqyewu.com"; classtype:trojan-activity; sid:100004133; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"dzinestudio87.co.uk"; classtype:trojan-activity; sid:100004134; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"e-commerce.saleensuporte.com.br"; classtype:trojan-activity; sid:100004135; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"e.sldov.ru"; classtype:trojan-activity; sid:100004136; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ebruyatkin.com"; classtype:trojan-activity; sid:100004137; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"econews.treegle.org"; classtype:trojan-activity; sid:100004138; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"efficientegroup.com"; classtype:trojan-activity; sid:100004139; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"elliot.newreadermedia.net"; classtype:trojan-activity; sid:100004140; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"en.baoend.com"; classtype:trojan-activity; sid:100004141; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"enc-tech.com"; classtype:trojan-activity; sid:100004142; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"endurotanzania.co.tz"; classtype:trojan-activity; sid:100004143; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ennovate.elin.co.za"; classtype:trojan-activity; sid:100004144; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"enriquecendocomconsorcio.com.br"; classtype:trojan-activity; sid:100004145; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"envios.petpienso.cl"; classtype:trojan-activity; sid:100004146; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"equimination.ee"; classtype:trojan-activity; sid:100004147; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"escola.probommar.org.br"; classtype:trojan-activity; sid:100004148; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"esnconsultants.com"; classtype:trojan-activity; sid:100004149; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"essentia.org.br"; classtype:trojan-activity; sid:100004150; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"eubanks7.com"; classtype:trojan-activity; sid:100004151; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"evidencemarketing.ca"; classtype:trojan-activity; sid:100004152; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"exilum.com"; classtype:trojan-activity; sid:100004153; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"exitoalfaomega.co"; classtype:trojan-activity; sid:100004154; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"extrovertoffers.com"; classtype:trojan-activity; sid:100004155; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"f1sol.com"; classtype:trojan-activity; sid:100004156; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"familydentist.site"; classtype:trojan-activity; sid:100004157; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"farmaciasdrogaminas.com.br"; classtype:trojan-activity; sid:100004158; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"faveraprojects.com"; classtype:trojan-activity; sid:100004159; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fc.co.mz"; classtype:trojan-activity; sid:100004160; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"felicienne.nl"; classtype:trojan-activity; sid:100004161; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fi.bonitastores.com"; classtype:trojan-activity; sid:100004162; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"files.martellexpress.us"; classtype:trojan-activity; sid:100004163; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"files6.uludagbilisim.com"; classtype:trojan-activity; sid:100004164; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"final.makkahkmcc.com"; classtype:trojan-activity; sid:100004165; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fineartgallerym.com"; classtype:trojan-activity; sid:100004166; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fkd.derpcity.ru"; classtype:trojan-activity; sid:100004167; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"flintspin.com"; classtype:trojan-activity; sid:100004168; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"flyingbuddhadesign.com"; classtype:trojan-activity; sid:100004169; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fmjplastering.co.uk"; classtype:trojan-activity; sid:100004170; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fms.buladde.or.ug"; classtype:trojan-activity; sid:100004171; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"foothills.com.br"; classtype:trojan-activity; sid:100004172; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"footweardirect.elin.co.za"; classtype:trojan-activity; sid:100004173; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"forum.mdb.nu"; classtype:trojan-activity; sid:100004174; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fotoobjetivo.com"; classtype:trojan-activity; sid:100004175; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"foundationrepairhoustontx.net"; classtype:trojan-activity; sid:100004176; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"foxeps.com.br"; classtype:trojan-activity; sid:100004177; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"freecnetdownload.com"; classtype:trojan-activity; sid:100004178; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"freisites.com.br"; classtype:trojan-activity; sid:100004179; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ftp.n3twork30cm.ml"; classtype:trojan-activity; sid:100004180; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fullelectronica.com.ar"; classtype:trojan-activity; sid:100004181; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"funletters.net"; classtype:trojan-activity; sid:100004182; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"fusionfiresolutions.com"; classtype:trojan-activity; sid:100004183; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"futuregraphics.com.ar"; classtype:trojan-activity; sid:100004184; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gametwogame.com"; classtype:trojan-activity; sid:100004185; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"garayvidalabogados.com"; classtype:trojan-activity; sid:100004186; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"garciadogshow.com"; classtype:trojan-activity; sid:100004187; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"garenanow.myvnc.com"; classtype:trojan-activity; sid:100004188; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"garenanow4.myvnc.com"; classtype:trojan-activity; sid:100004189; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gbbulls.co.uk"; classtype:trojan-activity; sid:100004190; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gcpc.co.id.chronoscurtain.com"; classtype:trojan-activity; sid:100004191; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"generaldeviales.com"; classtype:trojan-activity; sid:100004192; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gfmodd1.webselffiles01.com"; classtype:trojan-activity; sid:100004193; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gfold1.webselffiles01.com"; classtype:trojan-activity; sid:100004194; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ghettohub.co.za"; classtype:trojan-activity; sid:100004195; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ghislain.dartois.pagesperso-orange.fr"; classtype:trojan-activity; sid:100004196; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"giadungg7.com"; classtype:trojan-activity; sid:100004197; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"giddos.ga"; classtype:trojan-activity; sid:100004198; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gilliem.com"; classtype:trojan-activity; sid:100004199; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"girotexuniformes.com"; classtype:trojan-activity; sid:100004200; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"giteletropical.com"; classtype:trojan-activity; sid:100004201; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"globaltask.ar"; classtype:trojan-activity; sid:100004202; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"glowinmedia.co.ke"; classtype:trojan-activity; sid:100004203; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gmtransformationacademy.com"; classtype:trojan-activity; sid:100004204; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gmvadmission.org"; classtype:trojan-activity; sid:100004205; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gnimelf.net"; classtype:trojan-activity; sid:100004206; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gnscrew.ro"; classtype:trojan-activity; sid:100004207; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gold.investforex.id"; classtype:trojan-activity; sid:100004208; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldcake.co.id"; classtype:trojan-activity; sid:100004209; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldcoastoffice365.com"; classtype:trojan-activity; sid:100004210; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldcoastoffice365.com.au"; classtype:trojan-activity; sid:100004211; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldcupmortgage.com"; classtype:trojan-activity; sid:100004212; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"golden-memories-funerals.yourpageserver.com"; classtype:trojan-activity; sid:100004213; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"goldmen.in"; classtype:trojan-activity; sid:100004214; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gorecycle.fahadjutt.com"; classtype:trojan-activity; sid:100004215; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gracejukes.com"; classtype:trojan-activity; sid:100004216; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"grupoinmare.com"; classtype:trojan-activity; sid:100004217; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gruposelt.000webhostapp.com"; classtype:trojan-activity; sid:100004218; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gs.monerorx.com"; classtype:trojan-activity; sid:100004219; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"guide-to-cell-phones.com"; classtype:trojan-activity; sid:100004220; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gulfac-house.com"; classtype:trojan-activity; sid:100004221; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"gvpcdpgc.edu.in"; classtype:trojan-activity; sid:100004222; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"habbotips.free.fr"; classtype:trojan-activity; sid:100004223; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hagebakken.no"; classtype:trojan-activity; sid:100004224; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"harrisauto.no"; classtype:trojan-activity; sid:100004225; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"harshraval.in"; classtype:trojan-activity; sid:100004226; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hd11315.com"; classtype:trojan-activity; sid:100004227; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hdkamera2003.hu"; classtype:trojan-activity; sid:100004228; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hdrest.fastlinktz.com"; classtype:trojan-activity; sid:100004229; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hds.sz4h.com"; classtype:trojan-activity; sid:100004230; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"healthy20.net"; classtype:trojan-activity; sid:100004231; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hechiceriadeamormaestrabelen.com.hechiceriadeamormaestrabelen.com"; classtype:trojan-activity; sid:100004232; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hellogorgeous.com.au"; classtype:trojan-activity; sid:100004233; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"help.hizuko.com"; classtype:trojan-activity; sid:100004234; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"herchinfitout.com.sg"; classtype:trojan-activity; sid:100004235; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hhaward.org"; classtype:trojan-activity; sid:100004236; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"highlandroadcoc.com"; classtype:trojan-activity; sid:100004237; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"highlandslasvegas.atakdev.com"; classtype:trojan-activity; sid:100004238; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hindi.factsriver.com"; classtype:trojan-activity; sid:100004239; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hiptool.net"; classtype:trojan-activity; sid:100004240; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hitpe.com"; classtype:trojan-activity; sid:100004241; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hitstation.nl"; classtype:trojan-activity; sid:100004242; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hmpmall.co.kr"; classtype:trojan-activity; sid:100004243; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hoagietesting10.com"; classtype:trojan-activity; sid:100004244; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hoayeuthuong-my.sharepoint.com"; classtype:trojan-activity; sid:100004245; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"holmesprpmgmt.com"; classtype:trojan-activity; sid:100004246; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"homefindersolutions.com"; classtype:trojan-activity; sid:100004247; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hongluosi.com"; classtype:trojan-activity; sid:100004248; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hookedupboatclub.com"; classtype:trojan-activity; sid:100004249; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hostelkielce.com"; classtype:trojan-activity; sid:100004250; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hostzaa.com"; classtype:trojan-activity; sid:100004251; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"houstonshutters.site"; classtype:trojan-activity; sid:100004252; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hr2019.vrcom7.com"; classtype:trojan-activity; sid:100004253; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hseda.com"; classtype:trojan-activity; sid:100004254; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hsmwebapp.com"; classtype:trojan-activity; sid:100004255; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"htownbars.com"; classtype:trojan-activity; sid:100004256; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hubtech.co.za"; classtype:trojan-activity; sid:100004257; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"hunggiang.vn"; classtype:trojan-activity; sid:100004258; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"husamiyahschool.com"; classtype:trojan-activity; sid:100004259; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iam313.com"; classtype:trojan-activity; sid:100004260; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"icon.shatangmu.cn"; classtype:trojan-activity; sid:100004261; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idea-secure-login.com"; classtype:trojan-activity; sid:100004262; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idilsoft.com"; classtype:trojan-activity; sid:100004263; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idj.no"; classtype:trojan-activity; sid:100004264; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"idvindia.com"; classtype:trojan-activity; sid:100004265; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iesanjosemonitos.edu.co"; classtype:trojan-activity; sid:100004266; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ikexpert.com"; classtype:trojan-activity; sid:100004267; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ilrafrica.com"; classtype:trojan-activity; sid:100004268; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"images.jermiau.com"; classtype:trojan-activity; sid:100004269; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"imbueautoworx.co.za"; classtype:trojan-activity; sid:100004270; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"imperiumtherapy.co.za"; classtype:trojan-activity; sid:100004271; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"in-tune2016.com"; classtype:trojan-activity; sid:100004272; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"incodimsa.com"; classtype:trojan-activity; sid:100004273; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"incrediblepixels.com"; classtype:trojan-activity; sid:100004274; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"incredicole.com"; classtype:trojan-activity; sid:100004275; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"industriasyuli.com"; classtype:trojan-activity; sid:100004276; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"infair.vn"; classtype:trojan-activity; sid:100004277; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"infovator.com"; classtype:trojan-activity; sid:100004278; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"innatosbrand.com"; classtype:trojan-activity; sid:100004279; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"inodesthetotaldesigners.com"; classtype:trojan-activity; sid:100004280; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"inovations.searchkero.com"; classtype:trojan-activity; sid:100004281; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"inrajahmundry.co.in"; classtype:trojan-activity; sid:100004282; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"insignificantfinecore.testmail4.repl.co"; classtype:trojan-activity; sid:100004283; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"instantindialoan.com"; classtype:trojan-activity; sid:100004284; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"instvisionmexico.edu.mx"; classtype:trojan-activity; sid:100004285; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"intellectsmart.in"; classtype:trojan-activity; sid:100004286; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"intersel-idf.org"; classtype:trojan-activity; sid:100004287; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"intuitiveideas.com.my"; classtype:trojan-activity; sid:100004288; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"inversiones.arrayanfinanciero.cl"; classtype:trojan-activity; sid:100004289; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"invest.xpcorporative.com.br"; classtype:trojan-activity; sid:100004290; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ipmes.ma"; classtype:trojan-activity; sid:100004291; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iremart.es"; classtype:trojan-activity; sid:100004292; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iris101.co.uk"; classtype:trojan-activity; sid:100004293; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iscamenabe.com"; classtype:trojan-activity; sid:100004294; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ismf.com.ng"; classtype:trojan-activity; sid:100004295; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"iso-dubai.net"; classtype:trojan-activity; sid:100004296; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"israrulhaq.me"; classtype:trojan-activity; sid:100004297; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"isrorg.com"; classtype:trojan-activity; sid:100004298; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"issmbour.falllo.com"; classtype:trojan-activity; sid:100004299; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"isso.ps"; classtype:trojan-activity; sid:100004300; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"it123.ru"; classtype:trojan-activity; sid:100004301; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"itc-demo.softgig.co.ke"; classtype:trojan-activity; sid:100004302; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"itconsultus.com.co"; classtype:trojan-activity; sid:100004303; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jamesjorgensen.newreadermedia.net"; classtype:trojan-activity; sid:100004304; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jamiekaylive.com"; classtype:trojan-activity; sid:100004305; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jamshed.pk"; classtype:trojan-activity; sid:100004306; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jansen-heesch.nl"; classtype:trojan-activity; sid:100004307; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jathra.co.uk"; classtype:trojan-activity; sid:100004308; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jay.diamondrelationscrm.us"; classtype:trojan-activity; sid:100004309; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jebs.net.au"; classtype:trojan-activity; sid:100004310; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jeffdahlke.com"; classtype:trojan-activity; sid:100004311; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jhayesconsulting.com"; classtype:trojan-activity; sid:100004312; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jiaoyuzixun.cn"; classtype:trojan-activity; sid:100004313; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jing-da.com.tw"; classtype:trojan-activity; sid:100004314; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jktnet.xyz"; classtype:trojan-activity; sid:100004315; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jmtc.91756.cn"; classtype:trojan-activity; sid:100004316; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jnanbharati.com"; classtype:trojan-activity; sid:100004317; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jobs.thebeessolution.com"; classtype:trojan-activity; sid:100004318; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"joelbonissilver.com"; classtype:trojan-activity; sid:100004319; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"join.cl8movement.co.za"; classtype:trojan-activity; sid:100004320; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"josegene.com"; classtype:trojan-activity; sid:100004321; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"josuarochoa.com"; classtype:trojan-activity; sid:100004322; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jpwoodfordco.com"; classtype:trojan-activity; sid:100004323; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jumpmanualjacobhiller.com"; classtype:trojan-activity; sid:100004324; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jupiter.toxsl.in"; classtype:trojan-activity; sid:100004325; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"jurgensen.newreadermedia.net"; classtype:trojan-activity; sid:100004326; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"justinscott.com.au"; classtype:trojan-activity; sid:100004327; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kaizenjanitorial.com"; classtype:trojan-activity; sid:100004328; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kalawatihomes.com"; classtype:trojan-activity; sid:100004329; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kalpataru-elitus-mulund.thakkers.in"; classtype:trojan-activity; sid:100004330; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"karer.by"; classtype:trojan-activity; sid:100004331; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"katanvetov.co.il"; classtype:trojan-activity; sid:100004332; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kbdom.com"; classtype:trojan-activity; sid:100004333; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kensingtondriving.com"; classtype:trojan-activity; sid:100004334; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kevinjewelry.com.co"; classtype:trojan-activity; sid:100004335; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"keywatch.yourpageserver.com"; classtype:trojan-activity; sid:100004336; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kingssa.co.za"; classtype:trojan-activity; sid:100004337; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kjcpromo.com"; classtype:trojan-activity; sid:100004338; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kleinendeli.co.za"; classtype:trojan-activity; sid:100004339; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"korrectconceptservices.com"; classtype:trojan-activity; sid:100004340; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ktb.sch.id"; classtype:trojan-activity; sid:100004341; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kubatoglubaklava.com.tr"; classtype:trojan-activity; sid:100004342; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kumaralok.in"; classtype:trojan-activity; sid:100004343; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kwanfromhongkong.com"; classtype:trojan-activity; sid:100004344; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"kz.sldov.ru"; classtype:trojan-activity; sid:100004345; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lab18.it"; classtype:trojan-activity; sid:100004346; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lacasadelosalebrijes.com"; classtype:trojan-activity; sid:100004347; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ladylabonde.com"; classtype:trojan-activity; sid:100004348; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lameguard.ru"; classtype:trojan-activity; sid:100004349; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"landing.yetiapp.ec"; classtype:trojan-activity; sid:100004350; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"laodongnhat.vn"; classtype:trojan-activity; sid:100004351; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"laravel.pointersoftwares.com.br"; classtype:trojan-activity; sid:100004352; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lasermobilesounds.co.uk"; classtype:trojan-activity; sid:100004353; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lauratomismith.com"; classtype:trojan-activity; sid:100004354; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lautarosanmiguel.com"; classtype:trojan-activity; sid:100004355; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lawforall.edu.lk"; classtype:trojan-activity; sid:100004356; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lceventos.net"; classtype:trojan-activity; sid:100004357; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ld.mediaget.com"; classtype:trojan-activity; sid:100004358; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ldgcorp.com"; classtype:trojan-activity; sid:100004359; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"learning.real-academy.net"; classtype:trojan-activity; sid:100004360; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"leasiacherise.com"; classtype:trojan-activity; sid:100004361; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"leczkregoslup.acelero.pl"; classtype:trojan-activity; sid:100004362; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"legend.nu"; classtype:trojan-activity; sid:100004363; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"leluibuffet.com.br"; classtype:trojan-activity; sid:100004364; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lestesteux.ca"; classtype:trojan-activity; sid:100004365; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"libantravel.pl"; classtype:trojan-activity; sid:100004366; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"library.arihantmbainstitute.ac.in"; classtype:trojan-activity; sid:100004367; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"library.uib.ac.id"; classtype:trojan-activity; sid:100004368; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lickmylash.com"; classtype:trojan-activity; sid:100004369; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lidoraggiodisole.it"; classtype:trojan-activity; sid:100004370; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lifebeam.elin.co.za"; classtype:trojan-activity; sid:100004371; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lindnerelektroanlagen.de"; classtype:trojan-activity; sid:100004372; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"linkintec.cn"; classtype:trojan-activity; sid:100004373; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"litroxlitro.com"; classtype:trojan-activity; sid:100004374; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"livetrack.in"; classtype:trojan-activity; sid:100004375; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lloydsindian.co.uk"; classtype:trojan-activity; sid:100004376; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lm.stagingarea.co.za"; classtype:trojan-activity; sid:100004377; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lmaancha.co.il"; classtype:trojan-activity; sid:100004378; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lms.cstdevs.com"; classtype:trojan-activity; sid:100004379; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lms.login2.in"; classtype:trojan-activity; sid:100004380; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lmvirtualbookkeeping.com"; classtype:trojan-activity; sid:100004381; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lnt-rejuve-360.thakkers.in"; classtype:trojan-activity; sid:100004382; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"location-voitures.ma"; classtype:trojan-activity; sid:100004383; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"login.trezor.com.stockfootagesindia.com"; classtype:trojan-activity; sid:100004384; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"logotypfabriken.se"; classtype:trojan-activity; sid:100004385; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lotix.de"; classtype:trojan-activity; sid:100004386; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lotusanddragonfly.com"; classtype:trojan-activity; sid:100004387; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lp.definerisco.com"; classtype:trojan-activity; sid:100004388; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lp.difusodesign.com"; classtype:trojan-activity; sid:100004389; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lp.juancamilogarciareyes.com"; classtype:trojan-activity; sid:100004390; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"lp.tecnimasdecolombia.com.co"; classtype:trojan-activity; sid:100004391; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ltc.typoten.com"; classtype:trojan-activity; sid:100004392; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"luckybrownie.com"; classtype:trojan-activity; sid:100004393; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"luminouspneuma.com"; classtype:trojan-activity; sid:100004394; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"luxomodels.com"; classtype:trojan-activity; sid:100004395; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"m-technics.kz"; classtype:trojan-activity; sid:100004396; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"m.estudiomoros.com.ar"; classtype:trojan-activity; sid:100004397; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"madicon.co.za"; classtype:trojan-activity; sid:100004398; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"magianegramagiablancayamarres.com"; classtype:trojan-activity; sid:100004399; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mail.bs-eiendomme.co.za"; classtype:trojan-activity; sid:100004400; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mail.golimoapp.com"; classtype:trojan-activity; sid:100004401; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mail.jeffsono.org"; classtype:trojan-activity; sid:100004402; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"maksi.feb.unib.ac.id"; classtype:trojan-activity; sid:100004403; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"malaya.tv"; classtype:trojan-activity; sid:100004404; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"malwarecoding.github.io"; classtype:trojan-activity; sid:100004405; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"managed.oss-cn-beijing.aliyuncs.com"; classtype:trojan-activity; sid:100004406; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"managemysalon.in"; classtype:trojan-activity; sid:100004407; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"manantialesdelnorte.uy"; classtype:trojan-activity; sid:100004408; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marcapinyo.ru"; classtype:trojan-activity; sid:100004409; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mario-sunjic.com"; classtype:trojan-activity; sid:100004410; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mariobrown.net"; classtype:trojan-activity; sid:100004411; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mariotessarollo.com"; classtype:trojan-activity; sid:100004412; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marketinfosales.com"; classtype:trojan-activity; sid:100004413; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marketing.enexusgroup.com.au"; classtype:trojan-activity; sid:100004414; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"marksidfgs.ug"; classtype:trojan-activity; sid:100004415; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"masjidhabeebiyarazviya.mysunni.com"; classtype:trojan-activity; sid:100004416; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"materialescantu.com"; classtype:trojan-activity; sid:100004417; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"matruchhaya.co.in"; classtype:trojan-activity; sid:100004418; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mattysplayground.com"; classtype:trojan-activity; sid:100004419; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"maxtox.com.pk"; classtype:trojan-activity; sid:100004420; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mbgrm.com"; classtype:trojan-activity; sid:100004421; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mbsolutions.ge"; classtype:trojan-activity; sid:100004422; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mdasa.elin.co.za"; classtype:trojan-activity; sid:100004423; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"medevlb.org"; classtype:trojan-activity; sid:100004424; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"media-server.skyinternet.com.pk"; classtype:trojan-activity; sid:100004425; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mediamaster.co.za"; classtype:trojan-activity; sid:100004426; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"medianews.ge"; classtype:trojan-activity; sid:100004427; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"medistaffconsulting.com"; classtype:trojan-activity; sid:100004428; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"meditreat.itwebservice.in"; classtype:trojan-activity; sid:100004429; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"meeweb.com"; classtype:trojan-activity; sid:100004430; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"megamart.afnan-amc.com"; classtype:trojan-activity; sid:100004431; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"merbay.ru"; classtype:trojan-activity; sid:100004432; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"merkathink.com"; classtype:trojan-activity; sid:100004433; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mertlog.com"; classtype:trojan-activity; sid:100004434; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"metalin-cr.com"; classtype:trojan-activity; sid:100004435; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mettaanand.org"; classtype:trojan-activity; sid:100004436; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"meuoculosnanet.com.br"; classtype:trojan-activity; sid:100004437; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mfevr.com"; classtype:trojan-activity; sid:100004438; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mhkdhotbot.myvnc.com"; classtype:trojan-activity; sid:100004439; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mhkdhotbot80.myvnc.com"; classtype:trojan-activity; sid:100004440; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"micalle.com.au"; classtype:trojan-activity; sid:100004441; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"michaelphilip.com"; classtype:trojan-activity; sid:100004442; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"michimal2.000webhostapp.com"; classtype:trojan-activity; sid:100004443; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"microblading.mirliandias.com.br"; classtype:trojan-activity; sid:100004444; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"microcomm-group.com"; classtype:trojan-activity; sid:100004445; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"midlandtexasconstruction.com"; classtype:trojan-activity; sid:100004446; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mindfulbuildingandliving.com"; classtype:trojan-activity; sid:100004447; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mingguanwms.com"; classtype:trojan-activity; sid:100004448; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"minuevavida.org"; classtype:trojan-activity; sid:100004449; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mis.nbcc.ac.th"; classtype:trojan-activity; sid:100004450; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"misterson.com"; classtype:trojan-activity; sid:100004451; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mixr.at"; classtype:trojan-activity; sid:100004452; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mkontakt.az"; classtype:trojan-activity; sid:100004453; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mktf.mx"; classtype:trojan-activity; sid:100004454; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mmogollon.com.mx"; classtype:trojan-activity; sid:100004455; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mncarteam.com"; classtype:trojan-activity; sid:100004456; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mobile.illumetechnology.com"; classtype:trojan-activity; sid:100004457; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"modelhouseturkey.com"; classtype:trojan-activity; sid:100004458; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"modernmanna.org"; classtype:trojan-activity; sid:100004459; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"monetization.business"; classtype:trojan-activity; sid:100004460; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"moninediy.com"; classtype:trojan-activity; sid:100004461; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mopai.sg"; classtype:trojan-activity; sid:100004462; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"motorcomunicacion.com"; classtype:trojan-activity; sid:100004463; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"msacontabil.com.br"; classtype:trojan-activity; sid:100004464; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mtspsmjeli.sch.id"; classtype:trojan-activity; sid:100004465; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"muzimbiti.xigubo.co.mz"; classtype:trojan-activity; sid:100004466; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mxpiqw.am.files.1drv.com"; classtype:trojan-activity; sid:100004467; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mydatebook.in"; classtype:trojan-activity; sid:100004468; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mymlql.com"; classtype:trojan-activity; sid:100004469; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"myritz.vettickal.com"; classtype:trojan-activity; sid:100004470; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"myscape.in"; classtype:trojan-activity; sid:100004471; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"mysura.it"; classtype:trojan-activity; sid:100004472; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"namnyak.co.ke"; classtype:trojan-activity; sid:100004473; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nap.mgsservers.com"; classtype:trojan-activity; sid:100004474; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"navayurveda.in"; classtype:trojan-activity; sid:100004475; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nec-i.com"; classtype:trojan-activity; sid:100004476; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nelitrianggraeni.000webhostapp.com"; classtype:trojan-activity; sid:100004477; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nerve.untergrund.net"; classtype:trojan-activity; sid:100004478; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nettube.com.br"; classtype:trojan-activity; sid:100004479; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"networkwheels.co.za"; classtype:trojan-activity; sid:100004480; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"neuroenergy.fahadjutt.com"; classtype:trojan-activity; sid:100004481; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"neuromedic.com.br"; classtype:trojan-activity; sid:100004482; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"neverseenshop.com.mx"; classtype:trojan-activity; sid:100004483; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newinfinitysynergy.com"; classtype:trojan-activity; sid:100004484; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"news.dbstrony.pl"; classtype:trojan-activity; sid:100004485; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newtreedesign.co.uk"; classtype:trojan-activity; sid:100004486; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newtrendeg.com"; classtype:trojan-activity; sid:100004487; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newvisionopticallab.com"; classtype:trojan-activity; sid:100004488; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"newxing.com"; classtype:trojan-activity; sid:100004489; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nextdigitalday.ru"; classtype:trojan-activity; sid:100004490; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ngdaycare.co.za"; classtype:trojan-activity; sid:100004491; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nguyenkekhuyen.com"; classtype:trojan-activity; sid:100004492; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nhorangtreem.com"; classtype:trojan-activity; sid:100004493; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nicolas.ug"; classtype:trojan-activity; sid:100004494; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nidhi.iexist.in"; classtype:trojan-activity; sid:100004495; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nikanpolimer.ir"; classtype:trojan-activity; sid:100004496; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nilehouse.co.ug"; classtype:trojan-activity; sid:100004497; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nilinkeji.com"; classtype:trojan-activity; sid:100004498; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"njtiledesigncenter.com"; classtype:trojan-activity; sid:100004499; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nobius.org"; classtype:trojan-activity; sid:100004500; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nocalnoodle.elin.co.za"; classtype:trojan-activity; sid:100004501; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nomadicbees.com"; classtype:trojan-activity; sid:100004502; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nonnarina.ax"; classtype:trojan-activity; sid:100004503; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"notamuzikaletleri.com"; classtype:trojan-activity; sid:100004504; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"notif1.priruz.co.in"; classtype:trojan-activity; sid:100004505; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ns1.the-widyantos.com"; classtype:trojan-activity; sid:100004506; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nsb.org.uk"; classtype:trojan-activity; sid:100004507; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nsheldon.co.uk"; classtype:trojan-activity; sid:100004508; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nurmarkaz.org"; classtype:trojan-activity; sid:100004509; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nuthuassociates.com"; classtype:trojan-activity; sid:100004510; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nuwagi.com"; classtype:trojan-activity; sid:100004511; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"nyeh2o.com.au"; classtype:trojan-activity; sid:100004512; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oakleyandfriends.co.uk"; classtype:trojan-activity; sid:100004513; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"obseques-conseils.com"; classtype:trojan-activity; sid:100004514; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ocean.tecnasulstore.com.br"; classtype:trojan-activity; sid:100004515; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ohe.ie"; classtype:trojan-activity; sid:100004516; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ohsewgorgeous.co.uk"; classtype:trojan-activity; sid:100004517; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oknoplastik.sk"; classtype:trojan-activity; sid:100004518; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oleholeh.memangbeda.website"; classtype:trojan-activity; sid:100004519; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"olirecords.mixture.ltd"; classtype:trojan-activity; sid:100004520; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"olooom.com"; classtype:trojan-activity; sid:100004521; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omaia.org"; classtype:trojan-activity; sid:100004522; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omaromatic.com"; classtype:trojan-activity; sid:100004523; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omega.az"; classtype:trojan-activity; sid:100004524; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oms.pappai.com"; classtype:trojan-activity; sid:100004525; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"omscoc.pappai.com"; classtype:trojan-activity; sid:100004526; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"onedigitalcard.granvizionnecorp.com"; classtype:trojan-activity; sid:100004527; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"onedrive.listifyapp.co"; classtype:trojan-activity; sid:100004528; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"online.creedglobal.in"; classtype:trojan-activity; sid:100004529; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"onlinestatis.bar"; classtype:trojan-activity; sid:100004530; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ont.proman.id"; classtype:trojan-activity; sid:100004531; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"open.warehousesaas.co.uk"; classtype:trojan-activity; sid:100004532; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"opolis.io"; classtype:trojan-activity; sid:100004533; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"optimus.com.sg"; classtype:trojan-activity; sid:100004534; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"optitechsa.co.za"; classtype:trojan-activity; sid:100004535; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"order.bizpeed.com"; classtype:trojan-activity; sid:100004536; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"orientgatewayltd.com"; classtype:trojan-activity; sid:100004537; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"orion445.com"; classtype:trojan-activity; sid:100004538; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"oserve.pk"; classtype:trojan-activity; sid:100004539; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"otolithenrichment.fahadjutt.com"; classtype:trojan-activity; sid:100004540; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ottimade.com"; classtype:trojan-activity; sid:100004541; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ourteam.searchkero.com"; classtype:trojan-activity; sid:100004542; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ozemag.com"; classtype:trojan-activity; sid:100004543; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"p1.lingpao8.com"; classtype:trojan-activity; sid:100004544; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"p3.zbjimg.com"; classtype:trojan-activity; sid:100004545; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"p6.zbjimg.com"; classtype:trojan-activity; sid:100004546; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pablobrothel.com.ar"; classtype:trojan-activity; sid:100004547; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pacificgroup.ws"; classtype:trojan-activity; sid:100004548; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pacwebdesigns.com"; classtype:trojan-activity; sid:100004549; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pagos.krayem.com.mx"; classtype:trojan-activity; sid:100004550; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"palochusvet.szm.com"; classtype:trojan-activity; sid:100004551; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"parallel.rockvideos.at"; classtype:trojan-activity; sid:100004552; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"parejasfelices.mi-fs.com"; classtype:trojan-activity; sid:100004553; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"parkhussion.com"; classtype:trojan-activity; sid:100004554; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pastorpaulocosta.com"; classtype:trojan-activity; sid:100004555; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"patch2.51lg.com"; classtype:trojan-activity; sid:100004556; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"patch2.99ddd.com"; classtype:trojan-activity; sid:100004557; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"patch3.99ddd.com"; classtype:trojan-activity; sid:100004558; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"paths.elin.co.za"; classtype:trojan-activity; sid:100004559; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"paulmercier.biz"; classtype:trojan-activity; sid:100004560; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"payerrealty.com"; classtype:trojan-activity; sid:100004561; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"payments.atifsiddiqui.me"; classtype:trojan-activity; sid:100004562; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pcsoori.com"; classtype:trojan-activity; sid:100004563; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pd.oceaniarp.net"; classtype:trojan-activity; sid:100004564; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"perpus.onlineman7-jombang.sch.id"; classtype:trojan-activity; sid:100004565; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"perpustekim.untirta.ac.id"; classtype:trojan-activity; sid:100004566; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pestoclean.co.uk"; classtype:trojan-activity; sid:100004567; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"petercollie.com"; classtype:trojan-activity; sid:100004568; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ph4s.ru"; classtype:trojan-activity; sid:100004569; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"phenhuong.sanpham.online"; classtype:trojan-activity; sid:100004570; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"phittc.com"; classtype:trojan-activity; sid:100004571; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"photo360.kubooking.com"; classtype:trojan-activity; sid:100004572; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"photographytipsclub.com"; classtype:trojan-activity; sid:100004573; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pink99.com"; classtype:trojan-activity; sid:100004574; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pizzabarletta.com.br"; classtype:trojan-activity; sid:100004575; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"plasfan.ind.br"; classtype:trojan-activity; sid:100004576; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pmglance.startwriteup.com"; classtype:trojan-activity; sid:100004577; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pokojewewladyslawowie.pl"; classtype:trojan-activity; sid:100004578; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pole.com.vc"; classtype:trojan-activity; sid:100004579; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pool.phxdir.com"; classtype:trojan-activity; sid:100004580; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pooltablemoversdenver.net"; classtype:trojan-activity; sid:100004581; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"posmicrosystems.com"; classtype:trojan-activity; sid:100004582; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"poulman.panagiotopoulos-tours.gr"; classtype:trojan-activity; sid:100004583; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ppdb.smk-ciptaskill.sch.id"; classtype:trojan-activity; sid:100004584; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prestasicash.com.ar"; classtype:trojan-activity; sid:100004585; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prestigehomeautomation.net"; classtype:trojan-activity; sid:100004586; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prishaartcreations.com"; classtype:trojan-activity; sid:100004587; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"production.sparshims.com"; classtype:trojan-activity; sid:100004588; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"programaoperadoronline.com.br"; classtype:trojan-activity; sid:100004589; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"project.exquitec.com"; classtype:trojan-activity; sid:100004590; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"promolyko.com"; classtype:trojan-activity; sid:100004591; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"promotoradescomplica.com.br"; classtype:trojan-activity; sid:100004592; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"promoversdubai.com"; classtype:trojan-activity; sid:100004593; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"propertiq.elin.co.za"; classtype:trojan-activity; sid:100004594; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"propertiq2.elin.co.za"; classtype:trojan-activity; sid:100004595; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prosoc.nl"; classtype:trojan-activity; sid:100004596; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prostar.priruz.co.in"; classtype:trojan-activity; sid:100004597; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prosyarmakassar.com"; classtype:trojan-activity; sid:100004598; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"provence.elin.co.za"; classtype:trojan-activity; sid:100004599; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"prueba.danielluza.com"; classtype:trojan-activity; sid:100004600; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pujashoppe.in"; classtype:trojan-activity; sid:100004601; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"punchdialogues.com"; classtype:trojan-activity; sid:100004602; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"punjabdevelopersassociation.com.pk"; classtype:trojan-activity; sid:100004603; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"pvcprinting.co.uk"; classtype:trojan-activity; sid:100004604; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"qadir.tickfa.ir"; classtype:trojan-activity; sid:100004605; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"qatarglobalconsulting.com"; classtype:trojan-activity; sid:100004606; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"qmsled.com"; classtype:trojan-activity; sid:100004607; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"quartier-midi.be"; classtype:trojan-activity; sid:100004608; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"querocar.com"; classtype:trojan-activity; sid:100004609; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rachmat-assuhaimi.my.id"; classtype:trojan-activity; sid:100004610; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rainbowisp.info"; classtype:trojan-activity; sid:100004611; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"raodigitalmedia.com"; classtype:trojan-activity; sid:100004612; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rarlabarchiver.ac"; classtype:trojan-activity; sid:100004613; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rasadbar.ir"; classtype:trojan-activity; sid:100004614; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rashika.ascarvalho.co.za"; classtype:trojan-activity; sid:100004615; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ratemyfenancialadvisor.com"; classtype:trojan-activity; sid:100004616; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ravenproductionsltd.com"; classtype:trojan-activity; sid:100004617; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rc.ixiaoyang.cn"; classtype:trojan-activity; sid:100004618; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"readymmade.com"; classtype:trojan-activity; sid:100004619; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"redchillicrackers.com"; classtype:trojan-activity; sid:100004620; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"reifenquick.de"; classtype:trojan-activity; sid:100004621; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"relaxindulge.co.nz"; classtype:trojan-activity; sid:100004622; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"renehavis.com.ua"; classtype:trojan-activity; sid:100004623; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"repatriacioncolombia.com"; classtype:trojan-activity; sid:100004624; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"res.uf1.cn"; classtype:trojan-activity; sid:100004625; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"reseller.digimitra.in"; classtype:trojan-activity; sid:100004626; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"resuco.net"; classtype:trojan-activity; sid:100004627; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rezkabum.ru"; classtype:trojan-activity; sid:100004628; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rhema.com.sg"; classtype:trojan-activity; sid:100004629; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"richancyber.info"; classtype:trojan-activity; sid:100004630; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"richmondminerals.co.zm"; classtype:trojan-activity; sid:100004631; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rinaefoundation.org.za"; classtype:trojan-activity; sid:100004632; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rinkaisystem-ht.com"; classtype:trojan-activity; sid:100004633; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"riverfox.co.za"; classtype:trojan-activity; sid:100004634; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rkcable.co.in"; classtype:trojan-activity; sid:100004635; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rkverify.securestudies.com"; classtype:trojan-activity; sid:100004636; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"roadfurylifts.com"; classtype:trojan-activity; sid:100004637; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"robertmcardle.com"; classtype:trojan-activity; sid:100004638; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"robertsinclair.net"; classtype:trojan-activity; sid:100004639; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"robinhood-sports.com"; classtype:trojan-activity; sid:100004640; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"romanianpoints.com"; classtype:trojan-activity; sid:100004641; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ronnietucker.co.uk"; classtype:trojan-activity; sid:100004642; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"roomsvc.servegate.kr"; classtype:trojan-activity; sid:100004643; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"roshan.academy"; classtype:trojan-activity; sid:100004644; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"roshnijewellery.com"; classtype:trojan-activity; sid:100004645; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rs-toolkit.mikestclair.org"; classtype:trojan-activity; sid:100004646; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rsgym.net"; classtype:trojan-activity; sid:100004647; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rubazar.pro"; classtype:trojan-activity; sid:100004648; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rubycityvietnam.com"; classtype:trojan-activity; sid:100004649; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ruch.newreadermedia.net"; classtype:trojan-activity; sid:100004650; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ruisgood.ru"; classtype:trojan-activity; sid:100004651; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ruwadalkuwait.com"; classtype:trojan-activity; sid:100004652; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"rzminc.com"; classtype:trojan-activity; sid:100004653; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"s.51shijuan.com"; classtype:trojan-activity; sid:100004654; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"s.thechinesemuslim.com"; classtype:trojan-activity; sid:100004655; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sacredscentsonline.com"; classtype:trojan-activity; sid:100004656; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"safcol-colors.com"; classtype:trojan-activity; sid:100004657; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"safehubsecurity.ca"; classtype:trojan-activity; sid:100004658; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"safety.nanotechproautocare.com"; classtype:trojan-activity; sid:100004659; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sahathaikasetpan.com"; classtype:trojan-activity; sid:100004660; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"saisoftwareinc.com"; classtype:trojan-activity; sid:100004661; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"salecorner.yourpageserver.com"; classtype:trojan-activity; sid:100004662; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sandovalgraphics.com"; classtype:trojan-activity; sid:100004663; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"santebarleyshop.jakewebtechs.ml"; classtype:trojan-activity; sid:100004664; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"santyago.org"; classtype:trojan-activity; sid:100004665; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sarakem.cl"; classtype:trojan-activity; sid:100004666; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sasystemsuk.com"; classtype:trojan-activity; sid:100004667; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"savasaachi.systems"; classtype:trojan-activity; sid:100004668; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"scarfaceindustries.com"; classtype:trojan-activity; sid:100004669; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"scglobal.co.th"; classtype:trojan-activity; sid:100004670; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"schalke04rss.de"; classtype:trojan-activity; sid:100004671; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"scheff.com"; classtype:trojan-activity; sid:100004672; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"schoolbustracker.softgig.co.ke"; classtype:trojan-activity; sid:100004673; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sec-doc-w.com"; classtype:trojan-activity; sid:100004674; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"secure-doc-reader.com"; classtype:trojan-activity; sid:100004675; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"segalsmetals.elin.co.za"; classtype:trojan-activity; sid:100004676; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sellmyphonela.com"; classtype:trojan-activity; sid:100004677; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"senbiaojita.com"; classtype:trojan-activity; sid:100004678; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sentierodelviandante.ml"; classtype:trojan-activity; sid:100004679; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"serendibsourcing.com"; classtype:trojan-activity; sid:100004680; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"servicemhkd.myvnc.com"; classtype:trojan-activity; sid:100004681; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"servicemhkd80.myvnc.com"; classtype:trojan-activity; sid:100004682; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"serviciovirtual.com.ar"; classtype:trojan-activity; sid:100004683; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"seyranikenger.com.tr"; classtype:trojan-activity; sid:100004684; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sgessy.com.br"; classtype:trojan-activity; sid:100004685; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shaheentbfoundation.com"; classtype:trojan-activity; sid:100004686; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shahikhana.cstdevs.com"; classtype:trojan-activity; sid:100004687; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sharkrigs.com"; classtype:trojan-activity; sid:100004688; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sharpelevators.in"; classtype:trojan-activity; sid:100004689; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shembefoundation.com"; classtype:trojan-activity; sid:100004690; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shivakunwar.com.np"; classtype:trojan-activity; sid:100004691; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shoblasaathitrust.org"; classtype:trojan-activity; sid:100004692; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shooka-co.com"; classtype:trojan-activity; sid:100004693; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shop.goldspot.agency"; classtype:trojan-activity; sid:100004694; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shopsofe.com"; classtype:trojan-activity; sid:100004695; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"shrushtiinfotech.com"; classtype:trojan-activity; sid:100004696; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sibernetix.fr"; classtype:trojan-activity; sid:100004697; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"siddharthpanditpautra.com"; classtype:trojan-activity; sid:100004698; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sige.brisainformatica.com.br"; classtype:trojan-activity; sid:100004699; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"signatureads.co.in"; classtype:trojan-activity; sid:100004700; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"siili.net"; classtype:trojan-activity; sid:100004701; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"simoneporzi.it"; classtype:trojan-activity; sid:100004702; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"simplithy.co.uk"; classtype:trojan-activity; sid:100004703; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sindicato1ucm.cl"; classtype:trojan-activity; sid:100004704; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sindpol.tiejuris.com.br"; classtype:trojan-activity; sid:100004705; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sinergidwireka.com"; classtype:trojan-activity; sid:100004706; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sipahielektrik.com"; classtype:trojan-activity; sid:100004707; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"siperb.in"; classtype:trojan-activity; sid:100004708; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sistelligent.com"; classtype:trojan-activity; sid:100004709; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"skkksolo.beweiretail.com"; classtype:trojan-activity; sid:100004710; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"skyflyfares.com"; classtype:trojan-activity; sid:100004711; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"skyscan.com"; classtype:trojan-activity; sid:100004712; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smarthouseforum.ru"; classtype:trojan-activity; sid:100004713; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smarts.tj"; classtype:trojan-activity; sid:100004714; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smartzedu.com"; classtype:trojan-activity; sid:100004715; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smokeandgrowrichtour.com"; classtype:trojan-activity; sid:100004716; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"smokesolutionindia.com"; classtype:trojan-activity; sid:100004717; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sobethuacademy.com"; classtype:trojan-activity; sid:100004718; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"soft.officelabo.net"; classtype:trojan-activity; sid:100004719; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sohs.conceptechs.info"; classtype:trojan-activity; sid:100004720; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"solar.amazingtribe.lk"; classtype:trojan-activity; sid:100004721; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"solo2.dbstrony.pl"; classtype:trojan-activity; sid:100004722; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"somcorbera.cat"; classtype:trojan-activity; sid:100004723; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"somir.com.mx"; classtype:trojan-activity; sid:100004724; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"soralapps.com"; classtype:trojan-activity; sid:100004725; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sorteio.orgaostalita.com.br"; classtype:trojan-activity; sid:100004726; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sosgsm.fr"; classtype:trojan-activity; sid:100004727; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sota-france.fr"; classtype:trojan-activity; sid:100004728; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sowingminerals.cl"; classtype:trojan-activity; sid:100004729; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"space.proactint.org"; classtype:trojan-activity; sid:100004730; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spaceframe.mobi.space-frame.co.za"; classtype:trojan-activity; sid:100004731; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"special-key.cf"; classtype:trojan-activity; sid:100004732; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spent.com.pl"; classtype:trojan-activity; sid:100004733; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spetsesyachtcharter.gr"; classtype:trojan-activity; sid:100004734; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spititourism.com"; classtype:trojan-activity; sid:100004735; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"spittinfire.com"; classtype:trojan-activity; sid:100004736; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sports-net.de"; classtype:trojan-activity; sid:100004737; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"src1.minibai.com"; classtype:trojan-activity; sid:100004738; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sreenivasapaintingworks.com"; classtype:trojan-activity; sid:100004739; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sriglobalit.com"; classtype:trojan-activity; sid:100004740; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"srvmanos.no-ip.info"; classtype:trojan-activity; sid:100004741; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ss.monita.co.id"; classtype:trojan-activity; sid:100004742; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"staging.apparelpunch.com"; classtype:trojan-activity; sid:100004743; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"starcountry.net"; classtype:trojan-activity; sid:100004744; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"static.3001.net"; classtype:trojan-activity; sid:100004745; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"statsres.com"; classtype:trojan-activity; sid:100004746; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"statssound.com"; classtype:trojan-activity; sid:100004747; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"statsspot.com"; classtype:trojan-activity; sid:100004748; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"statsvilla.com"; classtype:trojan-activity; sid:100004749; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stattilion.bar"; classtype:trojan-activity; sid:100004750; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stiepancasetia.ac.id"; classtype:trojan-activity; sid:100004751; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stott-thompson.co.uk"; classtype:trojan-activity; sid:100004752; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"stratexec.co.za"; classtype:trojan-activity; sid:100004753; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"streetdemo.yourpageserver.com"; classtype:trojan-activity; sid:100004754; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"suboldesign.com"; classtype:trojan-activity; sid:100004755; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sumerians.org"; classtype:trojan-activity; sid:100004756; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sunbrero.com.au"; classtype:trojan-activity; sid:100004757; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sunmarkholidays.com"; classtype:trojan-activity; sid:100004758; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"supermercadostia.com"; classtype:trojan-activity; sid:100004759; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"support-4-free.com"; classtype:trojan-activity; sid:100004760; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"support.clz.kr"; classtype:trojan-activity; sid:100004761; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"supportit.online"; classtype:trojan-activity; sid:100004762; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"surestdysbonescagexc.dns.army"; classtype:trojan-activity; sid:100004763; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sw.yourpageserver.com"; classtype:trojan-activity; sid:100004764; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sweaty.dk"; classtype:trojan-activity; sid:100004765; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sweet-diet.com"; classtype:trojan-activity; sid:100004766; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"swentsai.com"; classtype:trojan-activity; sid:100004767; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"swiftlogisticseg.com"; classtype:trojan-activity; sid:100004768; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"swwbia.com"; classtype:trojan-activity; sid:100004769; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"syedpro.dezinetimes.com"; classtype:trojan-activity; sid:100004770; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"syracusecoffee.com"; classtype:trojan-activity; sid:100004771; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sys.pbmadu.co.id"; classtype:trojan-activity; sid:100004772; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"systemsecuritylock.com"; classtype:trojan-activity; sid:100004773; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"sytraders.co"; classtype:trojan-activity; sid:100004774; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"t.honker.info"; classtype:trojan-activity; sid:100004775; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tacticohosting.com"; classtype:trojan-activity; sid:100004776; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tadoo.ca"; classtype:trojan-activity; sid:100004777; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tafsantoursandtravels.com"; classtype:trojan-activity; sid:100004778; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tallyinvoicecustomization.com"; classtype:trojan-activity; sid:100004779; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"taltus.co.uk"; classtype:trojan-activity; sid:100004780; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tapalkoedacoffee.com"; classtype:trojan-activity; sid:100004781; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tarravalleyfoods.com.au"; classtype:trojan-activity; sid:100004782; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"taurus.ug"; classtype:trojan-activity; sid:100004783; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"taxicabsrilanka.com"; classtype:trojan-activity; sid:100004784; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"taxpos.com"; classtype:trojan-activity; sid:100004785; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tc.snpsresidential.com"; classtype:trojan-activity; sid:100004786; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tcy.198424.com"; classtype:trojan-activity; sid:100004787; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tdsp.yngw518.com"; classtype:trojan-activity; sid:100004788; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"techgms.com"; classtype:trojan-activity; sid:100004789; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"technogreen.crmmanivela.com"; classtype:trojan-activity; sid:100004790; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"technohub.searchkero.com"; classtype:trojan-activity; sid:100004791; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tecnicaencolectores.com.mx"; classtype:trojan-activity; sid:100004792; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tecnologyschool.com"; classtype:trojan-activity; sid:100004793; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"teduae.com"; classtype:trojan-activity; sid:100004794; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"teleargentina.com"; classtype:trojan-activity; sid:100004795; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"telescopelms.com"; classtype:trojan-activity; sid:100004796; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"telmed.cl"; classtype:trojan-activity; sid:100004797; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"temptmag.com"; classtype:trojan-activity; sid:100004798; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tennisafrica.com"; classtype:trojan-activity; sid:100004799; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tentandoserfitness.000webhostapp.com"; classtype:trojan-activity; sid:100004800; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.adventser.com"; classtype:trojan-activity; sid:100004801; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.letraele.es"; classtype:trojan-activity; sid:100004802; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.typoten.com"; classtype:trojan-activity; sid:100004803; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test.wanepghana.org"; classtype:trojan-activity; sid:100004804; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test1.asistencia247.com"; classtype:trojan-activity; sid:100004805; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test1.milenial.id"; classtype:trojan-activity; sid:100004806; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test1.tenplusone.my"; classtype:trojan-activity; sid:100004807; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test2.basis-web.com"; classtype:trojan-activity; sid:100004808; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"test2.marrenconstruction.ie"; classtype:trojan-activity; sid:100004809; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"testing.clickitsolutionsmw.com"; classtype:trojan-activity; sid:100004810; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"testing.thinkingcorp.in"; classtype:trojan-activity; sid:100004811; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"testnew.yourpageserver.com"; classtype:trojan-activity; sid:100004812; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"teteaffiche.stephanebillon.com"; classtype:trojan-activity; sid:100004813; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tewoerd.eu"; classtype:trojan-activity; sid:100004814; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"textile.softberg.ro"; classtype:trojan-activity; sid:100004815; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"texturesbyvinita.com"; classtype:trojan-activity; sid:100004816; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thecleaningladiespdx.com"; classtype:trojan-activity; sid:100004817; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thecreativecafe.co.uk"; classtype:trojan-activity; sid:100004818; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thefuturelife.in"; classtype:trojan-activity; sid:100004819; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thehighlightinterior.com"; classtype:trojan-activity; sid:100004820; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thehouseofpragya.com"; classtype:trojan-activity; sid:100004821; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thekassia.co.uk"; classtype:trojan-activity; sid:100004822; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thelaunchpadteam.com"; classtype:trojan-activity; sid:100004823; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thelogicalgroup.co.uk"; classtype:trojan-activity; sid:100004824; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thesummitpc.net"; classtype:trojan-activity; sid:100004825; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"theurbantutors.com"; classtype:trojan-activity; sid:100004826; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thewwpc.com"; classtype:trojan-activity; sid:100004827; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"thosewebbs.com"; classtype:trojan-activity; sid:100004828; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tianangdep.com"; classtype:trojan-activity; sid:100004829; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tickfood.tickme.lk"; classtype:trojan-activity; sid:100004830; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tickjobs.tickme.lk"; classtype:trojan-activity; sid:100004831; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tickmart.tickme.lk"; classtype:trojan-activity; sid:100004832; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"timegonebuy.com"; classtype:trojan-activity; sid:100004833; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tksb.net"; classtype:trojan-activity; sid:100004834; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tlcc.com.gt"; classtype:trojan-activity; sid:100004835; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"todoapp.cstdevs.com"; classtype:trojan-activity; sid:100004836; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tonydong.com"; classtype:trojan-activity; sid:100004837; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tonyzone.com"; classtype:trojan-activity; sid:100004838; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tooba.tenplusone.my"; classtype:trojan-activity; sid:100004839; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"topcell9.com"; classtype:trojan-activity; sid:100004840; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"topicsnepal.com"; classtype:trojan-activity; sid:100004841; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"toplevel.com.br"; classtype:trojan-activity; sid:100004842; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"torresquinterocorp.com"; classtype:trojan-activity; sid:100004843; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"towme.services"; classtype:trojan-activity; sid:100004844; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"toyotacollege.ac.th"; classtype:trojan-activity; sid:100004845; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tpef.lsoftdemo.com"; classtype:trojan-activity; sid:100004846; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tpke.hu"; classtype:trojan-activity; sid:100004847; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tradezone.ejuicysolutions.com"; classtype:trojan-activity; sid:100004848; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"translaterjemah.com"; classtype:trojan-activity; sid:100004849; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"travel.travelwadi.com"; classtype:trojan-activity; sid:100004850; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"travelwithmanta.co.za"; classtype:trojan-activity; sid:100004851; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"trezors.io.mahlongwa.com"; classtype:trojan-activity; sid:100004852; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"triplonet.com.br"; classtype:trojan-activity; sid:100004853; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"troki.com.co"; classtype:trojan-activity; sid:100004854; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tropics.codeleek.net"; classtype:trojan-activity; sid:100004855; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"trudelfavreau.com"; classtype:trojan-activity; sid:100004856; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tsd.jxwan.com"; classtype:trojan-activity; sid:100004857; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tulli.info"; classtype:trojan-activity; sid:100004858; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"tupperware.michaelroberge.ca"; classtype:trojan-activity; sid:100004859; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"turanggaresources.com"; classtype:trojan-activity; sid:100004860; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uat.indianfilmzone.com"; classtype:trojan-activity; sid:100004861; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ublretailerdemo.cstdevs.com"; classtype:trojan-activity; sid:100004862; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"udesk.searchkero.com"; classtype:trojan-activity; sid:100004863; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ugprs-ubih.org"; classtype:trojan-activity; sid:100004864; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ultimate-24.de"; classtype:trojan-activity; sid:100004865; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"umwelt-kirchhof.de"; classtype:trojan-activity; sid:100004866; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"unicorpbrunei.com"; classtype:trojan-activity; sid:100004867; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uniengrisb.com"; classtype:trojan-activity; sid:100004868; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"unisoftcc.com"; classtype:trojan-activity; sid:100004869; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"unyazitelecom.com"; classtype:trojan-activity; sid:100004870; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"upcbpta.com"; classtype:trojan-activity; sid:100004871; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"urbane.dezinetimes.com"; classtype:trojan-activity; sid:100004872; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"useformoney.000webhostapp.com"; classtype:trojan-activity; sid:100004873; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"usmadetshirts.com"; classtype:trojan-activity; sid:100004874; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uss.ac.th"; classtype:trojan-activity; sid:100004875; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"uzzepay.com.br"; classtype:trojan-activity; sid:100004876; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vanzare.cabanabrazi2.ro"; classtype:trojan-activity; sid:100004877; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vbcargo.hu"; classtype:trojan-activity; sid:100004878; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vcah.co.uk"; classtype:trojan-activity; sid:100004879; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vegadelcasero.cl"; classtype:trojan-activity; sid:100004880; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vendas.lidiacarmeli.com.br"; classtype:trojan-activity; sid:100004881; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"verify.aicosoft.com"; classtype:trojan-activity; sid:100004882; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vfocus.net"; classtype:trojan-activity; sid:100004883; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vidmattic.com"; classtype:trojan-activity; sid:100004884; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vienen.gblix.srv.br"; classtype:trojan-activity; sid:100004885; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"villamarand.com"; classtype:trojan-activity; sid:100004886; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"villatera.com"; classtype:trojan-activity; sid:100004887; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"violinstop.com"; classtype:trojan-activity; sid:100004888; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"viraltalking.com"; classtype:trojan-activity; sid:100004889; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"visions.alnisamart.com"; classtype:trojan-activity; sid:100004890; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"visualhome.cl"; classtype:trojan-activity; sid:100004891; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vitoriamodaintima.com.br"; classtype:trojan-activity; sid:100004892; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vivationdesign.com"; classtype:trojan-activity; sid:100004893; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"viveirodoiscorregos.com.br"; classtype:trojan-activity; sid:100004894; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vksales.com"; classtype:trojan-activity; sid:100004895; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vladimirinternational.com"; classtype:trojan-activity; sid:100004896; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vokasi.ub.ac.id"; classtype:trojan-activity; sid:100004897; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vologroup.com.br"; classtype:trojan-activity; sid:100004898; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"voteyouramerica.dekitout.com"; classtype:trojan-activity; sid:100004899; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vstsample.com"; classtype:trojan-activity; sid:100004900; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vtube.fadlymotivator.com"; classtype:trojan-activity; sid:100004901; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"vvsskmodinationalschool.com"; classtype:trojan-activity; sid:100004902; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wanepliberia.org"; classtype:trojan-activity; sid:100004903; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wanepniger.org"; classtype:trojan-activity; sid:100004904; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"weareactum.com"; classtype:trojan-activity; sid:100004905; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.eng.ubu.ac.th"; classtype:trojan-activity; sid:100004906; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.geetle.ga"; classtype:trojan-activity; sid:100004907; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.geomegasoft.net"; classtype:trojan-activity; sid:100004908; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.newinnovationtechnology.com"; classtype:trojan-activity; sid:100004909; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.smarts-works.com"; classtype:trojan-activity; sid:100004910; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"web.thebeessolution.com"; classtype:trojan-activity; sid:100004911; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"webgis.perumdasolo.com"; classtype:trojan-activity; sid:100004912; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"webmailwindstreamnetmessagesecureapp1rqr.ga"; classtype:trojan-activity; sid:100004913; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"webpresario.com"; classtype:trojan-activity; sid:100004914; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"website-work.com"; classtype:trojan-activity; sid:100004915; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"weinsteincounseling.com"; classtype:trojan-activity; sid:100004916; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wexfashion.com"; classtype:trojan-activity; sid:100004917; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"whcms.yourpageserver.com"; classtype:trojan-activity; sid:100004918; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"whiteglovetailgate.com"; classtype:trojan-activity; sid:100004919; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"whiteresponse.com"; classtype:trojan-activity; sid:100004920; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"whynt.xyz"; classtype:trojan-activity; sid:100004921; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wi522012.ferozo.com"; classtype:trojan-activity; sid:100004922; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wikalen.co.za"; classtype:trojan-activity; sid:100004923; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wildnights.co.uk"; classtype:trojan-activity; sid:100004924; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wildtrust.mediadevstaging.com"; classtype:trojan-activity; sid:100004925; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wimbamusica.com"; classtype:trojan-activity; sid:100004926; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wishesconcierge.com"; classtype:trojan-activity; sid:100004927; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"woezon.agency"; classtype:trojan-activity; sid:100004928; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wolfgang-brodte.de"; classtype:trojan-activity; sid:100004929; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"woodsytech.com"; classtype:trojan-activity; sid:100004930; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wordpress.saleensuporte.com.br"; classtype:trojan-activity; sid:100004931; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wozata.000webhostapp.com"; classtype:trojan-activity; sid:100004932; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wp.readhere.in"; classtype:trojan-activity; sid:100004933; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wpdemo.101clients.com.au"; classtype:trojan-activity; sid:100004934; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"writtendeer.com"; classtype:trojan-activity; sid:100004935; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ws5588.f3322.net"; classtype:trojan-activity; sid:100004936; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"wyklej.pl"; classtype:trojan-activity; sid:100004937; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"x2vn.com"; classtype:trojan-activity; sid:100004938; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xia.beihaixue.com"; classtype:trojan-activity; sid:100004939; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xixaoclothing.com"; classtype:trojan-activity; sid:100004940; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xk.996is.com"; classtype:trojan-activity; sid:100004941; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xn--80akinnkiib6h.xn--90ais"; classtype:trojan-activity; sid:100004942; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"xn--polimerbizmimarlk-rvc.com"; classtype:trojan-activity; sid:100004943; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ybom.urbanolab.com"; classtype:trojan-activity; sid:100004944; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yeichner.com"; classtype:trojan-activity; sid:100004945; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"ylfpremium.com"; classtype:trojan-activity; sid:100004946; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yoast.yourpageserver.com"; classtype:trojan-activity; sid:100004947; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"youtubetrainingacademy.com"; classtype:trojan-activity; sid:100004948; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yskadvisors.com"; classtype:trojan-activity; sid:100004949; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yummyyogaudaipur.com"; classtype:trojan-activity; sid:100004950; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"yzkzixun.com"; classtype:trojan-activity; sid:100004951; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"zakra.tecnasulstore.com.br"; classtype:trojan-activity; sid:100004952; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"zytrox.tk"; classtype:trojan-activity; sid:100004953; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.host; content:"zz.690tx.com"; classtype:trojan-activity; sid:100004954; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/64.exe"; endswith; nocase; http.host; content:"2.indexsinas.me:811"; classtype:trojan-activity; sid:100004955; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/86.exe"; endswith; nocase; http.host; content:"2.indexsinas.me:811"; classtype:trojan-activity; sid:100004956; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c64.exe"; endswith; nocase; http.host; content:"2.indexsinas.me:811"; classtype:trojan-activity; sid:100004957; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe"; endswith; nocase; http.host; content:"amumufree.weebly.com"; classtype:trojan-activity; sid:100004958; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/files/proxyi.exe"; endswith; nocase; http.host; content:"analogx.com"; classtype:trojan-activity; sid:100004959; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/abernathyjorge711/y6788/downloads/bubblebrowserext1.0.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004960; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/densjons/bro/downloads/rew.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004961; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dvdfv/anjj/downloads/jami.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004962; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jpavelski/chpock/downloads/4.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004963; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/jpavelski/chpock/downloads/6.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004964; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/clr.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004965; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/clr3.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004966; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/instaler.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004967; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/installer.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004968; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/updatej.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004969; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/updatev.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004970; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/mminminminmin05/testtest/downloads/work.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004971; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player2012/rumpa1/downloads/component.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004972; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player2012/rumpa1/downloads/nordvpnsetup.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004973; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player2012/rumpa1/downloads/regsvc.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004974; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/skygaming/updates/downloads/update.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004975; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/001.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004976; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1488.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004977; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1_cr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004978; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1cr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004979; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/1fc2d.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004980; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/26a5.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004981; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/6e7_2021-01-19_18-04.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004982; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/abjects.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004983; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/attached.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004984; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/b7f2c.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004985; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/battletext.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004986; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/bkghj_nowin.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004987; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/bsdasdasd333.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004988; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004989; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build_makros.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004990; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build_silent.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004991; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/build_sup.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004992; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildcmobiler.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004993; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildcmobiler.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004994; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildcr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004995; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/buildss.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004996; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/clientnik.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004997; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/clientrevers.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004998; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/dcrat.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100004999; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/dllservices.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005000; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/dllservices2.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005001; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/exe_morris.mcdermott.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005002; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/hans.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005003; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/hulu.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005004; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelfive.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005005; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelfour.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005006; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelone.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005007; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/intelthree.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005008; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/inteltwo.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005009; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/jjuufksfn.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005010; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/kleiman.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005011; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/lucky_fixed.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005012; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/notepadplus.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005013; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/osiris_qqkz_nauto.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005014; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/out.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005015; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/out.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005016; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/pacbe_bin.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005017; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/putty.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005018; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/rockethcd.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005019; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/scvhost900.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005020; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/sessionwin.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005021; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/siliculose.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005022; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/statemobi.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005023; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/stealers.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005024; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/stealers2.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005025; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/stgedo.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005026; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/svcperf.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005027; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/symptomaticshon5.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005028; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/taurjok.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005029; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/taurusbabac.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005030; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/telekiller.exe"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005031; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/updateanddr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005032; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/updateandr.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005033; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/vhajeja.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005034; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/word.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005035; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/www.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005036; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tanake5518/fi/downloads/xlsd.txt"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005037; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/teaserex/tease/downloads/b_kfmhkk172.bin"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005038; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/teaserex/tease/downloads/macro_xmprohiq27.bin"; endswith; nocase; http.host; content:"bitbucket.org"; classtype:trojan-activity; sid:100005039; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/hmatrix/data/hack1226.exe"; endswith; nocase; http.host; content:"cd.textfiles.com"; classtype:trojan-activity; sid:100005040; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/775238059083038744/821062129347067924/wxhyhyciuesjdefkxcqddvfbjqrofjq"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100005041; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/816070119281131570/816070273254162442/all.txt"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100005042; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/attachments/823355293043261515/823692323514482788/inquiry_-_rfq_hmg_u66_sw5558_pdf.iso"; endswith; nocase; http.host; content:"cdn.discordapp.com"; classtype:trojan-activity; sid:100005043; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/razor/rzr-winner_intro.zip"; endswith; nocase; http.host; content:"chiptune.com"; classtype:trojan-activity; sid:100005044; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz"; endswith; nocase; http.host; content:"cloudme.com"; classtype:trojan-activity; sid:100005045; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar"; endswith; nocase; http.host; content:"cloudme.com"; classtype:trojan-activity; sid:100005046; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/meteoradminz/hidden-tear/zip/master"; endswith; nocase; http.host; content:"codeload.github.com"; classtype:trojan-activity; sid:100005047; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/"; endswith; nocase; http.host; content:"colfincas.com"; classtype:trojan-activity; sid:100005048; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/qz0h69.pdf"; endswith; nocase; http.host; content:"deepfreedom.org"; classtype:trojan-activity; sid:100005049; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/frm0reseen/prntscrnofamzorderid.jpg.exe"; endswith; nocase; http.host; content:"drive.google.com.it-barcelona.com"; classtype:trojan-activity; sid:100005050; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=0byfg0_4xbjgnwvuyev9ltuh4rmm"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005051; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=13vodfxml9fg8kcnexuafh64dzmnqv8ch"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005052; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=167imxqgc8ehepa1gisxa6q6ifcjxceox"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005053; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1a-herfdxr6xamxeabcdao0mqw9bimrig"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005054; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1aphk_vq7gtn368zxpd5bg5rv8nk0bnhn"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005055; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005056; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1eqnvgn0qkunp7t6crk8oj7_e7rh5qxwi"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005057; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1in-rhdrss2qsjqj8xffb1hbwi9znp4je"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005058; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1iwc-lf99neesk6mvvo2al4futbmyoiev"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005059; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005060; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1n8o4hbvi7o9ks9jqhofny7okposfaz4y"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005061; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1nio_cdsggt4zv1kdrpubrfpd0pzsyffd"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005062; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1oabvvnazifkxktvt-izbcdqpb7dm6nrw"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005063; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1prxtn1juykhcr_9ilw-vtirv5anyeoej"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005064; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1t1bd_itjnhsmozdl9was0gouehujm1fn"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005065; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1tsmbsikhechaqedk6nktlfzasus_tghw"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005066; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1uvtmu3-hcryp3rskqnpkiodcjuchtz55"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005067; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1vevblftithattyguwyjot1p0wptg7l5t"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005068; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005069; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1yawygcfjs9inzoiwagqfcn3utaywxmwi"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005070; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1yhflwpk3yeyrdhlhanctlind-5j24iwv"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005071; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?export=download&id=1zbclvhabervgfryoyqklo4_oe6icd8sr"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005072; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uc?id=148pt6v0nlg8yoim7w6in7dpixkzaacbg&export=download&authuser=0"; endswith; nocase; http.host; content:"drive.google.com"; classtype:trojan-activity; sid:100005073; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/1zilg/"; endswith; nocase; http.host; content:"drpamelageorge.com"; classtype:trojan-activity; sid:100005074; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-includes/qcgfmfvh/"; endswith; nocase; http.host; content:"drpamelageorge.com"; classtype:trojan-activity; sid:100005075; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/downloads/emclick.zip"; endswith; nocase; http.host; content:"e-mudhra.com"; classtype:trojan-activity; sid:100005076; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/informatica/informatica-actief/hoofdstuk1/extrasoftware/getallen.exe"; endswith; nocase; http.host; content:"evertkok.nl"; classtype:trojan-activity; sid:100005077; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/informatica/informatica-actief/hoofdstuk2/software/hksetup.exe"; endswith; nocase; http.host; content:"evertkok.nl"; classtype:trojan-activity; sid:100005078; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/register/phpcaptcha/images/19dnqhg1p/sbhvtqlysxhxn/"; endswith; nocase; http.host; content:"expeditionquest.com"; classtype:trojan-activity; sid:100005079; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/register/phpcaptcha/images/35egphpl5uzpvdmz9bncmvon3p/"; endswith; nocase; http.host; content:"expeditionquest.com"; classtype:trojan-activity; sid:100005080; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/x/"; endswith; nocase; http.host; content:"expeditionquest.com"; classtype:trojan-activity; sid:100005081; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf/"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100005082; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf//"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100005083; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf///"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100005084; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/orbi-slow-glero/ggkuv5jkrmkn1kgyelyvka973qrxnwf////"; endswith; nocase; http.host; content:"exxonabnie.ir"; classtype:trojan-activity; sid:100005085; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/web1/m00/8f/36/o4ybafy-2m2aarfzaahkaiik5pi122.exe"; endswith; nocase; http.host; content:"file.elecfans.com"; classtype:trojan-activity; sid:100005086; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/4cb7cebd101/e5fb4174-ab23-48e8-bf05-e80ec5fa2169.xls"; endswith; nocase; http.host; content:"files.constantcontact.com"; classtype:trojan-activity; sid:100005087; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ee304de9001/7e533e73-e272-4a44-9d9e-138cab64bf19.docx"; endswith; nocase; http.host; content:"files.constantcontact.com"; classtype:trojan-activity; sid:100005088; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe"; endswith; nocase; http.host; content:"gist.githubusercontent.com"; classtype:trojan-activity; sid:100005089; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/cgi-bin/sni8w3fssb44iavmzss2nv0od6eiixlq6/"; endswith; nocase; http.host; content:"hqdecig.com"; classtype:trojan-activity; sid:100005090; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/suy/"; endswith; nocase; http.host; content:"hsecaravans.co.uk"; classtype:trojan-activity; sid:100005091; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/19/items/startup_20210219/startup.txt"; endswith; nocase; http.host; content:"ia801802.us.archive.org"; classtype:trojan-activity; sid:100005092; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/online-timer-kvhxz/ilxl/"; endswith; nocase; http.host; content:"ie-best.net"; classtype:trojan-activity; sid:100005093; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/64.exe"; endswith; nocase; http.host; content:"indonesias.me:9998"; classtype:trojan-activity; sid:100005094; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/c64.exe"; endswith; nocase; http.host; content:"indonesias.me:9998"; classtype:trojan-activity; sid:100005095; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ebook/cs17.exe"; endswith; nocase; http.host; content:"jcedu.org"; classtype:trojan-activity; sid:100005096; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/1"; endswith; nocase; http.host; content:"jointings.org"; classtype:trojan-activity; sid:100005097; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/2"; endswith; nocase; http.host; content:"jointings.org"; classtype:trojan-activity; sid:100005098; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/eng/wp-content/plugins/featurific-for-wordpress/3"; endswith; nocase; http.host; content:"jointings.org"; classtype:trojan-activity; sid:100005099; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/file/jl01o54yy09qrzg/fac215.tgz/file"; endswith; nocase; http.host; content:"justlficante.mediafire.com"; classtype:trojan-activity; sid:100005100; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/3/2/8/8/3288864/karma_koin_codes.exe"; endswith; nocase; http.host; content:"karmakoincodes.weebly.com"; classtype:trojan-activity; sid:100005101; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/dg/etrac/nf4emwz/"; endswith; nocase; http.host; content:"kotakwarna.co.id"; classtype:trojan-activity; sid:100005102; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/down/affiliate/kuaizip_setup_10029.exe"; endswith; nocase; http.host; content:"kuaizip.com"; classtype:trojan-activity; sid:100005103; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/linuxforensicscode.zip"; endswith; nocase; http.host; content:"linuxforensicsbook.com.s3.amazonaws.com"; classtype:trojan-activity; sid:100005104; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/k/big5/1giof6/"; endswith; nocase; http.host; content:"minpic.de"; classtype:trojan-activity; sid:100005105; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-contentbak/t9m/"; endswith; nocase; http.host; content:"morrobaydrugandgift.com"; classtype:trojan-activity; sid:100005106; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/v1/ws2/:gianni1962/:ie6setup/ie6setup.exe"; endswith; nocase; http.host; content:"my.cloudme.com"; classtype:trojan-activity; sid:100005107; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/components/aacenc.exe"; endswith; nocase; http.host; content:"nch.com.au"; classtype:trojan-activity; sid:100005108; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/components/doxillionsetup.exe"; endswith; nocase; http.host; content:"nch.com.au"; classtype:trojan-activity; sid:100005109; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/uploads/4/1/6/6/4166984/keygen.exe"; endswith; nocase; http.host; content:"newyarlfm.weebly.com"; classtype:trojan-activity; sid:100005110; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/efficiency-all-iuehb/bjug3jyhuyilwhcqs3ykssaqqw7tpyvmypb91wtzdbluio1ekope5vrbbcx8zhdar9yt/"; endswith; nocase; http.host; content:"nhipcauytevietnhat.com"; classtype:trojan-activity; sid:100005111; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/yws/api/personal/file/web3a243b322cf83ca7cae587a92916bac7?method=download&inline=true&sharekey=649ac0bb5d5b13d15cbf50b2609e193a"; endswith; nocase; http.host; content:"note.youdao.com"; classtype:trojan-activity; sid:100005112; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/spreadsheets/osv_stock_valuation-sample-dummy.exe"; endswith; nocase; http.host; content:"oldschoolvalue.s3.amazonaws.com"; classtype:trojan-activity; sid:100005113; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=81445407a9f44d37!197&authkey=apuz15kftzlrysa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005114; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=81445407a9f44d37!198&authkey=ags5rgb15_esaqq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005115; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=b4c15a27928f663b!229&authkey=aiarm61fwmd_npe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005116; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=b4c15a27928f663b!230&authkey=ancu1eabetiubzg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005117; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=b4c15a27928f663b!231&authkey=ai9h3sk_luxran0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005118; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?&resid=c127f9e0fb7cbbea!214&authkey=aat73nvghhjdr9g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005119; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=!aase4ma0-vo_cls&cid=4df11eda676a355f&resid=4df11eda676a355f!140"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005120; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=!akd6uxvljtlvpxu&cid=4df11eda676a355f&resid=4df11eda676a355f!130"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005121; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005122; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?authkey=adf5p_kn8rjf29y&cid=34224e3e49966a27&resid=34224e3e49966a27%211732"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005123; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=013413cfbbbcfae4&resid=13413cfbbbcfae4%211656&authkey=ai9wpcp_k9okgk4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005124; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c!111&authkey=aemrwamaaaiyyjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005125; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0153c2a7092ee91c&resid=153c2a7092ee91c%21111&authkey=aemrwamaaaiyyjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005126; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0175cdbe2d2944c5&resid=175cdbe2d2944c5%21107&authkey=al6uptubjmmugo0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005127; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!157&authkey=aagcsm7chqez6uu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005128; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4!158&authkey=amsoii5nr6pomhc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005129; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21157&authkey=aagcsm7chqez6uu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005130; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=01f191d863b4d5a4&resid=1f191d863b4d5a4%21158&authkey=amsoii5nr6pomhc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005131; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=023f39d21b700310&resid=23f39d21b700310%211204&authkey=an2utsuaopn0fhc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005132; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211177&authkey=am0i98nwgvzgqvq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005133; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=02e98840a4c9fd6c&resid=2e98840a4c9fd6c%211183&authkey=anv33trmzmi5cko"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005134; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005135; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=03286724f74117f9&resid=3286724f74117f9!1179&authkey=acr-_rvrgp39kk4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005136; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=03286724f74117f9&resid=3286724f74117f9%211179&authkey=acr-_rvrgp39kk4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005137; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005138; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005139; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005140; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005141; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005142; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!273&authkey=ae2m69e5nu3rrea"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005143; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!274&authkey=acqg0akutoxdpgo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005144; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21273&authkey=ae2m69e5nu3rrea"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005145; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21274&authkey=acqg0akutoxdpgo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005146; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0e26b39babdbf63c&resid=e26b39babdbf63c%21137&authkey=anshbgxg1_qa2h4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005147; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242!309&authkey=alfe36drai1zmwc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005148; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f0a5aadc4c3c242&resid=f0a5aadc4c3c242%21309&authkey=alfe36drai1zmwc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005149; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21123&authkey=aco5hiwppfq8vrw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005150; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=0f51d04c9d556964&resid=f51d04c9d556964%21124&authkey=ai6sfa2z-kqf6x0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005151; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=115bffdddaa40942&resid=115bffdddaa40942!540&authkey=aamhnqgfdtdsoxk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005152; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=115bffdddaa40942&resid=115bffdddaa40942%21540&authkey=aamhnqgfdtdsoxk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005153; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005154; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=13b301f1cb48f8cd&resid=13b301f1cb48f8cd%21106&authkey=aiae3olcs4lulz4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005155; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=14f52af71b98dbc5&resid=14f52af71b98dbc5%212449&authkey=anfs_n5cs1noojo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005156; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005157; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=165468846f076ee7&resid=165468846f076ee7%21118&authkey=antash3ig98aqte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005158; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f%21286&authkey=almwisomhv3c0zc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005159; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e!348&authkey=ahnjoxa4ufoxa54"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005160; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=174a158b69387a7e&resid=174a158b69387a7e%21348&authkey=ahnjoxa4ufoxa54"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005161; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!126&authkey=ad4yflrisq6d82g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005162; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2!129&authkey=apqoonsrce0ari4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005163; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21126&authkey=ad4yflrisq6d82g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005164; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=18418adacefed6e2&resid=18418adacefed6e2%21129&authkey=apqoonsrce0ari4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005165; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=196e83840ef8c152&resid=196e83840ef8c152%21107&authkey=ah2lhjyd0ukjcve"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005166; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1a162e8fcaaef5fa&resid=1a162e8fcaaef5fa%215495&authkey=aic7rmj1cm3rt2w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005167; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558!8182&authkey=aautw8tvzxr5v3a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005168; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1c14977b48a91558&resid=1c14977b48a91558%218182&authkey=aautw8tvzxr5v3a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005169; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1cbd82dd55d70086&resid=1cbd82dd55d70086%212526&authkey=aogaboensav3jrg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005170; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1dbdf62bc3c2b05b&resid=1dbdf62bc3c2b05b!134&authkey=ape6bhxn7c89z60"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005171; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005172; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005173; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005174; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!123&authkey=am1rcmkppbht8v0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005175; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!124&authkey=am5sltharf-j_cc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005176; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!125&authkey=acgvgbbuowodg4c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005177; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21122&authkey=aa2f8su-5bfjlvs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005178; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005179; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21123&authkey=am1rcmkppbht8v0&c=3ii9gcd&r=7azia71ojgc8rxd0dmkukm&k=7s1&s=htgxfkpr86ttvokhkcn3enmimk12ewqfiglklz23spd"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005180; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21124&authkey=am5sltharf-j_cc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005181; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2%21125&authkey=acgvgbbuowodg4c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005182; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21154&authkey=alkjikpdfxvm8po"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005183; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21155&authkey=afu-yax_gxxddoe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005184; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=24ef9e675b079af9&resid=24ef9e675b079af9%21156&authkey=alqvv8nixrvsqrk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005185; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f!191&authkey=ajvumpkzpla_nca"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005186; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=265daf943be0d06f&resid=265daf943be0d06f%21191&authkey=ajvumpkzpla_nca"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005187; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=26bbd7d5ad88dd29&resid=26bbd7d5ad88dd29%21115&authkey=acipfa3gbiqqcvu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005188; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=26f87316a7e32bb5&resid=26f87316a7e32bb5%21106&authkey=aepqo5hlkxn1t1k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005189; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2831401bbac0235e&resid=2831401bbac0235e%211037&authkey=aagnkp6l76yhrlo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005190; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!182&authkey=apogh8yf-fj8xvk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005191; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!183&authkey=am4thhgmi0nlxei"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005192; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0!185&authkey=akttgkvu39ugyte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005193; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21182&authkey=apogh8yf-fj8xvk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005194; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21183&authkey=am4thhgmi0nlxei"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005195; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=283ee3d25488f2c0&resid=283ee3d25488f2c0%21185&authkey=akttgkvu39ugyte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005196; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2894380eb084b79e&resid=2894380eb084b79e%21253&authkey=aimqerwvuylzjga"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005197; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2992e4d36c2a7dae&resid=2992e4d36c2a7dae%21132&authkey=af05vsjkocy8lly"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005198; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2b6e98d9e0cf1a17&resid=2b6e98d9e0cf1a17!2471&authkey=ai5r4hqy9i0g1qs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005199; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2b6e98d9e0cf1a17&resid=2b6e98d9e0cf1a17%212471&authkey=ai5r4hqy9i0g1qs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005200; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c1abc526306a6e1&resid=2c1abc526306a6e1%21106&authkey=adjthwhvjkbioc0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005201; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21109&authkey=aopcxq3owfiv620"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005202; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21114&authkey=ajzoj0ujggsnxlo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005203; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21115&authkey=aglznnsx71tbe9e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005204; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37!183&authkey=akon9i9zzhusiuk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005205; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37%21183&authkey=akon9i9zzhusiuk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005206; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6!161&authkey=aovldmsenzzpjrw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005207; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6%21161&authkey=aovldmsenzzpjrw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005208; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f01a497b687285e&resid=2f01a497b687285e!734&authkey=aiumuxtp3phppy4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005209; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f01a497b687285e&resid=2f01a497b687285e%21734&authkey=aiumuxtp3phppy4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005210; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!116&authkey=!abwledjhfsqwap4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005211; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!121&authkey=!aa0qbuuss-wb13w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005212; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1!119&authkey=apmakx2cqb9rimu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005213; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21118&authkey=acrl2iiem-zjer8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005214; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2f947402293c14c1&resid=2f947402293c14c1%21119&authkey=apmakx2cqb9rimu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005215; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=2ffaa48ef4bec51a&resid=2ffaa48ef4bec51a%21107&authkey=aiohrvrc3uuo_cw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005216; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=30e33fc2c147c72f&resid=30e33fc2c147c72f!2742&authkey=ajviks-nvgb4gqs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005217; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=30e33fc2c147c72f&resid=30e33fc2c147c72f!2743&authkey=ao4um908kkhavqg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005218; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=30e33fc2c147c72f&resid=30e33fc2c147c72f%212742&authkey=ajviks-nvgb4gqs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005219; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=30e33fc2c147c72f&resid=30e33fc2c147c72f%212743&authkey=ao4um908kkhavqg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005220; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!320&authkey=aooujzuf408dclw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005221; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693!321&authkey=almpxnbtsbzauna"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005222; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21320&authkey=aooujzuf408dclw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005223; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3112e77688f09693&resid=3112e77688f09693%21321&authkey=almpxnbtsbzauna"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005224; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3164ddeba70d2263&resid=3164ddeba70d2263%21106&authkey=afkvqrm4zoor8qq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005225; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=31771958ea3373a1&resid=31771958ea3373a1%21108&authkey=aiofxduo9rdb_-o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005226; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=34207675f7506d94&resid=34207675f7506d94%21137&authkey=angxnhqpe2x5koc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005227; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005228; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005229; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005230; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!198&authkey=acyz0gbpl6bp9mo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005231; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!199&authkey=admaszabh84m8ou"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005232; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e%21198&authkey=acyz0gbpl6bp9mo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005233; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e%21199&authkey=admaszabh84m8ou"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005234; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!152&authkey=am09sv26njxzyn0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005235; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65!153&authkey=ajs0jkoeqkqjrze"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005236; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21152&authkey=am09sv26njxzyn0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005237; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21153&authkey=ajs0jkoeqkqjrze"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005238; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3a1715e2cb964f25&resid=3a1715e2cb964f25%213713&authkey=aortxmfnibnoqkk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005239; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21432&authkey=aa_npsupyqb2kge"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005240; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21435&authkey=admsjhgpkbtcqzs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005241; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005242; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f%21154&authkey=aasj15d0g_p2pog"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005243; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f!134&authkey=aaipzy8nllirlky"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005244; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4000200b3fb8c24f&resid=4000200b3fb8c24f%21134&authkey=aaipzy8nllirlky"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005245; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=40cbf21d67b770f7&resid=40cbf21d67b770f7%21140&authkey=ah0uewz9k7-lzd0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005246; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2!106&authkey=aoigmqhuw6vqijm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005247; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4266fcac716657a2&resid=4266fcac716657a2%21106&authkey=aoigmqhuw6vqijm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005248; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21108&authkey=akr9cesktucbqik"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005249; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=44d422e98133708b&resid=44d422e98133708b%21109&authkey=adzxmpjk-etbkjq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005250; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=45f0213456d899c0&resid=45f0213456d899c0%211133&authkey=alwgkm79xod8hpy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005251; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa!450&authkey=ahw0j-cme0jg6pw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005252; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=470febb155be50fa&resid=470febb155be50fa%21450&authkey=ahw0j-cme0jg6pw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005253; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=489dd700ea74963a&resid=489dd700ea74963a%21206&authkey=acgkmxuk000jse8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005254; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=489dd700ea74963a&resid=489dd700ea74963a%21210&authkey=aotjil_l-s-xh1c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005255; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ada4e22fff3e13&resid=48ada4e22fff3e13%21421&authkey=acd1sidm8c5fk0y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005256; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13805&authkey=ae-zbfo2uwln_gg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005257; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66!13806&authkey=aakiq-ymrjjodns"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005258; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113805&authkey=ae-zbfo2uwln_gg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005259; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=48ed7695f8804d66&resid=48ed7695f8804d66%2113806&authkey=aakiq-ymrjjodns"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005260; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4ab7eafa48707b54&resid=4ab7eafa48707b54%21105&authkey=amb4gnkdn8igw8y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005261; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4b676ea3ff139b93&resid=4b676ea3ff139b93!133&authkey=amfix63glytflgo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005262; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21127&authkey=ablg20r-aat_ob4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005263; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4d4d07581d39b63d&resid=4d4d07581d39b63d%21131&authkey=akbwlkrrtso_bqm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005264; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4df11eda676a355f&resid=4df11eda676a355f!130&authkey=!akd6uxvljtlvpxu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005265; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b!108&authkey=anbjpqxg-iwr4g8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005266; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e45a2988ed9335b&resid=4e45a2988ed9335b%21108&authkey=anbjpqxg-iwr4g8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005267; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21337&authkey=ahhqrhiv2ei4xjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005268; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=4e57dde6c5c6b372&resid=4e57dde6c5c6b372%21344&authkey=aatlbjfo3tjnx2y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005269; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21105&authkey=ajkwu0e9dzantl8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005270; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21107&authkey=apd9um4_12-kpe0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005271; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21116&authkey=anbj_rrcgyturjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005272; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21119&authkey=amrs3-3hsvcmtfs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005273; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21158&authkey=aodderdrnvhruts"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005274; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21161&authkey=agdsfxdnre82jjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005275; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21192&authkey=agn2xvrvup-xvtg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005276; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21206&authkey=ai1r52mhtbdnm2y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005277; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21247&authkey=ae6weny1fa4pday"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005278; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21252&authkey=aphl0oi4r6lrty0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005279; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21257&authkey=afnyvqwcghnyoas"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005280; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21265&authkey=abxqdhlwiurjvve"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005281; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21271&authkey=ae5qwlr5ceeptmy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005282; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21272&authkey=ahrqeoaynibwt14"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005283; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21275&authkey=af_sgsaxsmaxg7i"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005284; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21289&authkey=angyngbqixtrjaa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005285; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21293&authkey=acvh08asxosbwfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005286; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21299&authkey=amicxuotubpok2c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005287; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21306&authkey=ahpivoukyerzcjy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005288; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21314&authkey=aex2uv2-eiofr8q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005289; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21332&authkey=ad0jmjxgbaebvbm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005290; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21335&authkey=ah0vupcfbdfa6g4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005291; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21357&authkey=ap8sswuqjjjexho"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005292; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21366&authkey=aoblpmbmx7o_v18"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005293; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21379&authkey=air-bsjj46et47q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005294; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21389&authkey=aduenohuq_rbyhm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005295; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21391&authkey=aa15sw51njbn_na"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005296; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21392&authkey=abp0heeg6ybn0lk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005297; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5012a067b5dec1df&resid=5012a067b5dec1df%21393&authkey=aa1pmur8sy8xtwe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005298; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212718&authkey=aie0v1d-cusuabi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005299; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212725&authkey=aanrz9et3bym3lc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005300; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=501b63131ab62dd6&resid=501b63131ab62dd6%212728&authkey=ahsmbkltfrwgqjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005301; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!395&authkey=alwvub_yhtogjxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005302; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!398&authkey=abaa_tjd7ohh4so"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005303; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!406&authkey=aarnp48wumgu6tq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005304; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!415&authkey=aglzsd6-g0nzj7s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005305; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!420&authkey=akk5droung_ecww"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005306; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c!440&authkey=ai7-dpr11wnzyq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005307; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21395&authkey=alwvub_yhtogjxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005308; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21398&authkey=abaa_tjd7ohh4so"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005309; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21406&authkey=aarnp48wumgu6tq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005310; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21415&authkey=aglzsd6-g0nzj7s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005311; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21420&authkey=akk5droung_ecww"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005312; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=505be76830f4dc4c&resid=505be76830f4dc4c%21440&authkey=ai7-dpr11wnzyq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005313; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211121&authkey=al_fmezwfay4za4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005314; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=513190d240e51e0e&resid=513190d240e51e0e%211122&authkey=anz_q5njlanv2mu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005315; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21110&authkey=akars6koxqzdwgi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005316; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=52ca67cbc48c0212&resid=52ca67cbc48c0212%21112&authkey=aadare1gec7nzy8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005317; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005318; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d!109&authkey=adriswrtwdpbuc8&em=2"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005319; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53965c96e65f4f6d&resid=53965c96e65f4f6d%21109&authkey=adriswrtwdpbuc8&em=2"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005320; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=53c5e6b8f6893887&resid=53c5e6b8f6893887!802&authkey=aapuufivkn2zwu8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005321; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!106&authkey=anzlf1ksptbqok8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005322; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3!107&authkey=ag4dr58jrjuxfyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005323; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21106&authkey=anzlf1ksptbqok8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005324; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=541a106160d50be3&resid=541a106160d50be3%21107&authkey=ag4dr58jrjuxfyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005325; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=547b1e4a6b15bf97&resid=547b1e4a6b15bf97%21106&authkey=akgsmzqhemioz8g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005326; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=54f92c3a2f5d8033&resid=54f92c3a2f5d8033%21200&authkey=aofadhhfwlm2gum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005327; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5521b68dc17baf21&resid=5521b68dc17baf21%21129&authkey=ajdr2dbh-9h63wa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005328; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=55381ffd75ef8cda&resid=55381ffd75ef8cda!270&authkey=aev4isgyubiofdi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005329; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613!157&authkey=an55tjzt-9vbjfy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005330; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=554bbd19bdd72613&resid=554bbd19bdd72613%21156&authkey=agiuawekkbxb_4o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005331; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=55c9feaf3907aae5&resid=55c9feaf3907aae5%21208&authkey=adwuyrapfdzkyoa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005332; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950!280&authkey=advq4p3xhfhinq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005333; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5607da13ee53f950&resid=5607da13ee53f950%21280&authkey=advq4p3xhfhinq8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005334; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5629da828892367d&resid=5629da828892367d!803&authkey=aphjbq-bsg7ohpc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005335; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21383&authkey=adldpuaya7kj1dk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005336; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5696478acb744989&resid=5696478acb744989%21384&authkey=alsuxvtsof32vea"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005337; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3599&authkey=am4yicme6lrjpki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005338; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d!3604&authkey=al6pb71mtq4jr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005339; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213599&authkey=am4yicme6lrjpki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005340; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57b52435d7fee30d&resid=57b52435d7fee30d%213604&authkey=al6pb71mtq4jr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005341; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b!68197&authkey=aowpm7ocl_21-oc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005342; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=57c0958db500fe0b&resid=57c0958db500fe0b%2168197&authkey=aowpm7ocl_21-oc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005343; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=59389d626d829e8c&resid=59389d626d829e8c%212940&authkey=anx1ngd27vqeiwo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005344; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211568&authkey=aemrnwoi75oflva"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005345; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211572&authkey=aelz-gxlrxcwtnc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005346; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5bf0e9600d9f9da0&resid=5bf0e9600d9f9da0%211573&authkey=ahksfdvda0doles"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005347; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5c5404bd403dbdc9&resid=5c5404bd403dbdc9!4464&authkey=ajskjf2hshbudeg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005348; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!406&authkey=aeyeq5j9zfepgai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005349; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052!407&authkey=adnh8af-rvoxlcc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005350; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21406&authkey=aeyeq5j9zfepgai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005351; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5f3a7a50acb94052&resid=5f3a7a50acb94052%21407&authkey=adnh8af-rvoxlcc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005352; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21892&authkey=apwphufzjdtsedw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005353; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=5fb9958ff55c0123&resid=5fb9958ff55c0123%21897&authkey=aomt6el1av5ruc8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005354; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21121&authkey=adjzlorvgx_ezhq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005355; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21123&authkey=ancfnepawtbmnug"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005356; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21124&authkey=ao7bknnuodxtfua"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005357; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=604aa6c584db9137&resid=604aa6c584db9137%21126&authkey=an6sswp8an1kfoe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005358; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6196314c52185efc&resid=6196314c52185efc%21106&authkey=ape4rx1hrtmrxxe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005359; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!490&authkey=aljraz5ktivqax4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005360; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!491&authkey=aopwdha2wyjx0aa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005361; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!492&authkey=akwg8p5adkpjm5w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005362; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26!493&authkey=aeg__7wcf7esydo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005363; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21490&authkey=aljraz5ktivqax4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005364; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21491&authkey=aopwdha2wyjx0aa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005365; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21492&authkey=akwg8p5adkpjm5w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005366; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=62c7ac7a7afece26&resid=62c7ac7a7afece26%21493&authkey=aeg__7wcf7esydo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005367; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=65d5e5f1b48c0d94&resid=65d5e5f1b48c0d94!852&authkey=adzvvmms349gxmi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005368; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=65f2f37122477ee7&resid=65f2f37122477ee7%211001&authkey=ap3umqxngmtk-6e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005369; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e!1094&authkey=anqjzd7pr18fu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005370; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6601b18b9069ce5e&resid=6601b18b9069ce5e%211094&authkey=anqjzd7pr18fu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005371; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21129&authkey=ak5szbnikeklmzk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005372; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6605275726c6094a&resid=6605275726c6094a%21132&authkey=ad3ia_1wkq0lyd4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005373; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6608a4dea9ff5918&resid=6608a4dea9ff5918%21399&authkey=aoya7flv_s9toxo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005374; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=67daf26e53a5f9c2&resid=67daf26e53a5f9c2%21505&authkey=ag7xi3lcnvi_hji"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005375; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad!1421&authkey=adixg2-asekemjw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005376; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=67f7a3925acbb2ad&resid=67f7a3925acbb2ad%211421&authkey=adixg2-asekemjw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005377; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213096&authkey=aob-cm9vv6erxqg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005378; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6819bca13312697b&resid=6819bca13312697b%213097&authkey=abcuevfyu6pdw70"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005379; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=69b503a3f081a183&resid=69b503a3f081a183%21111&authkey=aazm9wlg1rvgzoc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005380; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!112&authkey=aasndgbcwol3mys"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005381; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072!113&authkey=ak3tzu1lg4uuh5m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005382; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21112&authkey=aasndgbcwol3mys"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005383; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a1602e410531072&resid=6a1602e410531072%21113&authkey=ak3tzu1lg4uuh5m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005384; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21108&authkey=ameouv2jdxo5obw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005385; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a4147b45f4b0876&resid=6a4147b45f4b0876%21119&authkey=aazzzrl7mv2xbwq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005386; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6a7b40a2bc530c6c&resid=6a7b40a2bc530c6c%21112&authkey=afuov36rbymlvxm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005387; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3!118&authkey=aepf8f3mfmlsng0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005388; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b3ee3b3b5fb10d3&resid=6b3ee3b3b5fb10d3%21118&authkey=aepf8f3mfmlsng0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005389; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b61e983f930f79f&resid=6b61e983f930f79f!540&authkey=ap2n5w41ifew0i8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005390; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7!1154&authkey=acnbdscb8-rbmcu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005391; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=6b71cecfb2f8c8a7&resid=6b71cecfb2f8c8a7%211154&authkey=acnbdscb8-rbmcu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005392; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21106&authkey=apvhok6edhtogfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005393; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=70c4976fc04ddb54&resid=70c4976fc04ddb54%21115&authkey=amc_k1nnlywdc4i"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005394; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=724b5c509337556e&resid=724b5c509337556e%21908&authkey=agcbb3nakpteyam"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005395; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7285f51e65036769&resid=7285f51e65036769%21264&authkey=akyjvrz006qlble"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005396; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21243&authkey=apivjmxivosek60"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005397; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21256&authkey=adljht0ogfq775k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005398; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21260&authkey=aig6cydr4_e-qj8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005399; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21262&authkey=ak4fiz1-a1ks8rg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005400; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7366fefc2190d2e3&resid=7366fefc2190d2e3%21264&authkey=aizkjymvlgqwpte"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005401; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=77518d098ad4dfb0&resid=77518d098ad4dfb0%21939&authkey=akzqobxxxn89z34"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005402; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005403; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005404; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21117&authkey=aivf1ddcvvu22em"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005405; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb!211&authkey=anxavz-oaf9pv_c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005406; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21210&authkey=agpl0pgvft8faaa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005407; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21211&authkey=anxavz-oaf9pv_c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005408; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005409; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!120&authkey=ajj7ueqjvobgfum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005410; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21119&authkey=aozjai26izprqto"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005411; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f%21120&authkey=ajj7ueqjvobgfum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005412; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c1fc7da38ab958e&resid=7c1fc7da38ab958e!146&authkey=aktmjqz8n4s_sbm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005413; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125575&authkey=ahnmpmvzshrwoyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005414; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c3f8e95e474dff2&resid=7c3f8e95e474dff2%2125579&authkey=amhnrbwecb4hp_k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005415; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5295&authkey=aasceqj1mdodeuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005416; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5296&authkey=ank3vz5syaf6bny"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005417; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7!5298&authkey=albzyizuqczfv9s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005418; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215295&authkey=aasceqj1mdodeuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005419; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215296&authkey=ank3vz5syaf6bny"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005420; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7c41ddcfa01aeff7&resid=7c41ddcfa01aeff7%215298&authkey=albzyizuqczfv9s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005421; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7d109f249b512466&resid=7d109f249b512466!543&authkey=acqc4xjghclmwbs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005422; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b!183&authkey=aggjy50pjuecoli"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005423; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21181&authkey=ama3betib0dac18"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005424; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7d717e2107245d5b&resid=7d717e2107245d5b%21183&authkey=aggjy50pjuecoli"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005425; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!443&authkey=abue79u9di9axjm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005426; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0!444&authkey=abzxvycu0ggtmg8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005427; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0%21443&authkey=abue79u9di9axjm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005428; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7e5a4eadcfc79be0&resid=7e5a4eadcfc79be0%21444&authkey=abzxvycu0ggtmg8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005429; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7e81645429ac5a22&resid=7e81645429ac5a22%21105&authkey=aa691jwf5wqi80c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005430; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=7fed4fbea32e3c1e&resid=7fed4fbea32e3c1e%21107&authkey=aeoxfycpolifch0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005431; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=806bac90dc071edf&resid=806bac90dc071edf!105&authkey=!ao7jyz6-licb8hq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005432; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=81c2d8b116274e17&resid=81c2d8b116274e17%21107&authkey=aaqw-t4dx2sbvda"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005433; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=82977114b1af209d&resid=82977114b1af209d!220&authkey=abuin5vdedjughm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005434; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=860a0980486c93fa&resid=860a0980486c93fa!303&authkey=!agcmlab4r6syfvk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005435; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21164&authkey=agbeiinncf8ok_4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005436; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=87dc3e587977c459&resid=87dc3e587977c459%21165&authkey=aiof8rdvxglnm-c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005437; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4!2402&authkey=amigiam45mt6jia"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005438; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=883587d3e32ee1c4&resid=883587d3e32ee1c4%212402&authkey=amigiam45mt6jia"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005439; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=890837b4e4ca07c6&resid=890837b4e4ca07c6%21289&authkey=abujc0akmtbsxf4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005440; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8983011c6ecfb1d8&resid=8983011c6ecfb1d8%21132&authkey=ah0vja7wpyfjj84"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005441; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8a1574ed0cecd68a&resid=8a1574ed0cecd68a%21395&authkey=ane01evt0sz-1wk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005442; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8c77cee60e33a6b1&resid=8c77cee60e33a6b1%21106&authkey=af8h8jn801bjnbk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005443; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8ca507baa15fdb5c&resid=8ca507baa15fdb5c!213&authkey=acyrjlhflcrypae"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005444; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=8ffd8cbd6540c065&resid=8ffd8cbd6540c065!822&authkey=acfj7bbrmktj1i0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005445; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=907247dc330a3f33&resid=907247dc330a3f33!243&authkey=aeiqd4ihuqopwm8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005446; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005447; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25!130&authkey=ais_g9dqoddonsc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005448; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005449; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21109&authkey=akr1n3qxtmnttuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005450; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21113&authkey=ajpvf1h89sqstti"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005451; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!289&authkey=aoiy68zx8ddnjhe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005452; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!290&authkey=afn1bhvmpaicari"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005453; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!291&authkey=aknqfhnxttsrvz4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005454; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!297&authkey=agy0f-5almc6_ia"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005455; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896!298&authkey=ajiut2kebcaycok"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005456; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21288&authkey=ag9wi9pub-q4jly"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005457; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21289&authkey=aoiy68zx8ddnjhe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005458; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21290&authkey=afn1bhvmpaicari"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005459; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21291&authkey=aknqfhnxttsrvz4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005460; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21295&authkey=afvy6r0mspzeb6m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005461; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21297&authkey=agy0f-5almc6_ia"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005462; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21298&authkey=ajiut2kebcaycok"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005463; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9275d37a9c4d4896&resid=9275d37a9c4d4896%21299&authkey=agmfs3scdvngolm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005464; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21105&authkey=ah9x7rn0p03kd_m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005465; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=944cfbbd7823d265&resid=944cfbbd7823d265%21110&authkey=ammswulpdsjeu4w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005466; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3!107&authkey=ac-m9dlvo5l7wfk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005467; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=94fefff7000581d3&resid=94fefff7000581d3%21107&authkey=ac-m9dlvo5l7wfk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005468; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=96a54b19ff5f6bab&resid=96a54b19ff5f6bab%21107&authkey=anxv07ez7s5sh_k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005469; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21410&authkey=acwug6bewxk0pli"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005470; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=96e7ccc5d61517fc&resid=96e7ccc5d61517fc%21411&authkey=aj8o1fcvfhibmlm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005471; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=96fd249b957988a2&resid=96fd249b957988a2%211303&authkey=ah_etf1fqofknue"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005472; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935!778&authkey=aaezyk4ypt-elma"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005473; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21772&authkey=akeozmv0aafqlbg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005474; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21774&authkey=aly_m3fnrvh6dfq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005475; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21775&authkey=abblpjxi4mwomgs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005476; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=97b465ea1ddc3935&resid=97b465ea1ddc3935%21777&authkey=ahmuwqi4jg8rvho"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005477; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=98103c88c2d68867&resid=98103c88c2d68867!773&authkey=akptbml43mi4ufc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005478; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211925&authkey=amhhfhcsigeue9w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005479; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211927&authkey=an_3paqpemptbvm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005480; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211953&authkey=abdfqiyruwplpo0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005481; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=982b2c4bb2a23649&resid=982b2c4bb2a23649%211954&authkey=aok-srkhxjazccy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005482; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21172&authkey=ahharhcv0fmn5fm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005483; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21173&authkey=aecb3qcquacvzhi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005484; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21174&authkey=afv7cprqwxezgsi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005485; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005486; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005487; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005488; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005489; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005490; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005491; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340!997&authkey=akw6btyej2zht08"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005492; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a0fb3cde2e262340&resid=a0fb3cde2e262340%21997&authkey=akw6btyej2zht08"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005493; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a1c8c8055848b889&resid=a1c8c8055848b889!111&authkey=agzlftsgr4lspvo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005494; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a2cd2cdb93584d7e&resid=a2cd2cdb93584d7e%21106&authkey=aeifpqbwo1s3dyq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005495; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211064&authkey=apebndb6tstxywi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005496; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211065&authkey=aca4_dggi5gbbfs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005497; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211067&authkey=ae-3ej9zzj4ibhw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005498; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4000de54b92dcc6&resid=a4000de54b92dcc6%211069&authkey=agx6b8qjt_clm-o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005499; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a4acaf66051e469e&resid=a4acaf66051e469e!189&authkey=alnhzcg0wzhusdc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005500; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a502994ea313f5c7&resid=a502994ea313f5c7%21215&authkey=aiydvejv0l8stbs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005501; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21!6053&authkey=agfh0ahstj7rrki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005502; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21%216053&authkey=agfh0ahstj7rrki"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005503; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005504; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21414&authkey=akf9uwwkitvhrvc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005505; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21415&authkey=ag_5kthuezprnoy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005506; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21416&authkey=airlma-pycgfkyc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005507; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21419&authkey=ab1-sgyv2gibyey"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005508; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21422&authkey=acphsmdy415izjg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005509; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21424&authkey=afvfwz5uvde1pui"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005510; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=a819c72315838312&resid=a819c72315838312%21112&authkey=abl1vflnfw3nrgi"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005511; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=aa4e252db942faec&resid=aa4e252db942faec%21168&authkey=anlnjo7xnwtswuk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005512; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ae28961c75435487&resid=ae28961c75435487%21106&authkey=alph5awcis8r9iw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005513; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992!113&authkey=agh9q_zzyjjcspc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005514; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ae80108520d75992&resid=ae80108520d75992%21113&authkey=agh9q_zzyjjcspc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005515; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=af84ebf13dd5499c&resid=af84ebf13dd5499c!167&authkey=anqr_yvn_hdh2_e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005516; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308!2152&authkey=abutaac83l5utks"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005517; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b03ee17d51411308&resid=b03ee17d51411308%212152&authkey=abutaac83l5utks"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005518; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b0fddd36b3843d3b&resid=b0fddd36b3843d3b!561&authkey=abhena0pdghcveu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005519; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b0fddd36b3843d3b&resid=b0fddd36b3843d3b%21561&authkey=abhena0pdghcveu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005520; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21650&authkey=aht-wbxsofyx33u"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005521; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21651&authkey=aebbyk6sevdmzgm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005522; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1239884e2deb3b9&resid=b1239884e2deb3b9%21652&authkey=afsw5wahxo5kwjy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005523; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b1c3a5ef115e135c&resid=b1c3a5ef115e135c%216219&authkey=ahr7bklirbub0pc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005524; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b2289382b9cf7ba8&resid=b2289382b9cf7ba8%21106&authkey=ajwobaztcbbpxmy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005525; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21120&authkey=aozmspl2dqkgkgy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005526; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3805920e5eb0711&resid=b3805920e5eb0711%21123&authkey=aj18p0rtfbtwa84"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005527; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21139&authkey=ahwfjvw4zmjukeo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005528; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21140&authkey=aksvfpmrfqrrggw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005529; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21141&authkey=acznh6clby0qyww"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005530; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21142&authkey=ajf7j1rr3d7jcxy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005531; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b3a118354e81d1bb&resid=b3a118354e81d1bb%21143&authkey=ahs21wnsqb_vu9w"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005532; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b50c4248502103d0&resid=b50c4248502103d0%21107&authkey=alf1nley7ja4dbq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005533; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6!164&authkey=adfsfcdaw3biboy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005534; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b5ea8d4249d866e6&resid=b5ea8d4249d866e6%21164&authkey=adfsfcdaw3biboy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005535; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b7cb31db66675eb4&resid=b7cb31db66675eb4%21922&authkey=aghayyucvwey7lg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005536; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b86046e8cbd4254b&resid=b86046e8cbd4254b%21115&authkey=agwstptwpaquleg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005537; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b!7521&authkey=ablt9zdyq2d4rb0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005538; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b8ba73db68da7c0b&resid=b8ba73db68da7c0b%217521&authkey=ablt9zdyq2d4rb0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005539; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b90c1aa3b6cd0326&resid=b90c1aa3b6cd0326%21471&authkey=aoil8ra4oc4s_2m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005540; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=b9690a1860a591d0&resid=b9690a1860a591d0%21161&authkey=aehawjpwf6tqtm8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005541; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b!246&authkey=afyrchdutalpu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005542; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=beaf30da1f621c9b&resid=beaf30da1f621c9b%21246&authkey=afyrchdutalpu90"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005543; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=bf83d9247c2329e0&resid=bf83d9247c2329e0%211108&authkey=absaw-bpqrc6mpq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005544; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214199&authkey=adgqe8qiyu92bqm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005545; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214200&authkey=adqtju8i3nmlgai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005546; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c121261804708478&resid=c121261804708478%214201&authkey=ahqber27s7gg8kk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005547; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019!1251&authkey=act34eizpzjugfa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005548; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c359b1a8babc6019&resid=c359b1a8babc6019%211251&authkey=act34eizpzjugfa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005549; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1337&authkey=afnvu1fsuczht5e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005550; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1338&authkey=ajngambosws75_c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005551; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1340&authkey=al1ay3fbtude6d8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005552; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1342&authkey=acpr_htn2jtaxfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005553; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1343&authkey=abodysrxu9l2xxu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005554; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1344&authkey=aozerppd6mnokwy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005555; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1345&authkey=aevvyhonxhtcdh0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005556; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1346&authkey=achrnf5vlov1gf4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005557; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e!1347&authkey=al-zge-ttvr921s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005558; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211337&authkey=afnvu1fsuczht5e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005559; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211338&authkey=ajngambosws75_c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005560; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211340&authkey=al1ay3fbtude6d8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005561; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211342&authkey=acpr_htn2jtaxfu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005562; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211343&authkey=abodysrxu9l2xxu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005563; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211344&authkey=aozerppd6mnokwy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005564; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211345&authkey=aevvyhonxhtcdh0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005565; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211346&authkey=achrnf5vlov1gf4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005566; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c3d8ad85ba2add4e&resid=c3d8ad85ba2add4e%211347&authkey=al-zge-ttvr921s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005567; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c701663053a57d59&resid=c701663053a57d59%211009&authkey=ahowgkak7j0p2q8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005568; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21486&authkey=amy4euf_rrlcykc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005569; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c71b410673c49a80&resid=c71b410673c49a80%21489&authkey=ako3anwfnqfohnc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005570; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c7c32628aba70e70&resid=c7c32628aba70e70%21114&authkey=agdy8xpuh32sluw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005571; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c80630c4d385fb9d&resid=c80630c4d385fb9d%21286&authkey=amgaucv8bld_5qs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005572; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c8b0c7dc2b2570c5&resid=c8b0c7dc2b2570c5!122&authkey=aa4yfqt4cckzxhe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005573; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=c8b0c7dc2b2570c5&resid=c8b0c7dc2b2570c5%21122&authkey=aa4yfqt4cckzxhe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005574; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21546&authkey=aa6q-ryiifnet5m"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005575; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca308e3d3912d9e7&resid=ca308e3d3912d9e7%21547&authkey=aipm8qnwbgo4yga"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005576; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!355&authkey=aajjwf_sm4xdqdk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005577; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b!357&authkey=alw3vqqxz6myrle"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005578; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21354&authkey=aa_ukeour7rex1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005579; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21355&authkey=aajjwf_sm4xdqdk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005580; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca50a85094f0b78b&resid=ca50a85094f0b78b%21357&authkey=alw3vqqxz6myrle"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005581; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ca897bdd16fc7940&resid=ca897bdd16fc7940%21106&authkey=aniklpt8vtlahbg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005582; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2!109&authkey=ac4gxwjoopafr9a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005583; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cb64e6e1a6ce15a2&resid=cb64e6e1a6ce15a2%21109&authkey=ac4gxwjoopafr9a"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005584; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cbb66cac420484bc&resid=cbb66cac420484bc!10968&authkey=aj9bjkobu-rlnaw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005585; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!742&authkey=akbxju17f8g0r2s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005586; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d!744&authkey=adak4zftd0yhhhs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005587; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21742&authkey=akbxju17f8g0r2s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005588; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=cf0c6d1a4c15233d&resid=cf0c6d1a4c15233d%21744&authkey=adak4zftd0yhhhs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005589; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!872&authkey=ap9hchztywo8zuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005590; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!874&authkey=alkzcbxz-dscgum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005591; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85!875&authkey=aka55ybdhqnoc6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005592; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21872&authkey=ap9hchztywo8zuo"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005593; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21874&authkey=alkzcbxz-dscgum"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005594; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d06d60404544fb85&resid=d06d60404544fb85%21875&authkey=aka55ybdhqnoc6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005595; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d2f3748954f6f8a8&resid=d2f3748954f6f8a8%21119&authkey=aex5s9uoun2zps0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005596; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1029&authkey=ann3uz8huqi7ogw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005597; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1030&authkey=aeqnasuksxccax4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005598; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1031&authkey=acxtarrhbwrqt20"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005599; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1032&authkey=aemitbkn-vma9yk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005600; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1033&authkey=abiydifgst6musa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005601; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1035&authkey=ahd_ichsrf8ok_u"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005602; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7!1038&authkey=anxf-kuw1jn9-8y"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005603; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211029&authkey=ann3uz8huqi7ogw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005604; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211030&authkey=aeqnasuksxccax4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005605; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211031&authkey=acxtarrhbwrqt20"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005606; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211032&authkey=aemitbkn-vma9yk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005607; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211033&authkey=abiydifgst6musa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005608; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211035&authkey=ahd_ichsrf8ok_u"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005609; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!191&authkey=ajl2uegqunsgc3q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005610; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!192&authkey=acd_hx4bka3z0nw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005611; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21191&authkey=ajl2uegqunsgc3q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005612; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21192&authkey=acd_hx4bka3z0nw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005613; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005614; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21107&authkey=alo4lep7wht05na"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005615; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21109&authkey=adnbm6mekgzvvh8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005616; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!141&authkey=alya4infudqs53o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005617; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!142&authkey=aiemnxi-s-5vrz0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005618; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21141&authkey=alya4infudqs53o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005619; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21142&authkey=aiemnxi-s-5vrz0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005620; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5%21142&authkey=aiemnxi-s-5vrz0&c=3ii9gcd&r=5onulz3wldybwlmup37su3&k=7s1&s=kzymn52eroemh1tamvmlsfsn9jtvwguukky5hlxcfgw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005621; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=db0fc77df51690e1&resid=db0fc77df51690e1%21802&authkey=apefr8w_rdk--pe"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005622; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=db5548cd728f142b&resid=db5548cd728f142b%21187&authkey=aansxudby0o7uwq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005623; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=db62f747c6d887d0&resid=db62f747c6d887d0%21111&authkey=ai2guftczvfehs4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005624; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dcd65237fcd1a1a9&resid=dcd65237fcd1a1a9%21162&authkey=aprqs0hugnfo6uq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005625; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7527&authkey=aipybipwht56um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005626; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7530&authkey=am9p2ic6zdkgfmy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005627; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5!7532&authkey=aonjnubquvon_uk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005628; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217527&authkey=aipybipwht56um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005629; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217530&authkey=am9p2ic6zdkgfmy"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005630; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=dd0a0ec58f4ac5f5&resid=dd0a0ec58f4ac5f5%217532&authkey=aonjnubquvon_uk"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005631; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21107&authkey=akrabrcroiddkxw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005632; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21115&authkey=ad1ncwtj_zcjsh0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005633; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21132&authkey=akpbxohbtjebyn4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005634; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21150&authkey=aevazjbqnu7cmjs"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005635; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e08e2d452e10fc69&resid=e08e2d452e10fc69%21160&authkey=aiendf-9lyln0x0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005636; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e1065ab3e86a5fc2&resid=e1065ab3e86a5fc2%211443&authkey=apybkcvf4iwxp_q"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005637; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e3ddc3980f743711&resid=e3ddc3980f743711%21795&authkey=aptivsvyk2we5xc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005638; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21745&authkey=ah1i_jo73zgdxpc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005639; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e424d4f4fe44dedf&resid=e424d4f4fe44dedf%21746&authkey=ag1mhwlznwdxpw0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005640; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e43694f4bd6f68d1&resid=e43694f4bd6f68d1!563&authkey=aj8ovsob9ll6r-c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005641; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!509&authkey=akmdyqkzcsuf_gg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005642; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c!511&authkey=agfs0q7dz7os1lu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005643; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e4b1e1072dc91f5c&resid=e4b1e1072dc91f5c%21511&authkey=agfs0q7dz7os1lu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005644; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e54ea4e0368d023b&resid=e54ea4e0368d023b%21106&authkey=aozas6g9pm0fzvq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005645; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21349&authkey=ae9ea8jdsa7vmom"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005646; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21350&authkey=ao-vuexoihzj7da"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005647; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2!142&authkey=ais88uad5aom6qu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005648; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2%21142&authkey=ais88uad5aom6qu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005649; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e97110434470423e&resid=e97110434470423e%21113&authkey=afowclex54if0g0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005650; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005651; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005652; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211215&authkey=ac1jr_bieufz0ai"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005653; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ead0e1196bd04320&resid=ead0e1196bd04320%211219&authkey=akgo75rmvr4khlc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005654; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ebacca5dec27fd20&resid=ebacca5dec27fd20%2118735&authkey=ajfyl1mzidnylc8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005655; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21113&authkey=aovavpmokd2jrns"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005656; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=edd7401a7180b54c&resid=edd7401a7180b54c%21116&authkey=aadnj5xyfasugu8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005657; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ef04dd7f0a6a5f7c&resid=ef04dd7f0a6a5f7c%21142&authkey=aad-nuysvlhc-i4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005658; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!202&authkey=ah1gjq8j29darw4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005659; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!203&authkey=af8xr99mrqp8um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005660; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928!204&authkey=ad0nbzlscbg-0sa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005661; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21202&authkey=ah1gjq8j29darw4"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005662; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21203&authkey=af8xr99mrqp8um8"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005663; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=efdf2c8d834a1928&resid=efdf2c8d834a1928%21204&authkey=ad0nbzlscbg-0sa"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005664; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21489&authkey=ads_gff3tjkd0w0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005665; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21490&authkey=aj_rld7xooge6aw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005666; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f05e45800a084e63&resid=f05e45800a084e63%21492&authkey=ahdb75ptd1_uc8e"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005667; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f06038a5f7dbd6d6&resid=f06038a5f7dbd6d6%215498&authkey=aiozi3z5qzdysmu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005668; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f293cebb54e5ea71&resid=f293cebb54e5ea71%21293&authkey=aha74rsqiuewnpq"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005669; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21566&authkey=aevafh7rydhi19k"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005670; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21581&authkey=agx0b8ho87w4uie"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005671; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21582&authkey=af-9_xwysl1o7-c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005672; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21598&authkey=ah-gkc-b7fa8h-g"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005673; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f40a6c678d20c1eb&resid=f40a6c678d20c1eb%21599&authkey=aajunhe1ex_-zta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005674; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!216&authkey=alslscyemd7hr_o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005675; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081!223&authkey=ajbtso2laio00ao"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005676; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f4796beb10611081&resid=f4796beb10611081%21216&authkey=alslscyemd7hr_o"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005677; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f50a3aff00683adc&resid=f50a3aff00683adc%21108&authkey=ac44gtgp13l9xpw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005678; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f50a3aff00683adc&resid=f50a3aff00683adc%21139&authkey=aovmqh4ookdlkty"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005679; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f79e41c0e32d3314&resid=f79e41c0e32d3314%211182&authkey=aiqtptberyvlgqk&em=2%22"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005680; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806!1368&authkey=anphh1fijhvzv6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005681; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f7ae097903082806&resid=f7ae097903082806%211368&authkey=anphh1fijhvzv6c"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005682; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382!159&authkey=ai4_8srrzf48hw0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005683; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=f824f5d726d5c382&resid=f824f5d726d5c382%21159&authkey=ai4_8srrzf48hw0"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005684; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fb2177c192eed796&resid=fb2177c192eed796%21124&authkey=abotnmdhu_tg7bc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005685; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fd50774e5ce0e314&resid=fd50774e5ce0e314%21778&authkey=aoxb2vhhz3qodiu"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005686; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fe85161c3947f2c1&resid=fe85161c3947f2c1%211441&authkey=agb6c1ecr91svrw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005687; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e!192&authkey=ab_lrrmyxmcfrjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005688; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=fedbe7305e742a3e&resid=fedbe7305e742a3e%21192&authkey=ab_lrrmyxmcfrjc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005689; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!693&authkey=agcpkhnewfte_yc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005690; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73!694&authkey=aa5jqzjsp0esr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005691; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21693&authkey=agcpkhnewfte_yc"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005692; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff1d187273dfbf73&resid=ff1d187273dfbf73%21694&authkey=aa5jqzjsp0esr1s"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005693; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!330&authkey=adxnzkb0a09pizw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005694; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!334&authkey=agsvox_t7qim4ta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005695; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469!335&authkey=ach14e6omcghwgg"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005696; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21330&authkey=adxnzkb0a09pizw"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005697; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21333&authkey=aielwtaiuvcttlm"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005698; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta"; endswith; nocase; http.host; content:"onedrive.live.com"; classtype:trojan-activity; sid:100005699; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/raw/yqvsvlvq"; endswith; nocase; http.host; content:"pastebin.com"; classtype:trojan-activity; sid:100005700; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/llc/mwcacs65xienqdp/"; endswith; nocase; http.host; content:"pierreconsulting.info"; classtype:trojan-activity; sid:100005701; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bayesian-forecasting-amj5e/s5hqmf6/"; endswith; nocase; http.host; content:"pioneiraagronegocio.com.br"; classtype:trojan-activity; sid:100005702; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/uploads/2020/10/skoda22.jpg"; endswith; nocase; http.host; content:"procrossover.ru"; classtype:trojan-activity; sid:100005703; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-content/uploads/2020/10/skodaqq.jpg"; endswith; nocase; http.host; content:"procrossover.ru"; classtype:trojan-activity; sid:100005704; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wp-admin/zzcoiatsr5wujrwagsgbnm2wkjxldvgu/"; endswith; nocase; http.host; content:"qjbutterflyevents.co.za"; classtype:trojan-activity; sid:100005705; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/order+acknowledgement+bc202374++stock++20021+dem+p4.ace"; endswith; nocase; http.host; content:"quen.s3.us-east-2.amazonaws.com"; classtype:trojan-activity; sid:100005706; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/purchasing+ordersigned+contractinv-30067121.ace"; endswith; nocase; http.host; content:"quen.s3.us-east-2.amazonaws.com"; classtype:trojan-activity; sid:100005707; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/arntsonl/calc_security_poc/master/dll/calc.dll"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005708; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/bero1985/berotinypascal/e34bd4164f4b7c27e7cf667dffd9274d33d6dfbe/bin/btpc.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005709; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/evil-coder66/defendercontrol/main/defendercontrol.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005710; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/fuzzbunch/fuzzbunch/master/payloads/doublepulsar-1.3.1.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005711; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005712; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/malwares/webshell/master/ajax_php%20command%20shell.rar"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005713; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/myqseeaccount/one/main/one.htm"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005714; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/realtek25556/rhti2/gh-pages/90hfnvo69vk2ot.bmp"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005715; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/secwiki/windows-kernel-exploits/master/ms15-076/binary/trebuchet.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005716; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/secwiki/windows-kernel-exploits/master/ms16-098/bfill.exe"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005717; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/tennc/webshell/master/other/small_shell.txt"; endswith; nocase; http.host; content:"raw.githubusercontent.com"; classtype:trojan-activity; sid:100005718; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/player/launch/2017/09/12/da5f9a1c23034353852750488feeaf36.exe"; endswith; nocase; http.host; content:"res.yeshen.com"; classtype:trojan-activity; sid:100005719; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/pro/dl/q05z91"; endswith; nocase; http.host; content:"sendspace.com"; classtype:trojan-activity; sid:100005720; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/ey4lpx8rx.zip"; endswith; nocase; http.host; content:"shribharatvatika.com"; classtype:trojan-activity; sid:100005721; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/site/stormqk/dn/stormagent.apk?attredirects=0"; endswith; nocase; http.host; content:"sites.google.com"; classtype:trojan-activity; sid:100005722; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6ca94027662tilxa4p/base.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005723; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vw/base64.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005724; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6cd19c87f44r9fomit/base64jef.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005725; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6e2cbda22efxk3t7x2/base64.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005726; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6e2f6c8c5adup2yiwx/basejefin.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005727; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6eab37b8dadmy1gx7c/base3.5.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005728; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6eb2aa215a8cvwcf6s/fudjs.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005729; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aamus8/go.jpeg"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005730; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c7921a2cf26cunjcgvm/nanocoregomes.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005731; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/wzukusers/user-34654398/documents/5c9e24cc08a4dlmv7cjo/cdt.txt"; endswith; nocase; http.host; content:"storage.googleapis.com"; classtype:trojan-activity; sid:100005732; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/a-nurse-ss8d9/z/"; endswith; nocase; http.host; content:"technologydistilled.com"; classtype:trojan-activity; sid:100005733; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/databases/merit.php"; endswith; nocase; http.host; content:"truemerit.io"; classtype:trojan-activity; sid:100005734; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/23.exe"; endswith; nocase; http.host; content:"tsrv4.ws"; classtype:trojan-activity; sid:100005735; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/crisanar/defis/jek_crackme1.7.zip"; endswith; nocase; http.host; content:"users.skynet.be"; classtype:trojan-activity; sid:100005736; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gnuboard/data/scan/amowvegfrt9ja/"; endswith; nocase; http.host; content:"vniel.co.kr"; classtype:trojan-activity; sid:100005737; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/gnuboard/data/scan/fu6jvxzzs46uqlp7l/"; endswith; nocase; http.host; content:"vniel.co.kr"; classtype:trojan-activity; sid:100005738; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kolya/.f/root/net.mit.edu/net/user/chris/winnt/mit_agenda2a.doc"; endswith; nocase; http.host; content:"web.mit.edu"; classtype:trojan-activity; sid:100005739; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/kolya/.f/root/net.mit.edu/sipb/user/kolya/afs/root.afs/net/user/chris/winnt/mit_agenda2a.doc"; endswith; nocase; http.host; content:"web.mit.edu"; classtype:trojan-activity; sid:100005740; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/136_140/flt_shovemydiscoupyourarse.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100005741; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/136_140/kb%5efr_ouverture.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100005742; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/136_140/kb^fr_ouverture.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100005743; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/146_150/bc_memories_from_the_mcp.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100005744; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/issues/151_155/tidex_-_short_stuff.exe"; endswith; nocase; http.host; content:"websound.ru"; classtype:trojan-activity; sid:100005745; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/syria-files/attach/222/222051_instruction.zip"; endswith; nocase; http.host; content:"wikileaks.org"; classtype:trojan-activity; sid:100005746; rev:1;)
+alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"urlhaus-filter malicious website detected"; flow:established,from_client; http.method; content:"GET"; http.uri; content:"/common/yz.vbs"; endswith; nocase; http.host; content:"yp.hnggzyjy.cn"; classtype:trojan-activity; sid:100005747; rev:1;)
diff --git a/urlhaus-filter-unbound-online.conf b/urlhaus-filter-unbound-online.conf
index 8eed4140..9a3a0eae 100644
--- a/urlhaus-filter-unbound-online.conf
+++ b/urlhaus-filter-unbound-online.conf
@@ -1,5 +1,5 @@
 # Title: Online Malicious Domains Unbound Blocklist
-# Updated: Thu, 25 Mar 2021 12:12:40 UTC
+# Updated: Fri, 26 Mar 2021 00:12:29 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -19,7 +19,6 @@ local-zone: "360.lcy2zzx.pw" always_nxdomain
 local-zone: "360down7.miiyun.cn" always_nxdomain
 local-zone: "8402d53c-17e9-4250-8011-20f28f5d404f.certbooster.com" always_nxdomain
 local-zone: "8poieq.bn.files.1drv.com" always_nxdomain
-local-zone: "99centsdigitals.com" always_nxdomain
 local-zone: "abcd.bg" always_nxdomain
 local-zone: "abclicks.in" always_nxdomain
 local-zone: "abissnet.net" always_nxdomain
@@ -27,11 +26,12 @@ local-zone: "aboveandbelow.com.au" always_nxdomain
 local-zone: "absoftechworld.com" always_nxdomain
 local-zone: "absupplies.co.uk" always_nxdomain
 local-zone: "abyssos.eu" always_nxdomain
+local-zone: "academyshademani.com" always_nxdomain
 local-zone: "acbick.com" always_nxdomain
 local-zone: "accounts.thesmarttechhub.com" always_nxdomain
 local-zone: "aceeprc.com.aceeprc.com" always_nxdomain
 local-zone: "acellr.co.uk" always_nxdomain
-local-zone: "aclassapart.in" always_nxdomain
+local-zone: "aciabogados.com" always_nxdomain
 local-zone: "acteon.com.ar" always_nxdomain
 local-zone: "activateyourdiscount.com" always_nxdomain
 local-zone: "activecost.com.au" always_nxdomain
@@ -49,6 +49,7 @@ local-zone: "agemn.co.za" always_nxdomain
 local-zone: "agenciadigitalwdys.com" always_nxdomain
 local-zone: "agenciatabletshouse.com.br" always_nxdomain
 local-zone: "agenda.gmelloinformatica.com.br" always_nxdomain
+local-zone: "agenmovie.xyz" always_nxdomain
 local-zone: "agentt.ac.ug" always_nxdomain
 local-zone: "agile8studio.com" always_nxdomain
 local-zone: "agmcarpetcare.co.uk" always_nxdomain
@@ -60,7 +61,6 @@ local-zone: "al-wahd.com" always_nxdomain
 local-zone: "alasdemariposas.org" always_nxdomain
 local-zone: "alemelektronik.com" always_nxdomain
 local-zone: "alena1971.es" always_nxdomain
-local-zone: "alertlauncher.fr" always_nxdomain
 local-zone: "alexdubai.com.aldiabsteel.com" always_nxdomain
 local-zone: "alka.institute" always_nxdomain
 local-zone: "allforcreative.com.au" always_nxdomain
@@ -72,6 +72,7 @@ local-zone: "amarresdeamorymaestroshechiceros.com" always_nxdomain
 local-zone: "amarteargentina.com.ar" always_nxdomain
 local-zone: "amenyan.zouri.jp" always_nxdomain
 local-zone: "amos524.org" always_nxdomain
+local-zone: "ams.alvinasschools.org.ng" always_nxdomain
 local-zone: "anantam.net.in" always_nxdomain
 local-zone: "andreelapeyre.com" always_nxdomain
 local-zone: "andremaraisbeleggings.co.za" always_nxdomain
@@ -91,10 +92,9 @@ local-zone: "api.sampy.io" always_nxdomain
 local-zone: "aplicativoparasindicato.com.br" always_nxdomain
 local-zone: "apoolcondo.com" always_nxdomain
 local-zone: "app.adsensearticle.com" always_nxdomain
-local-zone: "app.explicitsurveys.co.uk" always_nxdomain
 local-zone: "app.prerana.info" always_nxdomain
 local-zone: "apps.saintsoporte.com" always_nxdomain
-local-zone: "aras.iuc.ac" always_nxdomain
+local-zone: "aqv.news" always_nxdomain
 local-zone: "areyoulivingwell.com" always_nxdomain
 local-zone: "arsapetrolab.com" always_nxdomain
 local-zone: "artedibujoyarquitectura.com" always_nxdomain
@@ -113,11 +113,12 @@ local-zone: "avissrilanka.com" always_nxdomain
 local-zone: "ayamallah.com" always_nxdomain
 local-zone: "azmeasurement.com" always_nxdomain
 local-zone: "azraktours.com" always_nxdomain
-local-zone: "b2b.toptanakaryakit.com.tr" always_nxdomain
 local-zone: "backgrounds.pk" always_nxdomain
 local-zone: "backup.agewsage.com" always_nxdomain
 local-zone: "badeggdesign.com" always_nxdomain
+local-zone: "balealgodon.mx" always_nxdomain
 local-zone: "bangkok-orchids.com" always_nxdomain
+local-zone: "barcionstw.eastus.cloudapp.azure.com" always_nxdomain
 local-zone: "bary.sz4h.com" always_nxdomain
 local-zone: "basma.com.kw" always_nxdomain
 local-zone: "bausch.kr-atlas.monaxikoslykos@zytrox.tk" always_nxdomain
@@ -126,7 +127,6 @@ local-zone: "bbia.co.uk" always_nxdomain
 local-zone: "bcmt.elin.co.za" always_nxdomain
 local-zone: "bcrg.co.za" always_nxdomain
 local-zone: "bearcatpumps.com.cn" always_nxdomain
-local-zone: "beatyamerican.com" always_nxdomain
 local-zone: "beautincollagen.rs" always_nxdomain
 local-zone: "bekape.co.id" always_nxdomain
 local-zone: "bespokeweddings.ie" always_nxdomain
@@ -134,6 +134,8 @@ local-zone: "bestcarenepal.com" always_nxdomain
 local-zone: "betone.co.kr" always_nxdomain
 local-zone: "betycopaints.com" always_nxdomain
 local-zone: "beveragesmiami.solucioneslink.com" always_nxdomain
+local-zone: "bhavaniengineering.com" always_nxdomain
+local-zone: "bigbag.wootraining.certificacion.cl" always_nxdomain
 local-zone: "bilbosaquet.ug" always_nxdomain
 local-zone: "bilhen.co.za" always_nxdomain
 local-zone: "billing.rahitechnosoft.com" always_nxdomain
@@ -141,11 +143,10 @@ local-zone: "birdi.elin.co.za" always_nxdomain
 local-zone: "birminghamlink.org" always_nxdomain
 local-zone: "blog.callensaxen.com" always_nxdomain
 local-zone: "blog.oyinblogs.com" always_nxdomain
-local-zone: "blog.takbelit.com" always_nxdomain
 local-zone: "bmlifestyle.co.uk" always_nxdomain
+local-zone: "bnrbook.com" always_nxdomain
 local-zone: "bnrnews.id" always_nxdomain
 local-zone: "bodenstein.co.za" always_nxdomain
-local-zone: "bolnicaloznica.rs" always_nxdomain
 local-zone: "booksearch.com" always_nxdomain
 local-zone: "bounces.mi-fs.com" always_nxdomain
 local-zone: "bpo.correct.go.th" always_nxdomain
@@ -159,23 +160,21 @@ local-zone: "brightonrooms.co.uk" always_nxdomain
 local-zone: "brightstarshop.com" always_nxdomain
 local-zone: "browardinsurancemiami.solucioneslink.com" always_nxdomain
 local-zone: "bt2.elin.co.za" always_nxdomain
-local-zone: "btdapi.robotake.com" always_nxdomain
 local-zone: "bucrinsuranlceonlines.com" always_nxdomain
 local-zone: "buenavista.co" always_nxdomain
-local-zone: "buigiaphat.com.vn" always_nxdomain
 local-zone: "bullseyemedia.in" always_nxdomain
 local-zone: "busandvanrentalmalaysia.com" always_nxdomain
 local-zone: "buscascolegios.diit.cl" always_nxdomain
 local-zone: "business.softberg.ro" always_nxdomain
 local-zone: "buyingmusiconline.com" always_nxdomain
-local-zone: "buypropertyfast.com" always_nxdomain
 local-zone: "bwsr.eu" always_nxdomain
 local-zone: "c.oooooooooo.ga" always_nxdomain
 local-zone: "c0140529.ferozo.com" always_nxdomain
+local-zone: "caballo.com.au" always_nxdomain
 local-zone: "cacapavaonline.sdserver144.com.br" always_nxdomain
+local-zone: "calgaryautorepairservice.com" always_nxdomain
 local-zone: "callbury.in" always_nxdomain
 local-zone: "camminachetipassa.it" always_nxdomain
-local-zone: "campusvirtual.cepsanjuanbosco.net.pe" always_nxdomain
 local-zone: "cancer.educandome.co" always_nxdomain
 local-zone: "capitalgroup-kw.com" always_nxdomain
 local-zone: "capitalnewsagency.com" always_nxdomain
@@ -188,12 +187,10 @@ local-zone: "cazyacustomfurniture.com" always_nxdomain
 local-zone: "ccauthority.net" always_nxdomain
 local-zone: "cdaonline.com.ar" always_nxdomain
 local-zone: "cec.asso.ac-amiens.fr" always_nxdomain
-local-zone: "cellas.sk" always_nxdomain
 local-zone: "cendekiabinaaksara.com" always_nxdomain
 local-zone: "cespol-bote.com.mx" always_nxdomain
 local-zone: "cfs5.tistory.com" always_nxdomain
 local-zone: "ch.rmu.ac.th" always_nxdomain
-local-zone: "changematterscounselling.com" always_nxdomain
 local-zone: "chardhamdodham.com" always_nxdomain
 local-zone: "cheacrilnsurances.com" always_nxdomain
 local-zone: "chealablilitycarinsurances.com" always_nxdomain
@@ -201,15 +198,14 @@ local-zone: "chezalice.co.za" always_nxdomain
 local-zone: "childselect.com" always_nxdomain
 local-zone: "chinhdropfile.myvnc.com" always_nxdomain
 local-zone: "chinhdropfile80.myvnc.com" always_nxdomain
-local-zone: "chipmania.it" always_nxdomain
 local-zone: "cible-energy.com" always_nxdomain
 local-zone: "cifeer.net" always_nxdomain
 local-zone: "citycapproperty.ru" always_nxdomain
 local-zone: "cityglobalgospel.com" always_nxdomain
 local-zone: "civi.istmejia.com" always_nxdomain
 local-zone: "cleanbydesignllc.com" always_nxdomain
-local-zone: "clim34000.fr" always_nxdomain
 local-zone: "cloud.fc.co.mz" always_nxdomain
+local-zone: "clurbgolf.com" always_nxdomain
 local-zone: "codsambal.com" always_nxdomain
 local-zone: "colinde.pricesne.com" always_nxdomain
 local-zone: "colorpak.pl" always_nxdomain
@@ -231,7 +227,6 @@ local-zone: "creationskateboards.com" always_nxdomain
 local-zone: "crecerco.com" always_nxdomain
 local-zone: "crittersbythebay.com" always_nxdomain
 local-zone: "crm.notariavieitoyvelamazan.com" always_nxdomain
-local-zone: "crmmanivela.net" always_nxdomain
 local-zone: "crscorretordeimoveis.com.br" always_nxdomain
 local-zone: "cse-engineer.com" always_nxdomain
 local-zone: "csnserver.com" always_nxdomain
@@ -278,7 +273,6 @@ local-zone: "destinymc.co.za" always_nxdomain
 local-zone: "detorre.es" always_nxdomain
 local-zone: "dev-interestingtech.pantheonsite.io" always_nxdomain
 local-zone: "dev.sebpo.net" always_nxdomain
-local-zone: "dezcom.com" always_nxdomain
 local-zone: "dfcf.91756.cn" always_nxdomain
 local-zone: "dfsfcsfcdsfsdvcfsvcscv.com" always_nxdomain
 local-zone: "diamantenegro.mi-fs.com" always_nxdomain
@@ -301,7 +295,6 @@ local-zone: "dom.daf.free.fr" always_nxdomain
 local-zone: "doncedyhall.com" always_nxdomain
 local-zone: "donghobinhminh.com" always_nxdomain
 local-zone: "dongphuctop.com" always_nxdomain
-local-zone: "donwnloasecury.ath.cx" always_nxdomain
 local-zone: "dosame.com" always_nxdomain
 local-zone: "dosman.pl" always_nxdomain
 local-zone: "dovberger.com" always_nxdomain
@@ -309,6 +302,9 @@ local-zone: "down.flash-plays.com" always_nxdomain
 local-zone: "down.pcclear.com" always_nxdomain
 local-zone: "down.posti-fi-fsa.top" always_nxdomain
 local-zone: "down.posti-fi-fwa.top" always_nxdomain
+local-zone: "down.posti-fi-ij.top" always_nxdomain
+local-zone: "down.posti-fi-in.top" always_nxdomain
+local-zone: "down.posti-fi-iz.top" always_nxdomain
 local-zone: "down.udashi.com" always_nxdomain
 local-zone: "down.webbora.com" always_nxdomain
 local-zone: "down1.arpun.com" always_nxdomain
@@ -325,7 +321,6 @@ local-zone: "dragonsknot.com" always_nxdomain
 local-zone: "drbaby.com.sa" always_nxdomain
 local-zone: "drohnen.ensenanzainteligente.com" always_nxdomain
 local-zone: "drools-moved.46999.n3.nabble.com" always_nxdomain
-local-zone: "drrohanfonseca.com" always_nxdomain
 local-zone: "drsha.innovativesolutions.mobi" always_nxdomain
 local-zone: "dsenterprize.co.za" always_nxdomain
 local-zone: "dsspainting.com" always_nxdomain
@@ -339,19 +334,15 @@ local-zone: "e-commerce.saleensuporte.com.br" always_nxdomain
 local-zone: "e.sldov.ru" always_nxdomain
 local-zone: "ebruyatkin.com" always_nxdomain
 local-zone: "econews.treegle.org" always_nxdomain
-local-zone: "edelweissdecoration.com" always_nxdomain
 local-zone: "efficientegroup.com" always_nxdomain
 local-zone: "elliot.newreadermedia.net" always_nxdomain
-local-zone: "emaids.co.za" always_nxdomain
 local-zone: "en.baoend.com" always_nxdomain
 local-zone: "enc-tech.com" always_nxdomain
 local-zone: "endurotanzania.co.tz" always_nxdomain
-local-zone: "enkonooh.com" always_nxdomain
 local-zone: "ennovate.elin.co.za" always_nxdomain
 local-zone: "enriquecendocomconsorcio.com.br" always_nxdomain
 local-zone: "envios.petpienso.cl" always_nxdomain
 local-zone: "equimination.ee" always_nxdomain
-local-zone: "es.paymelist.com" always_nxdomain
 local-zone: "escola.probommar.org.br" always_nxdomain
 local-zone: "esnconsultants.com" always_nxdomain
 local-zone: "essentia.org.br" always_nxdomain
@@ -363,15 +354,14 @@ local-zone: "extrovertoffers.com" always_nxdomain
 local-zone: "f1sol.com" always_nxdomain
 local-zone: "familydentist.site" always_nxdomain
 local-zone: "farmaciasdrogaminas.com.br" always_nxdomain
-local-zone: "farmnatural.in" always_nxdomain
 local-zone: "faveraprojects.com" always_nxdomain
 local-zone: "fc.co.mz" always_nxdomain
 local-zone: "felicienne.nl" always_nxdomain
 local-zone: "fi.bonitastores.com" always_nxdomain
 local-zone: "files.martellexpress.us" always_nxdomain
 local-zone: "files6.uludagbilisim.com" always_nxdomain
-local-zone: "filmotainment.com" always_nxdomain
 local-zone: "final.makkahkmcc.com" always_nxdomain
+local-zone: "fineartgallerym.com" always_nxdomain
 local-zone: "fkd.derpcity.ru" always_nxdomain
 local-zone: "flintspin.com" always_nxdomain
 local-zone: "flyingbuddhadesign.com" always_nxdomain
@@ -379,20 +369,17 @@ local-zone: "fmjplastering.co.uk" always_nxdomain
 local-zone: "fms.buladde.or.ug" always_nxdomain
 local-zone: "foothills.com.br" always_nxdomain
 local-zone: "footweardirect.elin.co.za" always_nxdomain
-local-zone: "formestore.evencsoft.co" always_nxdomain
 local-zone: "forum.mdb.nu" always_nxdomain
 local-zone: "fotoobjetivo.com" always_nxdomain
 local-zone: "foundationrepairhoustontx.net" always_nxdomain
 local-zone: "foxeps.com.br" always_nxdomain
 local-zone: "freecnetdownload.com" always_nxdomain
-local-zone: "freedombookshop.tickme.lk" always_nxdomain
 local-zone: "freisites.com.br" always_nxdomain
 local-zone: "ftp.n3twork30cm.ml" always_nxdomain
 local-zone: "fullelectronica.com.ar" always_nxdomain
 local-zone: "funletters.net" always_nxdomain
 local-zone: "fusionfiresolutions.com" always_nxdomain
 local-zone: "futuregraphics.com.ar" always_nxdomain
-local-zone: "gahanassociates.com" always_nxdomain
 local-zone: "gametwogame.com" always_nxdomain
 local-zone: "garayvidalabogados.com" always_nxdomain
 local-zone: "garciadogshow.com" always_nxdomain
@@ -400,7 +387,6 @@ local-zone: "garenanow.myvnc.com" always_nxdomain
 local-zone: "garenanow4.myvnc.com" always_nxdomain
 local-zone: "gbbulls.co.uk" always_nxdomain
 local-zone: "gcpc.co.id.chronoscurtain.com" always_nxdomain
-local-zone: "gcrcorporation.com" always_nxdomain
 local-zone: "generaldeviales.com" always_nxdomain
 local-zone: "gfmodd1.webselffiles01.com" always_nxdomain
 local-zone: "gfold1.webselffiles01.com" always_nxdomain
@@ -408,6 +394,8 @@ local-zone: "ghettohub.co.za" always_nxdomain
 local-zone: "ghislain.dartois.pagesperso-orange.fr" always_nxdomain
 local-zone: "giadungg7.com" always_nxdomain
 local-zone: "giddos.ga" always_nxdomain
+local-zone: "gilliem.com" always_nxdomain
+local-zone: "girotexuniformes.com" always_nxdomain
 local-zone: "giteletropical.com" always_nxdomain
 local-zone: "globaltask.ar" always_nxdomain
 local-zone: "glowinmedia.co.ke" always_nxdomain
@@ -422,10 +410,12 @@ local-zone: "goldcoastoffice365.com.au" always_nxdomain
 local-zone: "goldcupmortgage.com" always_nxdomain
 local-zone: "golden-memories-funerals.yourpageserver.com" always_nxdomain
 local-zone: "goldmen.in" always_nxdomain
+local-zone: "gorecycle.fahadjutt.com" always_nxdomain
 local-zone: "gracejukes.com" always_nxdomain
 local-zone: "grupoinmare.com" always_nxdomain
 local-zone: "gruposelt.000webhostapp.com" always_nxdomain
 local-zone: "gs.monerorx.com" always_nxdomain
+local-zone: "guide-to-cell-phones.com" always_nxdomain
 local-zone: "gulfac-house.com" always_nxdomain
 local-zone: "gvpcdpgc.edu.in" always_nxdomain
 local-zone: "habbotips.free.fr" always_nxdomain
@@ -451,6 +441,7 @@ local-zone: "hitstation.nl" always_nxdomain
 local-zone: "hmpmall.co.kr" always_nxdomain
 local-zone: "hoagietesting10.com" always_nxdomain
 local-zone: "hoayeuthuong-my.sharepoint.com" always_nxdomain
+local-zone: "holmesprpmgmt.com" always_nxdomain
 local-zone: "homefindersolutions.com" always_nxdomain
 local-zone: "hongluosi.com" always_nxdomain
 local-zone: "hookedupboatclub.com" always_nxdomain
@@ -462,7 +453,6 @@ local-zone: "hseda.com" always_nxdomain
 local-zone: "hsmwebapp.com" always_nxdomain
 local-zone: "htownbars.com" always_nxdomain
 local-zone: "hubtech.co.za" always_nxdomain
-local-zone: "huequito.evencsoft.co" always_nxdomain
 local-zone: "hunggiang.vn" always_nxdomain
 local-zone: "husamiyahschool.com" always_nxdomain
 local-zone: "iam313.com" always_nxdomain
@@ -474,6 +464,7 @@ local-zone: "idvindia.com" always_nxdomain
 local-zone: "iesanjosemonitos.edu.co" always_nxdomain
 local-zone: "ikexpert.com" always_nxdomain
 local-zone: "ilrafrica.com" always_nxdomain
+local-zone: "images.jermiau.com" always_nxdomain
 local-zone: "imbueautoworx.co.za" always_nxdomain
 local-zone: "imperiumtherapy.co.za" always_nxdomain
 local-zone: "in-tune2016.com" always_nxdomain
@@ -488,6 +479,7 @@ local-zone: "inodesthetotaldesigners.com" always_nxdomain
 local-zone: "inovations.searchkero.com" always_nxdomain
 local-zone: "inrajahmundry.co.in" always_nxdomain
 local-zone: "insignificantfinecore.testmail4.repl.co" always_nxdomain
+local-zone: "instantindialoan.com" always_nxdomain
 local-zone: "instvisionmexico.edu.mx" always_nxdomain
 local-zone: "intellectsmart.in" always_nxdomain
 local-zone: "intersel-idf.org" always_nxdomain
@@ -498,6 +490,7 @@ local-zone: "ipmes.ma" always_nxdomain
 local-zone: "iremart.es" always_nxdomain
 local-zone: "iris101.co.uk" always_nxdomain
 local-zone: "iscamenabe.com" always_nxdomain
+local-zone: "ismf.com.ng" always_nxdomain
 local-zone: "iso-dubai.net" always_nxdomain
 local-zone: "israrulhaq.me" always_nxdomain
 local-zone: "isrorg.com" always_nxdomain
@@ -518,7 +511,6 @@ local-zone: "jhayesconsulting.com" always_nxdomain
 local-zone: "jiaoyuzixun.cn" always_nxdomain
 local-zone: "jing-da.com.tw" always_nxdomain
 local-zone: "jktnet.xyz" always_nxdomain
-local-zone: "jmcomputacion.com.ar" always_nxdomain
 local-zone: "jmtc.91756.cn" always_nxdomain
 local-zone: "jnanbharati.com" always_nxdomain
 local-zone: "jobs.thebeessolution.com" always_nxdomain
@@ -527,9 +519,7 @@ local-zone: "join.cl8movement.co.za" always_nxdomain
 local-zone: "josegene.com" always_nxdomain
 local-zone: "josuarochoa.com" always_nxdomain
 local-zone: "jpwoodfordco.com" always_nxdomain
-local-zone: "julietlaser.site" always_nxdomain
 local-zone: "jumpmanualjacobhiller.com" always_nxdomain
-local-zone: "jumpnjamchicago.com" always_nxdomain
 local-zone: "jupiter.toxsl.in" always_nxdomain
 local-zone: "jurgensen.newreadermedia.net" always_nxdomain
 local-zone: "justinscott.com.au" always_nxdomain
@@ -551,6 +541,7 @@ local-zone: "kubatoglubaklava.com.tr" always_nxdomain
 local-zone: "kumaralok.in" always_nxdomain
 local-zone: "kwanfromhongkong.com" always_nxdomain
 local-zone: "kz.sldov.ru" always_nxdomain
+local-zone: "lab18.it" always_nxdomain
 local-zone: "lacasadelosalebrijes.com" always_nxdomain
 local-zone: "ladylabonde.com" always_nxdomain
 local-zone: "lameguard.ru" always_nxdomain
@@ -596,6 +587,7 @@ local-zone: "lp.definerisco.com" always_nxdomain
 local-zone: "lp.difusodesign.com" always_nxdomain
 local-zone: "lp.juancamilogarciareyes.com" always_nxdomain
 local-zone: "lp.tecnimasdecolombia.com.co" always_nxdomain
+local-zone: "ltc.typoten.com" always_nxdomain
 local-zone: "luckybrownie.com" always_nxdomain
 local-zone: "luminouspneuma.com" always_nxdomain
 local-zone: "luxomodels.com" always_nxdomain
@@ -604,15 +596,15 @@ local-zone: "m.estudiomoros.com.ar" always_nxdomain
 local-zone: "madicon.co.za" always_nxdomain
 local-zone: "magianegramagiablancayamarres.com" always_nxdomain
 local-zone: "mail.bs-eiendomme.co.za" always_nxdomain
+local-zone: "mail.golimoapp.com" always_nxdomain
 local-zone: "mail.jeffsono.org" always_nxdomain
 local-zone: "maksi.feb.unib.ac.id" always_nxdomain
 local-zone: "malaya.tv" always_nxdomain
 local-zone: "malwarecoding.github.io" always_nxdomain
 local-zone: "managed.oss-cn-beijing.aliyuncs.com" always_nxdomain
+local-zone: "managemysalon.in" always_nxdomain
 local-zone: "manantialesdelnorte.uy" always_nxdomain
-local-zone: "manivelasst.com" always_nxdomain
 local-zone: "marcapinyo.ru" always_nxdomain
-local-zone: "marcusthepoet.com" always_nxdomain
 local-zone: "mario-sunjic.com" always_nxdomain
 local-zone: "mariobrown.net" always_nxdomain
 local-zone: "mariotessarollo.com" always_nxdomain
@@ -621,7 +613,6 @@ local-zone: "marketing.enexusgroup.com.au" always_nxdomain
 local-zone: "marksidfgs.ug" always_nxdomain
 local-zone: "masjidhabeebiyarazviya.mysunni.com" always_nxdomain
 local-zone: "materialescantu.com" always_nxdomain
-local-zone: "matinal-nominal.pt" always_nxdomain
 local-zone: "matruchhaya.co.in" always_nxdomain
 local-zone: "mattysplayground.com" always_nxdomain
 local-zone: "maxtox.com.pk" always_nxdomain
@@ -633,6 +624,7 @@ local-zone: "media-server.skyinternet.com.pk" always_nxdomain
 local-zone: "mediamaster.co.za" always_nxdomain
 local-zone: "medianews.ge" always_nxdomain
 local-zone: "medistaffconsulting.com" always_nxdomain
+local-zone: "meditreat.itwebservice.in" always_nxdomain
 local-zone: "meeweb.com" always_nxdomain
 local-zone: "megamart.afnan-amc.com" always_nxdomain
 local-zone: "merbay.ru" always_nxdomain
@@ -653,7 +645,6 @@ local-zone: "midlandtexasconstruction.com" always_nxdomain
 local-zone: "mindfulbuildingandliving.com" always_nxdomain
 local-zone: "mingguanwms.com" always_nxdomain
 local-zone: "minuevavida.org" always_nxdomain
-local-zone: "mirror.mypage.sk" always_nxdomain
 local-zone: "mis.nbcc.ac.th" always_nxdomain
 local-zone: "misterson.com" always_nxdomain
 local-zone: "mixr.at" always_nxdomain
@@ -661,12 +652,14 @@ local-zone: "mkontakt.az" always_nxdomain
 local-zone: "mktf.mx" always_nxdomain
 local-zone: "mmogollon.com.mx" always_nxdomain
 local-zone: "mncarteam.com" always_nxdomain
+local-zone: "mobile.illumetechnology.com" always_nxdomain
 local-zone: "modelhouseturkey.com" always_nxdomain
 local-zone: "modernmanna.org" always_nxdomain
 local-zone: "monetization.business" always_nxdomain
 local-zone: "moninediy.com" always_nxdomain
 local-zone: "mopai.sg" always_nxdomain
 local-zone: "motorcomunicacion.com" always_nxdomain
+local-zone: "msacontabil.com.br" always_nxdomain
 local-zone: "mtspsmjeli.sch.id" always_nxdomain
 local-zone: "muzimbiti.xigubo.co.mz" always_nxdomain
 local-zone: "mxpiqw.am.files.1drv.com" always_nxdomain
@@ -699,8 +692,8 @@ local-zone: "nhorangtreem.com" always_nxdomain
 local-zone: "nicolas.ug" always_nxdomain
 local-zone: "nidhi.iexist.in" always_nxdomain
 local-zone: "nikanpolimer.ir" always_nxdomain
+local-zone: "nilehouse.co.ug" always_nxdomain
 local-zone: "nilinkeji.com" always_nxdomain
-local-zone: "nisacooks.com" always_nxdomain
 local-zone: "njtiledesigncenter.com" always_nxdomain
 local-zone: "nobius.org" always_nxdomain
 local-zone: "nocalnoodle.elin.co.za" always_nxdomain
@@ -718,10 +711,13 @@ local-zone: "nyeh2o.com.au" always_nxdomain
 local-zone: "oakleyandfriends.co.uk" always_nxdomain
 local-zone: "obseques-conseils.com" always_nxdomain
 local-zone: "ocean.tecnasulstore.com.br" always_nxdomain
+local-zone: "ohe.ie" always_nxdomain
 local-zone: "ohsewgorgeous.co.uk" always_nxdomain
+local-zone: "oknoplastik.sk" always_nxdomain
 local-zone: "oleholeh.memangbeda.website" always_nxdomain
 local-zone: "olirecords.mixture.ltd" always_nxdomain
 local-zone: "olooom.com" always_nxdomain
+local-zone: "omaia.org" always_nxdomain
 local-zone: "omaromatic.com" always_nxdomain
 local-zone: "omega.az" always_nxdomain
 local-zone: "oms.pappai.com" always_nxdomain
@@ -730,6 +726,7 @@ local-zone: "onedigitalcard.granvizionnecorp.com" always_nxdomain
 local-zone: "onedrive.listifyapp.co" always_nxdomain
 local-zone: "online.creedglobal.in" always_nxdomain
 local-zone: "onlinestatis.bar" always_nxdomain
+local-zone: "ont.proman.id" always_nxdomain
 local-zone: "open.warehousesaas.co.uk" always_nxdomain
 local-zone: "opolis.io" always_nxdomain
 local-zone: "optimus.com.sg" always_nxdomain
@@ -737,6 +734,8 @@ local-zone: "optitechsa.co.za" always_nxdomain
 local-zone: "order.bizpeed.com" always_nxdomain
 local-zone: "orientgatewayltd.com" always_nxdomain
 local-zone: "orion445.com" always_nxdomain
+local-zone: "oserve.pk" always_nxdomain
+local-zone: "otolithenrichment.fahadjutt.com" always_nxdomain
 local-zone: "ottimade.com" always_nxdomain
 local-zone: "ourteam.searchkero.com" always_nxdomain
 local-zone: "ozemag.com" always_nxdomain
@@ -758,6 +757,7 @@ local-zone: "patch3.99ddd.com" always_nxdomain
 local-zone: "paths.elin.co.za" always_nxdomain
 local-zone: "paulmercier.biz" always_nxdomain
 local-zone: "payerrealty.com" always_nxdomain
+local-zone: "payments.atifsiddiqui.me" always_nxdomain
 local-zone: "pcsoori.com" always_nxdomain
 local-zone: "pd.oceaniarp.net" always_nxdomain
 local-zone: "perpus.onlineman7-jombang.sch.id" always_nxdomain
@@ -770,6 +770,7 @@ local-zone: "phittc.com" always_nxdomain
 local-zone: "photo360.kubooking.com" always_nxdomain
 local-zone: "photographytipsclub.com" always_nxdomain
 local-zone: "pink99.com" always_nxdomain
+local-zone: "pizzabarletta.com.br" always_nxdomain
 local-zone: "plasfan.ind.br" always_nxdomain
 local-zone: "pmglance.startwriteup.com" always_nxdomain
 local-zone: "pokojewewladyslawowie.pl" always_nxdomain
@@ -779,15 +780,13 @@ local-zone: "pooltablemoversdenver.net" always_nxdomain
 local-zone: "posmicrosystems.com" always_nxdomain
 local-zone: "poulman.panagiotopoulos-tours.gr" always_nxdomain
 local-zone: "ppdb.smk-ciptaskill.sch.id" always_nxdomain
-local-zone: "pptvideotemplates.com" always_nxdomain
 local-zone: "prestasicash.com.ar" always_nxdomain
 local-zone: "prestigehomeautomation.net" always_nxdomain
 local-zone: "prishaartcreations.com" always_nxdomain
 local-zone: "production.sparshims.com" always_nxdomain
-local-zone: "productprecise.com" always_nxdomain
-local-zone: "prof-dr-ahmedalmoatasem.com" always_nxdomain
 local-zone: "programaoperadoronline.com.br" always_nxdomain
 local-zone: "project.exquitec.com" always_nxdomain
+local-zone: "promolyko.com" always_nxdomain
 local-zone: "promotoradescomplica.com.br" always_nxdomain
 local-zone: "promoversdubai.com" always_nxdomain
 local-zone: "propertiq.elin.co.za" always_nxdomain
@@ -800,7 +799,7 @@ local-zone: "prueba.danielluza.com" always_nxdomain
 local-zone: "pujashoppe.in" always_nxdomain
 local-zone: "punchdialogues.com" always_nxdomain
 local-zone: "punjabdevelopersassociation.com.pk" always_nxdomain
-local-zone: "purefoe.top" always_nxdomain
+local-zone: "pvcprinting.co.uk" always_nxdomain
 local-zone: "qadir.tickfa.ir" always_nxdomain
 local-zone: "qatarglobalconsulting.com" always_nxdomain
 local-zone: "qmsled.com" always_nxdomain
@@ -816,7 +815,6 @@ local-zone: "ratemyfenancialadvisor.com" always_nxdomain
 local-zone: "ravenproductionsltd.com" always_nxdomain
 local-zone: "rc.ixiaoyang.cn" always_nxdomain
 local-zone: "readymmade.com" always_nxdomain
-local-zone: "realtheprocess.co" always_nxdomain
 local-zone: "redchillicrackers.com" always_nxdomain
 local-zone: "reifenquick.de" always_nxdomain
 local-zone: "relaxindulge.co.nz" always_nxdomain
@@ -866,7 +864,6 @@ local-zone: "santyago.org" always_nxdomain
 local-zone: "sarakem.cl" always_nxdomain
 local-zone: "sasystemsuk.com" always_nxdomain
 local-zone: "savasaachi.systems" always_nxdomain
-local-zone: "savingchintu.com" always_nxdomain
 local-zone: "scarfaceindustries.com" always_nxdomain
 local-zone: "scglobal.co.th" always_nxdomain
 local-zone: "schalke04rss.de" always_nxdomain
@@ -874,10 +871,8 @@ local-zone: "scheff.com" always_nxdomain
 local-zone: "schoolbustracker.softgig.co.ke" always_nxdomain
 local-zone: "sec-doc-w.com" always_nxdomain
 local-zone: "secure-doc-reader.com" always_nxdomain
-local-zone: "sefp-boispro.fr" always_nxdomain
 local-zone: "segalsmetals.elin.co.za" always_nxdomain
 local-zone: "sellmyphonela.com" always_nxdomain
-local-zone: "selltechtoday.com" always_nxdomain
 local-zone: "senbiaojita.com" always_nxdomain
 local-zone: "sentierodelviandante.ml" always_nxdomain
 local-zone: "serendibsourcing.com" always_nxdomain
@@ -894,7 +889,6 @@ local-zone: "shembefoundation.com" always_nxdomain
 local-zone: "shivakunwar.com.np" always_nxdomain
 local-zone: "shoblasaathitrust.org" always_nxdomain
 local-zone: "shooka-co.com" always_nxdomain
-local-zone: "shop.clarostudio.ro" always_nxdomain
 local-zone: "shop.goldspot.agency" always_nxdomain
 local-zone: "shopsofe.com" always_nxdomain
 local-zone: "shrushtiinfotech.com" always_nxdomain
@@ -906,11 +900,11 @@ local-zone: "siili.net" always_nxdomain
 local-zone: "simoneporzi.it" always_nxdomain
 local-zone: "simplithy.co.uk" always_nxdomain
 local-zone: "sindicato1ucm.cl" always_nxdomain
+local-zone: "sindpol.tiejuris.com.br" always_nxdomain
 local-zone: "sinergidwireka.com" always_nxdomain
 local-zone: "sipahielektrik.com" always_nxdomain
 local-zone: "siperb.in" always_nxdomain
 local-zone: "sistelligent.com" always_nxdomain
-local-zone: "site.sjc.co.ke" always_nxdomain
 local-zone: "skkksolo.beweiretail.com" always_nxdomain
 local-zone: "skyflyfares.com" always_nxdomain
 local-zone: "skyscan.com" always_nxdomain
@@ -920,7 +914,6 @@ local-zone: "smartzedu.com" always_nxdomain
 local-zone: "smokeandgrowrichtour.com" always_nxdomain
 local-zone: "smokesolutionindia.com" always_nxdomain
 local-zone: "sobethuacademy.com" always_nxdomain
-local-zone: "soft.110route.com" always_nxdomain
 local-zone: "soft.officelabo.net" always_nxdomain
 local-zone: "sohs.conceptechs.info" always_nxdomain
 local-zone: "solar.amazingtribe.lk" always_nxdomain
@@ -929,11 +922,11 @@ local-zone: "somcorbera.cat" always_nxdomain
 local-zone: "somir.com.mx" always_nxdomain
 local-zone: "soralapps.com" always_nxdomain
 local-zone: "sorteio.orgaostalita.com.br" always_nxdomain
+local-zone: "sosgsm.fr" always_nxdomain
 local-zone: "sota-france.fr" always_nxdomain
 local-zone: "sowingminerals.cl" always_nxdomain
 local-zone: "space.proactint.org" always_nxdomain
 local-zone: "spaceframe.mobi.space-frame.co.za" always_nxdomain
-local-zone: "specfloors.net" always_nxdomain
 local-zone: "special-key.cf" always_nxdomain
 local-zone: "spent.com.pl" always_nxdomain
 local-zone: "spetsesyachtcharter.gr" always_nxdomain
@@ -965,6 +958,7 @@ local-zone: "supermercadostia.com" always_nxdomain
 local-zone: "support-4-free.com" always_nxdomain
 local-zone: "support.clz.kr" always_nxdomain
 local-zone: "supportit.online" always_nxdomain
+local-zone: "surestdysbonescagexc.dns.army" always_nxdomain
 local-zone: "sw.yourpageserver.com" always_nxdomain
 local-zone: "sweaty.dk" always_nxdomain
 local-zone: "sweet-diet.com" always_nxdomain
@@ -990,11 +984,11 @@ local-zone: "taxpos.com" always_nxdomain
 local-zone: "tc.snpsresidential.com" always_nxdomain
 local-zone: "tcy.198424.com" always_nxdomain
 local-zone: "tdsp.yngw518.com" always_nxdomain
-local-zone: "tech332.synology.me" always_nxdomain
 local-zone: "techgms.com" always_nxdomain
 local-zone: "technogreen.crmmanivela.com" always_nxdomain
 local-zone: "technohub.searchkero.com" always_nxdomain
 local-zone: "tecnicaencolectores.com.mx" always_nxdomain
+local-zone: "tecnologyschool.com" always_nxdomain
 local-zone: "teduae.com" always_nxdomain
 local-zone: "teleargentina.com" always_nxdomain
 local-zone: "telescopelms.com" always_nxdomain
@@ -1002,9 +996,9 @@ local-zone: "telmed.cl" always_nxdomain
 local-zone: "temptmag.com" always_nxdomain
 local-zone: "tennisafrica.com" always_nxdomain
 local-zone: "tentandoserfitness.000webhostapp.com" always_nxdomain
-local-zone: "tepresto.net.pe" always_nxdomain
 local-zone: "test.adventser.com" always_nxdomain
 local-zone: "test.letraele.es" always_nxdomain
+local-zone: "test.typoten.com" always_nxdomain
 local-zone: "test.wanepghana.org" always_nxdomain
 local-zone: "test1.asistencia247.com" always_nxdomain
 local-zone: "test1.milenial.id" always_nxdomain
@@ -1017,9 +1011,7 @@ local-zone: "testnew.yourpageserver.com" always_nxdomain
 local-zone: "teteaffiche.stephanebillon.com" always_nxdomain
 local-zone: "tewoerd.eu" always_nxdomain
 local-zone: "textile.softberg.ro" always_nxdomain
-local-zone: "texts.bfftexts.com" always_nxdomain
 local-zone: "texturesbyvinita.com" always_nxdomain
-local-zone: "tharringtonsponsorship.com" always_nxdomain
 local-zone: "thecleaningladiespdx.com" always_nxdomain
 local-zone: "thecreativecafe.co.uk" always_nxdomain
 local-zone: "thefuturelife.in" always_nxdomain
@@ -1027,12 +1019,11 @@ local-zone: "thehighlightinterior.com" always_nxdomain
 local-zone: "thehouseofpragya.com" always_nxdomain
 local-zone: "thekassia.co.uk" always_nxdomain
 local-zone: "thelaunchpadteam.com" always_nxdomain
-local-zone: "thelekhak.com" always_nxdomain
 local-zone: "thelogicalgroup.co.uk" always_nxdomain
 local-zone: "thesummitpc.net" always_nxdomain
 local-zone: "theurbantutors.com" always_nxdomain
+local-zone: "thewwpc.com" always_nxdomain
 local-zone: "thosewebbs.com" always_nxdomain
-local-zone: "thriveink.com" always_nxdomain
 local-zone: "tianangdep.com" always_nxdomain
 local-zone: "tickfood.tickme.lk" always_nxdomain
 local-zone: "tickjobs.tickme.lk" always_nxdomain
@@ -1065,7 +1056,6 @@ local-zone: "tsd.jxwan.com" always_nxdomain
 local-zone: "tulli.info" always_nxdomain
 local-zone: "tupperware.michaelroberge.ca" always_nxdomain
 local-zone: "turanggaresources.com" always_nxdomain
-local-zone: "tushartyagiji.digitalswagger.in" always_nxdomain
 local-zone: "uat.indianfilmzone.com" always_nxdomain
 local-zone: "ublretailerdemo.cstdevs.com" always_nxdomain
 local-zone: "udesk.searchkero.com" always_nxdomain
@@ -1075,7 +1065,6 @@ local-zone: "umwelt-kirchhof.de" always_nxdomain
 local-zone: "unicorpbrunei.com" always_nxdomain
 local-zone: "uniengrisb.com" always_nxdomain
 local-zone: "unisoftcc.com" always_nxdomain
-local-zone: "unitedpestsolutionstx.com" always_nxdomain
 local-zone: "unyazitelecom.com" always_nxdomain
 local-zone: "upcbpta.com" always_nxdomain
 local-zone: "urbane.dezinetimes.com" always_nxdomain
@@ -1102,17 +1091,18 @@ local-zone: "vitoriamodaintima.com.br" always_nxdomain
 local-zone: "vivationdesign.com" always_nxdomain
 local-zone: "viveirodoiscorregos.com.br" always_nxdomain
 local-zone: "vksales.com" always_nxdomain
+local-zone: "vladimirinternational.com" always_nxdomain
 local-zone: "vokasi.ub.ac.id" always_nxdomain
 local-zone: "vologroup.com.br" always_nxdomain
 local-zone: "voteyouramerica.dekitout.com" always_nxdomain
 local-zone: "vstsample.com" always_nxdomain
 local-zone: "vtube.fadlymotivator.com" always_nxdomain
 local-zone: "vvsskmodinationalschool.com" always_nxdomain
-local-zone: "wahrewah.nl" always_nxdomain
 local-zone: "wanepliberia.org" always_nxdomain
 local-zone: "wanepniger.org" always_nxdomain
 local-zone: "weareactum.com" always_nxdomain
 local-zone: "web.eng.ubu.ac.th" always_nxdomain
+local-zone: "web.geetle.ga" always_nxdomain
 local-zone: "web.geomegasoft.net" always_nxdomain
 local-zone: "web.newinnovationtechnology.com" always_nxdomain
 local-zone: "web.smarts-works.com" always_nxdomain
@@ -1126,13 +1116,12 @@ local-zone: "wexfashion.com" always_nxdomain
 local-zone: "whcms.yourpageserver.com" always_nxdomain
 local-zone: "whiteglovetailgate.com" always_nxdomain
 local-zone: "whiteresponse.com" always_nxdomain
+local-zone: "whynt.xyz" always_nxdomain
 local-zone: "wi522012.ferozo.com" always_nxdomain
 local-zone: "wikalen.co.za" always_nxdomain
 local-zone: "wildnights.co.uk" always_nxdomain
 local-zone: "wildtrust.mediadevstaging.com" always_nxdomain
 local-zone: "wimbamusica.com" always_nxdomain
-local-zone: "windcomtechnologies.com" always_nxdomain
-local-zone: "winnercircle.it" always_nxdomain
 local-zone: "wishesconcierge.com" always_nxdomain
 local-zone: "woezon.agency" always_nxdomain
 local-zone: "wolfgang-brodte.de" always_nxdomain
@@ -1148,7 +1137,6 @@ local-zone: "x2vn.com" always_nxdomain
 local-zone: "xia.beihaixue.com" always_nxdomain
 local-zone: "xixaoclothing.com" always_nxdomain
 local-zone: "xk.996is.com" always_nxdomain
-local-zone: "xmp.myracingaccounts.com" always_nxdomain
 local-zone: "xn--80akinnkiib6h.xn--90ais" always_nxdomain
 local-zone: "xn--polimerbizmimarlk-rvc.com" always_nxdomain
 local-zone: "ybom.urbanolab.com" always_nxdomain
@@ -1159,5 +1147,6 @@ local-zone: "youtubetrainingacademy.com" always_nxdomain
 local-zone: "yskadvisors.com" always_nxdomain
 local-zone: "yummyyogaudaipur.com" always_nxdomain
 local-zone: "yzkzixun.com" always_nxdomain
+local-zone: "zakra.tecnasulstore.com.br" always_nxdomain
 local-zone: "zytrox.tk" always_nxdomain
 local-zone: "zz.690tx.com" always_nxdomain
diff --git a/urlhaus-filter-unbound.conf b/urlhaus-filter-unbound.conf
index 60f4a596..e09aeab8 100644
--- a/urlhaus-filter-unbound.conf
+++ b/urlhaus-filter-unbound.conf
@@ -1,5 +1,5 @@
 # Title: Malicious Domains Unbound Blocklist
-# Updated: Thu, 25 Mar 2021 12:12:40 UTC
+# Updated: Fri, 26 Mar 2021 00:12:29 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -2496,6 +2496,7 @@ local-zone: "accesointerne.theworkpc.com" always_nxdomain
 local-zone: "access-24.jp" always_nxdomain
 local-zone: "access-cash.ae.org" always_nxdomain
 local-zone: "access-om.neomeric.us" always_nxdomain
+local-zone: "access-one.us" always_nxdomain
 local-zone: "access-to-web.com" always_nxdomain
 local-zone: "accessclub.jp" always_nxdomain
 local-zone: "accessdig.com" always_nxdomain
@@ -2673,6 +2674,7 @@ local-zone: "achremittanceservices.com" always_nxdomain
 local-zone: "acht-stuecken.de" always_nxdomain
 local-zone: "achuanchaolihai.cn" always_nxdomain
 local-zone: "aci.serabd.com" always_nxdomain
+local-zone: "aciabogados.com" always_nxdomain
 local-zone: "aciitaly.com" always_nxdomain
 local-zone: "acilevarkadasi.com" always_nxdomain
 local-zone: "acilisbalon.com" always_nxdomain
@@ -3089,6 +3091,7 @@ local-zone: "admin.grapejuiceofbrazil.com" always_nxdomain
 local-zone: "admin.greenlightcr.com" always_nxdomain
 local-zone: "admin.hopehorseback.org" always_nxdomain
 local-zone: "admin.jpcar.mystand.pt" always_nxdomain
+local-zone: "admin.mobilezenie.com" always_nxdomain
 local-zone: "admin.searchlowestprice.com" always_nxdomain
 local-zone: "admin.solissol.com" always_nxdomain
 local-zone: "admin.staging.buildsmart.io" always_nxdomain
@@ -3268,7 +3271,6 @@ local-zone: "adventuredsocks.com" always_nxdomain
 local-zone: "adventureexplorer.in" always_nxdomain
 local-zone: "adventurehr.com" always_nxdomain
 local-zone: "adventureitdate.com" always_nxdomain
-local-zone: "adventureits.com" always_nxdomain
 local-zone: "adventuremania.com" always_nxdomain
 local-zone: "adventurersafaris.com" always_nxdomain
 local-zone: "adventuresofarchibald.com" always_nxdomain
@@ -3688,6 +3690,7 @@ local-zone: "agenforedi.toko-abi.net" always_nxdomain
 local-zone: "agengarcinia5000.com" always_nxdomain
 local-zone: "agenity.com" always_nxdomain
 local-zone: "agenlama.com" always_nxdomain
+local-zone: "agenmovie.xyz" always_nxdomain
 local-zone: "agent-seo.jp" always_nxdomain
 local-zone: "agent.ken.by" always_nxdomain
 local-zone: "agent2.icu" always_nxdomain
@@ -10704,6 +10707,7 @@ local-zone: "barcaacademyistanbul.com" always_nxdomain
 local-zone: "barcelonaevent.es" always_nxdomain
 local-zone: "barcelonakartingcenter.com" always_nxdomain
 local-zone: "barchaklem.com" always_nxdomain
+local-zone: "barcionstw.eastus.cloudapp.azure.com" always_nxdomain
 local-zone: "barcla.ug" always_nxdomain
 local-zone: "barclaysdownloads.com" always_nxdomain
 local-zone: "barcoofoods.ir" always_nxdomain
@@ -12989,6 +12993,7 @@ local-zone: "bizzznez.com" always_nxdomain
 local-zone: "bj5800.com" always_nxdomain
 local-zone: "bjarndahl.dk" always_nxdomain
 local-zone: "bjbus.net" always_nxdomain
+local-zone: "bjconstructions.in" always_nxdomain
 local-zone: "bjdd.org" always_nxdomain
 local-zone: "bjenkins.webview.consulting" always_nxdomain
 local-zone: "bjenzer.com" always_nxdomain
@@ -14028,6 +14033,7 @@ local-zone: "bnote.novelux.com" always_nxdomain
 local-zone: "bnpartnersweb.com" always_nxdomain
 local-zone: "bnpgrup.com" always_nxdomain
 local-zone: "bnqzjy.cn" always_nxdomain
+local-zone: "bnrbook.com" always_nxdomain
 local-zone: "bnrnews.id" always_nxdomain
 local-zone: "bnsddfhjdfgvbxc.ru" always_nxdomain
 local-zone: "bnsgroupbd.com" always_nxdomain
@@ -14778,6 +14784,7 @@ local-zone: "brandzzy.com" always_nxdomain
 local-zone: "braner.com.ua" always_nxdomain
 local-zone: "branfinancial.com" always_nxdomain
 local-zone: "branner-chile.com" always_nxdomain
+local-zone: "brannon-powlowski25d.xyz" always_nxdomain
 local-zone: "brannudd.com" always_nxdomain
 local-zone: "brantech.com" always_nxdomain
 local-zone: "brar.aminfortgreene.com" always_nxdomain
@@ -15778,6 +15785,7 @@ local-zone: "buyrigrap.com" always_nxdomain
 local-zone: "buysellfx24.ru" always_nxdomain
 local-zone: "buysmart365.net" always_nxdomain
 local-zone: "buysmartwebmall.com" always_nxdomain
+local-zone: "buythebest.pk" always_nxdomain
 local-zone: "buytotake.online" always_nxdomain
 local-zone: "buytwitterlike.com" always_nxdomain
 local-zone: "buyuksigorta.com" always_nxdomain
@@ -17098,6 +17106,7 @@ local-zone: "cashonlinestore.com" always_nxdomain
 local-zone: "cashoutrefitips.com" always_nxdomain
 local-zone: "cashpickup.slmicrocredit.com" always_nxdomain
 local-zone: "cashslip.info" always_nxdomain
+local-zone: "cashtunel.com" always_nxdomain
 local-zone: "cashyinvestment.org" always_nxdomain
 local-zone: "casimiroartes.es" always_nxdomain
 local-zone: "casinarium.com" always_nxdomain
@@ -19670,6 +19679,7 @@ local-zone: "clubyourlife.ca" always_nxdomain
 local-zone: "clubzone.ca" always_nxdomain
 local-zone: "cluebazar.com" always_nxdomain
 local-zone: "clukva.ru" always_nxdomain
+local-zone: "clurbgolf.com" always_nxdomain
 local-zone: "clurit.com" always_nxdomain
 local-zone: "clusdirectory.xyz" always_nxdomain
 local-zone: "cluster-mixture.gq" always_nxdomain
@@ -19886,6 +19896,7 @@ local-zone: "coastmediagroup.com.au" always_nxdomain
 local-zone: "coastmedicalservice.com" always_nxdomain
 local-zone: "coastmotorsupply.com" always_nxdomain
 local-zone: "coastsignworks.com" always_nxdomain
+local-zone: "coastwidewaterproofing.com.au" always_nxdomain
 local-zone: "coatforwinter.com" always_nxdomain
 local-zone: "coavce.com" always_nxdomain
 local-zone: "cobam.xyz" always_nxdomain
@@ -21909,6 +21920,7 @@ local-zone: "cronicas.com.do" always_nxdomain
 local-zone: "cronolux.com.br" always_nxdomain
 local-zone: "croodly.com" always_nxdomain
 local-zone: "crookedchristicraddick.com" always_nxdomain
+local-zone: "crooks-cooper24g.xyz" always_nxdomain
 local-zone: "croos.org" always_nxdomain
 local-zone: "crope.shop" always_nxdomain
 local-zone: "cropfoods.com" always_nxdomain
@@ -23163,7 +23175,6 @@ local-zone: "dar-ltd.uk" always_nxdomain
 local-zone: "dar-sana.com" always_nxdomain
 local-zone: "darajelita.com" always_nxdomain
 local-zone: "daralsalam-mall.com" always_nxdomain
-local-zone: "daralsaqi.com" always_nxdomain
 local-zone: "darapartment.com" always_nxdomain
 local-zone: "darasrszs.online" always_nxdomain
 local-zone: "darassalam.ch" always_nxdomain
@@ -23272,7 +23283,6 @@ local-zone: "dashcenter.info" always_nxdomain
 local-zone: "dasheriemagazine.com" always_nxdomain
 local-zone: "dashfiles.tk" always_nxdomain
 local-zone: "dashkevichseo.ru" always_nxdomain
-local-zone: "dashonweb.com" always_nxdomain
 local-zone: "dashudance.com" always_nxdomain
 local-zone: "dashvaanjil.mn" always_nxdomain
 local-zone: "dasin-obchudek.cz" always_nxdomain
@@ -23600,6 +23610,7 @@ local-zone: "dboyusa.online" always_nxdomain
 local-zone: "dbravo.pro" always_nxdomain
 local-zone: "dbs-ebank.com" always_nxdomain
 local-zone: "dbsa-dream.com" always_nxdomain
+local-zone: "dbsandbox.ca" always_nxdomain
 local-zone: "dbsenvironmental.co.uk" always_nxdomain
 local-zone: "dbsgear.com" always_nxdomain
 local-zone: "dbsktoporder.yolasite.com" always_nxdomain
@@ -24508,6 +24519,7 @@ local-zone: "denlokale.nu" always_nxdomain
 local-zone: "denmaar.hplbusiness.com" always_nxdomain
 local-zone: "denmarkheating.net" always_nxdomain
 local-zone: "denmaytre.vn" always_nxdomain
+local-zone: "dennis-hill25lw.xyz" always_nxdomain
 local-zone: "dennis-roth.de" always_nxdomain
 local-zone: "dennishester.com" always_nxdomain
 local-zone: "dennisisasshole.com" always_nxdomain
@@ -27184,6 +27196,9 @@ local-zone: "down.posti-fi-fjwa.top" always_nxdomain
 local-zone: "down.posti-fi-fsa.top" always_nxdomain
 local-zone: "down.posti-fi-fsaq.top" always_nxdomain
 local-zone: "down.posti-fi-fwa.top" always_nxdomain
+local-zone: "down.posti-fi-ij.top" always_nxdomain
+local-zone: "down.posti-fi-in.top" always_nxdomain
+local-zone: "down.posti-fi-iz.top" always_nxdomain
 local-zone: "down.pzchao.com" always_nxdomain
 local-zone: "down.qm188.com" always_nxdomain
 local-zone: "down.qqfarmer.com.cn" always_nxdomain
@@ -29395,6 +29410,7 @@ local-zone: "egyptmaint.com" always_nxdomain
 local-zone: "egyptmotours.com" always_nxdomain
 local-zone: "egyptpharaohstours.com" always_nxdomain
 local-zone: "egyshadowmen.com" always_nxdomain
+local-zone: "egyutthato.eu" always_nxdomain
 local-zone: "egyuttkonnyebb.zolitoth.com" always_nxdomain
 local-zone: "egyvision.medicahealthy.net" always_nxdomain
 local-zone: "egywebtest.ml" always_nxdomain
@@ -30576,6 +30592,7 @@ local-zone: "ennaturismo.info" always_nxdomain
 local-zone: "ennessehospitality.id" always_nxdomain
 local-zone: "ennovate.elin.co.za" always_nxdomain
 local-zone: "eno.si" always_nxdomain
+local-zone: "enolil-loo.com" always_nxdomain
 local-zone: "enorichie.net" always_nxdomain
 local-zone: "enorka.info" always_nxdomain
 local-zone: "enosburgreading.pbworks.com" always_nxdomain
@@ -32549,6 +32566,7 @@ local-zone: "faithchorale.com" always_nxdomain
 local-zone: "faithcompassion.com" always_nxdomain
 local-zone: "faithconstructionltd.co.uk" always_nxdomain
 local-zone: "faithfight.my.id" always_nxdomain
+local-zone: "faithmethodistcheras.org" always_nxdomain
 local-zone: "faithmontessorischools.com" always_nxdomain
 local-zone: "faithoasis.000webhostapp.com" always_nxdomain
 local-zone: "faithworkx.com" always_nxdomain
@@ -33819,6 +33837,7 @@ local-zone: "findyourfocusph.com" always_nxdomain
 local-zone: "findyourvoice.ca" always_nxdomain
 local-zone: "fine-art-line.de" always_nxdomain
 local-zone: "fine.black" always_nxdomain
+local-zone: "fineartgallerym.com" always_nxdomain
 local-zone: "fineconera.com" always_nxdomain
 local-zone: "finefeather.info" always_nxdomain
 local-zone: "finefoodsfrozen.com" always_nxdomain
@@ -37447,6 +37466,7 @@ local-zone: "girlsphonenumbers.online" always_nxdomain
 local-zone: "girltalkza.co.za" always_nxdomain
 local-zone: "girlydesignart.com" always_nxdomain
 local-zone: "gironynavarro.com" always_nxdomain
+local-zone: "girotexuniformes.com" always_nxdomain
 local-zone: "girraj2016.gtranzit.com" always_nxdomain
 local-zone: "girrajwadi.com" always_nxdomain
 local-zone: "gisa.company" always_nxdomain
@@ -37536,6 +37556,7 @@ local-zone: "gladwynecapital.com" always_nxdomain
 local-zone: "glafka.com" always_nxdomain
 local-zone: "glambooth.nl" always_nxdomain
 local-zone: "glamoroushairextension.com" always_nxdomain
+local-zone: "glamorouspk.com" always_nxdomain
 local-zone: "glamour.rosolutions.com.mx" always_nxdomain
 local-zone: "glamourgarden-lb.com" always_nxdomain
 local-zone: "glamourlounge.org" always_nxdomain
@@ -38292,6 +38313,7 @@ local-zone: "gordondeen.net" always_nxdomain
 local-zone: "gordonmilktransport.com" always_nxdomain
 local-zone: "gordonruss.com" always_nxdomain
 local-zone: "gordyssensors.com" always_nxdomain
+local-zone: "gorecycle.fahadjutt.com" always_nxdomain
 local-zone: "gorenotoservisi.net" always_nxdomain
 local-zone: "gorestruly.com" always_nxdomain
 local-zone: "goretimmo.lu" always_nxdomain
@@ -39448,6 +39470,7 @@ local-zone: "gunesulkesi.com" always_nxdomain
 local-zone: "guneyaski.com" always_nxdomain
 local-zone: "gungazcomputer.co.ke" always_nxdomain
 local-zone: "gunk.insol.be" always_nxdomain
+local-zone: "gunma2u.com" always_nxdomain
 local-zone: "gunmak-com.tk" always_nxdomain
 local-zone: "gunnarasgeir.com" always_nxdomain
 local-zone: "gunnersexcavating.com" always_nxdomain
@@ -41799,6 +41822,7 @@ local-zone: "hollywoodremix.com" always_nxdomain
 local-zone: "hollywoodsmileeg.com" always_nxdomain
 local-zone: "holmdalehouse.co.uk" always_nxdomain
 local-zone: "holmesgroup-com.azurewebsites.net" always_nxdomain
+local-zone: "holmesprpmgmt.com" always_nxdomain
 local-zone: "holmnkolbas.com" always_nxdomain
 local-zone: "holmsater.se" always_nxdomain
 local-zone: "holod24.by" always_nxdomain
@@ -42492,6 +42516,7 @@ local-zone: "hpmamerica.com" always_nxdomain
 local-zone: "hpmaytinhtaophongcach.com" always_nxdomain
 local-zone: "hpmwqjub.com" always_nxdomain
 local-zone: "hpq8fa.db.files.1drv.com" always_nxdomain
+local-zone: "hprosacco25i.xyz" always_nxdomain
 local-zone: "hprpc.cn" always_nxdomain
 local-zone: "hps-sk.sk" always_nxdomain
 local-zone: "hps.nz" always_nxdomain
@@ -45068,6 +45093,7 @@ local-zone: "instant-resume.com" always_nxdomain
 local-zone: "instantbonheur.fr" always_nxdomain
 local-zone: "instantcashflowtoday.com.ng" always_nxdomain
 local-zone: "instantclients.network" always_nxdomain
+local-zone: "instantindialoan.com" always_nxdomain
 local-zone: "instanttaxsolutions.mobi" always_nxdomain
 local-zone: "instanttechnology.com.au" always_nxdomain
 local-zone: "instantworldpay.com" always_nxdomain
@@ -45892,6 +45918,7 @@ local-zone: "iscidavasi.com" always_nxdomain
 local-zone: "isciyizbiz.com" always_nxdomain
 local-zone: "iscleanone.com" always_nxdomain
 local-zone: "isclimatechangeahoax.com" always_nxdomain
+local-zone: "iscoegypt.com" always_nxdomain
 local-zone: "iscoming.ir" always_nxdomain
 local-zone: "iscon.com.br" always_nxdomain
 local-zone: "iscondisth.com" always_nxdomain
@@ -45947,7 +45974,6 @@ local-zone: "iskostrip.com" always_nxdomain
 local-zone: "iskro.textronic.info" always_nxdomain
 local-zone: "iskyservice.ru" always_nxdomain
 local-zone: "islaholics.com" always_nxdomain
-local-zone: "islamabadtrafficpolice.gov.pk" always_nxdomain
 local-zone: "islamabout.com" always_nxdomain
 local-zone: "islamappen.se" always_nxdomain
 local-zone: "islamforall.tv" always_nxdomain
@@ -47760,6 +47786,7 @@ local-zone: "jolly-saito-4993.sub.jp" always_nxdomain
 local-zone: "jollycharm.com" always_nxdomain
 local-zone: "jollyemma.com" always_nxdomain
 local-zone: "jolyscortinas.com.br" always_nxdomain
+local-zone: "jomansea.com" always_nxdomain
 local-zone: "jomar2020.com.br" always_nxdomain
 local-zone: "jomblo.com" always_nxdomain
 local-zone: "jomhermonex.com" always_nxdomain
@@ -49139,6 +49166,7 @@ local-zone: "kaspersky-security.com" always_nxdomain
 local-zone: "kasperskysecurity.club" always_nxdomain
 local-zone: "kasrasanatsepahan.com" always_nxdomain
 local-zone: "kassa.hostsites.ru" always_nxdomain
+local-zone: "kassandra5024d.xyz" always_nxdomain
 local-zone: "kassconnect.ru" always_nxdomain
 local-zone: "kasshmira.com" always_nxdomain
 local-zone: "kassohome.com.tr" always_nxdomain
@@ -49783,7 +49811,6 @@ local-zone: "khannamdo.com" always_nxdomain
 local-zone: "khannen.com.vn" always_nxdomain
 local-zone: "khannen.vn" always_nxdomain
 local-zone: "khanqahebrahimi.com" always_nxdomain
-local-zone: "khantil.com" always_nxdomain
 local-zone: "khantipong.com" always_nxdomain
 local-zone: "khaochills.com" always_nxdomain
 local-zone: "khaoden.tech" always_nxdomain
@@ -51645,6 +51672,7 @@ local-zone: "lab.sjworks.net" always_nxdomain
 local-zone: "lab.valvolari.it" always_nxdomain
 local-zone: "lab.ydigital.asia" always_nxdomain
 local-zone: "lab1.ozaki-kyousei.com" always_nxdomain
+local-zone: "lab18.it" always_nxdomain
 local-zone: "lab2.e-century.pl" always_nxdomain
 local-zone: "lab5.hu" always_nxdomain
 local-zone: "lab6.com.br" always_nxdomain
@@ -56683,6 +56711,7 @@ local-zone: "managegates.com" always_nxdomain
 local-zone: "manageitrisks.com" always_nxdomain
 local-zone: "management.vkims.com" always_nxdomain
 local-zone: "managementtop.id" always_nxdomain
+local-zone: "managemysalon.in" always_nxdomain
 local-zone: "managemyshoes.tools" always_nxdomain
 local-zone: "manageone.co.th" always_nxdomain
 local-zone: "manageprint.in" always_nxdomain
@@ -57064,6 +57093,7 @@ local-zone: "marecsko.hu" always_nxdomain
 local-zone: "marek-paysage-concept.fr" always_nxdomain
 local-zone: "marek.in" always_nxdomain
 local-zone: "marekvoprsal.cz" always_nxdomain
+local-zone: "marel.com.br" always_nxdomain
 local-zone: "marellengifts.com" always_nxdomain
 local-zone: "maremarius.pt" always_nxdomain
 local-zone: "marematto.it" always_nxdomain
@@ -58344,6 +58374,7 @@ local-zone: "meditationsurmesure.com" always_nxdomain
 local-zone: "meditec.ma" always_nxdomain
 local-zone: "mediterraneavacanze.com" always_nxdomain
 local-zone: "meditheraphy.com" always_nxdomain
+local-zone: "meditreat.itwebservice.in" always_nxdomain
 local-zone: "meditsinanarodnaya.ru" always_nxdomain
 local-zone: "medius.ge" always_nxdomain
 local-zone: "mediusvp.com" always_nxdomain
@@ -60520,6 +60551,7 @@ local-zone: "moitruongtunglam.com" always_nxdomain
 local-zone: "mojang.com.br" always_nxdomain
 local-zone: "mojehaftom.com" always_nxdomain
 local-zone: "mojewnetrza.pl" always_nxdomain
+local-zone: "mojno--vse.ru" always_nxdomain
 local-zone: "mojo-studios.co.uk" always_nxdomain
 local-zone: "mojorockstar.com" always_nxdomain
 local-zone: "mojstudent.net" always_nxdomain
@@ -61274,6 +61306,7 @@ local-zone: "mrpiratz.com" always_nxdomain
 local-zone: "mrpower.ir" always_nxdomain
 local-zone: "mrprintoke.com" always_nxdomain
 local-zone: "mrquick.co.il" always_nxdomain
+local-zone: "mrsambarbershop.nl" always_nxdomain
 local-zone: "mrsbow.com" always_nxdomain
 local-zone: "mrsconnect.org" always_nxdomain
 local-zone: "mrsdiggs.com" always_nxdomain
@@ -61874,6 +61907,7 @@ local-zone: "mvicente.com.br" always_nxdomain
 local-zone: "mvid.com" always_nxdomain
 local-zone: "mvidl.site" always_nxdomain
 local-zone: "mvisionproperties.com" always_nxdomain
+local-zone: "mvldesign.ca" always_nxdomain
 local-zone: "mvm368.com" always_nxdomain
 local-zone: "mvmskpd.com" always_nxdomain
 local-zone: "mvns.railfan.net" always_nxdomain
@@ -63208,6 +63242,7 @@ local-zone: "nellyvonalven.com" always_nxdomain
 local-zone: "nelsonhelps.com" always_nxdomain
 local-zone: "nelsonhostingcom.000webhostapp.com" always_nxdomain
 local-zone: "nelsonpto.org" always_nxdomain
+local-zone: "nelsonsbutchers.co.uk" always_nxdomain
 local-zone: "nelsonsilveti.com" always_nxdomain
 local-zone: "neltac.com" always_nxdomain
 local-zone: "nelyvos.nl" always_nxdomain
@@ -64542,7 +64577,6 @@ local-zone: "no18balloonroom.co.uk" always_nxdomain
 local-zone: "no1angelsescort.com" always_nxdomain
 local-zone: "no1spinningfields.90degrees.digital" always_nxdomain
 local-zone: "no1websitedesigner.com" always_nxdomain
-local-zone: "no2politics.com" always_nxdomain
 local-zone: "no70.fun" always_nxdomain
 local-zone: "noabuseshere.top" always_nxdomain
 local-zone: "noach.nl" always_nxdomain
@@ -65832,6 +65866,7 @@ local-zone: "ogxbody.com" always_nxdomain
 local-zone: "ohako.com.my" always_nxdomain
 local-zone: "ohamburguer.com.br" always_nxdomain
 local-zone: "ohanadev.com" always_nxdomain
+local-zone: "ohatsbd.com" always_nxdomain
 local-zone: "ohdratdigital.com" always_nxdomain
 local-zone: "ohe.ie" always_nxdomain
 local-zone: "ohelloguyzzqq.com" always_nxdomain
@@ -66136,6 +66171,7 @@ local-zone: "omada.edu.gr" always_nxdomain
 local-zone: "omagroup.ru" always_nxdomain
 local-zone: "omaharefugees.com" always_nxdomain
 local-zone: "omahduwur.com" always_nxdomain
+local-zone: "omaia.org" always_nxdomain
 local-zone: "omaint.ml" always_nxdomain
 local-zone: "omalleyco-my.sharepoint.com" always_nxdomain
 local-zone: "omalll.com" always_nxdomain
@@ -71766,6 +71802,7 @@ local-zone: "promodigital.tk" always_nxdomain
 local-zone: "promodont.com" always_nxdomain
 local-zone: "promokonyara.ru" always_nxdomain
 local-zone: "promolatinconferences.com" always_nxdomain
+local-zone: "promolyko.com" always_nxdomain
 local-zone: "promomitsubishitermurah.net" always_nxdomain
 local-zone: "promonoble.com" always_nxdomain
 local-zone: "promootzie.nl" always_nxdomain
@@ -73181,6 +73218,7 @@ local-zone: "quickmusings.com" always_nxdomain
 local-zone: "quickpickapp.co" always_nxdomain
 local-zone: "quickreachmedia.com" always_nxdomain
 local-zone: "quicksaleecuador.com" always_nxdomain
+local-zone: "quickshine.co.ke" always_nxdomain
 local-zone: "quickstorevn.com" always_nxdomain
 local-zone: "quicktechsupport247.com" always_nxdomain
 local-zone: "quicktowtowing.com" always_nxdomain
@@ -75282,6 +75320,7 @@ local-zone: "rgclimatizacion.com" always_nxdomain
 local-zone: "rgdecor.org" always_nxdomain
 local-zone: "rgfloors.com.au" always_nxdomain
 local-zone: "rgitabit.in" always_nxdomain
+local-zone: "rgleason25s.xyz" always_nxdomain
 local-zone: "rglgrupomedico.com.mx" always_nxdomain
 local-zone: "rgmobilegossip.com" always_nxdomain
 local-zone: "rgmvanijya.com" always_nxdomain
@@ -76126,6 +76165,7 @@ local-zone: "roselvi.cl" always_nxdomain
 local-zone: "rosemaryromero.com.br" always_nxdomain
 local-zone: "rosemiracle.com" always_nxdomain
 local-zone: "rosemurphy.co.uk" always_nxdomain
+local-zone: "rosenbaum-jaida24nz.xyz" always_nxdomain
 local-zone: "rosenfeldcapital.com" always_nxdomain
 local-zone: "rosenlaw.cratima.com" always_nxdomain
 local-zone: "roseperfeito.com.br" always_nxdomain
@@ -80044,6 +80084,7 @@ local-zone: "shastri.com" always_nxdomain
 local-zone: "shatabbytek.com" always_nxdomain
 local-zone: "shataikok.com" always_nxdomain
 local-zone: "shatelnews.ir" always_nxdomain
+local-zone: "shatteredglass.io" always_nxdomain
 local-zone: "shaukya.com" always_nxdomain
 local-zone: "shaulla.store" always_nxdomain
 local-zone: "shaunodonnell.com" always_nxdomain
@@ -81905,6 +81946,7 @@ local-zone: "smartlogo.com.br" always_nxdomain
 local-zone: "smartlync.pk" always_nxdomain
 local-zone: "smartmadira.com" always_nxdomain
 local-zone: "smartmassive.ru" always_nxdomain
+local-zone: "smartmatrixs.com" always_nxdomain
 local-zone: "smartmobilelearning.co.za" always_nxdomain
 local-zone: "smartmoneylife.com" always_nxdomain
 local-zone: "smartmovie.com.ua" always_nxdomain
@@ -82867,6 +82909,7 @@ local-zone: "sosctb.com" always_nxdomain
 local-zone: "sosenfantsburkinafaso.fr" always_nxdomain
 local-zone: "sosexymagazine.com" always_nxdomain
 local-zone: "sosflam.com" always_nxdomain
+local-zone: "sosgsm.fr" always_nxdomain
 local-zone: "sosh47.citycheb.ru" always_nxdomain
 local-zone: "sosoab.com" always_nxdomain
 local-zone: "sosofoto.cz" always_nxdomain
@@ -87503,6 +87546,7 @@ local-zone: "tecnologiaoficial.com" always_nxdomain
 local-zone: "tecnologiatech.com" always_nxdomain
 local-zone: "tecnologiaz.com" always_nxdomain
 local-zone: "tecnologicainformatica.com.br" always_nxdomain
+local-zone: "tecnologyschool.com" always_nxdomain
 local-zone: "tecnolora.com" always_nxdomain
 local-zone: "tecnoloxia.com" always_nxdomain
 local-zone: "tecnopc.info" always_nxdomain
@@ -90267,6 +90311,7 @@ local-zone: "tobpm.kz" always_nxdomain
 local-zone: "toby-warren.com" always_nxdomain
 local-zone: "tobyetc.com" always_nxdomain
 local-zone: "tobysherman.com" always_nxdomain
+local-zone: "tocaima.co" always_nxdomain
 local-zone: "tocakids.resultaweb.com.br" always_nxdomain
 local-zone: "tocgiajojo.com" always_nxdomain
 local-zone: "tochkae.ru" always_nxdomain
@@ -91394,6 +91439,7 @@ local-zone: "tresjoliejewellery.com" always_nxdomain
 local-zone: "tresnexus.com" always_nxdomain
 local-zone: "treterhef.download" always_nxdomain
 local-zone: "tretthing-bg.site" always_nxdomain
+local-zone: "treutel-jamir25ju.xyz" always_nxdomain
 local-zone: "trevellinglove.com" always_nxdomain
 local-zone: "trevinos.net" always_nxdomain
 local-zone: "trevorchristensen.com" always_nxdomain
@@ -94096,6 +94142,7 @@ local-zone: "vastintegrated.com" always_nxdomain
 local-zone: "vastraindia.com" always_nxdomain
 local-zone: "vastralaya.shop" always_nxdomain
 local-zone: "vastuanalyst.com" always_nxdomain
+local-zone: "vastubless.com" always_nxdomain
 local-zone: "vastuvidyaarchitects.com" always_nxdomain
 local-zone: "vasudhagoodharvest.com" always_nxdomain
 local-zone: "vasumadhi.com" always_nxdomain
@@ -95441,6 +95488,7 @@ local-zone: "vlad.iset.ro" always_nxdomain
 local-zone: "vladetel.org" always_nxdomain
 local-zone: "vladimirfilin.com" always_nxdomain
 local-zone: "vladimirfilin.ru" always_nxdomain
+local-zone: "vladimirinternational.com" always_nxdomain
 local-zone: "vladneta.lt" always_nxdomain
 local-zone: "vladsever.ru" always_nxdomain
 local-zone: "vladsp.ru" always_nxdomain
@@ -96439,6 +96487,7 @@ local-zone: "web.eficiens.cl" always_nxdomain
 local-zone: "web.emergingsun.com" always_nxdomain
 local-zone: "web.emsfabrik.de" always_nxdomain
 local-zone: "web.eng.ubu.ac.th" always_nxdomain
+local-zone: "web.geetle.ga" always_nxdomain
 local-zone: "web.geomegasoft.net" always_nxdomain
 local-zone: "web.golden-goblin.com" always_nxdomain
 local-zone: "web.gotham.com.au" always_nxdomain
@@ -97253,6 +97302,7 @@ local-zone: "why-h.xyz" always_nxdomain
 local-zone: "whyasksolution.com" always_nxdomain
 local-zone: "whybowl.thebotogs.com" always_nxdomain
 local-zone: "whyepicshop.com" always_nxdomain
+local-zone: "whynt.xyz" always_nxdomain
 local-zone: "whysquare.co.nz" always_nxdomain
 local-zone: "whystudio.cn" always_nxdomain
 local-zone: "whytech.info" always_nxdomain
@@ -98320,6 +98370,7 @@ local-zone: "wroxra.by.files.1drv.com" always_nxdomain
 local-zone: "wrrodrigo.com" always_nxdomain
 local-zone: "wrtech.com.pl" always_nxdomain
 local-zone: "wrusnollet.com" always_nxdomain
+local-zone: "wrzucacz.pl" always_nxdomain
 local-zone: "wrzutka.co" always_nxdomain
 local-zone: "ws-ebavisapia01-dll.ir" always_nxdomain
 local-zone: "ws3lfkm.com" always_nxdomain
@@ -98767,6 +98818,7 @@ local-zone: "xh.hj46.cn" always_nxdomain
 local-zone: "xhcmnews.com" always_nxdomain
 local-zone: "xhd.qhv.mybluehost.me" always_nxdomain
 local-zone: "xhencheng.tk" always_nxdomain
+local-zone: "xherzog24pv.xyz" always_nxdomain
 local-zone: "xhjclq.ch.files.1drv.com" always_nxdomain
 local-zone: "xhs9a81.com" always_nxdomain
 local-zone: "xhsdxm.com" always_nxdomain
@@ -100626,6 +100678,7 @@ local-zone: "zafinternational.co.id" always_nxdomain
 local-zone: "zafirotiendas.com" always_nxdomain
 local-zone: "zagnet.pl" always_nxdomain
 local-zone: "zagogulina.com" always_nxdomain
+local-zone: "zagoradesertcamp.com" always_nxdomain
 local-zone: "zagrodazbyszka.pl" always_nxdomain
 local-zone: "zagros-shahrekord.ir" always_nxdomain
 local-zone: "zagrosenergygroup.com" always_nxdomain
@@ -100681,6 +100734,7 @@ local-zone: "zakodujbiznes.ml" always_nxdomain
 local-zone: "zakopane.utazas.hu" always_nxdomain
 local-zone: "zakopanedomki.com.pl" always_nxdomain
 local-zone: "zakosciele66.cba.pl" always_nxdomain
+local-zone: "zakra.tecnasulstore.com.br" always_nxdomain
 local-zone: "zakrahgroup.com" always_nxdomain
 local-zone: "zakriasons.co" always_nxdomain
 local-zone: "zakromanoff.com" always_nxdomain
diff --git a/urlhaus-filter-vivaldi-online.txt b/urlhaus-filter-vivaldi-online.txt
index 50fb3ec4..4c33efff 100644
--- a/urlhaus-filter-vivaldi-online.txt
+++ b/urlhaus-filter-vivaldi-online.txt
@@ -1,5 +1,5 @@
 ! Title: Online Malicious URL Blocklist (Vivaldi)
-! Updated: Thu, 25 Mar 2021 12:12:40 UTC
+! Updated: Fri, 26 Mar 2021 00:12:29 UTC
 ! Expires: 1 day (update frequency)
 ! Homepage: https://gitlab.com/curben/urlhaus-filter
 ! License: https://gitlab.com/curben/urlhaus-filter#license
@@ -12,7 +12,6 @@
 ||1.192.180.19$document
 ||1.222.140.251$document
 ||1.222.196.60$document
-||1.24.132.118$document
 ||1.245.4.163$document
 ||1.246.222.107$document
 ||1.246.222.109$document
@@ -22,8 +21,10 @@
 ||1.246.222.153$document
 ||1.246.222.16$document
 ||1.246.222.165$document
+||1.246.222.228$document
 ||1.246.222.232$document
 ||1.246.222.234$document
+||1.246.222.237$document
 ||1.246.222.245$document
 ||1.246.222.249$document
 ||1.246.222.38$document
@@ -34,7 +35,6 @@
 ||1.246.222.69$document
 ||1.246.222.8$document
 ||1.246.222.80$document
-||1.246.222.9$document
 ||1.246.222.98$document
 ||1.246.223.10$document
 ||1.246.223.103$document
@@ -66,23 +66,19 @@
 ||1.250.159.41$document
 ||1.252.102.28$document
 ||1.254.250.52$document
+||1.58.223.96$document
 ||1.60.77.53$document
-||1.62.195.101$document
 ||1.65.166.225$document
 ||1.82.104.89$document
-||1.85.84.38$document
 ||100.12.184.63$document
 ||100.2.131.143$document
 ||100.8.77.4$document
 ||1008691.com$document
 ||101.108.130.108$document
-||101.108.131.202$document
-||101.108.133.231$document
 ||101.16.183.179$document
 ||101.16.98.170$document
 ||101.229.85.127$document
 ||101.255.36.154$document
-||101.28.102.38$document
 ||101.28.105.132$document
 ||101.28.106.134$document
 ||101.28.145.2$document
@@ -93,45 +89,49 @@
 ||101.75.157.99$document
 ||102.130.115.14$document
 ||102.141.240.139$document
-||103.106.29.148$document
 ||103.107.113.22$document
 ||103.113.99.79$document
 ||103.124.104.118$document
 ||103.125.218.107$document
 ||103.136.82.50$document
-||103.139.89.205$document
 ||103.141.138.12$document
 ||103.144.36.20$document
 ||103.145.13.24$document
 ||103.146.174.208$document
 ||103.156.221.66$document
 ||103.16.145.25$document
+||103.161.232.16$document
+||103.207.0.134$document
 ||103.217.215.21$document
 ||103.224.200.40$document
 ||103.233.64.182$document
-||103.235.165.183$document
 ||103.238.228.3$document
 ||103.238.228.4$document
 ||103.240.249.121$document
+||103.4.117.26$document
 ||103.70.160.51$document
 ||103.79.112.254$document
+||103.82.144.197$document
 ||103.82.145.111$document
+||103.82.98.151$document
 ||103.82.98.170$document
-||103.84.240.130$document
 ||103.84.240.228$document
-||103.91.245.11$document
 ||103.91.245.12$document
+||103.91.245.16$document
 ||103.91.245.17$document
 ||103.91.245.19$document
 ||103.91.245.20$document
+||103.91.245.27$document
 ||103.91.245.3$document
+||103.91.245.30$document
 ||103.91.245.36$document
+||103.91.245.41$document
 ||103.91.245.46$document
 ||103.91.245.47$document
 ||103.91.245.54$document
 ||103.92.25.90$document
 ||103.92.25.95$document
-||104.168.44.57$document
+||104.168.98.105$document
 ||104.184.75.123$document
 ||104.33.52.85$document
 ||104.61.86.37$document
@@ -140,6 +140,7 @@
 ||106.104.193.155$document
 ||106.113.145.32$document
 ||106.113.177.60$document
+||106.4.138.95$document
 ||107.172.134.48$document
 ||107.172.193.132$document
 ||107.172.249.148$document
@@ -158,8 +159,8 @@
 ||109.124.90.229$document
 ||109.233.196.232$document
 ||109.235.7.228$document
-||109.248.58.238$document
 ||109.86.85.253$document
+||109.88.185.119$document
 ||109.95.200.102$document
 ||109.95.200.230$document
 ||109.96.127.90$document
@@ -174,6 +175,7 @@
 ||110.228.195.46$document
 ||110.241.119.168$document
 ||110.241.23.107$document
+||110.247.151.4$document
 ||110.248.124.254$document
 ||110.248.224.19$document
 ||110.248.251.194$document
@@ -183,22 +185,25 @@
 ||110.253.51.112$document
 ||110.255.101.184$document
 ||110.255.167.147$document
-||110.35.145.127$document
 ||110.35.208.21$document
 ||110.35.209.175$document
-||110.35.221.77$document
 ||110.35.223.92$document
+||110.35.225.24$document
+||110.35.233.147$document
 ||110.35.235.57$document
+||110.35.249.21$document
 ||110.35.4.2$document
-||110.82.195.88$document
 ||110fss.net$document
-||111.118.124.223$document
+||111.118.111.207$document
 ||111.118.41.173$document
 ||111.118.88.61$document
+||111.119.245.114$document
 ||111.125.67.125$document
 ||111.160.112.142$document
 ||111.162.224.14$document
 ||111.163.50.120$document
+||111.165.21.195$document
+||111.165.28.234$document
 ||111.17.186.194$document
 ||111.170.84.182$document
 ||111.170.86.133$document
@@ -212,6 +217,7 @@
 ||111.185.230.136$document
 ||111.185.27.9$document
 ||111.185.48.248$document
+||111.38.103.114$document
 ||111.38.103.122$document
 ||111.38.103.13$document
 ||111.38.103.66$document
@@ -234,16 +240,16 @@
 ||111.61.52.53$document
 ||111.73.99.162$document
 ||111.91.185.131$document
+||111.92.63.24$document
 ||111.93.169.90$document
 ||112.105.117.227$document
 ||112.111.100.236$document
 ||112.111.108.184$document
 ||112.111.31.175$document
 ||112.122.36.108$document
-||112.123.109.156$document
 ||112.123.200.47$document
-||112.123.61.115$document
 ||112.132.134.106$document
+||112.159.108.96$document
 ||112.170.124.75$document
 ||112.170.233.9$document
 ||112.186.210.211$document
@@ -299,10 +305,10 @@
 ||112.242.2.247$document
 ||112.243.115.183$document
 ||112.245.12.89$document
-||112.245.246.253$document
 ||112.245.5.141$document
 ||112.245.8.24$document
 ||112.246.162.50$document
+||112.246.180.49$document
 ||112.247.100.14$document
 ||112.247.121.39$document
 ||112.247.14.135$document
@@ -310,6 +316,7 @@
 ||112.247.191.118$document
 ||112.247.214.146$document
 ||112.247.240.226$document
+||112.247.248.76$document
 ||112.247.81.173$document
 ||112.247.82.122$document
 ||112.247.89.81$document
@@ -318,8 +325,10 @@
 ||112.248.44.153$document
 ||112.249.109.217$document
 ||112.249.118.157$document
+||112.249.206.69$document
 ||112.249.26.129$document
 ||112.249.41.142$document
+||112.249.79.98$document
 ||112.250.102.173$document
 ||112.250.57.99$document
 ||112.251.17.5$document
@@ -332,6 +341,7 @@
 ||112.252.237.109$document
 ||112.252.239.103$document
 ||112.252.245.249$document
+||112.252.46.212$document
 ||112.254.208.123$document
 ||112.255.38.10$document
 ||112.255.52.179$document
@@ -346,6 +356,7 @@
 ||112.27.124.119$document
 ||112.27.124.120$document
 ||112.27.124.122$document
+||112.27.124.124$document
 ||112.27.124.127$document
 ||112.27.124.128$document
 ||112.27.124.130$document
@@ -361,7 +372,6 @@
 ||112.27.124.146$document
 ||112.27.124.149$document
 ||112.27.124.150$document
-||112.27.124.151$document
 ||112.27.124.155$document
 ||112.27.124.158$document
 ||112.27.124.160$document
@@ -450,12 +460,10 @@
 ||112.72.153.37$document
 ||112.72.162.159$document
 ||112.72.162.49$document
-||112.72.162.53$document
 ||112.72.175.147$document
 ||112.72.176.112$document
 ||112.72.176.84$document
 ||112.72.226.202$document
-||112.72.231.35$document
 ||112.78.45.158$document
 ||112.80.118.16$document
 ||112.80.127.91$document
@@ -472,18 +480,17 @@
 ||112.82.227.41$document
 ||112.82.228.175$document
 ||112.86.133.125$document
-||112.86.23.41$document
 ||112.86.253.238$document
 ||112.9.140.247$document
 ||112.93.29.211$document
 ||112.95.22.17$document
 ||112.95.23.121$document
 ||113.103.10.209$document
+||113.104.237.52$document
 ||113.105.71.239$document
-||113.11.95.254$document
-||113.110.247.207$document
 ||113.116.121.167$document
 ||113.116.149.83$document
+||113.116.150.147$document
 ||113.116.246.109$document
 ||113.116.48.217$document
 ||113.118.195.247$document
@@ -492,11 +499,11 @@
 ||113.161.58.249$document
 ||113.172.250.35$document
 ||113.179.129.99$document
-||113.188.76.31$document
 ||113.194.133.9$document
 ||113.194.135.154$document
 ||113.195.163.26$document
 ||113.195.166.46$document
+||113.201.24.26$document
 ||113.224.225.172$document
 ||113.226.42.250$document
 ||113.227.128.9$document
@@ -506,31 +513,28 @@
 ||113.231.93.142$document
 ||113.232.141.23$document
 ||113.232.211.182$document
+||113.234.224.130$document
 ||113.235.116.209$document
 ||113.237.129.7$document
-||113.245.218.18$document
+||113.253.144.141$document
 ||113.254.169.251$document
 ||113.3.153.57$document
 ||113.3.155.199$document
 ||113.59.133.16$document
-||113.59.136.39$document
-||113.59.144.42$document
 ||113.59.154.21$document
-||113.59.191.47$document
 ||113.61.204.205$document
+||113.81.112.35$document
 ||113.86.204.13$document
 ||113.87.175.112$document
-||113.87.32.93$document
+||113.87.248.177$document
+||113.88.100.120$document
 ||113.88.208.189$document
 ||113.88.232.36$document
+||113.88.242.0$document
 ||113.88.38.232$document
-||113.89.41.33$document
+||113.89.245.13$document
 ||113.89.41.51$document
-||113.92.156.196$document
-||113.93.225.12$document
 ||114.199.204.37$document
-||114.199.253.235$document
-||114.223.122.19$document
 ||114.226.100.56$document
 ||114.227.156.119$document
 ||114.228.205.101$document
@@ -539,53 +543,62 @@
 ||114.229.52.14$document
 ||114.235.115.236$document
 ||114.235.42.152$document
-||114.30.54.64$document
 ||114.79.161.94$document
 ||114.79.172.42$document
 ||115.165.216.112$document
+||115.171.239.28$document
 ||115.193.130.126$document
+||115.201.38.185$document
 ||115.208.101.195$document
+||115.213.187.251$document
 ||115.223.159.80$document
 ||115.23.88.135$document
 ||115.42.47.36$document
+||115.45.178.12$document
 ||115.48.130.181$document
+||115.48.130.187$document
+||115.48.135.151$document
 ||115.48.141.239$document
 ||115.48.198.142$document
-||115.48.215.189$document
+||115.48.200.115$document
 ||115.48.22.130$document
 ||115.48.228.176$document
 ||115.48.9.246$document
 ||115.49.100.124$document
-||115.49.18.53$document
-||115.49.216.150$document
+||115.49.152.10$document
+||115.49.242.100$document
 ||115.49.60.231$document
+||115.49.80.117$document
+||115.49.96.88$document
 ||115.50.1.143$document
 ||115.50.158.223$document
 ||115.50.2.251$document
-||115.50.219.100$document
-||115.50.22.86$document
+||115.50.202.11$document
 ||115.50.220.156$document
-||115.50.224.175$document
-||115.50.230.43$document
-||115.50.232.149$document
 ||115.50.239.222$document
-||115.50.3.25$document
-||115.50.56.198$document
-||115.50.8.131$document
+||115.50.240.230$document
+||115.50.61.247$document
+||115.50.64.182$document
 ||115.50.81.194$document
 ||115.51.104.85$document
+||115.51.107.18$document
 ||115.51.123.216$document
 ||115.51.93.76$document
 ||115.52.112.200$document
+||115.52.17.196$document
 ||115.52.19.250$document
 ||115.52.200.245$document
+||115.52.201.231$document
 ||115.52.21.5$document
-||115.54.192.172$document
-||115.54.222.126$document
+||115.52.22.162$document
+||115.54.160.25$document
+||115.54.212.227$document
 ||115.54.236.22$document
+||115.54.240.173$document
 ||115.54.241.122$document
+||115.54.70.108$document
 ||115.54.73.162$document
-||115.55.105.163$document
+||115.54.73.50$document
 ||115.55.144.146$document
 ||115.55.144.222$document
 ||115.55.144.42$document
@@ -593,58 +606,70 @@
 ||115.55.149.30$document
 ||115.55.178.67$document
 ||115.55.198.209$document
+||115.55.211.41$document
 ||115.55.211.86$document
+||115.55.3.36$document
 ||115.55.42.200$document
 ||115.55.53.51$document
 ||115.56.134.116$document
 ||115.56.134.220$document
+||115.56.136.144$document
 ||115.56.139.122$document
 ||115.56.142.251$document
 ||115.56.143.241$document
 ||115.56.148.22$document
+||115.56.154.147$document
 ||115.56.155.72$document
 ||115.56.156.185$document
+||115.56.156.54$document
 ||115.56.162.173$document
-||115.56.178.107$document
+||115.56.177.202$document
 ||115.56.188.24$document
 ||115.56.31.54$document
-||115.56.67.22$document
 ||115.56.86.251$document
 ||115.56.87.42$document
 ||115.56.98.205$document
 ||115.58.111.222$document
 ||115.58.119.171$document
+||115.58.132.199$document
 ||115.58.134.143$document
 ||115.58.141.177$document
+||115.58.167.90$document
+||115.58.20.186$document
 ||115.58.83.233$document
 ||115.58.88.163$document
 ||115.58.93.151$document
 ||115.59.197.123$document
 ||115.59.198.165$document
+||115.59.198.200$document
 ||115.59.210.228$document
+||115.59.215.96$document
 ||115.59.235.229$document
 ||115.59.253.202$document
-||115.59.26.134$document
 ||115.59.63.220$document
+||115.59.95.247$document
+||115.60.201.176$document
 ||115.61.107.203$document
-||115.61.111.142$document
+||115.61.118.201$document
 ||115.61.119.187$document
 ||115.61.119.198$document
 ||115.61.119.77$document
 ||115.61.125.184$document
-||115.61.137.47$document
 ||115.61.180.193$document
 ||115.61.182.138$document
 ||115.61.185.246$document
 ||115.61.97.190$document
+||115.61.97.55$document
+||115.62.152.207$document
 ||115.62.26.39$document
-||115.62.60.206$document
 ||115.63.135.206$document
+||115.63.140.242$document
 ||115.63.4.244$document
 ||115.63.56.176$document
 ||115.73.3.11$document
 ||115.74.217.2$document
 ||115.75.217.79$document
+||115.78.133.146$document
 ||115.92.174.231$document
 ||116.124.219.2$document
 ||116.127.207.224$document
@@ -655,18 +680,20 @@
 ||116.211.100.26$document
 ||116.212.142.215$document
 ||116.24.153.40$document
-||116.72.201.93$document
-||116.75.192.140$document
+||116.72.202.126$document
+||116.72.202.87$document
+||116.72.203.143$document
+||116.74.84.65$document
+||116.75.194.14$document
 ||116.76.114.71$document
 ||116.88.65.131$document
 ||117.11.234.35$document
-||117.11.95.179$document
 ||117.15.201.1$document
-||117.192.224.243$document
-||117.192.225.29$document
-||117.192.226.96$document
-||117.194.162.116$document
-||117.194.163.237$document
+||117.156.69.22$document
+||117.194.160.84$document
+||117.194.161.143$document
+||117.194.162.121$document
+||117.196.48.216$document
 ||117.20.204.138$document
 ||117.20.204.5$document
 ||117.20.210.52$document
@@ -676,39 +703,25 @@
 ||117.200.76.54$document
 ||117.200.76.60$document
 ||117.201.128.152$document
-||117.202.66.23$document
-||117.202.67.181$document
-||117.202.67.218$document
-||117.202.68.75$document
-||117.213.41.18$document
-||117.213.42.147$document
-||117.213.42.226$document
-||117.213.44.184$document
-||117.213.45.119$document
-||117.213.45.150$document
-||117.213.45.204$document
-||117.213.46.124$document
-||117.213.46.243$document
-||117.215.213.155$document
-||117.215.215.188$document
-||117.222.160.86$document
-||117.222.165.221$document
-||117.222.166.6$document
-||117.222.169.193$document
-||117.222.170.122$document
-||117.222.175.220$document
+||117.202.66.177$document
+||117.202.68.94$document
+||117.208.133.121$document
+||117.222.161.68$document
+||117.222.162.144$document
+||117.222.163.150$document
+||117.222.165.31$document
+||117.222.170.189$document
+||117.222.171.68$document
+||117.222.172.97$document
 ||117.241.66.200$document
 ||117.241.67.68$document
-||117.242.211.217$document
-||117.247.204.33$document
-||117.247.206.195$document
-||117.248.60.21$document
-||117.251.56.191$document
-||117.251.56.244$document
-||117.251.56.64$document
-||117.251.56.73$document
+||117.242.210.69$document
+||117.242.211.111$document
+||117.242.211.98$document
+||117.251.56.135$document
+||117.251.59.242$document
 ||117.251.60.161$document
-||117.251.63.211$document
+||117.251.60.69$document
 ||117.26.110.17$document
 ||117.26.235.164$document
 ||117.27.10.73$document
@@ -716,8 +729,11 @@
 ||117.63.195.140$document
 ||117.63.252.82$document
 ||117.63.53.15$document
+||117.63.56.81$document
+||117.86.105.110$document
 ||117.87.170.32$document
 ||117.90.78.120$document
+||117.91.240.50$document
 ||117.93.115.242$document
 ||117.93.79.40$document
 ||118.176.104.35$document
@@ -734,19 +750,20 @@
 ||118.232.88.146$document
 ||118.232.96.150$document
 ||118.232.96.6$document
-||118.233.165.213$document
 ||118.233.221.162$document
+||118.233.63.194$document
 ||118.233.65.93$document
 ||118.249.136.112$document
 ||118.250.51.192$document
-||118.38.189.207$document
 ||118.42.125.246$document
 ||118.43.180.33$document
 ||118.68.245.69$document
+||118.75.120.136$document
+||118.75.240.239$document
 ||118.75.50.253$document
 ||118.75.70.70$document
 ||118.79.125.92$document
-||118.79.143.45$document
+||118.79.164.102$document
 ||118.79.218.157$document
 ||118.79.50.203$document
 ||118.79.58.82$document
@@ -762,7 +779,7 @@
 ||119.112.22.58$document
 ||119.118.251.73$document
 ||119.119.52.202$document
-||119.123.219.137$document
+||119.123.175.133$document
 ||119.14.143.145$document
 ||119.147.213.57$document
 ||119.162.109.111$document
@@ -774,6 +791,7 @@
 ||119.165.107.93$document
 ||119.165.163.220$document
 ||119.165.174.63$document
+||119.165.208.73$document
 ||119.165.241.222$document
 ||119.165.27.77$document
 ||119.165.68.145$document
@@ -793,6 +811,7 @@
 ||119.179.170.212$document
 ||119.179.27.213$document
 ||119.179.43.1$document
+||119.179.44.141$document
 ||119.179.75.8$document
 ||119.18.38.144$document
 ||119.180.101.151$document
@@ -803,6 +822,7 @@
 ||119.180.231.79$document
 ||119.180.33.161$document
 ||119.180.80.69$document
+||119.180.9.35$document
 ||119.180.94.80$document
 ||119.181.124.203$document
 ||119.181.43.18$document
@@ -829,6 +849,7 @@
 ||119.191.215.221$document
 ||119.191.253.206$document
 ||119.204.30.144$document
+||119.250.129.231$document
 ||119.250.218.177$document
 ||119.251.105.221$document
 ||119.251.12.85$document
@@ -836,12 +857,12 @@
 ||119.56.131.155$document
 ||119.56.143.46$document
 ||119.56.143.71$document
+||119.56.144.75$document
 ||119.56.148.115$document
 ||119.56.155.57$document
+||119.56.166.36$document
 ||119.56.172.28$document
-||119.56.175.41$document
 ||119.56.206.43$document
-||119.56.220.170$document
 ||119.96.37.55$document
 ||119.96.70.116$document
 ||119.99.188.187$document
@@ -856,6 +877,7 @@
 ||12.207.39.227$document
 ||120.12.144.232$document
 ||120.12.153.54$document
+||120.12.212.5$document
 ||120.142.222.22$document
 ||120.150.213.110$document
 ||120.151.248.134$document
@@ -900,20 +922,19 @@
 ||120.43.54.218$document
 ||120.50.66.60$document
 ||120.50.93.115$document
-||120.59.245.212$document
 ||120.6.141.142$document
 ||120.6.8.11$document
 ||120.69.113.208$document
 ||120.69.131.51$document
 ||120.7.90.104$document
 ||120.85.165.141$document
-||120.85.169.138$document
+||120.85.173.137$document
 ||120.85.174.165$document
 ||120.85.174.175$document
-||120.85.186.112$document
+||120.85.174.39$document
+||120.85.199.222$document
+||120.85.212.45$document
 ||120.85.237.129$document
-||120.85.239.77$document
-||120.86.84.72$document
 ||120.9.32.51$document
 ||121.100.114.164$document
 ||121.100.96.8$document
@@ -941,6 +962,7 @@
 ||121.24.116.173$document
 ||121.25.101.86$document
 ||121.254.43.215$document
+||121.34.150.32$document
 ||121.61.101.93$document
 ||121.61.102.1$document
 ||121.61.107.189$document
@@ -950,6 +972,8 @@
 ||122.100.150.204$document
 ||122.137.52.122$document
 ||122.160.147.53$document
+||122.188.86.225$document
+||122.190.19.204$document
 ||122.192.190.203$document
 ||122.194.191.57$document
 ||122.199.72.23$document
@@ -957,19 +981,18 @@
 ||122.199.83.86$document
 ||122.202.37.85$document
 ||122.202.41.23$document
-||122.252.241.170$document
 ||122.252.250.22$document
 ||122.254.183.207$document
 ||122.254.29.37$document
 ||122.254.33.214$document
 ||123.0.240.58$document
 ||123.10.128.46$document
+||123.10.131.225$document
 ||123.10.140.225$document
-||123.10.210.87$document
+||123.10.209.95$document
 ||123.10.36.124$document
 ||123.10.41.32$document
-||123.11.1.232$document
-||123.11.74.72$document
+||123.10.83.136$document
 ||123.110.124.238$document
 ||123.110.124.244$document
 ||123.110.170.237$document
@@ -977,13 +1000,15 @@
 ||123.110.19.248$document
 ||123.110.200.98$document
 ||123.110.238.188$document
-||123.12.238.89$document
+||123.12.229.243$document
 ||123.12.3.58$document
+||123.12.36.185$document
 ||123.128.128.205$document
 ||123.128.133.91$document
 ||123.129.84.36$document
 ||123.129.88.123$document
-||123.130.169.45$document
+||123.13.101.56$document
+||123.13.30.75$document
 ||123.130.208.52$document
 ||123.130.23.110$document
 ||123.130.37.182$document
@@ -1000,9 +1025,9 @@
 ||123.135.71.150$document
 ||123.14.101.111$document
 ||123.14.150.79$document
+||123.14.205.23$document
 ||123.14.217.22$document
 ||123.14.235.65$document
-||123.14.248.97$document
 ||123.14.76.38$document
 ||123.14.88.195$document
 ||123.152.42.4$document
@@ -1013,6 +1038,7 @@
 ||123.159.137.101$document
 ||123.159.31.110$document
 ||123.159.8.100$document
+||123.183.123.41$document
 ||123.191.173.88$document
 ||123.192.101.163$document
 ||123.192.194.233$document
@@ -1033,7 +1059,6 @@
 ||123.234.116.110$document
 ||123.234.184.57$document
 ||123.234.246.103$document
-||123.235.107.135$document
 ||123.240.103.89$document
 ||123.240.181.57$document
 ||123.240.79.61$document
@@ -1041,39 +1066,42 @@
 ||123.241.184.124$document
 ||123.27.44.219$document
 ||123.28.217.23$document
+||123.4.180.137$document
+||123.4.185.137$document
 ||123.4.193.171$document
 ||123.4.44.217$document
 ||123.4.85.76$document
-||123.4.88.225$document
 ||123.4.92.3$document
 ||123.5.123.162$document
-||123.5.13.128$document
 ||123.5.178.213$document
+||123.5.188.181$document
+||123.5.22.220$document
 ||123.5.27.66$document
-||123.8.253.37$document
+||123.8.183.194$document
 ||123.8.254.172$document
 ||123.8.40.20$document
 ||123.8.41.63$document
 ||123.8.62.165$document
-||123.9.110.119$document
 ||123.9.243.93$document
-||123.9.245.134$document
 ||124.105.105.222$document
 ||124.129.162.169$document
 ||124.129.221.150$document
 ||124.129.76.230$document
 ||124.130.167.20$document
+||124.130.40.31$document
 ||124.131.104.82$document
 ||124.131.130.95$document
 ||124.131.136.75$document
 ||124.131.151.135$document
 ||124.131.21.39$document
+||124.131.26.243$document
 ||124.131.26.78$document
 ||124.131.54.33$document
 ||124.131.70.49$document
 ||124.131.72.208$document
 ||124.132.110.150$document
 ||124.135.34.49$document
+||124.153.136.175$document
 ||124.153.236.6$document
 ||124.160.126.238$document
 ||124.163.138.104$document
@@ -1093,9 +1121,11 @@
 ||124.6.0.4$document
 ||124.7.254.85$document
 ||124.80.46.73$document
-||124.92.132.207$document
 ||124.92.148.218$document
+||124.95.17.41$document
 ||125.106.125.119$document
+||125.106.252.96$document
+||125.126.69.95$document
 ||125.128.28.161$document
 ||125.142.93.34$document
 ||125.168.10.234$document
@@ -1103,79 +1133,82 @@
 ||125.40.1.127$document
 ||125.40.107.252$document
 ||125.40.113.66$document
+||125.40.136.25$document
 ||125.40.150.131$document
 ||125.40.16.231$document
 ||125.40.163.112$document
+||125.40.237.130$document
 ||125.40.65.120$document
 ||125.40.73.6$document
 ||125.40.74.153$document
 ||125.40.75.22$document
-||125.41.0.209$document
 ||125.41.106.180$document
 ||125.41.138.208$document
 ||125.41.189.235$document
 ||125.41.191.183$document
 ||125.41.196.151$document
-||125.41.2.58$document
+||125.41.200.189$document
 ||125.41.204.126$document
 ||125.41.205.197$document
-||125.41.245.135$document
 ||125.41.6.192$document
 ||125.41.7.204$document
 ||125.41.80.153$document
 ||125.41.86.72$document
 ||125.41.96.53$document
-||125.41.97.22$document
 ||125.42.124.114$document
+||125.42.125.103$document
 ||125.42.234.197$document
 ||125.42.96.17$document
-||125.42.96.209$document
 ||125.42.98.24$document
+||125.43.105.157$document
 ||125.43.106.162$document
 ||125.43.112.123$document
 ||125.43.126.184$document
+||125.43.130.232$document
 ||125.43.136.23$document
 ||125.43.177.48$document
+||125.43.21.157$document
 ||125.43.26.36$document
 ||125.43.34.132$document
-||125.43.5.247$document
 ||125.43.53.9$document
-||125.43.93.164$document
+||125.43.73.19$document
 ||125.44.168.169$document
+||125.44.212.107$document
 ||125.44.213.216$document
-||125.44.248.76$document
-||125.44.29.38$document
+||125.44.230.191$document
 ||125.44.30.143$document
-||125.44.42.12$document
-||125.44.61.172$document
+||125.44.31.79$document
 ||125.44.8.227$document
+||125.45.57.249$document
 ||125.45.65.166$document
+||125.45.90.158$document
+||125.46.138.117$document
 ||125.46.184.28$document
-||125.46.203.85$document
 ||125.46.206.206$document
 ||125.47.193.134$document
 ||125.47.200.11$document
-||125.47.207.239$document
 ||125.47.209.166$document
 ||125.47.244.201$document
-||125.47.29.173$document
+||125.47.252.106$document
+||125.47.254.44$document
+||125.47.28.217$document
 ||125.47.36.171$document
 ||125.47.45.218$document
 ||125.47.71.30$document
 ||125.47.90.82$document
 ||125.47.91.51$document
+||125.99.220.202$document
 ||128.116.133.92$document
 ||130.255.159.133$document
 ||134.195.139.4$document
-||134.236.252.28$document
 ||138.99.204.224$document
 ||139.159.226.180$document
 ||139.170.173.198$document
 ||139.170.174.162$document
+||139.170.228.166$document
 ||139.216.102.151$document
 ||139.227.46.137$document
 ||14.102.17.222$document
-||14.102.97.204$document
 ||14.136.80.242$document
 ||14.138.109.129$document
 ||14.138.109.26$document
@@ -1191,16 +1224,21 @@
 ||14.46.25.17$document
 ||14.46.98.241$document
 ||14.55.29.2$document
+||140.237.30.113$document
+||140.237.5.43$document
 ||142.11.216.5$document
 ||142.177.56.127$document
 ||146.71.79.230$document
 ||148.69.108.177$document
-||149.255.15.121$document
+||149.20.176.179$document
 ||149.255.15.180$document
 ||149.255.15.182$document
+||149.255.15.191$document
+||149.255.15.235$document
 ||149.255.15.87$document
-||149.3.36.210$document
+||149.3.85.55$document
 ||150.116.207.99$document
+||150.129.105.61$document
 ||151.177.163.87$document
 ||151.33.230.191$document
 ||151.51.158.195$document
@@ -1213,10 +1251,12 @@
 ||153.34.135.92$document
 ||153.34.23.76$document
 ||153.34.29.28$document
-||153.34.52.74$document
+||153.35.111.46$document
 ||153.35.27.49$document
 ||153.36.126.35$document
 ||154.126.178.16$document
+||154.91.1.27$document
+||157.122.105.142$document
 ||158.101.165.14$document
 ||158.174.213.128$document
 ||158.51.125.115$document
@@ -1226,12 +1266,16 @@
 ||162.191.249.195$document
 ||162.194.28.60$document
 ||162.209.98.174$document
-||162.212.203.250$document
+||163.125.183.111$document
 ||163.125.195.108$document
-||163.125.200.233$document
+||163.125.200.72$document
 ||163.125.200.73$document
-||163.125.203.85$document
-||163.125.223.16$document
+||163.125.202.174$document
+||163.125.202.74$document
+||163.125.203.179$document
+||163.125.207.125$document
+||163.125.250.202$document
+||163.125.68.29$document
 ||163.53.206.228$document
 ||165.90.16.5$document
 ||170.78.39.3$document
@@ -1245,30 +1289,31 @@
 ||171.120.125.147$document
 ||171.121.6.162$document
 ||171.123.189.154$document
-||171.125.114.254$document
 ||171.125.30.233$document
 ||171.125.30.93$document
 ||171.125.64.223$document
+||171.125.65.22$document
 ||171.126.109.145$document
 ||171.34.112.42$document
+||171.34.114.181$document
 ||171.34.179.178$document
 ||171.35.161.234$document
 ||171.35.162.156$document
 ||171.35.173.151$document
 ||171.35.174.198$document
+||171.36.42.154$document
 ||171.38.219.189$document
 ||171.44.254.4$document
 ||172.105.36.168$document
 ||172.114.244.127$document
 ||172.245.5.185$document
-||172.93.176.137$document
+||172.245.5.190$document
 ||173.167.85.89$document
 ||173.169.46.85$document
 ||173.19.58.108$document
 ||173.220.222.227$document
 ||173.233.85.171$document
 ||173.235.209.70$document
-||173.237.254.251$document
 ||173.25.113.8$document
 ||173.52.95.134$document
 ||173.52.97.25$document
@@ -1281,12 +1326,11 @@
 ||174.84.148.29$document
 ||174.96.30.156$document
 ||175.10.147.167$document
-||175.10.48.233$document
-||175.11.212.203$document
-||175.11.96.155$document
+||175.11.193.66$document
 ||175.115.241.87$document
 ||175.117.66.74$document
 ||175.145.200.216$document
+||175.146.17.227$document
 ||175.153.144.2$document
 ||175.162.69.13$document
 ||175.169.172.216$document
@@ -1303,17 +1347,20 @@
 ||176.111.174.63$document
 ||176.111.174.66$document
 ||176.111.174.67$document
+||176.113.161.101$document
 ||176.113.161.104$document
 ||176.113.161.113$document
 ||176.113.161.120$document
 ||176.113.161.128$document
 ||176.113.161.138$document
 ||176.113.161.59$document
+||176.113.161.60$document
 ||176.113.161.65$document
 ||176.113.161.66$document
 ||176.113.161.84$document
 ||176.113.161.88$document
 ||176.113.161.91$document
+||176.113.161.93$document
 ||176.113.174.139$document
 ||176.12.117.70$document
 ||176.123.4.115$document
@@ -1321,6 +1368,7 @@
 ||176.123.7.127$document
 ||176.123.9.243$document
 ||176.124.7.225$document
+||176.221.251.147$document
 ||176.240.40.142$document
 ||176.240.84.106$document
 ||176.32.151.180$document
@@ -1329,90 +1377,103 @@
 ||177.54.82.154$document
 ||177.86.235.143$document
 ||178.124.182.187$document
-||178.136.195.90$document
-||178.141.210.251$document
+||178.134.185.112$document
+||178.141.161.129$document
 ||178.141.25.82$document
 ||178.141.57.166$document
 ||178.150.174.65$document
 ||178.165.122.141$document
 ||178.175.0.140$document
-||178.175.1.109$document
+||178.175.0.232$document
 ||178.175.1.247$document
 ||178.175.1.250$document
+||178.175.1.252$document
 ||178.175.1.80$document
 ||178.175.10.108$document
 ||178.175.10.156$document
 ||178.175.10.26$document
+||178.175.10.34$document
+||178.175.10.42$document
 ||178.175.100.129$document
 ||178.175.100.180$document
 ||178.175.100.190$document
 ||178.175.100.223$document
 ||178.175.100.4$document
+||178.175.100.87$document
 ||178.175.101.110$document
+||178.175.101.207$document
 ||178.175.102.134$document
 ||178.175.102.136$document
 ||178.175.102.152$document
+||178.175.102.221$document
 ||178.175.102.228$document
-||178.175.102.232$document
 ||178.175.102.245$document
-||178.175.102.81$document
 ||178.175.103.172$document
+||178.175.103.195$document
 ||178.175.103.91$document
+||178.175.104.106$document
+||178.175.104.110$document
 ||178.175.104.120$document
 ||178.175.104.128$document
 ||178.175.104.153$document
+||178.175.104.155$document
 ||178.175.104.16$document
-||178.175.104.161$document
 ||178.175.104.169$document
 ||178.175.104.183$document
 ||178.175.104.206$document
-||178.175.104.220$document
 ||178.175.104.49$document
+||178.175.104.64$document
 ||178.175.104.80$document
 ||178.175.105.111$document
+||178.175.105.125$document
 ||178.175.105.146$document
+||178.175.105.177$document
 ||178.175.105.217$document
 ||178.175.105.245$document
 ||178.175.105.247$document
 ||178.175.105.27$document
+||178.175.105.28$document
 ||178.175.105.49$document
-||178.175.105.85$document
+||178.175.105.94$document
 ||178.175.106.118$document
 ||178.175.106.18$document
 ||178.175.106.193$document
 ||178.175.106.219$document
+||178.175.106.253$document
 ||178.175.106.37$document
-||178.175.106.63$document
 ||178.175.106.77$document
 ||178.175.106.87$document
 ||178.175.107.0$document
 ||178.175.107.133$document
+||178.175.107.245$document
 ||178.175.107.83$document
+||178.175.107.86$document
 ||178.175.108.116$document
 ||178.175.108.145$document
 ||178.175.108.148$document
-||178.175.108.16$document
 ||178.175.108.179$document
-||178.175.108.18$document
+||178.175.108.232$document
 ||178.175.108.67$document
 ||178.175.108.87$document
+||178.175.108.94$document
 ||178.175.109.1$document
+||178.175.109.127$document
+||178.175.109.193$document
+||178.175.109.37$document
 ||178.175.109.77$document
+||178.175.109.78$document
 ||178.175.11.176$document
 ||178.175.11.184$document
 ||178.175.11.204$document
 ||178.175.11.57$document
 ||178.175.110.150$document
 ||178.175.110.155$document
-||178.175.110.173$document
 ||178.175.110.214$document
 ||178.175.110.221$document
-||178.175.110.43$document
 ||178.175.110.90$document
 ||178.175.110.97$document
 ||178.175.111.105$document
 ||178.175.111.157$document
-||178.175.111.16$document
 ||178.175.111.190$document
 ||178.175.111.206$document
 ||178.175.111.36$document
@@ -1420,20 +1481,20 @@
 ||178.175.112.159$document
 ||178.175.112.26$document
 ||178.175.112.4$document
-||178.175.113.130$document
-||178.175.113.150$document
+||178.175.112.79$document
+||178.175.113.0$document
 ||178.175.113.171$document
 ||178.175.113.174$document
 ||178.175.113.35$document
+||178.175.113.64$document
 ||178.175.113.85$document
 ||178.175.114.107$document
-||178.175.114.211$document
 ||178.175.114.215$document
 ||178.175.114.234$document
 ||178.175.114.238$document
 ||178.175.114.241$document
+||178.175.114.247$document
 ||178.175.114.254$document
-||178.175.114.27$document
 ||178.175.114.5$document
 ||178.175.114.55$document
 ||178.175.114.63$document
@@ -1441,14 +1502,19 @@
 ||178.175.114.90$document
 ||178.175.114.99$document
 ||178.175.115.1$document
+||178.175.115.12$document
 ||178.175.115.13$document
 ||178.175.115.142$document
 ||178.175.115.143$document
 ||178.175.115.19$document
+||178.175.115.206$document
+||178.175.115.208$document
 ||178.175.115.221$document
-||178.175.115.222$document
 ||178.175.115.242$document
 ||178.175.115.35$document
+||178.175.115.40$document
+||178.175.116.15$document
+||178.175.116.236$document
 ||178.175.116.48$document
 ||178.175.116.64$document
 ||178.175.116.87$document
@@ -1456,123 +1522,124 @@
 ||178.175.117.32$document
 ||178.175.117.51$document
 ||178.175.117.63$document
-||178.175.117.90$document
+||178.175.117.84$document
 ||178.175.118.112$document
+||178.175.118.139$document
 ||178.175.118.192$document
 ||178.175.118.225$document
-||178.175.118.34$document
 ||178.175.118.60$document
 ||178.175.119.205$document
 ||178.175.119.209$document
+||178.175.119.26$document
 ||178.175.119.86$document
 ||178.175.119.88$document
-||178.175.12.179$document
+||178.175.12.114$document
 ||178.175.12.252$document
 ||178.175.12.53$document
 ||178.175.12.97$document
 ||178.175.120.133$document
 ||178.175.120.184$document
+||178.175.120.196$document
 ||178.175.120.203$document
 ||178.175.120.251$document
 ||178.175.121.123$document
 ||178.175.121.155$document
 ||178.175.121.55$document
 ||178.175.121.62$document
+||178.175.121.63$document
 ||178.175.121.68$document
 ||178.175.121.99$document
-||178.175.122.144$document
 ||178.175.122.172$document
 ||178.175.122.245$document
+||178.175.122.26$document
 ||178.175.122.28$document
 ||178.175.123.113$document
 ||178.175.123.2$document
 ||178.175.123.20$document
-||178.175.123.223$document
+||178.175.123.30$document
 ||178.175.123.56$document
 ||178.175.123.60$document
 ||178.175.124.109$document
 ||178.175.124.122$document
 ||178.175.124.131$document
 ||178.175.124.141$document
-||178.175.124.157$document
-||178.175.124.175$document
 ||178.175.124.211$document
-||178.175.124.233$document
 ||178.175.124.4$document
 ||178.175.124.79$document
 ||178.175.124.89$document
-||178.175.124.9$document
 ||178.175.125.118$document
 ||178.175.125.14$document
-||178.175.125.143$document
 ||178.175.125.153$document
 ||178.175.125.156$document
 ||178.175.125.174$document
 ||178.175.125.219$document
 ||178.175.125.39$document
-||178.175.125.54$document
-||178.175.126.101$document
+||178.175.126.124$document
 ||178.175.126.131$document
 ||178.175.126.141$document
 ||178.175.126.167$document
 ||178.175.126.220$document
 ||178.175.126.222$document
 ||178.175.126.237$document
-||178.175.126.80$document
 ||178.175.126.83$document
+||178.175.127.10$document
 ||178.175.127.109$document
 ||178.175.127.116$document
+||178.175.127.129$document
 ||178.175.127.142$document
 ||178.175.127.15$document
 ||178.175.127.182$document
-||178.175.127.212$document
 ||178.175.127.230$document
 ||178.175.127.231$document
 ||178.175.127.236$document
+||178.175.127.238$document
 ||178.175.127.63$document
 ||178.175.127.75$document
+||178.175.13.237$document
 ||178.175.14.106$document
 ||178.175.14.185$document
 ||178.175.14.246$document
-||178.175.14.28$document
 ||178.175.14.60$document
 ||178.175.15.17$document
 ||178.175.15.217$document
+||178.175.15.232$document
+||178.175.15.246$document
 ||178.175.15.252$document
 ||178.175.15.35$document
+||178.175.15.44$document
 ||178.175.15.45$document
 ||178.175.15.85$document
 ||178.175.16.1$document
 ||178.175.16.108$document
-||178.175.16.121$document
+||178.175.16.114$document
 ||178.175.16.17$document
 ||178.175.16.179$document
+||178.175.16.193$document
 ||178.175.16.208$document
+||178.175.16.73$document
 ||178.175.16.97$document
 ||178.175.17.176$document
 ||178.175.17.245$document
 ||178.175.18.238$document
-||178.175.18.6$document
+||178.175.18.27$document
 ||178.175.18.93$document
 ||178.175.19.144$document
 ||178.175.19.150$document
 ||178.175.19.163$document
 ||178.175.19.174$document
+||178.175.19.229$document
 ||178.175.19.242$document
 ||178.175.19.44$document
 ||178.175.19.47$document
 ||178.175.2.110$document
 ||178.175.2.237$document
-||178.175.2.245$document
 ||178.175.2.41$document
 ||178.175.2.5$document
-||178.175.2.80$document
 ||178.175.20.117$document
 ||178.175.20.145$document
 ||178.175.20.170$document
 ||178.175.20.21$document
 ||178.175.20.225$document
-||178.175.20.227$document
 ||178.175.20.237$document
 ||178.175.20.238$document
 ||178.175.20.24$document
@@ -1581,19 +1648,21 @@
 ||178.175.21.149$document
 ||178.175.21.184$document
 ||178.175.21.238$document
-||178.175.21.58$document
 ||178.175.21.76$document
+||178.175.22.207$document
+||178.175.22.248$document
+||178.175.23.102$document
 ||178.175.23.156$document
 ||178.175.23.250$document
+||178.175.23.6$document
 ||178.175.24.13$document
 ||178.175.24.138$document
 ||178.175.24.15$document
 ||178.175.24.171$document
 ||178.175.24.227$document
-||178.175.24.239$document
-||178.175.24.251$document
+||178.175.24.230$document
 ||178.175.25.117$document
-||178.175.25.156$document
+||178.175.25.169$document
 ||178.175.25.244$document
 ||178.175.25.28$document
 ||178.175.25.56$document
@@ -1601,17 +1670,16 @@
 ||178.175.25.77$document
 ||178.175.26.134$document
 ||178.175.26.164$document
-||178.175.26.168$document
+||178.175.26.165$document
+||178.175.26.215$document
 ||178.175.26.219$document
 ||178.175.26.224$document
 ||178.175.26.246$document
-||178.175.26.38$document
-||178.175.26.69$document
+||178.175.26.34$document
 ||178.175.27.122$document
 ||178.175.27.138$document
 ||178.175.27.14$document
 ||178.175.27.167$document
-||178.175.27.169$document
 ||178.175.27.179$document
 ||178.175.27.199$document
 ||178.175.27.202$document
@@ -1619,69 +1687,66 @@
 ||178.175.27.225$document
 ||178.175.27.233$document
 ||178.175.27.239$document
-||178.175.27.241$document
+||178.175.27.32$document
+||178.175.27.48$document
 ||178.175.27.68$document
 ||178.175.27.69$document
 ||178.175.27.84$document
-||178.175.28.118$document
 ||178.175.28.124$document
-||178.175.28.128$document
-||178.175.28.167$document
 ||178.175.28.168$document
+||178.175.28.75$document
 ||178.175.28.8$document
+||178.175.29.12$document
 ||178.175.29.16$document
 ||178.175.29.173$document
 ||178.175.29.174$document
-||178.175.29.184$document
 ||178.175.29.207$document
 ||178.175.3.116$document
+||178.175.3.123$document
 ||178.175.3.130$document
 ||178.175.3.172$document
 ||178.175.3.190$document
+||178.175.3.194$document
 ||178.175.3.196$document
 ||178.175.3.214$document
 ||178.175.3.56$document
 ||178.175.3.81$document
 ||178.175.30.0$document
-||178.175.30.213$document
-||178.175.30.255$document
 ||178.175.30.77$document
 ||178.175.31.211$document
 ||178.175.31.232$document
 ||178.175.31.249$document
 ||178.175.31.251$document
 ||178.175.32.0$document
-||178.175.32.105$document
-||178.175.32.141$document
 ||178.175.32.172$document
-||178.175.32.196$document
 ||178.175.32.198$document
 ||178.175.32.208$document
 ||178.175.32.211$document
+||178.175.32.229$document
 ||178.175.32.243$document
-||178.175.32.32$document
+||178.175.32.255$document
 ||178.175.32.42$document
 ||178.175.32.89$document
 ||178.175.33.112$document
-||178.175.33.118$document
-||178.175.33.151$document
 ||178.175.33.155$document
 ||178.175.33.161$document
 ||178.175.33.162$document
 ||178.175.33.170$document
+||178.175.33.173$document
 ||178.175.33.174$document
 ||178.175.33.181$document
 ||178.175.33.2$document
+||178.175.33.205$document
 ||178.175.33.216$document
 ||178.175.33.234$document
 ||178.175.33.236$document
-||178.175.33.239$document
 ||178.175.33.26$document
+||178.175.34.219$document
+||178.175.34.5$document
+||178.175.34.56$document
 ||178.175.34.96$document
-||178.175.35.160$document
 ||178.175.35.21$document
 ||178.175.35.215$document
-||178.175.35.253$document
 ||178.175.35.38$document
 ||178.175.35.83$document
 ||178.175.35.89$document
@@ -1690,37 +1755,39 @@
 ||178.175.36.102$document
 ||178.175.36.112$document
 ||178.175.36.12$document
-||178.175.36.16$document
+||178.175.36.127$document
+||178.175.36.176$document
+||178.175.36.19$document
 ||178.175.36.199$document
-||178.175.36.200$document
 ||178.175.36.218$document
 ||178.175.36.22$document
 ||178.175.36.223$document
 ||178.175.36.33$document
-||178.175.36.88$document
+||178.175.36.78$document
 ||178.175.37.121$document
 ||178.175.37.135$document
 ||178.175.37.159$document
 ||178.175.37.6$document
 ||178.175.38.1$document
-||178.175.38.126$document
 ||178.175.38.132$document
-||178.175.38.148$document
 ||178.175.38.162$document
 ||178.175.38.165$document
 ||178.175.38.191$document
-||178.175.38.7$document
+||178.175.38.200$document
+||178.175.38.53$document
 ||178.175.38.98$document
 ||178.175.39.167$document
+||178.175.39.176$document
 ||178.175.39.245$document
+||178.175.39.61$document
+||178.175.4.219$document
 ||178.175.4.222$document
 ||178.175.4.42$document
-||178.175.4.58$document
 ||178.175.4.95$document
 ||178.175.40.1$document
+||178.175.40.145$document
 ||178.175.40.151$document
 ||178.175.40.166$document
-||178.175.40.191$document
 ||178.175.40.199$document
 ||178.175.40.226$document
 ||178.175.40.41$document
@@ -1728,10 +1795,10 @@
 ||178.175.40.67$document
 ||178.175.40.70$document
 ||178.175.40.71$document
-||178.175.40.73$document
 ||178.175.40.82$document
 ||178.175.41.165$document
 ||178.175.41.178$document
+||178.175.41.200$document
 ||178.175.41.203$document
 ||178.175.41.210$document
 ||178.175.41.216$document
@@ -1748,74 +1815,81 @@
 ||178.175.43.121$document
 ||178.175.43.125$document
 ||178.175.43.147$document
-||178.175.43.17$document
-||178.175.43.176$document
-||178.175.43.22$document
+||178.175.43.16$document
 ||178.175.43.33$document
-||178.175.43.44$document
-||178.175.43.47$document
+||178.175.43.34$document
+||178.175.44.0$document
 ||178.175.44.134$document
 ||178.175.44.143$document
 ||178.175.44.155$document
+||178.175.44.197$document
+||178.175.44.209$document
 ||178.175.44.218$document
+||178.175.44.219$document
 ||178.175.44.22$document
 ||178.175.44.241$document
+||178.175.44.70$document
 ||178.175.44.89$document
 ||178.175.44.90$document
+||178.175.44.95$document
 ||178.175.45.205$document
 ||178.175.45.221$document
 ||178.175.45.224$document
 ||178.175.45.230$document
+||178.175.46.119$document
+||178.175.46.132$document
+||178.175.46.151$document
 ||178.175.46.187$document
 ||178.175.47.141$document
 ||178.175.47.151$document
 ||178.175.48.121$document
 ||178.175.48.195$document
 ||178.175.48.243$document
+||178.175.48.76$document
+||178.175.49.100$document
 ||178.175.49.107$document
+||178.175.49.129$document
+||178.175.49.138$document
+||178.175.49.188$document
 ||178.175.49.247$document
 ||178.175.49.3$document
-||178.175.49.98$document
-||178.175.5.16$document
 ||178.175.5.247$document
 ||178.175.5.251$document
 ||178.175.5.70$document
 ||178.175.50.131$document
 ||178.175.50.177$document
+||178.175.50.196$document
 ||178.175.50.201$document
 ||178.175.50.218$document
 ||178.175.50.236$document
 ||178.175.50.237$document
-||178.175.50.47$document
-||178.175.51.150$document
 ||178.175.51.197$document
 ||178.175.51.202$document
 ||178.175.51.223$document
-||178.175.51.37$document
 ||178.175.51.66$document
 ||178.175.52.149$document
 ||178.175.52.161$document
-||178.175.52.79$document
 ||178.175.53.103$document
-||178.175.53.15$document
 ||178.175.53.186$document
 ||178.175.53.20$document
+||178.175.53.228$document
 ||178.175.53.4$document
 ||178.175.53.5$document
 ||178.175.53.79$document
 ||178.175.54.105$document
 ||178.175.54.205$document
 ||178.175.54.214$document
+||178.175.54.35$document
 ||178.175.54.72$document
 ||178.175.55.101$document
-||178.175.55.111$document
 ||178.175.55.163$document
-||178.175.55.204$document
+||178.175.55.170$document
 ||178.175.55.216$document
+||178.175.55.248$document
 ||178.175.55.29$document
 ||178.175.55.41$document
 ||178.175.55.77$document
-||178.175.55.86$document
+||178.175.55.85$document
 ||178.175.56.103$document
 ||178.175.56.196$document
 ||178.175.56.33$document
@@ -1824,10 +1898,8 @@
 ||178.175.57.141$document
 ||178.175.57.178$document
 ||178.175.57.192$document
-||178.175.57.7$document
-||178.175.58.117$document
 ||178.175.58.141$document
-||178.175.58.223$document
+||178.175.58.42$document
 ||178.175.59.142$document
 ||178.175.59.161$document
 ||178.175.59.229$document
@@ -1837,37 +1909,40 @@
 ||178.175.59.91$document
 ||178.175.6.134$document
 ||178.175.6.151$document
-||178.175.6.154$document
 ||178.175.6.162$document
-||178.175.6.171$document
-||178.175.60.154$document
+||178.175.6.72$document
 ||178.175.60.181$document
-||178.175.60.32$document
-||178.175.60.99$document
-||178.175.61.151$document
+||178.175.60.209$document
+||178.175.61.117$document
 ||178.175.61.156$document
 ||178.175.61.219$document
 ||178.175.61.229$document
 ||178.175.61.234$document
 ||178.175.61.253$document
 ||178.175.61.40$document
-||178.175.61.96$document
+||178.175.61.42$document
+||178.175.61.82$document
 ||178.175.62.110$document
 ||178.175.62.115$document
+||178.175.62.168$document
+||178.175.62.216$document
 ||178.175.62.43$document
-||178.175.63.185$document
+||178.175.62.44$document
+||178.175.62.70$document
+||178.175.63.194$document
 ||178.175.63.21$document
 ||178.175.63.218$document
 ||178.175.64.116$document
 ||178.175.64.12$document
 ||178.175.64.142$document
 ||178.175.64.158$document
+||178.175.64.219$document
 ||178.175.64.30$document
 ||178.175.64.66$document
 ||178.175.65.115$document
-||178.175.65.136$document
 ||178.175.65.171$document
 ||178.175.65.223$document
+||178.175.65.44$document
 ||178.175.65.70$document
 ||178.175.65.95$document
 ||178.175.65.96$document
@@ -1878,17 +1953,15 @@
 ||178.175.66.199$document
 ||178.175.66.211$document
 ||178.175.66.228$document
-||178.175.66.237$document
 ||178.175.66.93$document
 ||178.175.67.0$document
 ||178.175.67.184$document
-||178.175.67.185$document
 ||178.175.67.201$document
 ||178.175.67.254$document
-||178.175.67.31$document
+||178.175.67.83$document
+||178.175.68.1$document
 ||178.175.68.109$document
 ||178.175.68.126$document
-||178.175.68.166$document
 ||178.175.68.170$document
 ||178.175.68.227$document
 ||178.175.68.232$document
@@ -1897,12 +1970,14 @@
 ||178.175.68.66$document
 ||178.175.68.83$document
 ||178.175.69.111$document
+||178.175.69.112$document
 ||178.175.69.119$document
 ||178.175.69.128$document
 ||178.175.69.138$document
+||178.175.69.148$document
 ||178.175.69.149$document
+||178.175.69.173$document
 ||178.175.69.188$document
-||178.175.69.205$document
 ||178.175.69.77$document
 ||178.175.7.163$document
 ||178.175.70.119$document
@@ -1916,64 +1991,57 @@
 ||178.175.71.148$document
 ||178.175.71.153$document
 ||178.175.71.185$document
-||178.175.71.196$document
 ||178.175.71.22$document
+||178.175.71.240$document
 ||178.175.71.55$document
 ||178.175.71.63$document
+||178.175.71.64$document
 ||178.175.71.84$document
-||178.175.71.89$document
-||178.175.72.113$document
 ||178.175.72.13$document
 ||178.175.72.164$document
-||178.175.72.173$document
 ||178.175.72.196$document
 ||178.175.72.222$document
-||178.175.72.47$document
-||178.175.72.75$document
-||178.175.72.91$document
-||178.175.72.98$document
-||178.175.73.220$document
+||178.175.73.211$document
+||178.175.73.71$document
 ||178.175.74.182$document
 ||178.175.74.48$document
-||178.175.75.135$document
+||178.175.74.77$document
 ||178.175.75.181$document
 ||178.175.75.19$document
 ||178.175.75.209$document
-||178.175.75.249$document
-||178.175.75.54$document
 ||178.175.75.84$document
 ||178.175.75.87$document
 ||178.175.76.109$document
+||178.175.76.121$document
 ||178.175.76.167$document
 ||178.175.76.187$document
 ||178.175.76.214$document
 ||178.175.76.215$document
 ||178.175.76.217$document
 ||178.175.76.24$document
-||178.175.77.132$document
-||178.175.77.145$document
 ||178.175.77.46$document
 ||178.175.77.47$document
 ||178.175.77.95$document
 ||178.175.78.106$document
-||178.175.78.202$document
+||178.175.78.118$document
 ||178.175.78.233$document
 ||178.175.78.46$document
 ||178.175.78.76$document
+||178.175.78.97$document
 ||178.175.79.156$document
 ||178.175.79.227$document
-||178.175.79.24$document
 ||178.175.79.247$document
 ||178.175.79.45$document
 ||178.175.79.77$document
 ||178.175.8.100$document
-||178.175.8.165$document
 ||178.175.8.199$document
-||178.175.8.205$document
 ||178.175.8.217$document
 ||178.175.8.254$document
+||178.175.8.97$document
+||178.175.80.100$document
+||178.175.80.136$document
 ||178.175.80.237$document
-||178.175.80.244$document
+||178.175.80.41$document
 ||178.175.80.79$document
 ||178.175.80.86$document
 ||178.175.81.1$document
@@ -1982,43 +2050,47 @@
 ||178.175.81.152$document
 ||178.175.81.17$document
 ||178.175.81.194$document
-||178.175.81.216$document
 ||178.175.81.226$document
 ||178.175.81.244$document
+||178.175.81.32$document
 ||178.175.81.50$document
-||178.175.81.82$document
+||178.175.81.8$document
+||178.175.82.120$document
 ||178.175.82.61$document
 ||178.175.83.147$document
 ||178.175.83.196$document
+||178.175.83.247$document
 ||178.175.84.102$document
 ||178.175.84.109$document
 ||178.175.84.148$document
+||178.175.84.158$document
 ||178.175.84.159$document
 ||178.175.84.215$document
 ||178.175.84.42$document
 ||178.175.85.153$document
-||178.175.85.165$document
 ||178.175.85.183$document
 ||178.175.85.190$document
-||178.175.85.229$document
+||178.175.85.23$document
+||178.175.85.81$document
 ||178.175.85.87$document
-||178.175.85.9$document
 ||178.175.86.119$document
-||178.175.86.218$document
-||178.175.87.107$document
+||178.175.86.159$document
+||178.175.86.166$document
+||178.175.87.108$document
 ||178.175.87.123$document
 ||178.175.87.162$document
 ||178.175.87.253$document
-||178.175.87.90$document
 ||178.175.88.180$document
 ||178.175.88.181$document
-||178.175.88.78$document
 ||178.175.89.130$document
-||178.175.89.19$document
+||178.175.89.157$document
+||178.175.89.160$document
+||178.175.89.169$document
 ||178.175.89.37$document
-||178.175.89.51$document
-||178.175.9.178$document
+||178.175.9.106$document
+||178.175.9.139$document
 ||178.175.9.183$document
+||178.175.9.210$document
 ||178.175.9.215$document
 ||178.175.9.217$document
 ||178.175.9.245$document
@@ -2026,8 +2098,8 @@
 ||178.175.9.80$document
 ||178.175.9.84$document
 ||178.175.9.95$document
-||178.175.90.115$document
-||178.175.90.160$document
+||178.175.90.104$document
+||178.175.90.122$document
 ||178.175.90.178$document
 ||178.175.90.187$document
 ||178.175.90.21$document
@@ -2038,72 +2110,73 @@
 ||178.175.91.165$document
 ||178.175.91.172$document
 ||178.175.91.191$document
+||178.175.91.223$document
+||178.175.91.230$document
 ||178.175.91.253$document
-||178.175.91.47$document
 ||178.175.91.58$document
-||178.175.91.71$document
 ||178.175.91.96$document
 ||178.175.92.132$document
 ||178.175.92.186$document
 ||178.175.92.201$document
 ||178.175.92.208$document
 ||178.175.92.215$document
-||178.175.92.224$document
 ||178.175.92.231$document
 ||178.175.92.248$document
 ||178.175.92.45$document
 ||178.175.93.143$document
+||178.175.93.148$document
 ||178.175.93.150$document
 ||178.175.93.155$document
+||178.175.93.171$document
 ||178.175.93.198$document
+||178.175.93.224$document
 ||178.175.93.225$document
-||178.175.93.245$document
 ||178.175.93.31$document
+||178.175.93.34$document
 ||178.175.93.4$document
 ||178.175.93.45$document
 ||178.175.93.6$document
+||178.175.93.90$document
 ||178.175.94.116$document
-||178.175.94.184$document
 ||178.175.94.195$document
 ||178.175.94.238$document
+||178.175.94.248$document
 ||178.175.94.40$document
+||178.175.95.111$document
+||178.175.95.132$document
 ||178.175.95.147$document
 ||178.175.95.227$document
+||178.175.95.237$document
 ||178.175.95.244$document
-||178.175.95.249$document
 ||178.175.95.4$document
+||178.175.95.7$document
 ||178.175.95.89$document
-||178.175.95.99$document
 ||178.175.96.13$document
-||178.175.96.180$document
 ||178.175.96.195$document
-||178.175.96.24$document
 ||178.175.96.6$document
-||178.175.97.111$document
-||178.175.97.181$document
-||178.175.97.243$document
-||178.175.98.140$document
+||178.175.97.1$document
+||178.175.97.128$document
+||178.175.97.135$document
+||178.175.97.162$document
+||178.175.97.17$document
+||178.175.97.208$document
 ||178.175.98.228$document
 ||178.175.98.254$document
 ||178.175.98.50$document
 ||178.175.98.68$document
-||178.175.99.108$document
 ||178.175.99.123$document
 ||178.175.99.130$document
 ||178.175.99.22$document
 ||178.175.99.45$document
-||178.175.99.75$document
 ||178.175.99.8$document
 ||178.175.99.91$document
 ||178.19.183.14$document
-||178.205.101.33$document
 ||178.21.164.68$document
 ||178.217.8.194$document
 ||178.22.117.102$document
 ||178.222.252.130$document
 ||178.34.183.30$document
 ||178.92.246.246$document
-||178.93.112.88$document
 ||178.95.115.33$document
 ||179.159.58.134$document
 ||179.4.187.39$document
@@ -2116,7 +2189,6 @@
 ||180.116.203.220$document
 ||180.120.149.106$document
 ||180.122.13.227$document
-||180.125.155.69$document
 ||180.125.44.194$document
 ||180.157.66.204$document
 ||180.175.93.52$document
@@ -2137,7 +2209,6 @@
 ||181.112.218.238$document
 ||181.112.218.6$document
 ||181.143.60.163$document
-||181.174.63.114$document
 ||181.193.107.10$document
 ||181.199.170.210$document
 ||181.199.170.222$document
@@ -2154,79 +2225,86 @@
 ||182.112.52.131$document
 ||182.113.0.79$document
 ||182.113.222.154$document
+||182.113.233.129$document
 ||182.113.24.21$document
 ||182.114.106.207$document
-||182.114.122.228$document
 ||182.114.202.186$document
-||182.114.31.65$document
-||182.114.50.124$document
-||182.114.50.93$document
 ||182.114.64.27$document
-||182.114.70.177$document
-||182.114.93.165$document
-||182.114.94.255$document
 ||182.116.101.82$document
-||182.116.104.125$document
+||182.116.103.81$document
+||182.116.108.180$document
+||182.116.108.244$document
 ||182.116.110.31$document
-||182.116.44.70$document
-||182.116.49.171$document
+||182.116.119.129$document
 ||182.116.60.73$document
 ||182.116.61.252$document
 ||182.116.65.157$document
 ||182.116.65.245$document
 ||182.116.68.40$document
 ||182.116.69.37$document
-||182.116.69.47$document
 ||182.116.94.196$document
+||182.116.99.150$document
 ||182.116.99.17$document
 ||182.117.155.204$document
 ||182.117.25.120$document
 ||182.117.26.235$document
-||182.117.27.150$document
+||182.117.29.220$document
 ||182.117.29.74$document
 ||182.117.43.27$document
 ||182.118.140.117$document
 ||182.119.100.228$document
+||182.119.13.141$document
 ||182.119.14.252$document
 ||182.119.166.208$document
+||182.119.196.182$document
 ||182.119.211.69$document
 ||182.119.220.48$document
-||182.119.227.82$document
-||182.119.229.96$document
 ||182.119.236.21$document
+||182.119.49.17$document
 ||182.119.50.155$document
+||182.119.7.54$document
 ||182.119.81.33$document
 ||182.120.10.21$document
 ||182.120.16.22$document
 ||182.120.16.46$document
 ||182.120.37.251$document
 ||182.120.43.0$document
+||182.120.86.248$document
 ||182.121.101.100$document
 ||182.121.109.190$document
+||182.121.12.128$document
 ||182.121.125.170$document
 ||182.121.129.232$document
-||182.121.131.69$document
 ||182.121.133.200$document
-||182.121.135.160$document
+||182.121.133.46$document
+||182.121.134.73$document
 ||182.121.148.236$document
 ||182.121.157.221$document
-||182.121.200.151$document
+||182.121.165.217$document
+||182.121.205.118$document
 ||182.121.206.132$document
 ||182.121.219.239$document
 ||182.121.233.191$document
 ||182.121.249.26$document
-||182.121.68.100$document
+||182.121.50.111$document
+||182.121.78.29$document
 ||182.121.81.241$document
 ||182.121.92.113$document
 ||182.121.93.174$document
 ||182.121.98.21$document
 ||182.122.170.19$document
+||182.122.202.37$document
 ||182.122.220.203$document
 ||182.122.229.102$document
 ||182.122.245.2$document
+||182.122.246.187$document
 ||182.122.249.24$document
+||182.122.251.141$document
+||182.124.134.80$document
+||182.124.15.108$document
+||182.124.166.57$document
 ||182.124.188.23$document
-||182.124.53.111$document
+||182.124.95.139$document
 ||182.126.113.127$document
 ||182.126.117.41$document
 ||182.126.124.47$document
@@ -2236,22 +2314,27 @@
 ||182.126.139.66$document
 ||182.126.140.30$document
 ||182.126.178.187$document
+||182.126.181.121$document
+||182.126.241.7$document
+||182.126.52.233$document
 ||182.126.82.29$document
 ||182.126.83.79$document
-||182.126.87.58$document
+||182.126.87.207$document
 ||182.126.95.209$document
 ||182.127.155.157$document
 ||182.127.166.232$document
 ||182.127.210.107$document
 ||182.127.6.12$document
+||182.127.70.195$document
 ||182.127.78.61$document
-||182.127.87.72$document
 ||182.127.91.161$document
+||182.127.96.120$document
 ||182.172.36.164$document
-||182.207.219.164$document
 ||182.233.0.252$document
 ||182.235.252.31$document
 ||182.53.197.62$document
+||182.58.160.0$document
+||182.59.227.125$document
 ||182.88.235.221$document
 ||183.105.104.83$document
 ||183.105.225.154$document
@@ -2264,7 +2347,9 @@
 ||183.188.151.225$document
 ||183.188.180.116$document
 ||183.188.180.68$document
-||183.188.76.196$document
+||183.188.188.186$document
+||183.191.162.120$document
+||183.83.105.21$document
 ||183.83.14.35$document
 ||183.83.15.116$document
 ||183.83.23.138$document
@@ -2273,6 +2358,7 @@
 ||183.95.147.102$document
 ||183.97.22.14$document
 ||184.164.185.41$document
+||184.175.115.10$document
 ||184.74.149.230$document
 ||185.106.209.68$document
 ||185.107.3.8$document
@@ -2293,50 +2379,47 @@
 ||185.68.230.207$document
 ||185.81.157.186$document
 ||185.82.217.185$document
-||185.82.217.213$document
 ||185.82.219.160$document
 ||185.82.219.161$document
 ||185.82.219.219$document
-||185.82.219.80$document
 ||185.90.166.56$document
 ||186.151.144.85$document
 ||186.179.219.164$document
 ||186.179.243.112$document
 ||186.179.243.77$document
+||186.179.243.91$document
 ||186.179.253.150$document
 ||186.225.120.173$document
 ||186.227.148.107$document
+||186.232.44.86$document
 ||186.28.60.184$document
-||186.4.125.48$document
+||186.33.112.28$document
 ||186.73.188.132$document
 ||187.12.10.98$document
 ||187.188.124.229$document
 ||187.212.200.162$document
-||187.56.88.170$document
-||187.75.218.102$document
 ||188.10.21.14$document
 ||188.10.231.246$document
+||188.113.102.18$document
 ||188.113.81.17$document
-||188.127.224.149$document
 ||188.127.224.61$document
+||188.127.227.173$document
 ||188.127.227.99$document
-||188.127.230.133$document
 ||188.127.231.226$document
 ||188.127.231.55$document
 ||188.127.235.232$document
-||188.127.235.70$document
+||188.127.235.244$document
 ||188.127.235.71$document
+||188.127.237.152$document
 ||188.127.254.114$document
 ||188.13.179.87$document
 ||188.138.200.32$document
 ||188.152.41.141$document
 ||188.169.178.50$document
-||188.169.199.59$document
 ||188.169.30.30$document
 ||188.169.36.163$document
 ||188.242.167.159$document
 ||188.242.242.144$document
-||188.81.100.83$document
 ||188.83.202.25$document
 ||188.93.233.223$document
 ||189.222.157.241$document
@@ -2355,14 +2438,12 @@
 ||190.130.15.212$document
 ||190.130.20.14$document
 ||190.141.117.41$document
-||190.147.16.184$document
 ||190.159.240.9$document
 ||190.187.55.150$document
 ||190.210.214.130$document
 ||190.213.177.39$document
 ||190.213.226.63$document
 ||190.213.49.207$document
-||190.214.24.194$document
 ||190.216.140.123$document
 ||190.35.225.36$document
 ||190.65.206.162$document
@@ -2376,13 +2457,17 @@
 ||192.227.185.106$document
 ||192.227.209.27$document
 ||192.227.228.67$document
+||192.3.152.166$document
 ||192.3.73.205$document
 ||192.99.240.77$document
+||193.142.146.25$document
 ||193.228.135.144$document
 ||193.91.131.237$document
+||194.15.36.167$document
+||194.15.36.202$document
 ||194.152.35.139$document
 ||194.38.20.199$document
-||195.123.208.140$document
+||194.87.139.10$document
 ||195.123.213.154$document
 ||195.139.126.51$document
 ||195.228.231.218$document
@@ -2395,12 +2480,14 @@
 ||197.159.2.106$document
 ||197.50.27.115$document
 ||198.23.133.218$document
+||198.23.207.121$document
+||198.23.213.57$document
 ||198.23.251.105$document
 ||198.46.201.76$document
 ||198.46.202.7$document
 ||1am.co.nz$document
 ||2.229.89.119$document
-||2.37.203.65$document
+||2.249.161.188$document
 ||2.45.111.158$document
 ||2.45.4.24$document
 ||2.55.125.182$document
@@ -2419,27 +2506,26 @@
 ||201.184.163.170$document
 ||201.184.248.190$document
 ||201.187.102.73$document
-||201.193.17.190$document
+||201.200.254.86$document
 ||201.203.221.20$document
+||201.208.139.84$document
 ||201.215.84.97$document
 ||201.218.97.142$document
 ||202.107.233.41$document
 ||202.111.131.91$document
-||202.150.176.100$document
 ||202.164.150.115$document
 ||202.166.217.54$document
+||202.169.234.22$document
 ||202.169.234.47$document
 ||202.169.234.52$document
 ||202.169.234.56$document
-||202.178.113.26$document
+||202.169.234.9$document
 ||202.29.95.12$document
 ||202.4.124.58$document
 ||202.51.176.114$document
 ||202.51.191.174$document
 ||202.74.236.9$document
 ||203.109.201.243$document
-||203.130.69.205$document
-||203.170.105.156$document
 ||203.170.115.82$document
 ||203.189.156.107$document
 ||203.202.248.237$document
@@ -2454,28 +2540,25 @@
 ||203.82.36.34$document
 ||203.93.6.28$document
 ||204.195.116.171$document
-||205.185.115.74$document
 ||205.185.123.217$document
+||206.248.137.132$document
 ||206.47.41.166$document
 ||207.200.247.187$document
 ||207.44.28.234$document
 ||207.5.32.6$document
 ||208.163.58.18$document
-||209.133.223.130$document
 ||209.141.39.50$document
 ||209.141.40.190$document
-||209.141.40.31$document
 ||209.145.60.38$document
+||210.102.196.200$document
 ||210.124.149.19$document
 ||210.216.152.122$document
 ||210.216.153.142$document
-||210.57.234.131$document
 ||210.57.237.70$document
+||210.57.245.109$document
 ||210.68.242.114$document
 ||210.96.116.236$document
-||211.116.220.37$document
 ||211.172.11.169$document
-||211.179.243.103$document
 ||211.187.132.204$document
 ||211.187.75.220$document
 ||211.204.215.157$document
@@ -2487,8 +2570,8 @@
 ||211.238.83.238$document
 ||211.247.113.49$document
 ||211.247.5.96$document
-||211.32.122.110$document
 ||211.36.174.137$document
+||211.41.197.30$document
 ||211.47.102.51$document
 ||211.51.174.149$document
 ||212.122.86.105$document
@@ -2502,24 +2585,22 @@
 ||213.14.173.117$document
 ||213.149.182.113$document
 ||213.149.190.193$document
+||213.163.104.10$document
 ||213.163.104.12$document
 ||213.163.104.20$document
 ||213.163.104.99$document
 ||213.163.113.100$document
 ||213.163.113.199$document
 ||213.163.113.225$document
-||213.163.113.226$document
-||213.163.113.237$document
 ||213.163.113.51$document
 ||213.163.113.79$document
-||213.163.114.107$document
-||213.163.114.36$document
+||213.163.114.80$document
 ||213.163.115.11$document
 ||213.163.115.15$document
 ||213.163.115.26$document
+||213.163.115.33$document
 ||213.163.115.71$document
-||213.163.116.149$document
-||213.163.116.160$document
+||213.163.116.132$document
 ||213.163.116.164$document
 ||213.163.116.203$document
 ||213.163.116.249$document
@@ -2533,10 +2614,8 @@
 ||213.163.126.131$document
 ||213.163.126.243$document
 ||213.163.126.60$document
-||213.163.126.61$document
 ||213.163.126.7$document
-||213.163.126.96$document
-||213.163.127.178$document
+||213.163.126.71$document
 ||213.163.127.217$document
 ||213.163.127.46$document
 ||213.189.178.163$document
@@ -2544,8 +2623,6 @@
 ||213.249.156.189$document
 ||213.27.8.6$document
 ||213.80.44.17$document
-||213.87.87.173$document
-||213.92.254.214$document
 ||213.92.254.52$document
 ||213.92.255.36$document
 ||213.92.255.84$document
@@ -2557,10 +2634,9 @@
 ||216.36.12.98$document
 ||217.11.75.162$document
 ||217.127.133.214$document
-||218.104.175.64$document
+||218.103.180.199$document
 ||218.215.243.65$document
 ||218.238.246.3$document
-||218.255.226.166$document
 ||218.28.160.174$document
 ||218.35.207.119$document
 ||218.35.227.133$document
@@ -2569,38 +2645,45 @@
 ||218.48.135.50$document
 ||218.56.93.129$document
 ||218.57.53.55$document
-||218.58.3.119$document
-||218.58.3.38$document
 ||218.59.116.203$document
 ||218.72.198.15$document
-||218.72.248.42$document
 ||218.79.103.159$document
 ||219.154.104.209$document
 ||219.154.119.145$document
+||219.154.141.222$document
 ||219.154.182.197$document
 ||219.155.102.14$document
+||219.155.12.221$document
 ||219.155.14.17$document
+||219.155.170.22$document
+||219.155.208.188$document
 ||219.155.24.246$document
+||219.155.241.135$document
 ||219.155.26.37$document
-||219.155.28.41$document
 ||219.155.31.15$document
 ||219.155.31.67$document
+||219.155.37.97$document
 ||219.155.9.202$document
-||219.155.97.226$document
+||219.156.103.248$document
 ||219.156.21.73$document
-||219.157.139.165$document
+||219.156.23.29$document
+||219.156.60.224$document
+||219.156.9.32$document
 ||219.157.146.200$document
 ||219.157.150.91$document
 ||219.157.162.205$document
 ||219.157.17.8$document
-||219.157.177.232$document
 ||219.157.178.201$document
 ||219.157.183.29$document
 ||219.157.202.66$document
-||219.157.215.242$document
+||219.157.220.170$document
 ||219.157.221.133$document
+||219.157.223.245$document
+||219.157.244.33$document
 ||219.157.32.244$document
-||219.157.64.251$document
+||219.157.50.211$document
+||219.157.54.158$document
+||219.157.56.46$document
 ||219.241.6.180$document
 ||219.68.1.148$document
 ||219.68.1.84$document
@@ -2618,34 +2701,34 @@
 ||220.173.160.53$document
 ||220.200.22.163$document
 ||220.71.239.115$document
+||220.90.159.188$document
 ||221.0.16.221$document
 ||221.1.162.82$document
 ||221.124.78.15$document
 ||221.14.122.127$document
 ||221.14.182.157$document
 ||221.14.46.33$document
+||221.14.58.5$document
 ||221.14.58.84$document
-||221.15.124.188$document
+||221.15.147.220$document
 ||221.15.153.17$document
-||221.15.160.67$document
-||221.15.194.218$document
-||221.15.199.35$document
 ||221.15.218.173$document
 ||221.15.234.159$document
 ||221.15.234.175$document
+||221.15.237.107$document
 ||221.15.54.237$document
+||221.15.7.202$document
 ||221.157.191.178$document
 ||221.160.136.213$document
 ||221.160.177.104$document
 ||221.160.177.107$document
 ||221.160.177.224$document
 ||221.196.12.96$document
-||221.208.4.71$document
 ||221.214.130.147$document
-||221.214.146.73$document
 ||221.214.162.109$document
 ||221.214.224.184$document
 ||221.215.116.167$document
+||221.215.172.207$document
 ||221.215.184.31$document
 ||221.215.237.220$document
 ||221.215.239.162$document
@@ -2660,6 +2743,7 @@
 ||221.3.34.43$document
 ||221.3.43.223$document
 ||221.3.68.16$document
+||221.5.30.118$document
 ||222.108.17.64$document
 ||222.119.65.145$document
 ||222.132.125.138$document
@@ -2669,13 +2753,10 @@
 ||222.135.113.41$document
 ||222.135.219.29$document
 ||222.135.26.161$document
-||222.136.21.126$document
-||222.136.218.233$document
 ||222.136.231.197$document
 ||222.136.49.252$document
 ||222.137.101.251$document
 ||222.137.113.184$document
-||222.137.120.3$document
 ||222.137.121.127$document
 ||222.137.136.241$document
 ||222.137.137.5$document
@@ -2687,18 +2768,26 @@
 ||222.137.172.250$document
 ||222.137.175.242$document
 ||222.137.186.150$document
+||222.137.22.79$document
+||222.137.220.94$document
 ||222.137.221.128$document
+||222.137.49.4$document
 ||222.137.5.150$document
 ||222.137.72.146$document
-||222.137.8.96$document
 ||222.137.81.67$document
+||222.137.83.53$document
 ||222.138.137.188$document
 ||222.138.143.84$document
+||222.138.189.88$document
 ||222.138.203.22$document
+||222.138.215.161$document
 ||222.138.232.159$document
+||222.138.232.84$document
+||222.138.49.93$document
 ||222.138.96.79$document
+||222.139.16.229$document
 ||222.139.59.63$document
-||222.140.10.235$document
+||222.140.112.150$document
 ||222.140.117.221$document
 ||222.140.161.11$document
 ||222.140.163.112$document
@@ -2706,27 +2795,26 @@
 ||222.140.209.222$document
 ||222.140.219.212$document
 ||222.140.39.66$document
-||222.141.120.17$document
-||222.141.147.104$document
 ||222.141.150.38$document
+||222.141.165.180$document
+||222.141.244.231$document
 ||222.141.40.136$document
-||222.141.40.2$document
 ||222.141.41.155$document
+||222.141.44.36$document
 ||222.141.45.153$document
-||222.141.45.255$document
 ||222.141.60.251$document
+||222.141.73.249$document
 ||222.141.85.128$document
 ||222.142.162.164$document
 ||222.142.192.66$document
 ||222.142.209.7$document
 ||222.142.65.30$document
-||222.184.129.122$document
+||222.179.215.189$document
 ||222.185.116.233$document
-||222.186.20.19$document
 ||222.187.9.178$document
 ||222.211.72.66$document
+||222.214.54.208$document
 ||222.218.220.219$document
-||222.236.85.220$document
 ||222.238.230.7$document
 ||222.239.83.232$document
 ||222.248.64.253$document
@@ -2736,21 +2824,17 @@
 ||222.99.171.192$document
 ||223.166.117.210$document
 ||223.167.118.17$document
-||223.175.121.249$document
 ||223.212.225.68$document
 ||223.212.234.84$document
 ||223.212.252.180$document
 ||223.212.5.29$document
-||223.212.57.78$document
 ||223.212.73.175$document
-||223.213.164.81$document
 ||23.125.186.135$document
 ||23.126.120.25$document
 ||23.228.143.58$document
 ||23.24.213.121$document
 ||23.243.149.13$document
 ||23.243.21.167$document
-||23.81.246.58$document
 ||23.95.89.21$document
 ||24.103.74.180$document
 ||24.11.141.134$document
@@ -2777,6 +2861,7 @@
 ||27.105.106.201$document
 ||27.105.152.107$document
 ||27.116.84.57$document
+||27.12.234.4$document
 ||27.12.245.238$document
 ||27.13.83.77$document
 ||27.14.211.219$document
@@ -2792,7 +2877,6 @@
 ||27.193.217.210$document
 ||27.194.149.142$document
 ||27.194.158.229$document
-||27.194.166.45$document
 ||27.194.192.66$document
 ||27.194.210.20$document
 ||27.194.224.96$document
@@ -2844,14 +2928,15 @@
 ||27.208.166.13$document
 ||27.208.201.212$document
 ||27.208.247.130$document
+||27.208.25.59$document
 ||27.208.34.2$document
 ||27.208.92.64$document
 ||27.209.160.222$document
 ||27.209.231.15$document
 ||27.209.60.21$document
-||27.21.159.174$document
 ||27.210.107.125$document
 ||27.210.127.11$document
+||27.210.146.61$document
 ||27.210.172.245$document
 ||27.210.234.28$document
 ||27.210.236.134$document
@@ -2860,6 +2945,8 @@
 ||27.213.104.201$document
 ||27.213.109.105$document
 ||27.213.109.58$document
+||27.213.145.221$document
+||27.213.167.175$document
 ||27.213.175.208$document
 ||27.213.220.5$document
 ||27.213.255.202$document
@@ -2874,6 +2961,7 @@
 ||27.215.38.166$document
 ||27.215.71.243$document
 ||27.215.98.242$document
+||27.216.131.66$document
 ||27.216.144.66$document
 ||27.216.193.217$document
 ||27.216.197.193$document
@@ -2900,7 +2988,6 @@
 ||27.219.184.94$document
 ||27.219.192.223$document
 ||27.219.83.244$document
-||27.220.243.172$document
 ||27.220.40.189$document
 ||27.220.85.168$document
 ||27.221.239.223$document
@@ -2912,25 +2999,27 @@
 ||27.223.242.164$document
 ||27.223.44.106$document
 ||27.24.28.134$document
-||27.35.127.129$document
 ||27.35.129.198$document
 ||27.35.154.13$document
+||27.35.16.145$document
 ||27.35.2.30$document
 ||27.35.212.124$document
 ||27.35.58.5$document
-||27.36.143.238$document
-||27.41.159.216$document
-||27.41.36.15$document
-||27.41.38.79$document
-||27.46.45.90$document
-||27.5.38.169$document
-||27.5.41.251$document
-||27.5.42.169$document
-||27.6.196.172$document
+||27.41.153.66$document
+||27.41.154.31$document
+||27.43.82.210$document
+||27.46.45.248$document
+||27.46.47.74$document
+||27.5.16.243$document
+||27.5.26.105$document
+||27.5.26.4$document
+||27.5.27.1$document
+||27.5.35.127$document
 ||31.0.98.131$document
 ||31.11.51.57$document
 ||31.13.23.180$document
 ||31.154.234.3$document
+||31.163.191.11$document
 ||31.168.124.130$document
 ||31.168.179.83$document
 ||31.168.184.59$document
@@ -2949,8 +3038,10 @@
 ||31.204.174.180$document
 ||31.210.20.138$document
 ||31.210.20.177$document
+||31.210.20.227$document
 ||31.28.7.159$document
 ||31.30.119.23$document
+||31.62.255.3$document
 ||32.208.157.193$document
 ||32792.prolocksmithwinterpark.com$document
 ||35.184.169.169$document
@@ -2962,8 +3053,6 @@
 ||36.251.19.88$document
 ||36.251.51.244$document
 ||36.255.90.219$document
-||36.32.203.118$document
-||36.32.25.158$document
 ||36.33.128.60$document
 ||36.33.160.167$document
 ||36.36.243.67$document
@@ -2973,7 +3062,6 @@
 ||36.66.139.36$document
 ||36.67.152.161$document
 ||36.89.18.133$document
-||36.91.89.187$document
 ||36.96.187.93$document
 ||360.lcy2zzx.pw$document
 ||360down7.miiyun.cn$document
@@ -3011,8 +3099,8 @@
 ||39.72.67.64$document
 ||39.73.10.198$document
 ||39.73.163.231$document
-||39.73.183.14$document
 ||39.73.203.225$document
+||39.73.44.17$document
 ||39.74.104.228$document
 ||39.74.21.201$document
 ||39.74.28.89$document
@@ -3038,7 +3126,6 @@
 ||39.79.91.244$document
 ||39.79.93.171$document
 ||39.80.127.214$document
-||39.80.188.238$document
 ||39.80.191.137$document
 ||39.80.205.255$document
 ||39.80.24.54$document
@@ -3055,8 +3142,10 @@
 ||39.84.34.217$document
 ||39.84.95.200$document
 ||39.85.54.191$document
+||39.85.54.4$document
 ||39.86.129.233$document
 ||39.86.13.0$document
+||39.86.151.49$document
 ||39.86.170.209$document
 ||39.86.184.164$document
 ||39.86.211.20$document
@@ -3067,6 +3156,7 @@
 ||39.86.76.9$document
 ||39.86.78.228$document
 ||39.87.63.58$document
+||39.87.90.210$document
 ||39.87.93.109$document
 ||39.88.141.172$document
 ||39.88.155.96$document
@@ -3087,95 +3177,100 @@
 ||41.219.185.171$document
 ||41.230.31.58$document
 ||41.72.203.82$document
-||41.76.157.2$document
+||41.86.18.133$document
 ||41.86.18.147$document
 ||41.86.18.148$document
+||41.86.18.165$document
 ||41.86.18.200$document
 ||41.86.18.71$document
-||41.86.21.35$document
-||41.86.21.40$document
+||41.86.21.28$document
+||41.86.21.5$document
+||41.86.21.62$document
 ||41.86.5.103$document
-||41.86.5.104$document
-||41.86.5.198$document
-||41.86.5.237$document
 ||42.176.112.72$document
 ||42.202.101.147$document
+||42.224.122.39$document
 ||42.224.128.210$document
 ||42.224.168.142$document
 ||42.224.168.97$document
-||42.224.170.140$document
+||42.224.176.214$document
 ||42.224.179.49$document
-||42.224.181.121$document
-||42.224.183.11$document
 ||42.224.209.156$document
 ||42.224.212.124$document
 ||42.224.218.16$document
 ||42.224.233.247$document
 ||42.224.235.4$document
+||42.224.249.8$document
 ||42.224.37.186$document
 ||42.224.37.44$document
 ||42.224.43.25$document
 ||42.224.64.34$document
-||42.224.66.246$document
 ||42.224.70.213$document
 ||42.224.76.168$document
 ||42.224.76.198$document
 ||42.224.8.136$document
+||42.224.90.17$document
 ||42.224.91.8$document
-||42.225.24.101$document
 ||42.225.240.244$document
 ||42.225.250.39$document
-||42.226.76.62$document
+||42.225.33.31$document
+||42.226.89.25$document
 ||42.227.179.209$document
-||42.227.204.4$document
 ||42.227.66.88$document
 ||42.228.198.102$document
 ||42.228.60.114$document
 ||42.228.65.201$document
 ||42.228.70.126$document
 ||42.228.70.231$document
+||42.228.75.7$document
 ||42.228.76.135$document
 ||42.230.100.114$document
+||42.230.174.125$document
+||42.230.219.243$document
 ||42.230.228.78$document
-||42.230.57.145$document
 ||42.230.66.255$document
 ||42.230.82.44$document
 ||42.230.88.107$document
 ||42.230.93.169$document
+||42.231.223.215$document
+||42.231.244.80$document
 ||42.231.66.174$document
+||42.231.95.195$document
 ||42.232.102.163$document
 ||42.232.170.117$document
 ||42.232.226.16$document
+||42.233.90.183$document
+||42.234.105.6$document
+||42.234.162.44$document
 ||42.234.166.242$document
-||42.234.180.136$document
 ||42.234.255.20$document
 ||42.235.124.55$document
-||42.235.160.215$document
 ||42.235.169.85$document
 ||42.235.23.163$document
 ||42.235.66.249$document
-||42.235.83.180$document
+||42.235.90.32$document
+||42.235.92.111$document
 ||42.236.148.201$document
 ||42.236.212.174$document
 ||42.236.212.83$document
 ||42.236.215.63$document
 ||42.236.236.179$document
+||42.237.45.223$document
 ||42.237.54.162$document
-||42.238.175.61$document
+||42.238.175.32$document
 ||42.238.191.210$document
 ||42.238.241.239$document
 ||42.238.59.222$document
 ||42.239.192.128$document
-||42.239.207.166$document
-||42.239.42.135$document
 ||42.242.200.90$document
 ||42.52.180.36$document
 ||42.56.15.227$document
 ||42.61.99.155$document
+||42.82.217.241$document
 ||42.84.14.5$document
 ||43.230.156.44$document
-||43.230.207.204$document
 ||43.241.106.183$document
+||43.241.106.234$document
 ||43.252.8.94$document
 ||45.112.203.218$document
 ||45.130.138.66$document
@@ -3187,16 +3282,20 @@
 ||45.14.149.204$document
 ||45.14.149.244$document
 ||45.14.149.66$document
-||45.141.84.182$document
 ||45.141.84.184$document
+||45.144.225.142$document
+||45.144.225.213$document
 ||45.144.225.65$document
 ||45.148.10.47$document
 ||45.15.143.158$document
 ||45.164.140.133$document
-||45.165.215.19$document
 ||45.176.108.116$document
 ||45.176.108.248$document
+||45.176.110.99$document
+||45.176.111.154$document
 ||45.176.111.16$document
+||45.176.111.202$document
+||45.176.111.84$document
 ||45.178.101.22$document
 ||45.201.165.164$document
 ||45.22.209.58$document
@@ -3210,10 +3309,8 @@
 ||46.172.75.231$document
 ||46.175.184.121$document
 ||46.182.173.246$document
-||46.182.173.247$document
 ||46.20.63.218$document
 ||46.201.214.64$document
-||46.201.38.162$document
 ||46.21.153.231$document
 ||46.214.27.4$document
 ||46.24.130.254$document
@@ -3245,7 +3342,6 @@
 ||49.68.221.252$document
 ||49.68.249.121$document
 ||49.70.15.16$document
-||49.70.2.100$document
 ||5.181.135.114$document
 ||5.2.70.50$document
 ||5.53.146.179$document
@@ -3255,6 +3351,7 @@
 ||50.252.47.29$document
 ||51.171.146.13$document
 ||51.222.56.159$document
+||54.180.158.181$document
 ||54.253.194.14$document
 ||54.36.114.136$document
 ||54.36.180.122$document
@@ -3267,9 +3364,10 @@
 ||58.142.166.120$document
 ||58.142.200.124$document
 ||58.143.142.142$document
+||58.143.189.75$document
 ||58.18.103.109$document
+||58.19.249.50$document
 ||58.217.171.157$document
-||58.218.67.253$document
 ||58.22.212.107$document
 ||58.226.129.29$document
 ||58.229.194.122$document
@@ -3280,44 +3378,36 @@
 ||58.240.147.97$document
 ||58.241.57.237$document
 ||58.241.78.55$document
-||58.248.112.16$document
-||58.248.116.2$document
 ||58.248.117.188$document
-||58.248.140.132$document
-||58.248.142.137$document
-||58.248.142.174$document
+||58.248.143.173$document
+||58.248.144.97$document
 ||58.248.149.117$document
-||58.248.150.204$document
-||58.248.150.244$document
-||58.248.153.194$document
+||58.248.149.226$document
 ||58.248.154.55$document
 ||58.248.154.66$document
 ||58.248.76.206$document
 ||58.248.79.25$document
-||58.249.15.148$document
 ||58.249.18.244$document
-||58.249.22.210$document
-||58.249.72.121$document
+||58.249.74.104$document
 ||58.249.74.124$document
 ||58.249.74.248$document
 ||58.249.77.227$document
-||58.249.79.134$document
+||58.249.78.155$document
 ||58.249.80.23$document
+||58.249.80.46$document
 ||58.249.86.85$document
-||58.249.88.207$document
-||58.252.177.212$document
+||58.249.87.248$document
+||58.249.89.210$document
+||58.249.90.206$document
+||58.249.90.86$document
+||58.252.176.107$document
 ||58.252.177.66$document
-||58.252.178.167$document
-||58.252.178.55$document
-||58.253.14.46$document
-||58.255.140.156$document
 ||58.255.43.163$document
 ||58.48.154.143$document
 ||58.50.178.137$document
 ||58.50.221.148$document
 ||58.72.165.153$document
 ||58.72.165.39$document
-||58.76.151.51$document
 ||58.97.201.45$document
 ||58.97.206.33$document
 ||59.0.211.161$document
@@ -3325,48 +3415,18 @@
 ||59.151.202.3$document
 ||59.151.214.4$document
 ||59.151.237.51$document
-||59.151.246.125$document
 ||59.29.133.229$document
 ||59.30.12.254$document
+||59.32.97.190$document
 ||59.58.104.244$document
 ||59.58.117.226$document
 ||59.7.124.148$document
 ||59.8.35.22$document
-||59.89.243.76$document
-||59.92.176.136$document
-||59.92.178.202$document
-||59.92.18.175$document
-||59.92.182.177$document
-||59.92.216.255$document
-||59.93.17.196$document
-||59.93.17.204$document
-||59.93.17.72$document
-||59.93.19.11$document
-||59.93.23.154$document
-||59.93.23.215$document
-||59.93.23.23$document
-||59.93.23.7$document
-||59.94.180.237$document
-||59.96.36.131$document
-||59.96.36.137$document
-||59.96.39.91$document
-||59.97.168.110$document
-||59.97.170.16$document
-||59.97.175.101$document
-||59.97.175.96$document
-||59.97.193.118$document
-||59.99.137.46$document
-||59.99.138.222$document
-||59.99.139.252$document
-||59.99.139.66$document
-||59.99.141.103$document
-||59.99.141.219$document
-||59.99.142.43$document
-||59.99.188.93$document
-||59.99.41.26$document
-||59.99.43.225$document
-||59.99.46.7$document
-||59.99.47.64$document
+||59.92.182.72$document
+||59.92.218.77$document
+||59.92.219.28$document
+||59.97.174.85$document
+||59.99.47.93$document
 ||60.13.61.12$document
 ||60.14.48.221$document
 ||60.162.122.36$document
@@ -3405,24 +3465,24 @@
 ||60.220.22.89$document
 ||60.25.115.48$document
 ||60.25.76.224$document
-||60.253.15.104$document
-||60.253.39.88$document
+||60.253.4.72$document
 ||60.253.42.72$document
-||60.253.44.99$document
 ||60.253.51.127$document
 ||60.253.60.174$document
+||60.253.8.36$document
 ||60.253.8.81$document
+||60.254.49.59$document
 ||60.7.10.121$document
 ||60.7.136.8$document
 ||60.7.202.153$document
+||60.7.8.43$document
 ||60.7.99.254$document
 ||61.102.243.124$document
+||61.109.164.140$document
+||61.141.124.123$document
 ||61.162.169.210$document
 ||61.162.55.42$document
-||61.163.129.97$document
 ||61.164.96.98$document
-||61.167.211.218$document
-||61.168.139.87$document
 ||61.179.171.60$document
 ||61.179.91.194$document
 ||61.179.91.230$document
@@ -3432,37 +3492,42 @@
 ||61.213.118.28$document
 ||61.247.224.66$document
 ||61.253.94.230$document
-||61.3.126.128$document
-||61.3.144.90$document
-||61.3.147.175$document
+||61.3.124.3$document
+||61.3.124.51$document
 ||61.47.220.169$document
 ||61.52.102.61$document
 ||61.52.103.144$document
 ||61.52.11.87$document
+||61.52.135.192$document
 ||61.52.157.4$document
 ||61.52.159.231$document
 ||61.52.195.226$document
 ||61.52.212.191$document
+||61.52.212.250$document
 ||61.52.243.169$document
 ||61.52.247.208$document
-||61.52.30.49$document
 ||61.52.35.86$document
+||61.52.39.119$document
 ||61.52.43.174$document
 ||61.52.48.112$document
+||61.52.5.217$document
+||61.52.63.119$document
+||61.52.76.72$document
 ||61.52.9.166$document
-||61.52.97.134$document
 ||61.52.99.183$document
 ||61.53.100.87$document
-||61.53.121.19$document
+||61.53.123.162$document
+||61.53.125.182$document
 ||61.53.251.243$document
 ||61.53.62.169$document
 ||61.53.73.171$document
-||61.53.74.27$document
 ||61.53.81.18$document
 ||61.53.83.14$document
-||61.53.86.195$document
 ||61.54.172.248$document
-||61.54.41.143$document
+||61.54.240.20$document
+||61.54.58.190$document
+||61.54.58.20$document
+||61.54.61.18$document
 ||61.54.64.104$document
 ||61.54.77.175$document
 ||61.56.180.67$document
@@ -3485,6 +3550,7 @@
 ||62.141.73.58$document
 ||62.219.131.205$document
 ||62.219.143.46$document
+||62.219.155.61$document
 ||62.219.227.31$document
 ||62.31.126.33$document
 ||62.38.149.66$document
@@ -3496,16 +3562,13 @@
 ||65.125.128.196$document
 ||65.21.58.252$document
 ||65.26.155.131$document
-||65.35.61.255$document
 ||66.153.233.87$document
-||66.207.93.46$document
 ||66.229.214.115$document
 ||66.57.55.210$document
 ||66.74.7.197$document
 ||66.91.21.31$document
 ||66.97.181.196$document
 ||66.97.181.213$document
-||67.221.107.75$document
 ||67.245.151.203$document
 ||67.3.169.223$document
 ||67.8.138.101$document
@@ -3544,7 +3607,7 @@
 ||70.33.144.248$document
 ||70.93.129.118$document
 ||71.127.148.69$document
-||71.146.190.91$document
+||71.19.150.93$document
 ||71.204.63.239$document
 ||71.29.48.164$document
 ||71.34.191.213$document
@@ -3569,7 +3632,6 @@
 ||74.199.84.77$document
 ||74.75.165.81$document
 ||75.127.141.52$document
-||75.176.213.114$document
 ||75.82.36.220$document
 ||75.83.102.27$document
 ||75.99.213.61$document
@@ -3581,11 +3643,13 @@
 ||76.84.134.33$document
 ||76.95.12.137$document
 ||77.237.25.210$document
+||77.45.183.39$document
 ||77.71.50.153$document
 ||77.71.52.220$document
 ||77.79.191.32$document
 ||77.89.203.238$document
 ||78.179.225.254$document
+||78.186.155.18$document
 ||78.187.141.144$document
 ||78.187.240.125$document
 ||78.187.41.200$document
@@ -3603,7 +3667,6 @@
 ||79.170.31.56$document
 ||79.175.42.244$document
 ||79.21.84.63$document
-||79.22.176.145$document
 ||79.7.170.58$document
 ||79.79.58.94$document
 ||79.8.70.162$document
@@ -3619,7 +3682,6 @@
 ||81.198.7.22$document
 ||81.213.111.60$document
 ||81.213.141.184$document
-||81.213.166.175$document
 ||81.215.199.29$document
 ||81.218.187.113$document
 ||81.218.195.216$document
@@ -3663,7 +3725,7 @@
 ||84.210.219.208$document
 ||84.210.219.213$document
 ||84.212.219.127$document
-||84.214.103.73$document
+||84.224.162.170$document
 ||84.228.50.118$document
 ||84.228.95.204$document
 ||84.238.24.35$document
@@ -3680,12 +3742,12 @@
 ||85.105.208.25$document
 ||85.105.224.141$document
 ||85.105.241.2$document
+||85.105.9.152$document
 ||85.214.149.236$document
 ||85.64.181.50$document
 ||85.74.215.180$document
 ||85.97.130.227$document
 ||85.97.195.129$document
-||85.98.40.5$document
 ||86.35.43.220$document
 ||87.121.98.51$document
 ||87.61.89.40$document
@@ -3700,7 +3762,6 @@
 ||88.250.204.12$document
 ||88.250.226.26$document
 ||88.250.254.90$document
-||88.37.171.141$document
 ||89.122.183.130$document
 ||89.136.197.170$document
 ||89.29.213.33$document
@@ -3721,11 +3782,10 @@
 ||91.244.169.139$document
 ||91.92.16.244$document
 ||91.98.4.181$document
-||92.113.192.30$document
-||92.113.195.115$document
 ||92.114.191.82$document
 ||92.241.78.114$document
 ||92.27.246.202$document
+||92.54.237.237$document
 ||92.85.18.138$document
 ||93.171.157.73$document
 ||93.21.224.154$document
@@ -3750,7 +3810,6 @@
 ||95.170.201.34$document
 ||95.181.155.112$document
 ||95.214.52.64$document
-||95.53.229.84$document
 ||95.54.11.179$document
 ||95.60.146.134$document
 ||95.60.6.114$document
@@ -3771,7 +3830,6 @@
 ||98.30.24.54$document
 ||99.150.245.203$document
 ||99.33.195.164$document
-||99centsdigitals.com$document
 ||abcd.bg$document
 ||abclicks.in$document
 ||abissnet.net$document
@@ -3779,11 +3837,12 @@
 ||absoftechworld.com$document
 ||absupplies.co.uk$document
 ||abyssos.eu$document
+||academyshademani.com$document
 ||acbick.com$document
 ||accounts.thesmarttechhub.com$document
 ||aceeprc.com.aceeprc.com$document
 ||acellr.co.uk$document
-||aclassapart.in$document
+||aciabogados.com$document
 ||acteon.com.ar$document
 ||activateyourdiscount.com$document
 ||activecost.com.au$document
@@ -3801,6 +3860,7 @@
 ||agenciadigitalwdys.com$document
 ||agenciatabletshouse.com.br$document
 ||agenda.gmelloinformatica.com.br$document
+||agenmovie.xyz$document
 ||agentt.ac.ug$document
 ||agile8studio.com$document
 ||agmcarpetcare.co.uk$document
@@ -3808,12 +3868,10 @@
 ||ajpharmaholding.com$document
 ||ajstudiollc.com$document
 ||aktyd05.top$document
-||akwer03.top/downfiles/file.exe$document
 ||al-wahd.com$document
 ||alasdemariposas.org$document
 ||alemelektronik.com$document
 ||alena1971.es$document
-||alertlauncher.fr$document
 ||alexdubai.com.aldiabsteel.com$document
 ||alka.institute$document
 ||allforcreative.com.au$document
@@ -3825,6 +3883,7 @@
 ||amarteargentina.com.ar$document
 ||amenyan.zouri.jp$document
 ||amos524.org$document
+||ams.alvinasschools.org.ng$document
 ||amumufree.weebly.com/uploads/8/1/2/9/81294208/growtopiastaff_setup1.61.exe$document
 ||analogx.com/files/proxyi.exe$document
 ||anantam.net.in$document
@@ -3846,10 +3905,9 @@
 ||aplicativoparasindicato.com.br$document
 ||apoolcondo.com$document
 ||app.adsensearticle.com$document
-||app.explicitsurveys.co.uk$document
 ||app.prerana.info$document
 ||apps.saintsoporte.com$document
-||aras.iuc.ac$document
+||aqv.news$document
 ||areyoulivingwell.com$document
 ||arsapetrolab.com$document
 ||artedibujoyarquitectura.com$document
@@ -3868,11 +3926,12 @@
 ||ayamallah.com$document
 ||azmeasurement.com$document
 ||azraktours.com$document
-||b2b.toptanakaryakit.com.tr$document
 ||backgrounds.pk$document
 ||backup.agewsage.com$document
 ||badeggdesign.com$document
+||balealgodon.mx$document
 ||bangkok-orchids.com$document
+||barcionstw.eastus.cloudapp.azure.com$document
 ||bary.sz4h.com$document
 ||basma.com.kw$document
 ||bausch.kr-atlas.monaxikoslykos@zytrox.tk$document
@@ -3881,7 +3940,6 @@
 ||bcmt.elin.co.za$document
 ||bcrg.co.za$document
 ||bearcatpumps.com.cn$document
-||beatyamerican.com$document
 ||beautincollagen.rs$document
 ||bekape.co.id$document
 ||bespokeweddings.ie$document
@@ -3889,6 +3947,8 @@
 ||betone.co.kr$document
 ||betycopaints.com$document
 ||beveragesmiami.solucioneslink.com$document
+||bhavaniengineering.com$document
+||bigbag.wootraining.certificacion.cl$document
 ||bilbosaquet.ug$document
 ||bilhen.co.za$document
 ||billing.rahitechnosoft.com$document
@@ -3976,11 +4036,10 @@
 ||bitbucket.org/teaserex/tease/downloads/macro_xmprohiq27.bin$document
 ||blog.callensaxen.com$document
 ||blog.oyinblogs.com$document
-||blog.takbelit.com$document
 ||bmlifestyle.co.uk$document
+||bnrbook.com$document
 ||bnrnews.id$document
 ||bodenstein.co.za$document
-||bolnicaloznica.rs$document
 ||booksearch.com$document
 ||bounces.mi-fs.com$document
 ||bpo.correct.go.th$document
@@ -3994,23 +4053,21 @@
 ||brightstarshop.com$document
 ||browardinsurancemiami.solucioneslink.com$document
 ||bt2.elin.co.za$document
-||btdapi.robotake.com$document
 ||bucrinsuranlceonlines.com$document
 ||buenavista.co$document
-||buigiaphat.com.vn$document
 ||bullseyemedia.in$document
 ||busandvanrentalmalaysia.com$document
 ||buscascolegios.diit.cl$document
 ||business.softberg.ro$document
 ||buyingmusiconline.com$document
-||buypropertyfast.com$document
 ||bwsr.eu$document
 ||c.oooooooooo.ga$document
 ||c0140529.ferozo.com$document
+||caballo.com.au$document
 ||cacapavaonline.sdserver144.com.br$document
+||calgaryautorepairservice.com$document
 ||callbury.in$document
 ||camminachetipassa.it$document
-||campusvirtual.cepsanjuanbosco.net.pe$document
 ||cancer.educandome.co$document
 ||capitalgroup-kw.com$document
 ||capitalnewsagency.com$document
@@ -4027,12 +4084,10 @@
 ||cdn.discordapp.com/attachments/816070119281131570/816070273254162442/all.txt$document
 ||cdn.discordapp.com/attachments/823355293043261515/823692323514482788/inquiry_-_rfq_hmg_u66_sw5558_pdf.iso$document
 ||cec.asso.ac-amiens.fr$document
-||cellas.sk$document
 ||cendekiabinaaksara.com$document
 ||cespol-bote.com.mx$document
 ||cfs5.tistory.com$document
 ||ch.rmu.ac.th$document
-||changematterscounselling.com$document
 ||chardhamdodham.com$document
 ||cheacrilnsurances.com$document
 ||chealablilitycarinsurances.com$document
@@ -4040,7 +4095,6 @@
 ||childselect.com$document
 ||chinhdropfile.myvnc.com$document
 ||chinhdropfile80.myvnc.com$document
-||chipmania.it$document
 ||chiptune.com/razor/rzr-winner_intro.zip$document
 ||cible-energy.com$document
 ||cifeer.net$document
@@ -4048,10 +4102,10 @@
 ||cityglobalgospel.com$document
 ||civi.istmejia.com$document
 ||cleanbydesignllc.com$document
-||clim34000.fr$document
 ||cloud.fc.co.mz$document
 ||cloudme.com/v1/ws2/:suengpen/:buyerlist.js/buyerlist.js.xz$document
 ||cloudme.com/v1/ws2/:suengpen/:buyerlist1/buyerlist1.rar$document
+||clurbgolf.com$document
 ||codeload.github.com/meteoradminz/hidden-tear/zip/master$document
 ||codsambal.com$document
 ||colfincas.com/tmp/protected-cek9qz4zvk2n65e-c5d84gi5/security-cloud/kypqw-52kkq0n9ywj9oa/$document
@@ -4075,7 +4129,6 @@
 ||crecerco.com$document
 ||crittersbythebay.com$document
 ||crm.notariavieitoyvelamazan.com$document
-||crmmanivela.net$document
 ||crscorretordeimoveis.com.br$document
 ||cse-engineer.com$document
 ||csnserver.com$document
@@ -4090,7 +4143,6 @@
 ||czas.dbstrony.pl$document
 ||czsl.91756.cn$document
 ||d.powerofwish.com$document
-||d.ttr3p.com/kr.bin$document
 ||d9.99ddd.com$document
 ||da.alibuf.com$document
 ||damagedessentialtelecommunications.testmail4.repl.co$document
@@ -4124,7 +4176,6 @@
 ||detorre.es$document
 ||dev-interestingtech.pantheonsite.io$document
 ||dev.sebpo.net$document
-||dezcom.com$document
 ||dfcf.91756.cn$document
 ||dfsfcsfcdsfsdvcfsvcscv.com$document
 ||diamantenegro.mi-fs.com$document
@@ -4147,7 +4198,6 @@
 ||doncedyhall.com$document
 ||donghobinhminh.com$document
 ||dongphuctop.com$document
-||donwnloasecury.ath.cx$document
 ||dosame.com$document
 ||dosman.pl$document
 ||dovberger.com$document
@@ -4155,6 +4205,9 @@
 ||down.pcclear.com$document
 ||down.posti-fi-fsa.top$document
 ||down.posti-fi-fwa.top$document
+||down.posti-fi-ij.top$document
+||down.posti-fi-in.top$document
+||down.posti-fi-iz.top$document
 ||down.udashi.com$document
 ||down.webbora.com$document
 ||down1.arpun.com$document
@@ -4172,85 +4225,31 @@
 ||drive.google.com.it-barcelona.com/frm0reseen/prntscrnofamzorderid.jpg.exe$document
 ||drive.google.com/uc?export=download&id=0byfg0_4xbjgnwvuyev9ltuh4rmm$document
 ||drive.google.com/uc?export=download&id=13vodfxml9fg8kcnexuafh64dzmnqv8ch$document
-||drive.google.com/uc?export=download&id=14l8sj2dqo04ozum88tvuy74yfcwk5fnf$document
-||drive.google.com/uc?export=download&id=15bd1dksg4pkrxehoczi7e0uok4vblz4e$document
 ||drive.google.com/uc?export=download&id=167imxqgc8ehepa1gisxa6q6ifcjxceox$document
-||drive.google.com/uc?export=download&id=17xvn-rlhei5n9f6unuqqb_wh84u4w5cx$document
-||drive.google.com/uc?export=download&id=1_vz7veeec-juwt23g9d9wjuid2kusew7$document
 ||drive.google.com/uc?export=download&id=1a-herfdxr6xamxeabcdao0mqw9bimrig$document
 ||drive.google.com/uc?export=download&id=1aphk_vq7gtn368zxpd5bg5rv8nk0bnhn$document
-||drive.google.com/uc?export=download&id=1aqhdbelnscyjygigfopt7x_oafaqgwg1$document
-||drive.google.com/uc?export=download&id=1cf8d3ljsfn3toddczqtkkbhrd5g00cjg$document
 ||drive.google.com/uc?export=download&id=1cvicrmlbj2ak666h6wsaaqegjpflnben$document
-||drive.google.com/uc?export=download&id=1cynoc3t9rp-xvso3jcmx_prwppp8u-dv$document
-||drive.google.com/uc?export=download&id=1d8fykmpewc_4yurihjh_cdehkdp_nuik$document
-||drive.google.com/uc?export=download&id=1dgcin9vevl9f63cbhbkmc_gpa2b0zlrh$document
-||drive.google.com/uc?export=download&id=1do7c-fjuscbueu0un2dbxe3-pnwdufb_$document
 ||drive.google.com/uc?export=download&id=1eqnvgn0qkunp7t6crk8oj7_e7rh5qxwi$document
-||drive.google.com/uc?export=download&id=1f3kxfcvbpaaexgnchpvmyoxkcdmickjj$document
-||drive.google.com/uc?export=download&id=1gsmk1t_yigh7jablxkuhbmmh93vwgikb$document
-||drive.google.com/uc?export=download&id=1hmud67vsl-shqddzpxniqmyj92iynyis$document
-||drive.google.com/uc?export=download&id=1ik-x4_bsr5dbocs9j1ryg1ybw75fqu8t$document
 ||drive.google.com/uc?export=download&id=1in-rhdrss2qsjqj8xffb1hbwi9znp4je$document
 ||drive.google.com/uc?export=download&id=1iwc-lf99neesk6mvvo2al4futbmyoiev$document
 ||drive.google.com/uc?export=download&id=1ix4yfvtfik605yavvm7wyo0bk4ch93fr$document
-||drive.google.com/uc?export=download&id=1jgykopezccdq3q5qprmkl1zdl1auymkq$document
-||drive.google.com/uc?export=download&id=1lplk8rixxuboakkmut_qgzn92bkoulna$document
-||drive.google.com/uc?export=download&id=1mug8m5o6kl_bx68x8cuxmzhn0gxnc7ki$document
 ||drive.google.com/uc?export=download&id=1n8o4hbvi7o9ks9jqhofny7okposfaz4y$document
-||drive.google.com/uc?export=download&id=1nindqtjvyyzz-qk-hqa9gls5ccwhys-e$document
 ||drive.google.com/uc?export=download&id=1nio_cdsggt4zv1kdrpubrfpd0pzsyffd$document
-||drive.google.com/uc?export=download&id=1nsyqwodoi1t9-i29arbxwe7fkafjydsz$document
-||drive.google.com/uc?export=download&id=1nwctbvlr_1bewpvgdbmuhnny-zi6kp1l$document
-||drive.google.com/uc?export=download&id=1o2dcrdwgu91moicmterbx9avcl9cavy1$document
-||drive.google.com/uc?export=download&id=1o4lh97cmfnztr_hkocnwiucy5l6oskpy$document
 ||drive.google.com/uc?export=download&id=1oabvvnazifkxktvt-izbcdqpb7dm6nrw$document
-||drive.google.com/uc?export=download&id=1oys1nkexzsuci6pfghowlbpwaw-_btxk$document
 ||drive.google.com/uc?export=download&id=1prxtn1juykhcr_9ilw-vtirv5anyeoej$document
-||drive.google.com/uc?export=download&id=1pzywywxrwl2plk82nuodgvmcckpzrufb$document
-||drive.google.com/uc?export=download&id=1q0uxhnzfs4j91rxz5x45iov8tjkomsgr$document
-||drive.google.com/uc?export=download&id=1q9vzzhu-n9cu8ixdginpzaxxgvb1lrjv$document
-||drive.google.com/uc?export=download&id=1qk8_jouqbnrfkky7x1aqunudfyl6fjii$document
-||drive.google.com/uc?export=download&id=1qxv3i0dwy_cdx2bm1lqx6ef0qjwmhbpk$document
-||drive.google.com/uc?export=download&id=1qzmi4jvter0_cwexcp4grjhxvr7lep5k$document
-||drive.google.com/uc?export=download&id=1r-kstukxtxjqxlwypgd764dw-puj_7fz$document
-||drive.google.com/uc?export=download&id=1r-zn6o95qzworq8e4fhz637bfuoxayby$document
-||drive.google.com/uc?export=download&id=1rcykjynwhlc487sn1vwcsmjse_ctlrox$document
-||drive.google.com/uc?export=download&id=1rdxnm_kxegbwlojlucu4qiff7kyax3oi$document
-||drive.google.com/uc?export=download&id=1s9tu6akdxquy7cezquljtb2yarci99ab$document
-||drive.google.com/uc?export=download&id=1serasql3bw7nc-sllzyrishnhodmefyf$document
-||drive.google.com/uc?export=download&id=1shuxviwx167elbuz8mfcjc2bk99zzov_$document
-||drive.google.com/uc?export=download&id=1sjzynfvpwdcwsr1p3w_q8-6ktsqiwadx$document
-||drive.google.com/uc?export=download&id=1sogqqdapgyioillf7u62widsprhw3cjh$document
 ||drive.google.com/uc?export=download&id=1t1bd_itjnhsmozdl9was0gouehujm1fn$document
-||drive.google.com/uc?export=download&id=1tfra7fzrjl2vdj73hcmcru5ynuqmz61g$document
 ||drive.google.com/uc?export=download&id=1tsmbsikhechaqedk6nktlfzasus_tghw$document
-||drive.google.com/uc?export=download&id=1ur9qebooqc-mjcdzn9wcbavocumdlosm$document
 ||drive.google.com/uc?export=download&id=1uvtmu3-hcryp3rskqnpkiodcjuchtz55$document
-||drive.google.com/uc?export=download&id=1v4ima0sfnmboxmyoklp4g0_uehaj22x2$document
 ||drive.google.com/uc?export=download&id=1vevblftithattyguwyjot1p0wptg7l5t$document
-||drive.google.com/uc?export=download&id=1vl9gje5llm7ja3dadct9okr6bzbmijc3$document
-||drive.google.com/uc?export=download&id=1vvvujegfrgey39w6y3ybwpptl1guwf8a$document
-||drive.google.com/uc?export=download&id=1ws2ptumptku-imi9sv_k5g4fhsx30gnl$document
-||drive.google.com/uc?export=download&id=1wtxdbb1fm9ozinx09a63-o-tn4ssgzpw$document
-||drive.google.com/uc?export=download&id=1xbeqbw67xz4iqpu8dgmdrlkpa6kzotes$document
-||drive.google.com/uc?export=download&id=1xdpxbb9gifdrugqxmg2_06xygbfq-x2k$document
 ||drive.google.com/uc?export=download&id=1xfwgl7xdqzqjccteivad-snxb_8yim1e$document
-||drive.google.com/uc?export=download&id=1xu9wvl5ktadwfxd94dicuej6y_j6kf8-$document
 ||drive.google.com/uc?export=download&id=1yawygcfjs9inzoiwagqfcn3utaywxmwi$document
-||drive.google.com/uc?export=download&id=1ycggxvacywdkt3jvqbpxpz9cyjcwvl_c$document
 ||drive.google.com/uc?export=download&id=1yhflwpk3yeyrdhlhanctlind-5j24iwv$document
-||drive.google.com/uc?export=download&id=1ys9rupdqvnhvrngizxfzstzcos0dlx-u$document
-||drive.google.com/uc?export=download&id=1z6wmqtnaa-jtpm5bqkb3ebi_btjcvmat$document
 ||drive.google.com/uc?export=download&id=1zbclvhabervgfryoyqklo4_oe6icd8sr$document
-||drive.google.com/uc?export=download&id=1zor7cinphnazfkldkthucb2h8jthlh9d$document
-||drive.google.com/uc?export=download&id=1zsghzos5foggoqxq6w12xeqvanhccdyk$document
 ||drive.google.com/uc?id=148pt6v0nlg8yoim7w6in7dpixkzaacbg&export=download&authuser=0$document
 ||drohnen.ensenanzainteligente.com$document
 ||drools-moved.46999.n3.nabble.com$document
 ||drpamelageorge.com/wp-includes/1zilg/$document
 ||drpamelageorge.com/wp-includes/qcgfmfvh/$document
-||drrohanfonseca.com$document
 ||drsha.innovativesolutions.mobi$document
 ||dsenterprize.co.za$document
 ||dsspainting.com$document
@@ -4265,19 +4264,15 @@
 ||e.sldov.ru$document
 ||ebruyatkin.com$document
 ||econews.treegle.org$document
-||edelweissdecoration.com$document
 ||efficientegroup.com$document
 ||elliot.newreadermedia.net$document
-||emaids.co.za$document
 ||en.baoend.com$document
 ||enc-tech.com$document
 ||endurotanzania.co.tz$document
-||enkonooh.com$document
 ||ennovate.elin.co.za$document
 ||enriquecendocomconsorcio.com.br$document
 ||envios.petpienso.cl$document
 ||equimination.ee$document
-||es.paymelist.com$document
 ||escola.probommar.org.br$document
 ||esnconsultants.com$document
 ||essentia.org.br$document
@@ -4298,7 +4293,6 @@
 ||f1sol.com$document
 ||familydentist.site$document
 ||farmaciasdrogaminas.com.br$document
-||farmnatural.in$document
 ||faveraprojects.com$document
 ||fc.co.mz$document
 ||felicienne.nl$document
@@ -4308,8 +4302,8 @@
 ||files.constantcontact.com/ee304de9001/7e533e73-e272-4a44-9d9e-138cab64bf19.docx$document
 ||files.martellexpress.us$document
 ||files6.uludagbilisim.com$document
-||filmotainment.com$document
 ||final.makkahkmcc.com$document
+||fineartgallerym.com$document
 ||fkd.derpcity.ru$document
 ||flintspin.com$document
 ||flyingbuddhadesign.com$document
@@ -4317,20 +4311,17 @@
 ||fms.buladde.or.ug$document
 ||foothills.com.br$document
 ||footweardirect.elin.co.za$document
-||formestore.evencsoft.co$document
 ||forum.mdb.nu$document
 ||fotoobjetivo.com$document
 ||foundationrepairhoustontx.net$document
 ||foxeps.com.br$document
 ||freecnetdownload.com$document
-||freedombookshop.tickme.lk$document
 ||freisites.com.br$document
 ||ftp.n3twork30cm.ml$document
 ||fullelectronica.com.ar$document
 ||funletters.net$document
 ||fusionfiresolutions.com$document
 ||futuregraphics.com.ar$document
-||gahanassociates.com$document
 ||gametwogame.com$document
 ||garayvidalabogados.com$document
 ||garciadogshow.com$document
@@ -4338,7 +4329,6 @@
 ||garenanow4.myvnc.com$document
 ||gbbulls.co.uk$document
 ||gcpc.co.id.chronoscurtain.com$document
-||gcrcorporation.com$document
 ||generaldeviales.com$document
 ||gfmodd1.webselffiles01.com$document
 ||gfold1.webselffiles01.com$document
@@ -4346,6 +4336,8 @@
 ||ghislain.dartois.pagesperso-orange.fr$document
 ||giadungg7.com$document
 ||giddos.ga$document
+||gilliem.com$document
+||girotexuniformes.com$document
 ||gist.githubusercontent.com/zibri/19f9838ffd12349bb2c6c3afddc9388f/raw/01977fd3c7e036c3a38f062f626fd189ba1e1aa3/uefivar.exe$document
 ||giteletropical.com$document
 ||globaltask.ar$document
@@ -4361,10 +4353,12 @@
 ||goldcupmortgage.com$document
 ||golden-memories-funerals.yourpageserver.com$document
 ||goldmen.in$document
+||gorecycle.fahadjutt.com$document
 ||gracejukes.com$document
 ||grupoinmare.com$document
 ||gruposelt.000webhostapp.com$document
 ||gs.monerorx.com$document
+||guide-to-cell-phones.com$document
 ||gulfac-house.com$document
 ||gvpcdpgc.edu.in$document
 ||habbotips.free.fr$document
@@ -4390,6 +4384,7 @@
 ||hmpmall.co.kr$document
 ||hoagietesting10.com$document
 ||hoayeuthuong-my.sharepoint.com$document
+||holmesprpmgmt.com$document
 ||homefindersolutions.com$document
 ||hongluosi.com$document
 ||hookedupboatclub.com$document
@@ -4403,7 +4398,6 @@
 ||hsmwebapp.com$document
 ||htownbars.com$document
 ||hubtech.co.za$document
-||huequito.evencsoft.co$document
 ||hunggiang.vn$document
 ||husamiyahschool.com$document
 ||ia801802.us.archive.org/19/items/startup_20210219/startup.txt$document
@@ -4417,6 +4411,7 @@
 ||iesanjosemonitos.edu.co$document
 ||ikexpert.com$document
 ||ilrafrica.com$document
+||images.jermiau.com$document
 ||imbueautoworx.co.za$document
 ||imperiumtherapy.co.za$document
 ||in-tune2016.com$document
@@ -4433,6 +4428,7 @@
 ||inovations.searchkero.com$document
 ||inrajahmundry.co.in$document
 ||insignificantfinecore.testmail4.repl.co$document
+||instantindialoan.com$document
 ||instvisionmexico.edu.mx$document
 ||intellectsmart.in$document
 ||intersel-idf.org$document
@@ -4443,6 +4439,7 @@
 ||iremart.es$document
 ||iris101.co.uk$document
 ||iscamenabe.com$document
+||ismf.com.ng$document
 ||iso-dubai.net$document
 ||israrulhaq.me$document
 ||isrorg.com$document
@@ -4464,7 +4461,6 @@
 ||jiaoyuzixun.cn$document
 ||jing-da.com.tw$document
 ||jktnet.xyz$document
-||jmcomputacion.com.ar$document
 ||jmtc.91756.cn$document
 ||jnanbharati.com$document
 ||jobs.thebeessolution.com$document
@@ -4476,12 +4472,11 @@
 ||josegene.com$document
 ||josuarochoa.com$document
 ||jpwoodfordco.com$document
-||julietlaser.site$document
 ||jumpmanualjacobhiller.com$document
-||jumpnjamchicago.com$document
 ||jupiter.toxsl.in$document
 ||jurgensen.newreadermedia.net$document
 ||justinscott.com.au$document
+||justlficante.mediafire.com/file/jl01o54yy09qrzg/fac215.tgz/file$document
 ||kaizenjanitorial.com$document
 ||kalawatihomes.com$document
 ||kalpataru-elitus-mulund.thakkers.in$document
@@ -4503,6 +4498,7 @@
 ||kumaralok.in$document
 ||kwanfromhongkong.com$document
 ||kz.sldov.ru$document
+||lab18.it$document
 ||lacasadelosalebrijes.com$document
 ||ladylabonde.com$document
 ||lameguard.ru$document
@@ -4549,6 +4545,7 @@
 ||lp.difusodesign.com$document
 ||lp.juancamilogarciareyes.com$document
 ||lp.tecnimasdecolombia.com.co$document
+||ltc.typoten.com$document
 ||luckybrownie.com$document
 ||luminouspneuma.com$document
 ||luxomodels.com$document
@@ -4557,15 +4554,15 @@
 ||madicon.co.za$document
 ||magianegramagiablancayamarres.com$document
 ||mail.bs-eiendomme.co.za$document
+||mail.golimoapp.com$document
 ||mail.jeffsono.org$document
 ||maksi.feb.unib.ac.id$document
 ||malaya.tv$document
 ||malwarecoding.github.io$document
 ||managed.oss-cn-beijing.aliyuncs.com$document
+||managemysalon.in$document
 ||manantialesdelnorte.uy$document
-||manivelasst.com$document
 ||marcapinyo.ru$document
-||marcusthepoet.com$document
 ||mario-sunjic.com$document
 ||mariobrown.net$document
 ||mariotessarollo.com$document
@@ -4574,7 +4571,6 @@
 ||marksidfgs.ug$document
 ||masjidhabeebiyarazviya.mysunni.com$document
 ||materialescantu.com$document
-||matinal-nominal.pt$document
 ||matruchhaya.co.in$document
 ||mattysplayground.com$document
 ||maxtox.com.pk$document
@@ -4586,6 +4582,7 @@
 ||mediamaster.co.za$document
 ||medianews.ge$document
 ||medistaffconsulting.com$document
+||meditreat.itwebservice.in$document
 ||meeweb.com$document
 ||megamart.afnan-amc.com$document
 ||merbay.ru$document
@@ -4607,7 +4604,6 @@
 ||mingguanwms.com$document
 ||minpic.de/k/big5/1giof6/$document
 ||minuevavida.org$document
-||mirror.mypage.sk$document
 ||mis.nbcc.ac.th$document
 ||misterson.com$document
 ||mixr.at$document
@@ -4615,12 +4611,15 @@
 ||mktf.mx$document
 ||mmogollon.com.mx$document
 ||mncarteam.com$document
+||mobile.illumetechnology.com$document
 ||modelhouseturkey.com$document
 ||modernmanna.org$document
 ||monetization.business$document
 ||moninediy.com$document
 ||mopai.sg$document
+||morrobaydrugandgift.com/wp-contentbak/t9m/$document
 ||motorcomunicacion.com$document
+||msacontabil.com.br$document
 ||mtspsmjeli.sch.id$document
 ||muzimbiti.xigubo.co.mz$document
 ||mxpiqw.am.files.1drv.com$document
@@ -4658,8 +4657,8 @@
 ||nicolas.ug$document
 ||nidhi.iexist.in$document
 ||nikanpolimer.ir$document
+||nilehouse.co.ug$document
 ||nilinkeji.com$document
-||nisacooks.com$document
 ||njtiledesigncenter.com$document
 ||nobius.org$document
 ||nocalnoodle.elin.co.za$document
@@ -4678,11 +4677,14 @@
 ||oakleyandfriends.co.uk$document
 ||obseques-conseils.com$document
 ||ocean.tecnasulstore.com.br$document
+||ohe.ie$document
 ||ohsewgorgeous.co.uk$document
+||oknoplastik.sk$document
 ||oldschoolvalue.s3.amazonaws.com/spreadsheets/osv_stock_valuation-sample-dummy.exe$document
 ||oleholeh.memangbeda.website$document
 ||olirecords.mixture.ltd$document
 ||olooom.com$document
+||omaia.org$document
 ||omaromatic.com$document
 ||omega.az$document
 ||oms.pappai.com$document
@@ -4694,6 +4696,7 @@
 ||onedrive.live.com/download?&resid=b4c15a27928f663b!229&authkey=aiarm61fwmd_npe$document
 ||onedrive.live.com/download?&resid=b4c15a27928f663b!230&authkey=ancu1eabetiubzg$document
 ||onedrive.live.com/download?&resid=b4c15a27928f663b!231&authkey=ai9h3sk_luxran0$document
+||onedrive.live.com/download?&resid=c127f9e0fb7cbbea!214&authkey=aat73nvghhjdr9g$document
 ||onedrive.live.com/download?authkey=!aase4ma0-vo_cls&cid=4df11eda676a355f&resid=4df11eda676a355f!140$document
 ||onedrive.live.com/download?authkey=!akd6uxvljtlvpxu&cid=4df11eda676a355f&resid=4df11eda676a355f!130$document
 ||onedrive.live.com/download?authkey=!aomvnemlpgwfuie&cid=4df11eda676a355f&resid=4df11eda676a355f!135$document
@@ -4712,14 +4715,13 @@
 ||onedrive.live.com/download?cid=0319bb40eba80dcc&resid=319bb40eba80dcc%21110&authkey=ag8bs48lq9n-piw$document
 ||onedrive.live.com/download?cid=03286724f74117f9&resid=3286724f74117f9!1179&authkey=acr-_rvrgp39kk4$document
 ||onedrive.live.com/download?cid=03286724f74117f9&resid=3286724f74117f9%211179&authkey=acr-_rvrgp39kk4$document
-||onedrive.live.com/download?cid=032ce380af7ab389&resid=32ce380af7ab389!210&authkey=akcynbtc0h3ui7e$document
-||onedrive.live.com/download?cid=032ce380af7ab389&resid=32ce380af7ab389%21210&authkey=akcynbtc0h3ui7e$document
 ||onedrive.live.com/download?cid=045adcdfe91be4f5&resid=45adcdfe91be4f5%21318&authkey=aa6lutarluhyj48$document
 ||onedrive.live.com/download?cid=0489c74de4facb30&resid=489c74de4facb30!109&authkey=ajo32arrzl_vwdq$document
 ||onedrive.live.com/download?cid=062a585e433edce3&resid=62a585e433edce3%211618&authkey=ahzfppat_uettfg$document
 ||onedrive.live.com/download?cid=087f57dcf1bd61bc&resid=87f57dcf1bd61bc!113&authkey=ap0wsc-rsiegllw$document
 ||onedrive.live.com/download?cid=09eebe7829f6351d&resid=9eebe7829f6351d%21827&authkey=amysfuvfuc5jezq$document
 ||onedrive.live.com/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!273&authkey=ae2m69e5nu3rrea$document
+||onedrive.live.com/download?cid=0d59c202e35694c2&resid=d59c202e35694c2!274&authkey=acqg0akutoxdpgo$document
 ||onedrive.live.com/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21273&authkey=ae2m69e5nu3rrea$document
 ||onedrive.live.com/download?cid=0d59c202e35694c2&resid=d59c202e35694c2%21274&authkey=acqg0akutoxdpgo$document
 ||onedrive.live.com/download?cid=0e26b39babdbf63c&resid=e26b39babdbf63c%21137&authkey=anshbgxg1_qa2h4$document
@@ -4731,8 +4733,10 @@
 ||onedrive.live.com/download?cid=115bffdddaa40942&resid=115bffdddaa40942%21540&authkey=aamhnqgfdtdsoxk$document
 ||onedrive.live.com/download?cid=125290ca4dc682c9&resid=125290ca4dc682c9%21452&authkey=afdp5rurqhdqa2a$document
 ||onedrive.live.com/download?cid=13b301f1cb48f8cd&resid=13b301f1cb48f8cd%21106&authkey=aiae3olcs4lulz4$document
+||onedrive.live.com/download?cid=14f52af71b98dbc5&resid=14f52af71b98dbc5%212449&authkey=anfs_n5cs1noojo$document
 ||onedrive.live.com/download?cid=165468846f076ee7&resid=165468846f076ee7!118&authkey=antash3ig98aqte$document
 ||onedrive.live.com/download?cid=165468846f076ee7&resid=165468846f076ee7%21118&authkey=antash3ig98aqte$document
+||onedrive.live.com/download?cid=16b1c02dce9ea41f&resid=16b1c02dce9ea41f%21286&authkey=almwisomhv3c0zc$document
 ||onedrive.live.com/download?cid=174a158b69387a7e&resid=174a158b69387a7e!348&authkey=ahnjoxa4ufoxa54$document
 ||onedrive.live.com/download?cid=174a158b69387a7e&resid=174a158b69387a7e%21348&authkey=ahnjoxa4ufoxa54$document
 ||onedrive.live.com/download?cid=18418adacefed6e2&resid=18418adacefed6e2!126&authkey=ad4yflrisq6d82g$document
@@ -4748,10 +4752,6 @@
 ||onedrive.live.com/download?cid=1f48501ee4e8735a&resid=1f48501ee4e8735a%215268&authkey=advgihzjzelvkdg$document
 ||onedrive.live.com/download?cid=208dce306fa91736&resid=208dce306fa91736%21184&authkey=ae6l_lmeqbcwqs4$document
 ||onedrive.live.com/download?cid=208dce306fa91736&resid=208dce306fa91736%21185&authkey=abpinbsiqu9kj0c$document
-||onedrive.live.com/download?cid=2184cd6093fdd997&resid=2184cd6093fdd997!136&authkey=agsnq9l7ncf4p-w$document
-||onedrive.live.com/download?cid=2184cd6093fdd997&resid=2184cd6093fdd997!137&authkey=aawcijw8fv4m-8g$document
-||onedrive.live.com/download?cid=2184cd6093fdd997&resid=2184cd6093fdd997%21136&authkey=agsnq9l7ncf4p-w$document
-||onedrive.live.com/download?cid=2184cd6093fdd997&resid=2184cd6093fdd997%21137&authkey=aawcijw8fv4m-8g$document
 ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!123&authkey=am1rcmkppbht8v0$document
 ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!124&authkey=am5sltharf-j_cc$document
 ||onedrive.live.com/download?cid=226be871a1b8f1a2&resid=226be871a1b8f1a2!125&authkey=acgvgbbuowodg4c$document
@@ -4784,6 +4784,8 @@
 ||onedrive.live.com/download?cid=2c38c37ed8430789&resid=2c38c37ed8430789%21115&authkey=aglznnsx71tbe9e$document
 ||onedrive.live.com/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37!183&authkey=akon9i9zzhusiuk$document
 ||onedrive.live.com/download?cid=2cbd310015bc2d37&resid=2cbd310015bc2d37%21183&authkey=akon9i9zzhusiuk$document
+||onedrive.live.com/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6!161&authkey=aovldmsenzzpjrw$document
+||onedrive.live.com/download?cid=2e9502659b6b82a6&resid=2e9502659b6b82a6%21161&authkey=aovldmsenzzpjrw$document
 ||onedrive.live.com/download?cid=2f01a497b687285e&resid=2f01a497b687285e!734&authkey=aiumuxtp3phppy4$document
 ||onedrive.live.com/download?cid=2f01a497b687285e&resid=2f01a497b687285e%21734&authkey=aiumuxtp3phppy4$document
 ||onedrive.live.com/download?cid=2f4d6884e933cb1a&resid=2f4d6884e933cb1a!116&authkey=!abwledjhfsqwap4$document
@@ -4806,8 +4808,6 @@
 ||onedrive.live.com/download?cid=3447601ab357f8c1&resid=3447601ab357f8c1!114&authkey=aitwerxd-t2cxl0$document
 ||onedrive.live.com/download?cid=3541c4a292f61866&resid=3541c4a292f61866!107&authkey=af08d9zk1yestqa$document
 ||onedrive.live.com/download?cid=3541c4a292f61866&resid=3541c4a292f61866%21107&authkey=af08d9zk1yestqa$document
-||onedrive.live.com/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c!139&authkey=ap4bbakgkikau-a$document
-||onedrive.live.com/download?cid=3674d56d2003f59c&resid=3674d56d2003f59c%21139&authkey=ap4bbakgkikau-a$document
 ||onedrive.live.com/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!198&authkey=acyz0gbpl6bp9mo$document
 ||onedrive.live.com/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e!199&authkey=admaszabh84m8ou$document
 ||onedrive.live.com/download?cid=37e7951c4b00fe8e&resid=37e7951c4b00fe8e%21198&authkey=acyz0gbpl6bp9mo$document
@@ -4817,21 +4817,6 @@
 ||onedrive.live.com/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21152&authkey=am09sv26njxzyn0$document
 ||onedrive.live.com/download?cid=3892a0364cb5da65&resid=3892a0364cb5da65%21153&authkey=ajs0jkoeqkqjrze$document
 ||onedrive.live.com/download?cid=3a1715e2cb964f25&resid=3a1715e2cb964f25%213713&authkey=aortxmfnibnoqkk$document
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237!963&authkey=aewqwrtr9szefem$document
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237!965&authkey=aaayllvoxl-rbdi$document
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237!966&authkey=apsg26pur_hpk6k$document
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237!971&authkey=amfm0a4mjjup0o8$document
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237!973&authkey=acfwvefa0v7myb4$document
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237!975&authkey=ajreyx8ik2l5uxm$document
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237!976&authkey=alpmp7w4cfupsvu$document
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237!977&authkey=adju1b_cnsxdxni$document
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21965&authkey=aaayllvoxl-rbdi$document
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21966&authkey=apsg26pur_hpk6k$document
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21971&authkey=amfm0a4mjjup0o8$document
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21975&authkey=ajreyx8ik2l5uxm$document
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21976&authkey=alpmp7w4cfupsvu$document
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21977&authkey=adju1b_cnsxdxni$document
-||onedrive.live.com/download?cid=3a488f75395fd237&resid=3a488f75395fd237%21978&authkey=agg7tntwzgctq7s$document
 ||onedrive.live.com/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21432&authkey=aa_npsupyqb2kge$document
 ||onedrive.live.com/download?cid=3bcd34d8ac2d7789&resid=3bcd34d8ac2d7789%21435&authkey=admsjhgpkbtcqzs$document
 ||onedrive.live.com/download?cid=3f2905efa1c7ac3f&resid=3f2905efa1c7ac3f!154&authkey=aasj15d0g_p2pog$document
@@ -4998,6 +4983,7 @@
 ||onedrive.live.com/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21111&authkey=aggnhgqj6uhxm2w$document
 ||onedrive.live.com/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21112&authkey=abser1xtkpb3-ta$document
 ||onedrive.live.com/download?cid=78bfb08e0f7bc86f&resid=78bfb08e0f7bc86f%21117&authkey=aivf1ddcvvu22em$document
+||onedrive.live.com/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb!211&authkey=anxavz-oaf9pv_c$document
 ||onedrive.live.com/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21210&authkey=agpl0pgvft8faaa$document
 ||onedrive.live.com/download?cid=797a869a9b6359eb&resid=797a869a9b6359eb%21211&authkey=anxavz-oaf9pv_c$document
 ||onedrive.live.com/download?cid=7a5e689dd1dc641f&resid=7a5e689dd1dc641f!119&authkey=aozjai26izprqto$document
@@ -5038,7 +5024,6 @@
 ||onedrive.live.com/download?cid=8ca507baa15fdb5c&resid=8ca507baa15fdb5c!213&authkey=acyrjlhflcrypae$document
 ||onedrive.live.com/download?cid=8ffd8cbd6540c065&resid=8ffd8cbd6540c065!822&authkey=acfj7bbrmktj1i0$document
 ||onedrive.live.com/download?cid=907247dc330a3f33&resid=907247dc330a3f33!243&authkey=aeiqd4ihuqopwm8$document
-||onedrive.live.com/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21276&authkey=afig5wsljtdc33s$document
 ||onedrive.live.com/download?cid=911a03165832a3d6&resid=911a03165832a3d6%21278&authkey=abdo23i3bvy0_my$document
 ||onedrive.live.com/download?cid=914146ba02b70d25&resid=914146ba02b70d25!130&authkey=ais_g9dqoddonsc$document
 ||onedrive.live.com/download?cid=914146ba02b70d25&resid=914146ba02b70d25%21106&authkey=ahfgxp0p6nk0eby$document
@@ -5081,7 +5066,6 @@
 ||onedrive.live.com/download?cid=9a8688776fe2dbf4&resid=9a8688776fe2dbf4%21177&authkey=als6_be40lt5jk8$document
 ||onedrive.live.com/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2!113&authkey=akeqdnxllfzf8hq$document
 ||onedrive.live.com/download?cid=9e4e4faca91ad3d2&resid=9e4e4faca91ad3d2%21113&authkey=akeqdnxllfzf8hq$document
-||onedrive.live.com/download?cid=9fb622acb27482ef&resid=9fb622acb27482ef%211197&authkey=aeacibxy2zlyxro$document
 ||onedrive.live.com/download?cid=9fba865c1fdce17f&resid=9fba865c1fdce17f%211109&authkey=achpeiyvsphyn9o$document
 ||onedrive.live.com/download?cid=a023fe2d1ac611f2&resid=a023fe2d1ac611f2!514&authkey=alaxh02uycquui4$document
 ||onedrive.live.com/download?cid=a04a98741fafee2b&resid=a04a98741fafee2b%211857&authkey=af3qhnjtfnffevi$document
@@ -5098,7 +5082,6 @@
 ||onedrive.live.com/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21!6053&authkey=agfh0ahstj7rrki$document
 ||onedrive.live.com/download?cid=a6dd95780c6c7e21&resid=a6dd95780c6c7e21%216053&authkey=agfh0ahstj7rrki$document
 ||onedrive.live.com/download?cid=a75074ec168603e4&resid=a75074ec168603e4%21108&authkey=apnjueurszwr7fi$document
-||onedrive.live.com/download?cid=a76c2c9b2bbef5ec&resid=a76c2c9b2bbef5ec%21141&authkey=akcfuxzfafd_c9c$document
 ||onedrive.live.com/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21414&authkey=akf9uwwkitvhrvc$document
 ||onedrive.live.com/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21415&authkey=ag_5kthuezprnoy$document
 ||onedrive.live.com/download?cid=a7d52fea62ebd0f0&resid=a7d52fea62ebd0f0%21416&authkey=airlma-pycgfkyc$document
@@ -5202,12 +5185,14 @@
 ||onedrive.live.com/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211030&authkey=aeqnasuksxccax4$document
 ||onedrive.live.com/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211031&authkey=acxtarrhbwrqt20$document
 ||onedrive.live.com/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211032&authkey=aemitbkn-vma9yk$document
+||onedrive.live.com/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211033&authkey=abiydifgst6musa$document
 ||onedrive.live.com/download?cid=d5825cd44ffd03a7&resid=d5825cd44ffd03a7%211035&authkey=ahd_ichsrf8ok_u$document
 ||onedrive.live.com/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!191&authkey=ajl2uegqunsgc3q$document
 ||onedrive.live.com/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0!192&authkey=acd_hx4bka3z0nw$document
 ||onedrive.live.com/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21191&authkey=ajl2uegqunsgc3q$document
 ||onedrive.live.com/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21192&authkey=acd_hx4bka3z0nw$document
 ||onedrive.live.com/download?cid=d718e3c8e3bc53c0&resid=d718e3c8e3bc53c0%21193&authkey=ah68m6pamjvyscy$document
+||onedrive.live.com/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21107&authkey=alo4lep7wht05na$document
 ||onedrive.live.com/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21109&authkey=adnbm6mekgzvvh8$document
 ||onedrive.live.com/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!141&authkey=alya4infudqs53o$document
 ||onedrive.live.com/download?cid=d8baa6d17fe7ceb5&resid=d8baa6d17fe7ceb5!142&authkey=aiemnxi-s-5vrz0$document
@@ -5242,8 +5227,6 @@
 ||onedrive.live.com/download?cid=e790c3d4dd4fa5db&resid=e790c3d4dd4fa5db%21350&authkey=ao-vuexoihzj7da$document
 ||onedrive.live.com/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2!142&authkey=ais88uad5aom6qu$document
 ||onedrive.live.com/download?cid=e859da0f2c81d5f2&resid=e859da0f2c81d5f2%21142&authkey=ais88uad5aom6qu$document
-||onedrive.live.com/download?cid=e86539a3497e46a2&resid=e86539a3497e46a2!120&authkey=amd6o5flalahjsy$document
-||onedrive.live.com/download?cid=e86539a3497e46a2&resid=e86539a3497e46a2%21120&authkey=amd6o5flalahjsy$document
 ||onedrive.live.com/download?cid=e97110434470423e&resid=e97110434470423e%21113&authkey=afowclex54if0g0$document
 ||onedrive.live.com/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33!1192&authkey=apnhep6fmmxxdkw$document
 ||onedrive.live.com/download?cid=e9a57719b11feb33&resid=e9a57719b11feb33%211192&authkey=apnhep6fmmxxdkw$document
@@ -5296,6 +5279,7 @@
 ||onedrive.live.com/download?cid=ff9d39cbb0e96469&resid=ff9d39cbb0e96469%21334&authkey=agsvox_t7qim4ta$document
 ||online.creedglobal.in$document
 ||onlinestatis.bar$document
+||ont.proman.id$document
 ||open.warehousesaas.co.uk$document
 ||opolis.io$document
 ||optimus.com.sg$document
@@ -5303,6 +5287,8 @@
 ||order.bizpeed.com$document
 ||orientgatewayltd.com$document
 ||orion445.com$document
+||oserve.pk$document
+||otolithenrichment.fahadjutt.com$document
 ||ottimade.com$document
 ||ourteam.searchkero.com$document
 ||ozemag.com$document
@@ -5325,6 +5311,7 @@
 ||paths.elin.co.za$document
 ||paulmercier.biz$document
 ||payerrealty.com$document
+||payments.atifsiddiqui.me$document
 ||pcsoori.com$document
 ||pd.oceaniarp.net$document
 ||perpus.onlineman7-jombang.sch.id$document
@@ -5339,6 +5326,7 @@
 ||pierreconsulting.info/wp-admin/llc/mwcacs65xienqdp/$document
 ||pink99.com$document
 ||pioneiraagronegocio.com.br/bayesian-forecasting-amj5e/s5hqmf6/$document
+||pizzabarletta.com.br$document
 ||plasfan.ind.br$document
 ||pmglance.startwriteup.com$document
 ||pokojewewladyslawowie.pl$document
@@ -5348,17 +5336,15 @@
 ||posmicrosystems.com$document
 ||poulman.panagiotopoulos-tours.gr$document
 ||ppdb.smk-ciptaskill.sch.id$document
-||pptvideotemplates.com$document
 ||prestasicash.com.ar$document
 ||prestigehomeautomation.net$document
 ||prishaartcreations.com$document
 ||procrossover.ru/wp-content/uploads/2020/10/skoda22.jpg$document
 ||procrossover.ru/wp-content/uploads/2020/10/skodaqq.jpg$document
 ||production.sparshims.com$document
-||productprecise.com$document
-||prof-dr-ahmedalmoatasem.com$document
 ||programaoperadoronline.com.br$document
 ||project.exquitec.com$document
+||promolyko.com$document
 ||promotoradescomplica.com.br$document
 ||promoversdubai.com$document
 ||propertiq.elin.co.za$document
@@ -5371,7 +5357,7 @@
 ||pujashoppe.in$document
 ||punchdialogues.com$document
 ||punjabdevelopersassociation.com.pk$document
-||purefoe.top$document
+||pvcprinting.co.uk$document
 ||qadir.tickfa.ir$document
 ||qatarglobalconsulting.com$document
 ||qjbutterflyevents.co.za/wp-admin/zzcoiatsr5wujrwagsgbnm2wkjxldvgu/$document
@@ -5401,7 +5387,6 @@
 ||raw.githubusercontent.com/tennc/webshell/master/other/small_shell.txt$document
 ||rc.ixiaoyang.cn$document
 ||readymmade.com$document
-||realtheprocess.co$document
 ||redchillicrackers.com$document
 ||reifenquick.de$document
 ||relaxindulge.co.nz$document
@@ -5452,7 +5437,6 @@
 ||sarakem.cl$document
 ||sasystemsuk.com$document
 ||savasaachi.systems$document
-||savingchintu.com$document
 ||scarfaceindustries.com$document
 ||scglobal.co.th$document
 ||schalke04rss.de$document
@@ -5460,10 +5444,8 @@
 ||schoolbustracker.softgig.co.ke$document
 ||sec-doc-w.com$document
 ||secure-doc-reader.com$document
-||sefp-boispro.fr$document
 ||segalsmetals.elin.co.za$document
 ||sellmyphonela.com$document
-||selltechtoday.com$document
 ||senbiaojita.com$document
 ||sendspace.com/pro/dl/q05z91$document
 ||sentierodelviandante.ml$document
@@ -5481,7 +5463,6 @@
 ||shivakunwar.com.np$document
 ||shoblasaathitrust.org$document
 ||shooka-co.com$document
-||shop.clarostudio.ro$document
 ||shop.goldspot.agency$document
 ||shopsofe.com$document
 ||shribharatvatika.com/ey4lpx8rx.zip$document
@@ -5494,11 +5475,11 @@
 ||simoneporzi.it$document
 ||simplithy.co.uk$document
 ||sindicato1ucm.cl$document
+||sindpol.tiejuris.com.br$document
 ||sinergidwireka.com$document
 ||sipahielektrik.com$document
 ||siperb.in$document
 ||sistelligent.com$document
-||site.sjc.co.ke$document
 ||sites.google.com/site/stormqk/dn/stormagent.apk?attredirects=0$document
 ||skkksolo.beweiretail.com$document
 ||skyflyfares.com$document
@@ -5509,7 +5490,6 @@
 ||smokeandgrowrichtour.com$document
 ||smokesolutionindia.com$document
 ||sobethuacademy.com$document
-||soft.110route.com$document
 ||soft.officelabo.net$document
 ||sohs.conceptechs.info$document
 ||solar.amazingtribe.lk$document
@@ -5518,11 +5498,11 @@
 ||somir.com.mx$document
 ||soralapps.com$document
 ||sorteio.orgaostalita.com.br$document
+||sosgsm.fr$document
 ||sota-france.fr$document
 ||sowingminerals.cl$document
 ||space.proactint.org$document
 ||spaceframe.mobi.space-frame.co.za$document
-||specfloors.net$document
 ||special-key.cf$document
 ||spent.com.pl$document
 ||spetsesyachtcharter.gr$document
@@ -5564,6 +5544,7 @@
 ||support-4-free.com$document
 ||support.clz.kr$document
 ||supportit.online$document
+||surestdysbonescagexc.dns.army$document
 ||sw.yourpageserver.com$document
 ||sweaty.dk$document
 ||sweet-diet.com$document
@@ -5589,12 +5570,12 @@
 ||tc.snpsresidential.com$document
 ||tcy.198424.com$document
 ||tdsp.yngw518.com$document
-||tech332.synology.me$document
 ||techgms.com$document
 ||technogreen.crmmanivela.com$document
 ||technohub.searchkero.com$document
 ||technologydistilled.com/a-nurse-ss8d9/z/$document
 ||tecnicaencolectores.com.mx$document
+||tecnologyschool.com$document
 ||teduae.com$document
 ||teleargentina.com$document
 ||telescopelms.com$document
@@ -5602,9 +5583,9 @@
 ||temptmag.com$document
 ||tennisafrica.com$document
 ||tentandoserfitness.000webhostapp.com$document
-||tepresto.net.pe$document
 ||test.adventser.com$document
 ||test.letraele.es$document
+||test.typoten.com$document
 ||test.wanepghana.org$document
 ||test1.asistencia247.com$document
 ||test1.milenial.id$document
@@ -5617,9 +5598,7 @@
 ||teteaffiche.stephanebillon.com$document
 ||tewoerd.eu$document
 ||textile.softberg.ro$document
-||texts.bfftexts.com$document
 ||texturesbyvinita.com$document
-||tharringtonsponsorship.com$document
 ||thecleaningladiespdx.com$document
 ||thecreativecafe.co.uk$document
 ||thefuturelife.in$document
@@ -5627,12 +5606,11 @@
 ||thehouseofpragya.com$document
 ||thekassia.co.uk$document
 ||thelaunchpadteam.com$document
-||thelekhak.com$document
 ||thelogicalgroup.co.uk$document
 ||thesummitpc.net$document
 ||theurbantutors.com$document
+||thewwpc.com$document
 ||thosewebbs.com$document
-||thriveink.com$document
 ||tianangdep.com$document
 ||tickfood.tickme.lk$document
 ||tickjobs.tickme.lk$document
@@ -5667,7 +5645,6 @@
 ||tulli.info$document
 ||tupperware.michaelroberge.ca$document
 ||turanggaresources.com$document
-||tushartyagiji.digitalswagger.in$document
 ||uat.indianfilmzone.com$document
 ||ublretailerdemo.cstdevs.com$document
 ||udesk.searchkero.com$document
@@ -5677,7 +5654,6 @@
 ||unicorpbrunei.com$document
 ||uniengrisb.com$document
 ||unisoftcc.com$document
-||unitedpestsolutionstx.com$document
 ||unyazitelecom.com$document
 ||upcbpta.com$document
 ||urbane.dezinetimes.com$document
@@ -5705,6 +5681,7 @@
 ||vivationdesign.com$document
 ||viveirodoiscorregos.com.br$document
 ||vksales.com$document
+||vladimirinternational.com$document
 ||vniel.co.kr/gnuboard/data/scan/amowvegfrt9ja/$document
 ||vniel.co.kr/gnuboard/data/scan/fu6jvxzzs46uqlp7l/$document
 ||vokasi.ub.ac.id$document
@@ -5713,11 +5690,11 @@
 ||vstsample.com$document
 ||vtube.fadlymotivator.com$document
 ||vvsskmodinationalschool.com$document
-||wahrewah.nl$document
 ||wanepliberia.org$document
 ||wanepniger.org$document
 ||weareactum.com$document
 ||web.eng.ubu.ac.th$document
+||web.geetle.ga$document
 ||web.geomegasoft.net$document
 ||web.mit.edu/kolya/.f/root/net.mit.edu/net/user/chris/winnt/mit_agenda2a.doc$document
 ||web.mit.edu/kolya/.f/root/net.mit.edu/sipb/user/kolya/afs/root.afs/net/user/chris/winnt/mit_agenda2a.doc$document
@@ -5738,14 +5715,13 @@
 ||whcms.yourpageserver.com$document
 ||whiteglovetailgate.com$document
 ||whiteresponse.com$document
+||whynt.xyz$document
 ||wi522012.ferozo.com$document
 ||wikalen.co.za$document
 ||wikileaks.org/syria-files/attach/222/222051_instruction.zip$document
 ||wildnights.co.uk$document
 ||wildtrust.mediadevstaging.com$document
 ||wimbamusica.com$document
-||windcomtechnologies.com$document
-||winnercircle.it$document
 ||wishesconcierge.com$document
 ||woezon.agency$document
 ||wolfgang-brodte.de$document
@@ -5761,7 +5737,6 @@
 ||xia.beihaixue.com$document
 ||xixaoclothing.com$document
 ||xk.996is.com$document
-||xmp.myracingaccounts.com$document
 ||xn--80akinnkiib6h.xn--90ais$document
 ||xn--polimerbizmimarlk-rvc.com$document
 ||ybom.urbanolab.com$document
@@ -5773,5 +5748,6 @@
 ||yskadvisors.com$document
 ||yummyyogaudaipur.com$document
 ||yzkzixun.com$document
+||zakra.tecnasulstore.com.br$document
 ||zytrox.tk$document
 ||zz.690tx.com$document
diff --git a/urlhaus-filter-vivaldi.txt b/urlhaus-filter-vivaldi.txt
index d43f2a6e..17e0b795 100644
--- a/urlhaus-filter-vivaldi.txt
+++ b/urlhaus-filter-vivaldi.txt
@@ -1,5 +1,5 @@
 ! Title: Malicious URL Blocklist (Vivaldi)
-! Updated: Thu, 25 Mar 2021 12:12:40 UTC
+! Updated: Fri, 26 Mar 2021 00:12:29 UTC
 ! Expires: 1 day (update frequency)
 ! Homepage: https://gitlab.com/curben/urlhaus-filter
 ! License: https://gitlab.com/curben/urlhaus-filter#license
@@ -1024,6 +1024,7 @@
 ||1.58.206.122$document
 ||1.58.206.199$document
 ||1.58.220.198$document
+||1.58.223.96$document
 ||1.58.50.67$document
 ||1.59.181.177$document
 ||1.59.249.83$document
@@ -3600,6 +3601,7 @@
 ||103.217.116.166$document
 ||103.217.116.245$document
 ||103.217.117.108$document
+||103.217.117.134$document
 ||103.217.119.74$document
 ||103.217.119.75$document
 ||103.217.119.76$document
@@ -3670,6 +3672,7 @@
 ||103.217.121.228$document
 ||103.217.121.23$document
 ||103.217.121.231$document
+||103.217.121.234$document
 ||103.217.121.237$document
 ||103.217.121.238$document
 ||103.217.121.239$document
@@ -3735,6 +3738,7 @@
 ||103.217.123.2$document
 ||103.217.123.200$document
 ||103.217.123.204$document
+||103.217.123.210$document
 ||103.217.123.213$document
 ||103.217.123.216$document
 ||103.217.123.218$document
@@ -5207,6 +5211,7 @@
 ||103.78.183.4$document
 ||103.78.183.40$document
 ||103.78.21.238$document
+||103.78.22.157$document
 ||103.78.22.177$document
 ||103.78.22.207$document
 ||103.78.22.219$document
@@ -6684,6 +6689,7 @@
 ||104.168.151.198$document
 ||104.168.152.230$document
 ||104.168.157.45$document
+||104.168.158.127$document
 ||104.168.158.148$document
 ||104.168.158.248$document
 ||104.168.158.38$document
@@ -6778,6 +6784,7 @@
 ||104.168.96.11$document
 ||104.168.96.168$document
 ||104.168.96.194$document
+||104.168.98.105$document
 ||104.168.98.206$document
 ||104.168.99.220$document
 ||104.168.99.30$document
@@ -8390,6 +8397,7 @@
 ||106.36.159.125$document
 ||106.36.4.112$document
 ||106.37.121.250$document
+||106.4.138.95$document
 ||106.4.140.29$document
 ||106.4.209.123$document
 ||106.4.241.59$document
@@ -10194,6 +10202,7 @@
 ||110.244.46.196$document
 ||110.244.48.104$document
 ||110.244.51.22$document
+||110.247.151.4$document
 ||110.247.16.153$document
 ||110.247.16.64$document
 ||110.247.180.69$document
@@ -10818,6 +10827,7 @@
 ||111.165.186.127$document
 ||111.165.202.37$document
 ||111.165.207.179$document
+||111.165.21.195$document
 ||111.165.210.227$document
 ||111.165.210.249$document
 ||111.165.214.179$document
@@ -10850,6 +10860,7 @@
 ||111.165.255.240$document
 ||111.165.26.73$document
 ||111.165.27.112$document
+||111.165.28.234$document
 ||111.165.31.62$document
 ||111.165.33.132$document
 ||111.165.33.210$document
@@ -16985,6 +16996,7 @@
 ||112.246.18.70$document
 ||112.246.18.84$document
 ||112.246.18.99$document
+||112.246.180.49$document
 ||112.246.181.139$document
 ||112.246.184.252$document
 ||112.246.184.97$document
@@ -17235,6 +17247,7 @@
 ||112.247.247.234$document
 ||112.247.248.114$document
 ||112.247.248.14$document
+||112.247.248.76$document
 ||112.247.249.198$document
 ||112.247.249.82$document
 ||112.247.250.193$document
@@ -17922,6 +17935,7 @@
 ||112.249.205.67$document
 ||112.249.206.105$document
 ||112.249.206.52$document
+||112.249.206.69$document
 ||112.249.206.8$document
 ||112.249.207.154$document
 ||112.249.207.198$document
@@ -18285,6 +18299,7 @@
 ||112.249.78.69$document
 ||112.249.79.230$document
 ||112.249.79.88$document
+||112.249.79.98$document
 ||112.249.80.217$document
 ||112.249.80.53$document
 ||112.249.80.69$document
@@ -18567,6 +18582,7 @@
 ||112.252.41.80$document
 ||112.252.42.128$document
 ||112.252.43.218$document
+||112.252.46.212$document
 ||112.252.59.78$document
 ||112.252.66.17$document
 ||112.252.66.55$document
@@ -20164,6 +20180,7 @@
 ||112.93.7.60$document
 ||112.93.89.37$document
 ||112.94.188.182$document
+||112.94.188.230$document
 ||112.94.189.107$document
 ||112.95.12.157$document
 ||112.95.13.15$document
@@ -20529,6 +20546,7 @@
 ||113.104.237.236$document
 ||113.104.237.34$document
 ||113.104.237.36$document
+||113.104.237.52$document
 ||113.104.237.72$document
 ||113.104.237.74$document
 ||113.104.237.83$document
@@ -21250,6 +21268,7 @@
 ||113.116.150.101$document
 ||113.116.150.110$document
 ||113.116.150.144$document
+||113.116.150.147$document
 ||113.116.150.161$document
 ||113.116.150.176$document
 ||113.116.150.180$document
@@ -22455,6 +22474,7 @@
 ||113.118.13.222$document
 ||113.118.13.226$document
 ||113.118.13.26$document
+||113.118.13.29$document
 ||113.118.13.44$document
 ||113.118.13.47$document
 ||113.118.13.50$document
@@ -23961,6 +23981,7 @@
 ||113.201.24.202$document
 ||113.201.24.206$document
 ||113.201.24.24$document
+||113.201.24.26$document
 ||113.201.24.30$document
 ||113.201.24.4$document
 ||113.201.24.5$document
@@ -24402,6 +24423,7 @@
 ||113.234.185.255$document
 ||113.234.195.226$document
 ||113.234.197.125$document
+||113.234.224.130$document
 ||113.234.224.160$document
 ||113.234.231.172$document
 ||113.234.231.202$document
@@ -25301,6 +25323,7 @@
 ||113.81.112.13$document
 ||113.81.112.159$document
 ||113.81.112.228$document
+||113.81.112.35$document
 ||113.81.112.66$document
 ||113.81.112.72$document
 ||113.81.113.119$document
@@ -25822,6 +25845,7 @@
 ||113.87.248.159$document
 ||113.87.248.162$document
 ||113.87.248.163$document
+||113.87.248.177$document
 ||113.87.248.181$document
 ||113.87.248.206$document
 ||113.87.248.28$document
@@ -26008,6 +26032,7 @@
 ||113.88.1.69$document
 ||113.88.100.105$document
 ||113.88.100.117$document
+||113.88.100.120$document
 ||113.88.100.130$document
 ||113.88.100.160$document
 ||113.88.100.172$document
@@ -26633,6 +26658,7 @@
 ||113.88.241.9$document
 ||113.88.241.92$document
 ||113.88.241.98$document
+||113.88.242.0$document
 ||113.88.242.1$document
 ||113.88.242.10$document
 ||113.88.242.116$document
@@ -26961,6 +26987,7 @@
 ||113.89.244.91$document
 ||113.89.244.93$document
 ||113.89.245.118$document
+||113.89.245.13$document
 ||113.89.245.132$document
 ||113.89.245.144$document
 ||113.89.245.174$document
@@ -29689,6 +29716,7 @@
 ||115.171.238.92$document
 ||115.171.239.20$document
 ||115.171.239.25$document
+||115.171.239.28$document
 ||115.171.90.159$document
 ||115.171.91.155$document
 ||115.171.91.195$document
@@ -29860,6 +29888,7 @@
 ||115.201.37.74$document
 ||115.201.37.84$document
 ||115.201.37.88$document
+||115.201.38.185$document
 ||115.201.40.156$document
 ||115.201.40.65$document
 ||115.201.40.66$document
@@ -29933,6 +29962,7 @@
 ||115.202.187.124$document
 ||115.202.187.242$document
 ||115.202.187.61$document
+||115.202.188.84$document
 ||115.202.210.224$document
 ||115.202.210.228$document
 ||115.202.214.217$document
@@ -30261,6 +30291,7 @@
 ||115.213.176.80$document
 ||115.213.186.121$document
 ||115.213.186.152$document
+||115.213.187.251$document
 ||115.213.188.167$document
 ||115.213.198.25$document
 ||115.213.199.79$document
@@ -30754,6 +30785,7 @@
 ||115.48.130.177$document
 ||115.48.130.181$document
 ||115.48.130.184$document
+||115.48.130.187$document
 ||115.48.130.193$document
 ||115.48.130.196$document
 ||115.48.130.197$document
@@ -30917,6 +30949,7 @@
 ||115.48.135.123$document
 ||115.48.135.126$document
 ||115.48.135.150$document
+||115.48.135.151$document
 ||115.48.135.152$document
 ||115.48.135.154$document
 ||115.48.135.155$document
@@ -32471,6 +32504,7 @@
 ||115.48.200.103$document
 ||115.48.200.104$document
 ||115.48.200.114$document
+||115.48.200.115$document
 ||115.48.200.124$document
 ||115.48.200.126$document
 ||115.48.200.134$document
@@ -33718,6 +33752,7 @@
 ||115.49.113.126$document
 ||115.49.113.59$document
 ||115.49.116.148$document
+||115.49.116.237$document
 ||115.49.118.13$document
 ||115.49.12.164$document
 ||115.49.12.26$document
@@ -33835,6 +33870,7 @@
 ||115.49.150.203$document
 ||115.49.150.86$document
 ||115.49.151.207$document
+||115.49.152.10$document
 ||115.49.152.116$document
 ||115.49.152.140$document
 ||115.49.152.89$document
@@ -34329,6 +34365,7 @@
 ||115.49.241.61$document
 ||115.49.241.87$document
 ||115.49.241.94$document
+||115.49.242.100$document
 ||115.49.242.17$document
 ||115.49.242.79$document
 ||115.49.242.91$document
@@ -35161,6 +35198,7 @@
 ||115.49.79.87$document
 ||115.49.79.98$document
 ||115.49.8.244$document
+||115.49.80.117$document
 ||115.49.80.149$document
 ||115.49.80.161$document
 ||115.49.80.74$document
@@ -37026,6 +37064,7 @@
 ||115.50.201.85$document
 ||115.50.201.87$document
 ||115.50.201.91$document
+||115.50.202.11$document
 ||115.50.202.13$document
 ||115.50.202.131$document
 ||115.50.202.157$document
@@ -38460,6 +38499,7 @@
 ||115.50.240.216$document
 ||115.50.240.220$document
 ||115.50.240.228$document
+||115.50.240.230$document
 ||115.50.240.237$document
 ||115.50.240.252$document
 ||115.50.240.27$document
@@ -39876,6 +39916,7 @@
 ||115.50.61.228$document
 ||115.50.61.23$document
 ||115.50.61.233$document
+||115.50.61.247$document
 ||115.50.61.25$document
 ||115.50.61.252$document
 ||115.50.61.254$document
@@ -40008,6 +40049,7 @@
 ||115.50.64.177$document
 ||115.50.64.178$document
 ||115.50.64.179$document
+||115.50.64.182$document
 ||115.50.64.189$document
 ||115.50.64.212$document
 ||115.50.64.229$document
@@ -41127,6 +41169,7 @@
 ||115.51.107.156$document
 ||115.51.107.163$document
 ||115.51.107.164$document
+||115.51.107.18$document
 ||115.51.107.183$document
 ||115.51.107.193$document
 ||115.51.107.195$document
@@ -42444,6 +42487,7 @@
 ||115.52.20.97$document
 ||115.52.200.245$document
 ||115.52.201.220$document
+||115.52.201.231$document
 ||115.52.201.254$document
 ||115.52.202.73$document
 ||115.52.204.80$document
@@ -42487,6 +42531,7 @@
 ||115.52.22.140$document
 ||115.52.22.145$document
 ||115.52.22.149$document
+||115.52.22.162$document
 ||115.52.22.166$document
 ||115.52.22.177$document
 ||115.52.22.19$document
@@ -42743,6 +42788,7 @@
 ||115.52.35.151$document
 ||115.52.35.6$document
 ||115.52.36.27$document
+||115.52.37.164$document
 ||115.52.38.110$document
 ||115.52.38.132$document
 ||115.52.38.182$document
@@ -43947,6 +43993,7 @@
 ||115.54.159.16$document
 ||115.54.159.206$document
 ||115.54.159.33$document
+||115.54.160.25$document
 ||115.54.168.18$document
 ||115.54.168.190$document
 ||115.54.168.237$document
@@ -44733,6 +44780,7 @@
 ||115.54.212.205$document
 ||115.54.212.207$document
 ||115.54.212.22$document
+||115.54.212.227$document
 ||115.54.212.233$document
 ||115.54.212.239$document
 ||115.54.212.249$document
@@ -45046,6 +45094,7 @@
 ||115.54.240.128$document
 ||115.54.240.166$document
 ||115.54.240.170$document
+||115.54.240.173$document
 ||115.54.240.195$document
 ||115.54.240.197$document
 ||115.54.240.198$document
@@ -45221,6 +45270,7 @@
 ||115.54.69.60$document
 ||115.54.69.89$document
 ||115.54.69.9$document
+||115.54.70.108$document
 ||115.54.70.139$document
 ||115.54.70.150$document
 ||115.54.70.161$document
@@ -45267,6 +45317,7 @@
 ||115.54.73.254$document
 ||115.54.73.37$document
 ||115.54.73.42$document
+||115.54.73.50$document
 ||115.54.73.51$document
 ||115.54.74.109$document
 ||115.54.74.142$document
@@ -48108,6 +48159,7 @@
 ||115.55.211.247$document
 ||115.55.211.251$document
 ||115.55.211.4$document
+||115.55.211.41$document
 ||115.55.211.48$document
 ||115.55.211.54$document
 ||115.55.211.75$document
@@ -48510,6 +48562,7 @@
 ||115.55.3.155$document
 ||115.55.3.20$document
 ||115.55.3.204$document
+||115.55.3.36$document
 ||115.55.3.54$document
 ||115.55.30.105$document
 ||115.55.30.138$document
@@ -49826,6 +49879,7 @@
 ||115.56.136.124$document
 ||115.56.136.127$document
 ||115.56.136.141$document
+||115.56.136.144$document
 ||115.56.136.145$document
 ||115.56.136.146$document
 ||115.56.136.154$document
@@ -50716,6 +50770,7 @@
 ||115.56.154.14$document
 ||115.56.154.142$document
 ||115.56.154.145$document
+||115.56.154.147$document
 ||115.56.154.164$document
 ||115.56.154.17$document
 ||115.56.154.173$document
@@ -50833,6 +50888,7 @@
 ||115.56.156.30$document
 ||115.56.156.39$document
 ||115.56.156.53$document
+||115.56.156.54$document
 ||115.56.156.55$document
 ||115.56.156.6$document
 ||115.56.156.62$document
@@ -51163,6 +51219,7 @@
 ||115.56.177.192$document
 ||115.56.177.198$document
 ||115.56.177.2$document
+||115.56.177.202$document
 ||115.56.177.205$document
 ||115.56.177.214$document
 ||115.56.177.220$document
@@ -52963,6 +53020,7 @@
 ||115.58.132.194$document
 ||115.58.132.196$document
 ||115.58.132.197$document
+||115.58.132.199$document
 ||115.58.132.2$document
 ||115.58.132.205$document
 ||115.58.132.211$document
@@ -53608,6 +53666,7 @@
 ||115.58.167.23$document
 ||115.58.167.50$document
 ||115.58.167.78$document
+||115.58.167.90$document
 ||115.58.168.104$document
 ||115.58.168.117$document
 ||115.58.168.14$document
@@ -53747,6 +53806,7 @@
 ||115.58.20.147$document
 ||115.58.20.152$document
 ||115.58.20.180$document
+||115.58.20.186$document
 ||115.58.20.193$document
 ||115.58.20.197$document
 ||115.58.20.199$document
@@ -55040,6 +55100,7 @@
 ||115.59.198.181$document
 ||115.59.198.184$document
 ||115.59.198.194$document
+||115.59.198.200$document
 ||115.59.198.211$document
 ||115.59.198.215$document
 ||115.59.198.218$document
@@ -55591,6 +55652,7 @@
 ||115.59.215.74$document
 ||115.59.215.8$document
 ||115.59.215.95$document
+||115.59.215.96$document
 ||115.59.215.99$document
 ||115.59.216.103$document
 ||115.59.216.106$document
@@ -57073,6 +57135,7 @@
 ||115.59.90.149$document
 ||115.59.90.155$document
 ||115.59.90.182$document
+||115.59.90.197$document
 ||115.59.90.204$document
 ||115.59.90.22$document
 ||115.59.90.236$document
@@ -57195,6 +57258,7 @@
 ||115.60.201.105$document
 ||115.60.201.142$document
 ||115.60.201.144$document
+||115.60.201.176$document
 ||115.60.201.181$document
 ||115.60.201.186$document
 ||115.60.201.21$document
@@ -57842,6 +57906,7 @@
 ||115.61.118.182$document
 ||115.61.118.185$document
 ||115.61.118.189$document
+||115.61.118.201$document
 ||115.61.118.210$document
 ||115.61.118.226$document
 ||115.61.118.245$document
@@ -59521,6 +59586,7 @@
 ||115.61.97.250$document
 ||115.61.97.39$document
 ||115.61.97.46$document
+||115.61.97.55$document
 ||115.61.97.63$document
 ||115.61.97.65$document
 ||115.61.97.70$document
@@ -59753,6 +59819,7 @@
 ||115.62.152.143$document
 ||115.62.152.144$document
 ||115.62.152.206$document
+||115.62.152.207$document
 ||115.62.152.37$document
 ||115.62.152.55$document
 ||115.62.152.70$document
@@ -60267,6 +60334,7 @@
 ||115.63.130.140$document
 ||115.63.130.150$document
 ||115.63.130.161$document
+||115.63.130.162$document
 ||115.63.130.169$document
 ||115.63.130.170$document
 ||115.63.130.173$document
@@ -60567,6 +60635,7 @@
 ||115.63.140.216$document
 ||115.63.140.218$document
 ||115.63.140.236$document
+||115.63.140.242$document
 ||115.63.140.27$document
 ||115.63.140.32$document
 ||115.63.140.39$document
@@ -66910,6 +66979,7 @@
 ||115.96.87.95$document
 ||115.96.88.171$document
 ||115.96.90.226$document
+||115.96.92.151$document
 ||115.96.94.114$document
 ||115.97.102.100$document
 ||115.97.102.102$document
@@ -68386,6 +68456,7 @@
 ||115.97.142.175$document
 ||115.97.142.176$document
 ||115.97.142.178$document
+||115.97.142.18$document
 ||115.97.142.180$document
 ||115.97.142.182$document
 ||115.97.142.188$document
@@ -91411,6 +91482,7 @@
 ||116.24.152.157$document
 ||116.24.152.158$document
 ||116.24.152.164$document
+||116.24.152.217$document
 ||116.24.152.245$document
 ||116.24.152.34$document
 ||116.24.152.80$document
@@ -94037,6 +94109,7 @@
 ||116.72.202.80$document
 ||116.72.202.81$document
 ||116.72.202.83$document
+||116.72.202.87$document
 ||116.72.202.89$document
 ||116.72.202.90$document
 ||116.72.202.92$document
@@ -94078,6 +94151,7 @@
 ||116.72.203.14$document
 ||116.72.203.141$document
 ||116.72.203.142$document
+||116.72.203.143$document
 ||116.72.203.145$document
 ||116.72.203.146$document
 ||116.72.203.148$document
@@ -102334,6 +102408,7 @@
 ||116.74.83.90$document
 ||116.74.83.94$document
 ||116.74.83.98$document
+||116.74.84.65$document
 ||116.74.85.1$document
 ||116.74.85.131$document
 ||116.74.87.107$document
@@ -105658,6 +105733,7 @@
 ||116.75.194.137$document
 ||116.75.194.138$document
 ||116.75.194.139$document
+||116.75.194.14$document
 ||116.75.194.140$document
 ||116.75.194.141$document
 ||116.75.194.143$document
@@ -107852,6 +107928,7 @@
 ||116.75.214.51$document
 ||116.75.214.52$document
 ||116.75.214.53$document
+||116.75.214.56$document
 ||116.75.214.58$document
 ||116.75.214.59$document
 ||116.75.214.6$document
@@ -107881,6 +107958,7 @@
 ||116.75.214.96$document
 ||116.75.214.97$document
 ||116.75.214.98$document
+||116.75.214.99$document
 ||116.75.215.0$document
 ||116.75.215.1$document
 ||116.75.215.100$document
@@ -112647,6 +112725,7 @@
 ||117.194.149.247$document
 ||117.194.149.250$document
 ||117.194.149.252$document
+||117.194.149.26$document
 ||117.194.149.28$document
 ||117.194.149.33$document
 ||117.194.149.37$document
@@ -112991,6 +113070,7 @@
 ||117.194.160.8$document
 ||117.194.160.81$document
 ||117.194.160.83$document
+||117.194.160.84$document
 ||117.194.160.85$document
 ||117.194.160.87$document
 ||117.194.160.88$document
@@ -116424,6 +116504,7 @@
 ||117.202.70.224$document
 ||117.202.70.225$document
 ||117.202.70.226$document
+||117.202.70.227$document
 ||117.202.70.228$document
 ||117.202.70.229$document
 ||117.202.70.23$document
@@ -118622,6 +118703,7 @@
 ||117.213.11.106$document
 ||117.213.11.136$document
 ||117.213.11.205$document
+||117.213.11.225$document
 ||117.213.11.47$document
 ||117.213.11.50$document
 ||117.213.11.8$document
@@ -119041,6 +119123,7 @@
 ||117.213.42.153$document
 ||117.213.42.154$document
 ||117.213.42.157$document
+||117.213.42.158$document
 ||117.213.42.159$document
 ||117.213.42.16$document
 ||117.213.42.160$document
@@ -120080,6 +120163,7 @@
 ||117.213.9.58$document
 ||117.213.9.71$document
 ||117.213.9.77$document
+||117.213.9.78$document
 ||117.214.11.249$document
 ||117.214.11.8$document
 ||117.214.242.73$document
@@ -120377,6 +120461,7 @@
 ||117.215.248.208$document
 ||117.215.248.214$document
 ||117.215.248.217$document
+||117.215.248.223$document
 ||117.215.248.23$document
 ||117.215.248.237$document
 ||117.215.248.242$document
@@ -120415,6 +120500,7 @@
 ||117.215.249.20$document
 ||117.215.249.22$document
 ||117.215.249.221$document
+||117.215.249.23$document
 ||117.215.249.230$document
 ||117.215.249.240$document
 ||117.215.249.241$document
@@ -121002,6 +121088,7 @@
 ||117.222.161.65$document
 ||117.222.161.66$document
 ||117.222.161.67$document
+||117.222.161.68$document
 ||117.222.161.7$document
 ||117.222.161.70$document
 ||117.222.161.74$document
@@ -121270,6 +121357,7 @@
 ||117.222.163.148$document
 ||117.222.163.149$document
 ||117.222.163.15$document
+||117.222.163.150$document
 ||117.222.163.151$document
 ||117.222.163.153$document
 ||117.222.163.154$document
@@ -121396,6 +121484,7 @@
 ||117.222.163.59$document
 ||117.222.163.6$document
 ||117.222.163.60$document
+||117.222.163.61$document
 ||117.222.163.62$document
 ||117.222.163.63$document
 ||117.222.163.65$document
@@ -121407,6 +121496,7 @@
 ||117.222.163.70$document
 ||117.222.163.71$document
 ||117.222.163.72$document
+||117.222.163.73$document
 ||117.222.163.74$document
 ||117.222.163.77$document
 ||117.222.163.78$document
@@ -121774,6 +121864,7 @@
 ||117.222.165.28$document
 ||117.222.165.29$document
 ||117.222.165.3$document
+||117.222.165.31$document
 ||117.222.165.32$document
 ||117.222.165.33$document
 ||117.222.165.34$document
@@ -122221,6 +122312,7 @@
 ||117.222.168.114$document
 ||117.222.168.115$document
 ||117.222.168.116$document
+||117.222.168.119$document
 ||117.222.168.122$document
 ||117.222.168.123$document
 ||117.222.168.124$document
@@ -122241,6 +122333,7 @@
 ||117.222.168.181$document
 ||117.222.168.183$document
 ||117.222.168.185$document
+||117.222.168.186$document
 ||117.222.168.191$document
 ||117.222.168.194$document
 ||117.222.168.195$document
@@ -122307,6 +122400,7 @@
 ||117.222.169.112$document
 ||117.222.169.113$document
 ||117.222.169.114$document
+||117.222.169.115$document
 ||117.222.169.117$document
 ||117.222.169.12$document
 ||117.222.169.124$document
@@ -122522,6 +122616,7 @@
 ||117.222.171.192$document
 ||117.222.171.202$document
 ||117.222.171.203$document
+||117.222.171.205$document
 ||117.222.171.209$document
 ||117.222.171.217$document
 ||117.222.171.218$document
@@ -122670,6 +122765,7 @@
 ||117.222.172.9$document
 ||117.222.172.92$document
 ||117.222.172.94$document
+||117.222.172.97$document
 ||117.222.172.98$document
 ||117.222.173.10$document
 ||117.222.173.100$document
@@ -124124,6 +124220,7 @@
 ||117.242.210.65$document
 ||117.242.210.67$document
 ||117.242.210.68$document
+||117.242.210.69$document
 ||117.242.210.7$document
 ||117.242.210.70$document
 ||117.242.210.71$document
@@ -124672,6 +124769,7 @@
 ||117.247.200.169$document
 ||117.247.200.170$document
 ||117.247.200.172$document
+||117.247.200.179$document
 ||117.247.200.181$document
 ||117.247.200.182$document
 ||117.247.200.185$document
@@ -124750,6 +124848,7 @@
 ||117.247.201.156$document
 ||117.247.201.158$document
 ||117.247.201.161$document
+||117.247.201.163$document
 ||117.247.201.172$document
 ||117.247.201.175$document
 ||117.247.201.179$document
@@ -124871,6 +124970,7 @@
 ||117.247.202.31$document
 ||117.247.202.32$document
 ||117.247.202.37$document
+||117.247.202.4$document
 ||117.247.202.46$document
 ||117.247.202.48$document
 ||117.247.202.50$document
@@ -124972,6 +125072,7 @@
 ||117.247.203.3$document
 ||117.247.203.31$document
 ||117.247.203.33$document
+||117.247.203.38$document
 ||117.247.203.39$document
 ||117.247.203.40$document
 ||117.247.203.45$document
@@ -126645,6 +126746,7 @@
 ||117.251.59.232$document
 ||117.251.59.237$document
 ||117.251.59.24$document
+||117.251.59.242$document
 ||117.251.59.243$document
 ||117.251.59.244$document
 ||117.251.59.246$document
@@ -127507,6 +127609,7 @@
 ||117.63.51.128$document
 ||117.63.53.15$document
 ||117.63.53.172$document
+||117.63.56.81$document
 ||117.63.69.253$document
 ||117.63.7.177$document
 ||117.63.7.192$document
@@ -127570,6 +127673,7 @@
 ||117.85.89.213$document
 ||117.85.95.220$document
 ||117.86.1.7$document
+||117.86.105.110$document
 ||117.86.110.91$document
 ||117.86.148.199$document
 ||117.86.155.77$document
@@ -127808,6 +127912,7 @@
 ||117.91.156.66$document
 ||117.91.172.11$document
 ||117.91.172.49$document
+||117.91.240.50$document
 ||117.91.241.17$document
 ||117.92.177.76$document
 ||117.92.196.126$document
@@ -129136,6 +129241,7 @@
 ||118.75.114.227$document
 ||118.75.115.154$document
 ||118.75.119.214$document
+||118.75.120.136$document
 ||118.75.120.209$document
 ||118.75.120.229$document
 ||118.75.120.98$document
@@ -129264,6 +129370,7 @@
 ||118.75.236.238$document
 ||118.75.239.142$document
 ||118.75.240.141$document
+||118.75.240.239$document
 ||118.75.240.9$document
 ||118.75.241.204$document
 ||118.75.241.26$document
@@ -129575,6 +129682,7 @@
 ||118.79.163.61$document
 ||118.79.163.86$document
 ||118.79.163.91$document
+||118.79.164.102$document
 ||118.79.164.108$document
 ||118.79.167.240$document
 ||118.79.167.41$document
@@ -130608,6 +130716,7 @@
 ||119.123.175.124$document
 ||119.123.175.126$document
 ||119.123.175.128$document
+||119.123.175.133$document
 ||119.123.175.139$document
 ||119.123.175.144$document
 ||119.123.175.145$document
@@ -131798,6 +131907,7 @@
 ||119.165.207.118$document
 ||119.165.208.188$document
 ||119.165.208.216$document
+||119.165.208.73$document
 ||119.165.209.0$document
 ||119.165.209.121$document
 ||119.165.209.127$document
@@ -132948,6 +133058,7 @@
 ||119.179.42.247$document
 ||119.179.43.1$document
 ||119.179.43.27$document
+||119.179.44.141$document
 ||119.179.44.157$document
 ||119.179.44.192$document
 ||119.179.45.108$document
@@ -133423,6 +133534,7 @@
 ||119.180.9.183$document
 ||119.180.9.209$document
 ||119.180.9.241$document
+||119.180.9.35$document
 ||119.180.90.121$document
 ||119.180.92.176$document
 ||119.180.92.224$document
@@ -135247,6 +135359,7 @@
 ||119.250.10.222$document
 ||119.250.117.131$document
 ||119.250.119.227$document
+||119.250.129.231$document
 ||119.250.132.83$document
 ||119.250.166.153$document
 ||119.250.218.177$document
@@ -135774,6 +135887,7 @@
 ||120.12.211.237$document
 ||120.12.212.231$document
 ||120.12.212.234$document
+||120.12.212.5$document
 ||120.12.213.82$document
 ||120.12.217.158$document
 ||120.12.217.9$document
@@ -136959,6 +137073,7 @@
 ||120.57.102.243$document
 ||120.57.102.246$document
 ||120.57.102.254$document
+||120.57.102.32$document
 ||120.57.102.46$document
 ||120.57.102.5$document
 ||120.57.102.58$document
@@ -139441,6 +139556,7 @@
 ||120.82.169.73$document
 ||120.82.170.40$document
 ||120.82.170.75$document
+||120.82.217.176$document
 ||120.82.217.197$document
 ||120.82.228.185$document
 ||120.82.38.219$document
@@ -139764,6 +139880,7 @@
 ||120.85.173.121$document
 ||120.85.173.126$document
 ||120.85.173.135$document
+||120.85.173.137$document
 ||120.85.173.143$document
 ||120.85.173.145$document
 ||120.85.173.149$document
@@ -139809,6 +139926,7 @@
 ||120.85.174.24$document
 ||120.85.174.30$document
 ||120.85.174.38$document
+||120.85.174.39$document
 ||120.85.174.41$document
 ||120.85.174.42$document
 ||120.85.174.45$document
@@ -140065,6 +140183,7 @@
 ||120.85.199.184$document
 ||120.85.199.19$document
 ||120.85.199.195$document
+||120.85.199.222$document
 ||120.85.199.242$document
 ||120.85.199.247$document
 ||120.85.199.253$document
@@ -140186,6 +140305,7 @@
 ||120.85.211.82$document
 ||120.85.211.84$document
 ||120.85.211.85$document
+||120.85.212.45$document
 ||120.85.232.107$document
 ||120.85.232.64$document
 ||120.85.234.15$document
@@ -140285,6 +140405,7 @@
 ||120.85.238.80$document
 ||120.85.238.87$document
 ||120.85.238.89$document
+||120.85.238.97$document
 ||120.85.239.100$document
 ||120.85.239.11$document
 ||120.85.239.113$document
@@ -140701,6 +140822,7 @@
 ||121.154.163.88$document
 ||121.154.190.19$document
 ||121.154.190.232$document
+||121.154.190.73$document
 ||121.154.226.39$document
 ||121.154.37.14$document
 ||121.154.39.26$document
@@ -141696,6 +141818,7 @@
 ||121.34.150.234$document
 ||121.34.150.251$document
 ||121.34.150.27$document
+||121.34.150.32$document
 ||121.34.150.36$document
 ||121.34.150.43$document
 ||121.34.150.45$document
@@ -142489,6 +142612,7 @@
 ||122.188.61.157$document
 ||122.188.61.231$document
 ||122.188.61.239$document
+||122.188.86.225$document
 ||122.189.101.23$document
 ||122.189.105.132$document
 ||122.189.105.250$document
@@ -142498,6 +142622,7 @@
 ||122.189.7.14$document
 ||122.190.115.86$document
 ||122.190.19.131$document
+||122.190.19.204$document
 ||122.190.192.182$document
 ||122.190.192.92$document
 ||122.190.244.85$document
@@ -143091,6 +143216,7 @@
 ||123.10.131.179$document
 ||123.10.131.204$document
 ||123.10.131.223$document
+||123.10.131.225$document
 ||123.10.131.245$document
 ||123.10.131.251$document
 ||123.10.131.47$document
@@ -143753,6 +143879,7 @@
 ||123.10.209.61$document
 ||123.10.209.65$document
 ||123.10.209.87$document
+||123.10.209.95$document
 ||123.10.21.116$document
 ||123.10.21.172$document
 ||123.10.21.184$document
@@ -143797,6 +143924,7 @@
 ||123.10.214.114$document
 ||123.10.214.129$document
 ||123.10.214.174$document
+||123.10.214.193$document
 ||123.10.214.25$document
 ||123.10.214.60$document
 ||123.10.214.75$document
@@ -144550,6 +144678,7 @@
 ||123.10.82.119$document
 ||123.10.82.192$document
 ||123.10.82.228$document
+||123.10.83.136$document
 ||123.10.84.166$document
 ||123.10.84.18$document
 ||123.10.84.187$document
@@ -145334,6 +145463,7 @@
 ||123.11.174.47$document
 ||123.11.174.61$document
 ||123.11.175.108$document
+||123.11.175.136$document
 ||123.11.175.190$document
 ||123.11.175.197$document
 ||123.11.175.227$document
@@ -147114,6 +147244,7 @@
 ||123.12.229.211$document
 ||123.12.229.232$document
 ||123.12.229.24$document
+||123.12.229.243$document
 ||123.12.229.25$document
 ||123.12.229.252$document
 ||123.12.229.253$document
@@ -147531,6 +147662,7 @@
 ||123.12.35.198$document
 ||123.12.35.29$document
 ||123.12.36.167$document
+||123.12.36.185$document
 ||123.12.36.193$document
 ||123.12.36.3$document
 ||123.12.36.54$document
@@ -148139,6 +148271,7 @@
 ||123.13.100.254$document
 ||123.13.101.202$document
 ||123.13.101.30$document
+||123.13.101.56$document
 ||123.13.102.179$document
 ||123.13.102.204$document
 ||123.13.102.205$document
@@ -148445,6 +148578,7 @@
 ||123.13.30.167$document
 ||123.13.30.2$document
 ||123.13.30.219$document
+||123.13.30.75$document
 ||123.13.31.104$document
 ||123.13.31.144$document
 ||123.13.31.175$document
@@ -150451,6 +150585,7 @@
 ||123.14.205.198$document
 ||123.14.205.212$document
 ||123.14.205.223$document
+||123.14.205.23$document
 ||123.14.205.236$document
 ||123.14.205.241$document
 ||123.14.205.246$document
@@ -152262,6 +152397,7 @@
 ||123.183.123.153$document
 ||123.183.123.187$document
 ||123.183.123.212$document
+||123.183.123.41$document
 ||123.183.123.5$document
 ||123.183.124.131$document
 ||123.183.124.18$document
@@ -153693,6 +153829,7 @@
 ||123.4.179.75$document
 ||123.4.179.8$document
 ||123.4.179.82$document
+||123.4.180.137$document
 ||123.4.180.152$document
 ||123.4.180.156$document
 ||123.4.180.171$document
@@ -153740,6 +153877,7 @@
 ||123.4.184.8$document
 ||123.4.185.112$document
 ||123.4.185.12$document
+||123.4.185.137$document
 ||123.4.185.14$document
 ||123.4.185.168$document
 ||123.4.185.220$document
@@ -156555,6 +156693,7 @@
 ||123.5.145.23$document
 ||123.5.145.233$document
 ||123.5.145.242$document
+||123.5.145.245$document
 ||123.5.145.248$document
 ||123.5.145.42$document
 ||123.5.145.55$document
@@ -157751,6 +157890,7 @@
 ||123.5.22.110$document
 ||123.5.22.175$document
 ||123.5.22.210$document
+||123.5.22.220$document
 ||123.5.22.221$document
 ||123.5.22.238$document
 ||123.5.22.49$document
@@ -158429,6 +158569,7 @@
 ||123.8.183.124$document
 ||123.8.183.145$document
 ||123.8.183.185$document
+||123.8.183.194$document
 ||123.8.183.207$document
 ||123.8.183.31$document
 ||123.8.183.46$document
@@ -159425,6 +159566,7 @@
 ||123.9.103.190$document
 ||123.9.103.200$document
 ||123.9.103.23$document
+||123.9.103.252$document
 ||123.9.103.36$document
 ||123.9.103.53$document
 ||123.9.103.61$document
@@ -161546,6 +161688,7 @@
 ||124.130.31.18$document
 ||124.130.40.15$document
 ||124.130.40.162$document
+||124.130.40.31$document
 ||124.130.56.200$document
 ||124.130.56.42$document
 ||124.130.57.12$document
@@ -162189,6 +162332,7 @@
 ||124.131.24.86$document
 ||124.131.25.69$document
 ||124.131.26.238$document
+||124.131.26.243$document
 ||124.131.26.78$document
 ||124.131.28.172$document
 ||124.131.28.196$document
@@ -163601,6 +163745,7 @@
 ||124.94.244.153$document
 ||124.94.57.133$document
 ||124.95.16.252$document
+||124.95.17.41$document
 ||124.95.81.24$document
 ||124.com.ua$document
 ||124.cpanel.realwebsitesite.com$document
@@ -164017,6 +164162,7 @@
 ||125.126.66.6$document
 ||125.126.67.145$document
 ||125.126.69.198$document
+||125.126.69.95$document
 ||125.126.71.207$document
 ||125.126.72.174$document
 ||125.126.73.123$document
@@ -164147,6 +164293,7 @@
 ||125.160.137.80$document
 ||125.160.213.219$document
 ||125.161.14.114$document
+||125.161.70.34$document
 ||125.161.96.233$document
 ||125.162.65.174$document
 ||125.163.199.90$document
@@ -164932,6 +165079,7 @@
 ||125.40.136.22$document
 ||125.40.136.220$document
 ||125.40.136.222$document
+||125.40.136.25$document
 ||125.40.136.252$document
 ||125.40.136.253$document
 ||125.40.136.33$document
@@ -165477,6 +165625,7 @@
 ||125.40.234.169$document
 ||125.40.234.73$document
 ||125.40.235.80$document
+||125.40.237.130$document
 ||125.40.24.117$document
 ||125.40.24.134$document
 ||125.40.24.143$document
@@ -167356,6 +167505,7 @@
 ||125.41.200.172$document
 ||125.41.200.181$document
 ||125.41.200.188$document
+||125.41.200.189$document
 ||125.41.200.193$document
 ||125.41.200.203$document
 ||125.41.200.210$document
@@ -169357,6 +169507,7 @@
 ||125.42.120.98$document
 ||125.42.121.101$document
 ||125.42.121.103$document
+||125.42.121.106$document
 ||125.42.121.108$document
 ||125.42.121.109$document
 ||125.42.121.11$document
@@ -169656,6 +169807,7 @@
 ||125.42.124.88$document
 ||125.42.124.93$document
 ||125.42.124.97$document
+||125.42.125.103$document
 ||125.42.125.107$document
 ||125.42.125.110$document
 ||125.42.125.115$document
@@ -170459,6 +170611,7 @@
 ||125.42.97.100$document
 ||125.42.97.101$document
 ||125.42.97.102$document
+||125.42.97.103$document
 ||125.42.97.119$document
 ||125.42.97.122$document
 ||125.42.97.123$document
@@ -170717,6 +170870,7 @@
 ||125.43.105.129$document
 ||125.43.105.135$document
 ||125.43.105.149$document
+||125.43.105.157$document
 ||125.43.105.158$document
 ||125.43.105.168$document
 ||125.43.105.172$document
@@ -171001,6 +171155,7 @@
 ||125.43.13.92$document
 ||125.43.130.108$document
 ||125.43.130.23$document
+||125.43.130.232$document
 ||125.43.130.24$document
 ||125.43.131.111$document
 ||125.43.131.182$document
@@ -171349,6 +171504,7 @@
 ||125.43.21.146$document
 ||125.43.21.147$document
 ||125.43.21.152$document
+||125.43.21.157$document
 ||125.43.21.159$document
 ||125.43.21.161$document
 ||125.43.21.174$document
@@ -174476,6 +174632,7 @@
 ||125.44.211.83$document
 ||125.44.211.98$document
 ||125.44.212.105$document
+||125.44.212.107$document
 ||125.44.212.108$document
 ||125.44.212.109$document
 ||125.44.212.114$document
@@ -174936,6 +175093,7 @@
 ||125.44.230.125$document
 ||125.44.230.164$document
 ||125.44.230.176$document
+||125.44.230.191$document
 ||125.44.230.200$document
 ||125.44.230.226$document
 ||125.44.230.244$document
@@ -175398,6 +175556,7 @@
 ||125.44.31.61$document
 ||125.44.31.64$document
 ||125.44.31.69$document
+||125.44.31.79$document
 ||125.44.31.8$document
 ||125.44.31.82$document
 ||125.44.31.84$document
@@ -176650,6 +176809,7 @@
 ||125.45.57.231$document
 ||125.45.57.238$document
 ||125.45.57.247$document
+||125.45.57.249$document
 ||125.45.57.35$document
 ||125.45.57.46$document
 ||125.45.57.50$document
@@ -177200,6 +177360,7 @@
 ||125.45.90.131$document
 ||125.45.90.151$document
 ||125.45.90.153$document
+||125.45.90.158$document
 ||125.45.90.16$document
 ||125.45.90.184$document
 ||125.45.90.189$document
@@ -177318,6 +177479,7 @@
 ||125.46.137.54$document
 ||125.46.138.0$document
 ||125.46.138.10$document
+||125.46.138.117$document
 ||125.46.138.122$document
 ||125.46.138.149$document
 ||125.46.138.151$document
@@ -179996,6 +180158,7 @@
 ||125.47.251.96$document
 ||125.47.251.98$document
 ||125.47.252.105$document
+||125.47.252.106$document
 ||125.47.252.107$document
 ||125.47.252.109$document
 ||125.47.252.110$document
@@ -180213,6 +180376,7 @@
 ||125.47.255.94$document
 ||125.47.255.97$document
 ||125.47.28.150$document
+||125.47.28.217$document
 ||125.47.29.173$document
 ||125.47.29.191$document
 ||125.47.32.201$document
@@ -182345,10 +182509,12 @@
 ||125.99.207.92$document
 ||125.99.212.13$document
 ||125.99.220.105$document
+||125.99.220.202$document
 ||125.99.222.152$document
 ||125.99.222.245$document
 ||125.99.222.76$document
 ||125.99.223.227$document
+||125.99.223.26$document
 ||125.99.224.101$document
 ||125.99.224.102$document
 ||125.99.224.106$document
@@ -184214,6 +184380,7 @@
 ||134.209.202.202$document
 ||134.209.203.101$document
 ||134.209.203.205$document
+||134.209.203.221$document
 ||134.209.203.223$document
 ||134.209.203.70$document
 ||134.209.204.77$document
@@ -184721,6 +184888,7 @@
 ||139.170.181.68$document
 ||139.170.200.29$document
 ||139.170.206.148$document
+||139.170.228.166$document
 ||139.170.228.217$document
 ||139.170.228.55$document
 ||139.170.230.204$document
@@ -186133,6 +186301,7 @@
 ||140.237.255.239$document
 ||140.237.28.148$document
 ||140.237.29.28$document
+||140.237.30.113$document
 ||140.237.30.179$document
 ||140.237.30.188$document
 ||140.237.31.197$document
@@ -186143,6 +186312,7 @@
 ||140.237.4.82$document
 ||140.237.5.254$document
 ||140.237.5.41$document
+||140.237.5.43$document
 ||140.240.100.181$document
 ||140.240.100.94$document
 ||140.240.102.181$document
@@ -186931,6 +187101,8 @@
 ||149.255.15.121$document
 ||149.255.15.180$document
 ||149.255.15.182$document
+||149.255.15.191$document
+||149.255.15.235$document
 ||149.255.15.87$document
 ||149.255.36.133$document
 ||149.255.36.156$document
@@ -187182,6 +187354,7 @@
 ||151.226.2.198$document
 ||151.227.42.63$document
 ||151.232.180.152$document
+||151.232.249.222$document
 ||151.232.56.134$document
 ||151.233.52.223$document
 ||151.233.56.139$document
@@ -187316,6 +187489,7 @@
 ||152.173.25.125$document
 ||152.231.127.54$document
 ||152.231.25.253$document
+||152.241.13.197$document
 ||152.241.13.246$document
 ||152.241.24.181$document
 ||152.241.33.96$document
@@ -187548,6 +187722,7 @@
 ||153.34.65.168$document
 ||153.34.67.119$document
 ||153.34.86.53$document
+||153.35.111.46$document
 ||153.35.141.25$document
 ||153.35.141.60$document
 ||153.35.141.74$document
@@ -187748,6 +187923,7 @@
 ||157.119.214.172$document
 ||157.119.214.233$document
 ||157.119.215.224$document
+||157.122.105.142$document
 ||157.122.106.12$document
 ||157.230.0.237$document
 ||157.230.1.18$document
@@ -189498,6 +189674,7 @@
 ||163.125.181.187$document
 ||163.125.181.76$document
 ||163.125.181.87$document
+||163.125.183.111$document
 ||163.125.183.142$document
 ||163.125.183.180$document
 ||163.125.183.75$document
@@ -189622,6 +189799,7 @@
 ||163.125.200.6$document
 ||163.125.200.64$document
 ||163.125.200.70$document
+||163.125.200.72$document
 ||163.125.200.73$document
 ||163.125.200.75$document
 ||163.125.200.76$document
@@ -189679,6 +189857,7 @@
 ||163.125.202.158$document
 ||163.125.202.159$document
 ||163.125.202.16$document
+||163.125.202.174$document
 ||163.125.202.183$document
 ||163.125.202.186$document
 ||163.125.202.190$document
@@ -189696,6 +189875,7 @@
 ||163.125.202.4$document
 ||163.125.202.57$document
 ||163.125.202.72$document
+||163.125.202.74$document
 ||163.125.202.8$document
 ||163.125.202.83$document
 ||163.125.202.9$document
@@ -189706,6 +189886,7 @@
 ||163.125.203.146$document
 ||163.125.203.148$document
 ||163.125.203.154$document
+||163.125.203.179$document
 ||163.125.203.184$document
 ||163.125.203.198$document
 ||163.125.203.200$document
@@ -189784,6 +189965,7 @@
 ||163.125.207.0$document
 ||163.125.207.102$document
 ||163.125.207.116$document
+||163.125.207.125$document
 ||163.125.207.140$document
 ||163.125.207.143$document
 ||163.125.207.158$document
@@ -189868,6 +190050,7 @@
 ||163.125.248.230$document
 ||163.125.248.254$document
 ||163.125.250.176$document
+||163.125.250.202$document
 ||163.125.251.214$document
 ||163.125.251.225$document
 ||163.125.251.227$document
@@ -189889,6 +190072,7 @@
 ||163.125.30.28$document
 ||163.125.31.183$document
 ||163.125.34.24$document
+||163.125.37.201$document
 ||163.125.38.226$document
 ||163.125.4.131$document
 ||163.125.4.147$document
@@ -189932,6 +190116,7 @@
 ||163.125.68.229$document
 ||163.125.68.240$document
 ||163.125.68.243$document
+||163.125.68.29$document
 ||163.125.68.31$document
 ||163.125.68.65$document
 ||163.125.68.7$document
@@ -192422,6 +192607,7 @@
 ||171.125.65.115$document
 ||171.125.65.193$document
 ||171.125.65.202$document
+||171.125.65.22$document
 ||171.125.66.6$document
 ||171.125.68.45$document
 ||171.125.7.181$document
@@ -192673,6 +192859,7 @@
 ||171.34.114.167$document
 ||171.34.114.179$document
 ||171.34.114.180$document
+||171.34.114.181$document
 ||171.34.114.215$document
 ||171.34.114.217$document
 ||171.34.114.227$document
@@ -192884,6 +193071,7 @@
 ||171.36.251.189$document
 ||171.36.251.66$document
 ||171.36.41.151$document
+||171.36.42.154$document
 ||171.36.42.159$document
 ||171.36.42.3$document
 ||171.36.42.39$document
@@ -193579,6 +193767,7 @@
 ||172.245.5.120$document
 ||172.245.5.122$document
 ||172.245.5.185$document
+||172.245.5.190$document
 ||172.245.52.102$document
 ||172.245.52.122$document
 ||172.245.52.160$document
@@ -196970,6 +197159,7 @@
 ||175.11.193.118$document
 ||175.11.193.122$document
 ||175.11.193.157$document
+||175.11.193.66$document
 ||175.11.193.71$document
 ||175.11.193.82$document
 ||175.11.194.130$document
@@ -197130,6 +197320,7 @@
 ||175.145.200.51$document
 ||175.146.121.210$document
 ||175.146.16.118$document
+||175.146.17.227$document
 ||175.146.18.195$document
 ||175.146.19.126$document
 ||175.146.20.229$document
@@ -200180,6 +200371,7 @@
 ||178.141.159.159$document
 ||178.141.16.64$document
 ||178.141.160.15$document
+||178.141.161.129$document
 ||178.141.162.124$document
 ||178.141.162.211$document
 ||178.141.162.8$document
@@ -200573,8 +200765,10 @@
 ||178.175.0.225$document
 ||178.175.0.226$document
 ||178.175.0.229$document
+||178.175.0.232$document
 ||178.175.0.234$document
 ||178.175.0.236$document
+||178.175.0.239$document
 ||178.175.0.241$document
 ||178.175.0.246$document
 ||178.175.0.249$document
@@ -200644,6 +200838,7 @@
 ||178.175.1.178$document
 ||178.175.1.179$document
 ||178.175.1.186$document
+||178.175.1.187$document
 ||178.175.1.188$document
 ||178.175.1.193$document
 ||178.175.1.194$document
@@ -200663,6 +200858,7 @@
 ||178.175.1.247$document
 ||178.175.1.25$document
 ||178.175.1.250$document
+||178.175.1.252$document
 ||178.175.1.255$document
 ||178.175.1.26$document
 ||178.175.1.28$document
@@ -200738,8 +200934,10 @@
 ||178.175.10.255$document
 ||178.175.10.26$document
 ||178.175.10.28$document
+||178.175.10.34$document
 ||178.175.10.37$document
 ||178.175.10.41$document
+||178.175.10.42$document
 ||178.175.10.44$document
 ||178.175.10.46$document
 ||178.175.10.50$document
@@ -200886,6 +201084,7 @@
 ||178.175.101.203$document
 ||178.175.101.204$document
 ||178.175.101.205$document
+||178.175.101.207$document
 ||178.175.101.208$document
 ||178.175.101.209$document
 ||178.175.101.21$document
@@ -200994,6 +201193,7 @@
 ||178.175.102.216$document
 ||178.175.102.22$document
 ||178.175.102.220$document
+||178.175.102.221$document
 ||178.175.102.223$document
 ||178.175.102.225$document
 ||178.175.102.227$document
@@ -201129,6 +201329,7 @@
 ||178.175.104.104$document
 ||178.175.104.106$document
 ||178.175.104.11$document
+||178.175.104.110$document
 ||178.175.104.112$document
 ||178.175.104.114$document
 ||178.175.104.116$document
@@ -201150,6 +201351,7 @@
 ||178.175.104.152$document
 ||178.175.104.153$document
 ||178.175.104.154$document
+||178.175.104.155$document
 ||178.175.104.158$document
 ||178.175.104.16$document
 ||178.175.104.161$document
@@ -201205,6 +201407,7 @@
 ||178.175.104.54$document
 ||178.175.104.59$document
 ||178.175.104.62$document
+||178.175.104.64$document
 ||178.175.104.66$document
 ||178.175.104.69$document
 ||178.175.104.80$document
@@ -201233,6 +201436,7 @@
 ||178.175.105.121$document
 ||178.175.105.122$document
 ||178.175.105.124$document
+||178.175.105.125$document
 ||178.175.105.130$document
 ||178.175.105.131$document
 ||178.175.105.143$document
@@ -201285,6 +201489,7 @@
 ||178.175.105.255$document
 ||178.175.105.26$document
 ||178.175.105.27$document
+||178.175.105.28$document
 ||178.175.105.29$document
 ||178.175.105.3$document
 ||178.175.105.30$document
@@ -201314,6 +201519,7 @@
 ||178.175.105.90$document
 ||178.175.105.91$document
 ||178.175.105.93$document
+||178.175.105.94$document
 ||178.175.105.96$document
 ||178.175.106.100$document
 ||178.175.106.102$document
@@ -201370,6 +201576,7 @@
 ||178.175.106.219$document
 ||178.175.106.22$document
 ||178.175.106.220$document
+||178.175.106.222$document
 ||178.175.106.224$document
 ||178.175.106.226$document
 ||178.175.106.228$document
@@ -201385,6 +201592,7 @@
 ||178.175.106.25$document
 ||178.175.106.251$document
 ||178.175.106.252$document
+||178.175.106.253$document
 ||178.175.106.27$document
 ||178.175.106.28$document
 ||178.175.106.31$document
@@ -201582,6 +201790,7 @@
 ||178.175.108.227$document
 ||178.175.108.229$document
 ||178.175.108.23$document
+||178.175.108.232$document
 ||178.175.108.237$document
 ||178.175.108.239$document
 ||178.175.108.24$document
@@ -201621,6 +201830,7 @@
 ||178.175.108.88$document
 ||178.175.108.90$document
 ||178.175.108.93$document
+||178.175.108.94$document
 ||178.175.108.97$document
 ||178.175.108.98$document
 ||178.175.108.99$document
@@ -201636,6 +201846,7 @@
 ||178.175.109.121$document
 ||178.175.109.123$document
 ||178.175.109.126$document
+||178.175.109.127$document
 ||178.175.109.132$document
 ||178.175.109.134$document
 ||178.175.109.137$document
@@ -201661,6 +201872,7 @@
 ||178.175.109.19$document
 ||178.175.109.190$document
 ||178.175.109.191$document
+||178.175.109.193$document
 ||178.175.109.195$document
 ||178.175.109.196$document
 ||178.175.109.198$document
@@ -201705,6 +201917,7 @@
 ||178.175.109.71$document
 ||178.175.109.75$document
 ||178.175.109.77$document
+||178.175.109.78$document
 ||178.175.109.82$document
 ||178.175.109.83$document
 ||178.175.109.86$document
@@ -202107,6 +202320,7 @@
 ||178.175.112.90$document
 ||178.175.112.97$document
 ||178.175.112.99$document
+||178.175.113.0$document
 ||178.175.113.100$document
 ||178.175.113.106$document
 ||178.175.113.112$document
@@ -202270,6 +202484,7 @@
 ||178.175.114.242$document
 ||178.175.114.244$document
 ||178.175.114.245$document
+||178.175.114.247$document
 ||178.175.114.250$document
 ||178.175.114.251$document
 ||178.175.114.254$document
@@ -202319,6 +202534,7 @@
 ||178.175.115.112$document
 ||178.175.115.113$document
 ||178.175.115.116$document
+||178.175.115.12$document
 ||178.175.115.125$document
 ||178.175.115.126$document
 ||178.175.115.127$document
@@ -202362,6 +202578,7 @@
 ||178.175.115.20$document
 ||178.175.115.202$document
 ||178.175.115.205$document
+||178.175.115.206$document
 ||178.175.115.207$document
 ||178.175.115.208$document
 ||178.175.115.209$document
@@ -202395,6 +202612,7 @@
 ||178.175.115.37$document
 ||178.175.115.39$document
 ||178.175.115.4$document
+||178.175.115.40$document
 ||178.175.115.43$document
 ||178.175.115.45$document
 ||178.175.115.46$document
@@ -202443,6 +202661,7 @@
 ||178.175.116.143$document
 ||178.175.116.145$document
 ||178.175.116.147$document
+||178.175.116.15$document
 ||178.175.116.150$document
 ||178.175.116.152$document
 ||178.175.116.154$document
@@ -202477,6 +202696,7 @@
 ||178.175.116.226$document
 ||178.175.116.228$document
 ||178.175.116.23$document
+||178.175.116.236$document
 ||178.175.116.237$document
 ||178.175.116.238$document
 ||178.175.116.24$document
@@ -202644,6 +202864,7 @@
 ||178.175.118.133$document
 ||178.175.118.137$document
 ||178.175.118.138$document
+||178.175.118.139$document
 ||178.175.118.141$document
 ||178.175.118.143$document
 ||178.175.118.144$document
@@ -202829,6 +203050,7 @@
 ||178.175.12.109$document
 ||178.175.12.11$document
 ||178.175.12.111$document
+||178.175.12.114$document
 ||178.175.12.118$document
 ||178.175.12.12$document
 ||178.175.12.123$document
@@ -202949,6 +203171,7 @@
 ||178.175.120.189$document
 ||178.175.120.191$document
 ||178.175.120.193$document
+||178.175.120.196$document
 ||178.175.120.197$document
 ||178.175.120.20$document
 ||178.175.120.203$document
@@ -203174,6 +203397,7 @@
 ||178.175.122.246$document
 ||178.175.122.252$document
 ||178.175.122.254$document
+||178.175.122.26$document
 ||178.175.122.27$document
 ||178.175.122.28$document
 ||178.175.122.3$document
@@ -203617,6 +203841,7 @@
 ||178.175.126.93$document
 ||178.175.126.95$document
 ||178.175.126.99$document
+||178.175.127.10$document
 ||178.175.127.100$document
 ||178.175.127.102$document
 ||178.175.127.106$document
@@ -203632,6 +203857,7 @@
 ||178.175.127.120$document
 ||178.175.127.122$document
 ||178.175.127.125$document
+||178.175.127.129$document
 ||178.175.127.13$document
 ||178.175.127.130$document
 ||178.175.127.133$document
@@ -203661,6 +203887,7 @@
 ||178.175.127.185$document
 ||178.175.127.19$document
 ||178.175.127.190$document
+||178.175.127.192$document
 ||178.175.127.195$document
 ||178.175.127.197$document
 ||178.175.127.198$document
@@ -203683,6 +203910,7 @@
 ||178.175.127.231$document
 ||178.175.127.236$document
 ||178.175.127.237$document
+||178.175.127.238$document
 ||178.175.127.24$document
 ||178.175.127.240$document
 ||178.175.127.242$document
@@ -203924,6 +204152,7 @@
 ||178.175.15.225$document
 ||178.175.15.228$document
 ||178.175.15.229$document
+||178.175.15.232$document
 ||178.175.15.233$document
 ||178.175.15.236$document
 ||178.175.15.238$document
@@ -203932,6 +204161,7 @@
 ||178.175.15.241$document
 ||178.175.15.244$document
 ||178.175.15.245$document
+||178.175.15.246$document
 ||178.175.15.248$document
 ||178.175.15.25$document
 ||178.175.15.250$document
@@ -203946,6 +204176,7 @@
 ||178.175.15.35$document
 ||178.175.15.37$document
 ||178.175.15.38$document
+||178.175.15.44$document
 ||178.175.15.45$document
 ||178.175.15.47$document
 ||178.175.15.48$document
@@ -203974,10 +204205,12 @@
 ||178.175.15.97$document
 ||178.175.15.99$document
 ||178.175.16.1$document
+||178.175.16.10$document
 ||178.175.16.108$document
 ||178.175.16.110$document
 ||178.175.16.112$document
 ||178.175.16.113$document
+||178.175.16.114$document
 ||178.175.16.115$document
 ||178.175.16.118$document
 ||178.175.16.12$document
@@ -204009,6 +204242,7 @@
 ||178.175.16.181$document
 ||178.175.16.186$document
 ||178.175.16.189$document
+||178.175.16.193$document
 ||178.175.16.195$document
 ||178.175.16.196$document
 ||178.175.16.205$document
@@ -204180,6 +204414,7 @@
 ||178.175.18.249$document
 ||178.175.18.250$document
 ||178.175.18.253$document
+||178.175.18.27$document
 ||178.175.18.32$document
 ||178.175.18.42$document
 ||178.175.18.45$document
@@ -204251,6 +204486,7 @@
 ||178.175.19.224$document
 ||178.175.19.225$document
 ||178.175.19.227$document
+||178.175.19.229$document
 ||178.175.19.232$document
 ||178.175.19.236$document
 ||178.175.19.237$document
@@ -204582,6 +204818,7 @@
 ||178.175.22.188$document
 ||178.175.22.194$document
 ||178.175.22.203$document
+||178.175.22.207$document
 ||178.175.22.209$document
 ||178.175.22.210$document
 ||178.175.22.211$document
@@ -204598,6 +204835,7 @@
 ||178.175.22.237$document
 ||178.175.22.241$document
 ||178.175.22.245$document
+||178.175.22.248$document
 ||178.175.22.249$document
 ||178.175.22.255$document
 ||178.175.22.32$document
@@ -204695,6 +204933,7 @@
 ||178.175.23.55$document
 ||178.175.23.56$document
 ||178.175.23.58$document
+||178.175.23.6$document
 ||178.175.23.61$document
 ||178.175.23.69$document
 ||178.175.23.71$document
@@ -204760,6 +204999,7 @@
 ||178.175.24.222$document
 ||178.175.24.223$document
 ||178.175.24.227$document
+||178.175.24.230$document
 ||178.175.24.232$document
 ||178.175.24.238$document
 ||178.175.24.239$document
@@ -204826,6 +205066,7 @@
 ||178.175.25.164$document
 ||178.175.25.166$document
 ||178.175.25.168$document
+||178.175.25.169$document
 ||178.175.25.172$document
 ||178.175.25.173$document
 ||178.175.25.177$document
@@ -204917,6 +205158,7 @@
 ||178.175.26.161$document
 ||178.175.26.162$document
 ||178.175.26.164$document
+||178.175.26.165$document
 ||178.175.26.168$document
 ||178.175.26.169$document
 ||178.175.26.17$document
@@ -204941,6 +205183,7 @@
 ||178.175.26.207$document
 ||178.175.26.211$document
 ||178.175.26.214$document
+||178.175.26.215$document
 ||178.175.26.217$document
 ||178.175.26.218$document
 ||178.175.26.219$document
@@ -204964,6 +205207,7 @@
 ||178.175.26.3$document
 ||178.175.26.31$document
 ||178.175.26.32$document
+||178.175.26.34$document
 ||178.175.26.36$document
 ||178.175.26.38$document
 ||178.175.26.4$document
@@ -205059,12 +205303,14 @@
 ||178.175.27.25$document
 ||178.175.27.252$document
 ||178.175.27.30$document
+||178.175.27.32$document
 ||178.175.27.36$document
 ||178.175.27.38$document
 ||178.175.27.39$document
 ||178.175.27.4$document
 ||178.175.27.41$document
 ||178.175.27.47$document
+||178.175.27.48$document
 ||178.175.27.49$document
 ||178.175.27.5$document
 ||178.175.27.53$document
@@ -205168,6 +205414,7 @@
 ||178.175.28.7$document
 ||178.175.28.72$document
 ||178.175.28.74$document
+||178.175.28.75$document
 ||178.175.28.79$document
 ||178.175.28.8$document
 ||178.175.28.81$document
@@ -205185,6 +205432,7 @@
 ||178.175.29.106$document
 ||178.175.29.111$document
 ||178.175.29.114$document
+||178.175.29.12$document
 ||178.175.29.127$document
 ||178.175.29.128$document
 ||178.175.29.130$document
@@ -205296,6 +205544,7 @@
 ||178.175.3.190$document
 ||178.175.3.192$document
 ||178.175.3.193$document
+||178.175.3.194$document
 ||178.175.3.196$document
 ||178.175.3.199$document
 ||178.175.3.201$document
@@ -205380,6 +205629,7 @@
 ||178.175.30.178$document
 ||178.175.30.18$document
 ||178.175.30.180$document
+||178.175.30.181$document
 ||178.175.30.183$document
 ||178.175.30.185$document
 ||178.175.30.186$document
@@ -205573,6 +205823,7 @@
 ||178.175.32.221$document
 ||178.175.32.223$document
 ||178.175.32.227$document
+||178.175.32.229$document
 ||178.175.32.23$document
 ||178.175.32.230$document
 ||178.175.32.233$document
@@ -205601,6 +205852,7 @@
 ||178.175.32.70$document
 ||178.175.32.72$document
 ||178.175.32.77$document
+||178.175.32.83$document
 ||178.175.32.85$document
 ||178.175.32.87$document
 ||178.175.32.89$document
@@ -205637,6 +205889,7 @@
 ||178.175.33.165$document
 ||178.175.33.167$document
 ||178.175.33.170$document
+||178.175.33.173$document
 ||178.175.33.174$document
 ||178.175.33.177$document
 ||178.175.33.178$document
@@ -205649,6 +205902,7 @@
 ||178.175.33.198$document
 ||178.175.33.2$document
 ||178.175.33.202$document
+||178.175.33.205$document
 ||178.175.33.209$document
 ||178.175.33.21$document
 ||178.175.33.210$document
@@ -205735,6 +205989,7 @@
 ||178.175.34.21$document
 ||178.175.34.216$document
 ||178.175.34.217$document
+||178.175.34.219$document
 ||178.175.34.22$document
 ||178.175.34.223$document
 ||178.175.34.224$document
@@ -205763,6 +206018,7 @@
 ||178.175.34.49$document
 ||178.175.34.5$document
 ||178.175.34.53$document
+||178.175.34.56$document
 ||178.175.34.58$document
 ||178.175.34.60$document
 ||178.175.34.61$document
@@ -205909,11 +206165,13 @@
 ||178.175.36.172$document
 ||178.175.36.173$document
 ||178.175.36.174$document
+||178.175.36.176$document
 ||178.175.36.177$document
 ||178.175.36.182$document
 ||178.175.36.184$document
 ||178.175.36.187$document
 ||178.175.36.189$document
+||178.175.36.19$document
 ||178.175.36.192$document
 ||178.175.36.194$document
 ||178.175.36.198$document
@@ -206122,6 +206380,7 @@
 ||178.175.38.196$document
 ||178.175.38.2$document
 ||178.175.38.20$document
+||178.175.38.200$document
 ||178.175.38.203$document
 ||178.175.38.204$document
 ||178.175.38.206$document
@@ -206198,6 +206457,7 @@
 ||178.175.39.17$document
 ||178.175.39.174$document
 ||178.175.39.175$document
+||178.175.39.176$document
 ||178.175.39.181$document
 ||178.175.39.183$document
 ||178.175.39.190$document
@@ -206292,6 +206552,7 @@
 ||178.175.4.215$document
 ||178.175.4.216$document
 ||178.175.4.218$document
+||178.175.4.219$document
 ||178.175.4.220$document
 ||178.175.4.222$document
 ||178.175.4.233$document
@@ -206362,6 +206623,7 @@
 ||178.175.40.138$document
 ||178.175.40.139$document
 ||178.175.40.14$document
+||178.175.40.145$document
 ||178.175.40.149$document
 ||178.175.40.15$document
 ||178.175.40.151$document
@@ -206497,6 +206759,7 @@
 ||178.175.41.56$document
 ||178.175.41.57$document
 ||178.175.41.6$document
+||178.175.41.60$document
 ||178.175.41.62$document
 ||178.175.41.65$document
 ||178.175.41.66$document
@@ -206615,6 +206878,7 @@
 ||178.175.43.154$document
 ||178.175.43.157$document
 ||178.175.43.158$document
+||178.175.43.16$document
 ||178.175.43.162$document
 ||178.175.43.163$document
 ||178.175.43.165$document
@@ -206656,6 +206920,7 @@
 ||178.175.43.30$document
 ||178.175.43.31$document
 ||178.175.43.33$document
+||178.175.43.34$document
 ||178.175.43.37$document
 ||178.175.43.38$document
 ||178.175.43.41$document
@@ -206686,6 +206951,7 @@
 ||178.175.43.91$document
 ||178.175.43.93$document
 ||178.175.43.94$document
+||178.175.44.0$document
 ||178.175.44.100$document
 ||178.175.44.101$document
 ||178.175.44.102$document
@@ -206785,6 +207051,7 @@
 ||178.175.44.89$document
 ||178.175.44.9$document
 ||178.175.44.90$document
+||178.175.44.95$document
 ||178.175.45.10$document
 ||178.175.45.102$document
 ||178.175.45.107$document
@@ -206897,6 +207164,7 @@
 ||178.175.46.110$document
 ||178.175.46.114$document
 ||178.175.46.116$document
+||178.175.46.119$document
 ||178.175.46.120$document
 ||178.175.46.124$document
 ||178.175.46.125$document
@@ -206909,6 +207177,7 @@
 ||178.175.46.145$document
 ||178.175.46.149$document
 ||178.175.46.150$document
+||178.175.46.151$document
 ||178.175.46.152$document
 ||178.175.46.154$document
 ||178.175.46.158$document
@@ -207161,6 +207430,7 @@
 ||178.175.48.65$document
 ||178.175.48.66$document
 ||178.175.48.71$document
+||178.175.48.76$document
 ||178.175.48.80$document
 ||178.175.48.82$document
 ||178.175.48.85$document
@@ -207187,6 +207457,7 @@
 ||178.175.49.123$document
 ||178.175.49.126$document
 ||178.175.49.127$document
+||178.175.49.129$document
 ||178.175.49.136$document
 ||178.175.49.137$document
 ||178.175.49.138$document
@@ -207200,6 +207471,7 @@
 ||178.175.49.18$document
 ||178.175.49.180$document
 ||178.175.49.185$document
+||178.175.49.188$document
 ||178.175.49.189$document
 ||178.175.49.19$document
 ||178.175.49.194$document
@@ -207387,6 +207659,7 @@
 ||178.175.50.233$document
 ||178.175.50.236$document
 ||178.175.50.237$document
+||178.175.50.239$document
 ||178.175.50.248$document
 ||178.175.50.249$document
 ||178.175.50.27$document
@@ -207414,6 +207687,7 @@
 ||178.175.50.84$document
 ||178.175.50.86$document
 ||178.175.50.87$document
+||178.175.50.9$document
 ||178.175.50.90$document
 ||178.175.50.92$document
 ||178.175.50.95$document
@@ -207652,6 +207926,7 @@
 ||178.175.53.224$document
 ||178.175.53.225$document
 ||178.175.53.227$document
+||178.175.53.228$document
 ||178.175.53.229$document
 ||178.175.53.231$document
 ||178.175.53.233$document
@@ -207813,6 +208088,7 @@
 ||178.175.55.165$document
 ||178.175.55.167$document
 ||178.175.55.169$document
+||178.175.55.170$document
 ||178.175.55.191$document
 ||178.175.55.192$document
 ||178.175.55.194$document
@@ -207860,6 +208136,7 @@
 ||178.175.55.70$document
 ||178.175.55.72$document
 ||178.175.55.77$document
+||178.175.55.85$document
 ||178.175.55.86$document
 ||178.175.55.88$document
 ||178.175.55.91$document
@@ -208127,6 +208404,7 @@
 ||178.175.58.35$document
 ||178.175.58.39$document
 ||178.175.58.40$document
+||178.175.58.42$document
 ||178.175.58.43$document
 ||178.175.58.48$document
 ||178.175.58.49$document
@@ -208383,6 +208661,7 @@
 ||178.175.60.32$document
 ||178.175.60.34$document
 ||178.175.60.36$document
+||178.175.60.37$document
 ||178.175.60.41$document
 ||178.175.60.42$document
 ||178.175.60.46$document
@@ -208463,6 +208742,7 @@
 ||178.175.61.36$document
 ||178.175.61.37$document
 ||178.175.61.40$document
+||178.175.61.42$document
 ||178.175.61.43$document
 ||178.175.61.45$document
 ||178.175.61.52$document
@@ -208520,6 +208800,7 @@
 ||178.175.62.209$document
 ||178.175.62.211$document
 ||178.175.62.213$document
+||178.175.62.216$document
 ||178.175.62.219$document
 ||178.175.62.220$document
 ||178.175.62.222$document
@@ -208545,11 +208826,13 @@
 ||178.175.62.39$document
 ||178.175.62.42$document
 ||178.175.62.43$document
+||178.175.62.44$document
 ||178.175.62.45$document
 ||178.175.62.46$document
 ||178.175.62.50$document
 ||178.175.62.51$document
 ||178.175.62.56$document
+||178.175.62.70$document
 ||178.175.62.72$document
 ||178.175.62.74$document
 ||178.175.62.76$document
@@ -209046,6 +209329,7 @@
 ||178.175.67.78$document
 ||178.175.67.8$document
 ||178.175.67.82$document
+||178.175.67.83$document
 ||178.175.67.84$document
 ||178.175.67.86$document
 ||178.175.67.88$document
@@ -209170,6 +209454,7 @@
 ||178.175.69.140$document
 ||178.175.69.141$document
 ||178.175.69.143$document
+||178.175.69.148$document
 ||178.175.69.149$document
 ||178.175.69.153$document
 ||178.175.69.154$document
@@ -209182,6 +209467,7 @@
 ||178.175.69.166$document
 ||178.175.69.169$document
 ||178.175.69.171$document
+||178.175.69.173$document
 ||178.175.69.174$document
 ||178.175.69.175$document
 ||178.175.69.182$document
@@ -209429,6 +209715,7 @@
 ||178.175.70.92$document
 ||178.175.70.93$document
 ||178.175.70.94$document
+||178.175.71.1$document
 ||178.175.71.102$document
 ||178.175.71.103$document
 ||178.175.71.104$document
@@ -209522,6 +209809,7 @@
 ||178.175.71.59$document
 ||178.175.71.60$document
 ||178.175.71.63$document
+||178.175.71.64$document
 ||178.175.71.65$document
 ||178.175.71.68$document
 ||178.175.71.69$document
@@ -209545,6 +209833,7 @@
 ||178.175.72.101$document
 ||178.175.72.102$document
 ||178.175.72.108$document
+||178.175.72.109$document
 ||178.175.72.110$document
 ||178.175.72.111$document
 ||178.175.72.113$document
@@ -209672,6 +209961,7 @@
 ||178.175.73.199$document
 ||178.175.73.2$document
 ||178.175.73.21$document
+||178.175.73.211$document
 ||178.175.73.214$document
 ||178.175.73.216$document
 ||178.175.73.219$document
@@ -209705,6 +209995,7 @@
 ||178.175.73.6$document
 ||178.175.73.68$document
 ||178.175.73.7$document
+||178.175.73.71$document
 ||178.175.73.72$document
 ||178.175.73.76$document
 ||178.175.73.86$document
@@ -209909,6 +210200,7 @@
 ||178.175.76.11$document
 ||178.175.76.113$document
 ||178.175.76.119$document
+||178.175.76.121$document
 ||178.175.76.124$document
 ||178.175.76.125$document
 ||178.175.76.129$document
@@ -210166,6 +210458,7 @@
 ||178.175.78.92$document
 ||178.175.78.93$document
 ||178.175.78.94$document
+||178.175.78.97$document
 ||178.175.79.101$document
 ||178.175.79.105$document
 ||178.175.79.106$document
@@ -210325,7 +210618,9 @@
 ||178.175.8.9$document
 ||178.175.8.93$document
 ||178.175.8.94$document
+||178.175.8.97$document
 ||178.175.80.10$document
+||178.175.80.100$document
 ||178.175.80.103$document
 ||178.175.80.11$document
 ||178.175.80.110$document
@@ -210404,6 +210699,7 @@
 ||178.175.80.37$document
 ||178.175.80.4$document
 ||178.175.80.40$document
+||178.175.80.41$document
 ||178.175.80.43$document
 ||178.175.80.44$document
 ||178.175.80.46$document
@@ -210496,6 +210792,7 @@
 ||178.175.81.251$document
 ||178.175.81.252$document
 ||178.175.81.30$document
+||178.175.81.32$document
 ||178.175.81.44$document
 ||178.175.81.45$document
 ||178.175.81.49$document
@@ -210510,6 +210807,7 @@
 ||178.175.81.7$document
 ||178.175.81.70$document
 ||178.175.81.79$document
+||178.175.81.8$document
 ||178.175.81.80$document
 ||178.175.81.82$document
 ||178.175.81.83$document
@@ -210530,6 +210828,7 @@
 ||178.175.82.115$document
 ||178.175.82.117$document
 ||178.175.82.12$document
+||178.175.82.120$document
 ||178.175.82.122$document
 ||178.175.82.123$document
 ||178.175.82.126$document
@@ -210883,6 +211182,7 @@
 ||178.175.85.171$document
 ||178.175.85.172$document
 ||178.175.85.183$document
+||178.175.85.184$document
 ||178.175.85.185$document
 ||178.175.85.190$document
 ||178.175.85.192$document
@@ -210899,6 +211199,7 @@
 ||178.175.85.227$document
 ||178.175.85.228$document
 ||178.175.85.229$document
+||178.175.85.23$document
 ||178.175.85.230$document
 ||178.175.85.242$document
 ||178.175.85.243$document
@@ -210938,6 +211239,7 @@
 ||178.175.85.79$document
 ||178.175.85.8$document
 ||178.175.85.80$document
+||178.175.85.81$document
 ||178.175.85.83$document
 ||178.175.85.87$document
 ||178.175.85.89$document
@@ -210965,9 +211267,11 @@
 ||178.175.86.146$document
 ||178.175.86.15$document
 ||178.175.86.157$document
+||178.175.86.159$document
 ||178.175.86.160$document
 ||178.175.86.164$document
 ||178.175.86.165$document
+||178.175.86.166$document
 ||178.175.86.167$document
 ||178.175.86.169$document
 ||178.175.86.174$document
@@ -211032,6 +211336,7 @@
 ||178.175.86.81$document
 ||178.175.86.86$document
 ||178.175.86.90$document
+||178.175.86.92$document
 ||178.175.86.93$document
 ||178.175.86.96$document
 ||178.175.86.97$document
@@ -211040,6 +211345,7 @@
 ||178.175.87.101$document
 ||178.175.87.106$document
 ||178.175.87.107$document
+||178.175.87.108$document
 ||178.175.87.110$document
 ||178.175.87.113$document
 ||178.175.87.115$document
@@ -211213,6 +211519,7 @@
 ||178.175.88.51$document
 ||178.175.88.52$document
 ||178.175.88.53$document
+||178.175.88.57$document
 ||178.175.88.60$document
 ||178.175.88.64$document
 ||178.175.88.78$document
@@ -211249,8 +211556,11 @@
 ||178.175.89.150$document
 ||178.175.89.151$document
 ||178.175.89.153$document
+||178.175.89.157$document
 ||178.175.89.159$document
+||178.175.89.160$document
 ||178.175.89.168$document
+||178.175.89.169$document
 ||178.175.89.171$document
 ||178.175.89.173$document
 ||178.175.89.177$document
@@ -211327,6 +211637,7 @@
 ||178.175.9.132$document
 ||178.175.9.135$document
 ||178.175.9.138$document
+||178.175.9.139$document
 ||178.175.9.140$document
 ||178.175.9.153$document
 ||178.175.9.155$document
@@ -211350,6 +211661,7 @@
 ||178.175.9.196$document
 ||178.175.9.200$document
 ||178.175.9.21$document
+||178.175.9.210$document
 ||178.175.9.215$document
 ||178.175.9.217$document
 ||178.175.9.220$document
@@ -211390,12 +211702,14 @@
 ||178.175.9.92$document
 ||178.175.9.95$document
 ||178.175.9.98$document
+||178.175.90.104$document
 ||178.175.90.109$document
 ||178.175.90.11$document
 ||178.175.90.114$document
 ||178.175.90.115$document
 ||178.175.90.116$document
 ||178.175.90.119$document
+||178.175.90.122$document
 ||178.175.90.124$document
 ||178.175.90.127$document
 ||178.175.90.128$document
@@ -211530,8 +211844,10 @@
 ||178.175.91.219$document
 ||178.175.91.22$document
 ||178.175.91.221$document
+||178.175.91.223$document
 ||178.175.91.224$document
 ||178.175.91.23$document
+||178.175.91.230$document
 ||178.175.91.232$document
 ||178.175.91.236$document
 ||178.175.91.237$document
@@ -211694,6 +212010,7 @@
 ||178.175.93.144$document
 ||178.175.93.145$document
 ||178.175.93.147$document
+||178.175.93.148$document
 ||178.175.93.149$document
 ||178.175.93.15$document
 ||178.175.93.150$document
@@ -211722,6 +212039,7 @@
 ||178.175.93.219$document
 ||178.175.93.220$document
 ||178.175.93.223$document
+||178.175.93.224$document
 ||178.175.93.225$document
 ||178.175.93.226$document
 ||178.175.93.23$document
@@ -211739,6 +212057,7 @@
 ||178.175.93.30$document
 ||178.175.93.31$document
 ||178.175.93.33$document
+||178.175.93.34$document
 ||178.175.93.36$document
 ||178.175.93.38$document
 ||178.175.93.4$document
@@ -211762,6 +212081,7 @@
 ||178.175.93.8$document
 ||178.175.93.82$document
 ||178.175.93.89$document
+||178.175.93.90$document
 ||178.175.93.93$document
 ||178.175.93.95$document
 ||178.175.93.96$document
@@ -211886,6 +212206,7 @@
 ||178.175.95.119$document
 ||178.175.95.122$document
 ||178.175.95.126$document
+||178.175.95.132$document
 ||178.175.95.135$document
 ||178.175.95.136$document
 ||178.175.95.137$document
@@ -211927,6 +212248,7 @@
 ||178.175.95.228$document
 ||178.175.95.230$document
 ||178.175.95.236$document
+||178.175.95.237$document
 ||178.175.95.238$document
 ||178.175.95.24$document
 ||178.175.95.241$document
@@ -212048,6 +212370,7 @@
 ||178.175.96.97$document
 ||178.175.96.98$document
 ||178.175.96.99$document
+||178.175.97.1$document
 ||178.175.97.100$document
 ||178.175.97.101$document
 ||178.175.97.103$document
@@ -212066,6 +212389,7 @@
 ||178.175.97.129$document
 ||178.175.97.130$document
 ||178.175.97.132$document
+||178.175.97.135$document
 ||178.175.97.139$document
 ||178.175.97.140$document
 ||178.175.97.141$document
@@ -212079,6 +212403,7 @@
 ||178.175.97.163$document
 ||178.175.97.167$document
 ||178.175.97.168$document
+||178.175.97.17$document
 ||178.175.97.173$document
 ||178.175.97.175$document
 ||178.175.97.177$document
@@ -212263,6 +212588,7 @@
 ||178.175.99.222$document
 ||178.175.99.223$document
 ||178.175.99.225$document
+||178.175.99.226$document
 ||178.175.99.230$document
 ||178.175.99.233$document
 ||178.175.99.237$document
@@ -214549,6 +214875,7 @@
 ||180.188.241.79$document
 ||180.188.241.86$document
 ||180.188.241.91$document
+||180.188.247.140$document
 ||180.188.252.185$document
 ||180.188.252.37$document
 ||180.188.253.153$document
@@ -218318,6 +218645,7 @@
 ||182.113.232.248$document
 ||182.113.232.81$document
 ||182.113.233.120$document
+||182.113.233.129$document
 ||182.113.233.13$document
 ||182.113.233.20$document
 ||182.113.233.3$document
@@ -221864,6 +222192,7 @@
 ||182.116.103.68$document
 ||182.116.103.76$document
 ||182.116.103.77$document
+||182.116.103.81$document
 ||182.116.103.85$document
 ||182.116.103.90$document
 ||182.116.103.91$document
@@ -222132,6 +222461,7 @@
 ||182.116.108.177$document
 ||182.116.108.178$document
 ||182.116.108.179$document
+||182.116.108.180$document
 ||182.116.108.182$document
 ||182.116.108.183$document
 ||182.116.108.185$document
@@ -222724,6 +223054,7 @@
 ||182.116.119.110$document
 ||182.116.119.111$document
 ||182.116.119.122$document
+||182.116.119.129$document
 ||182.116.119.134$document
 ||182.116.119.139$document
 ||182.116.119.140$document
@@ -224407,6 +224738,7 @@
 ||182.116.99.132$document
 ||182.116.99.141$document
 ||182.116.99.142$document
+||182.116.99.150$document
 ||182.116.99.153$document
 ||182.116.99.160$document
 ||182.116.99.17$document
@@ -225995,6 +226327,7 @@
 ||182.117.29.202$document
 ||182.117.29.212$document
 ||182.117.29.216$document
+||182.117.29.220$document
 ||182.117.29.227$document
 ||182.117.29.228$document
 ||182.117.29.229$document
@@ -229121,6 +229454,7 @@
 ||182.119.13.107$document
 ||182.119.13.109$document
 ||182.119.13.119$document
+||182.119.13.141$document
 ||182.119.13.148$document
 ||182.119.13.159$document
 ||182.119.13.160$document
@@ -230154,6 +230488,7 @@
 ||182.119.191.87$document
 ||182.119.191.92$document
 ||182.119.196.160$document
+||182.119.196.182$document
 ||182.119.196.190$document
 ||182.119.199.158$document
 ||182.119.199.85$document
@@ -230827,6 +231162,7 @@
 ||182.119.227.188$document
 ||182.119.227.194$document
 ||182.119.227.199$document
+||182.119.227.20$document
 ||182.119.227.207$document
 ||182.119.227.21$document
 ||182.119.227.245$document
@@ -231413,6 +231749,7 @@
 ||182.119.49.148$document
 ||182.119.49.162$document
 ||182.119.49.168$document
+||182.119.49.17$document
 ||182.119.49.185$document
 ||182.119.49.207$document
 ||182.119.49.220$document
@@ -231920,6 +232257,7 @@
 ||182.119.7.3$document
 ||182.119.7.41$document
 ||182.119.7.47$document
+||182.119.7.54$document
 ||182.119.7.73$document
 ||182.119.7.75$document
 ||182.119.7.88$document
@@ -233584,6 +233922,7 @@
 ||182.120.85.9$document
 ||182.120.86.203$document
 ||182.120.86.234$document
+||182.120.86.248$document
 ||182.120.86.46$document
 ||182.120.87.160$document
 ||182.120.87.227$document
@@ -234671,6 +235010,7 @@
 ||182.121.133.32$document
 ||182.121.133.37$document
 ||182.121.133.41$document
+||182.121.133.46$document
 ||182.121.133.50$document
 ||182.121.133.58$document
 ||182.121.133.72$document
@@ -235450,6 +235790,7 @@
 ||182.121.164.75$document
 ||182.121.164.85$document
 ||182.121.165.184$document
+||182.121.165.217$document
 ||182.121.166.105$document
 ||182.121.166.123$document
 ||182.121.166.85$document
@@ -235838,6 +236179,7 @@
 ||182.121.204.99$document
 ||182.121.205.100$document
 ||182.121.205.114$document
+||182.121.205.118$document
 ||182.121.205.124$document
 ||182.121.205.131$document
 ||182.121.205.137$document
@@ -237633,6 +237975,7 @@
 ||182.121.49.92$document
 ||182.121.49.94$document
 ||182.121.49.97$document
+||182.121.50.111$document
 ||182.121.50.112$document
 ||182.121.50.119$document
 ||182.121.50.121$document
@@ -238111,6 +238454,7 @@
 ||182.121.78.201$document
 ||182.121.78.220$document
 ||182.121.78.27$document
+||182.121.78.29$document
 ||182.121.78.3$document
 ||182.121.78.36$document
 ||182.121.78.42$document
@@ -239348,6 +239692,7 @@
 ||182.122.202.219$document
 ||182.122.202.229$document
 ||182.122.202.246$document
+||182.122.202.37$document
 ||182.122.202.59$document
 ||182.122.202.62$document
 ||182.122.202.82$document
@@ -239750,6 +240095,7 @@
 ||182.122.246.167$document
 ||182.122.246.170$document
 ||182.122.246.181$document
+||182.122.246.187$document
 ||182.122.246.190$document
 ||182.122.246.197$document
 ||182.122.246.199$document
@@ -239889,6 +240235,7 @@
 ||182.122.251.122$document
 ||182.122.251.124$document
 ||182.122.251.133$document
+||182.122.251.141$document
 ||182.122.251.143$document
 ||182.122.251.145$document
 ||182.122.251.150$document
@@ -240998,6 +241345,7 @@
 ||182.124.134.216$document
 ||182.124.134.235$document
 ||182.124.134.75$document
+||182.124.134.80$document
 ||182.124.134.9$document
 ||182.124.134.90$document
 ||182.124.134.96$document
@@ -241101,6 +241449,7 @@
 ||182.124.149.52$document
 ||182.124.149.67$document
 ||182.124.15.106$document
+||182.124.15.108$document
 ||182.124.15.109$document
 ||182.124.15.111$document
 ||182.124.15.13$document
@@ -241206,6 +241555,7 @@
 ||182.124.166.2$document
 ||182.124.166.228$document
 ||182.124.166.38$document
+||182.124.166.57$document
 ||182.124.166.6$document
 ||182.124.166.7$document
 ||182.124.167.11$document
@@ -243276,6 +243626,7 @@
 ||182.126.180.65$document
 ||182.126.180.72$document
 ||182.126.181.115$document
+||182.126.181.121$document
 ||182.126.181.149$document
 ||182.126.181.204$document
 ||182.126.181.214$document
@@ -243845,6 +244196,7 @@
 ||182.126.241.244$document
 ||182.126.241.30$document
 ||182.126.241.42$document
+||182.126.241.7$document
 ||182.126.241.71$document
 ||182.126.241.92$document
 ||182.126.242.10$document
@@ -243922,6 +244274,7 @@
 ||182.126.52.202$document
 ||182.126.52.214$document
 ||182.126.52.229$document
+||182.126.52.233$document
 ||182.126.52.252$document
 ||182.126.52.47$document
 ||182.126.52.70$document
@@ -244514,6 +244867,7 @@
 ||182.126.87.20$document
 ||182.126.87.201$document
 ||182.126.87.205$document
+||182.126.87.207$document
 ||182.126.87.209$document
 ||182.126.87.217$document
 ||182.126.87.22$document
@@ -248013,6 +248367,7 @@
 ||182.127.70.172$document
 ||182.127.70.185$document
 ||182.127.70.194$document
+||182.127.70.195$document
 ||182.127.70.213$document
 ||182.127.70.216$document
 ||182.127.70.218$document
@@ -249311,6 +249666,7 @@
 ||182.56.115.187$document
 ||182.56.115.191$document
 ||182.56.116.121$document
+||182.56.116.135$document
 ||182.56.116.178$document
 ||182.56.116.56$document
 ||182.56.117.14$document
@@ -251860,6 +252216,7 @@
 ||182.58.137.168$document
 ||182.58.137.66$document
 ||182.58.137.94$document
+||182.58.160.0$document
 ||182.58.160.122$document
 ||182.58.160.252$document
 ||182.58.160.89$document
@@ -254357,6 +254714,7 @@
 ||182.59.226.71$document
 ||182.59.227.10$document
 ||182.59.227.123$document
+||182.59.227.125$document
 ||182.59.227.130$document
 ||182.59.227.151$document
 ||182.59.227.175$document
@@ -257018,6 +257376,7 @@
 ||183.188.184.94$document
 ||183.188.186.52$document
 ||183.188.187.52$document
+||183.188.188.186$document
 ||183.188.194.119$document
 ||183.188.194.231$document
 ||183.188.195.189$document
@@ -257254,6 +257613,7 @@
 ||183.190.24.165$document
 ||183.190.26.125$document
 ||183.190.55.62$document
+||183.191.162.120$document
 ||183.191.204.241$document
 ||183.191.217.113$document
 ||183.191.65.166$document
@@ -257310,6 +257670,7 @@
 ||183.27.195.242$document
 ||183.28.50.158$document
 ||183.28.61.52$document
+||183.30.202.230$document
 ||183.30.202.247$document
 ||183.30.202.59$document
 ||183.30.202.67$document
@@ -257439,6 +257800,7 @@
 ||183.83.104.44$document
 ||183.83.104.68$document
 ||183.83.105.181$document
+||183.83.105.21$document
 ||183.83.105.228$document
 ||183.83.105.252$document
 ||183.83.105.253$document
@@ -258130,6 +258492,7 @@
 ||185.132.53.88$document
 ||185.132.53.9$document
 ||185.132.53.98$document
+||185.133.42.86$document
 ||185.134.122.209$document
 ||185.134.123.140$document
 ||185.134.21.75$document
@@ -258534,6 +258897,7 @@
 ||185.184.221.44$document
 ||185.184.54.15$document
 ||185.185.126.123$document
+||185.185.126.82$document
 ||185.186.142.100$document
 ||185.186.198.120$document
 ||185.186.244.186$document
@@ -262069,6 +262433,7 @@
 ||188.10.21.14$document
 ||188.10.231.246$document
 ||188.112.169.59$document
+||188.113.102.18$document
 ||188.113.107.75$document
 ||188.113.116.133$document
 ||188.113.81.17$document
@@ -262222,6 +262587,7 @@
 ||188.166.179.28$document
 ||188.166.18.52$document
 ||188.166.19.196$document
+||188.166.19.45$document
 ||188.166.207.182$document
 ||188.166.21.10$document
 ||188.166.21.86$document
@@ -264954,6 +265320,7 @@
 ||192.119.106.235$document
 ||192.119.106.9$document
 ||192.119.107.81$document
+||192.119.110.168$document
 ||192.119.110.222$document
 ||192.119.110.44$document
 ||192.119.110.49$document
@@ -265736,6 +266103,7 @@
 ||194.15.36.193$document
 ||194.15.36.194$document
 ||194.15.36.196$document
+||194.15.36.202$document
 ||194.15.36.204$document
 ||194.15.36.207$document
 ||194.15.36.208$document
@@ -265993,6 +266361,7 @@
 ||194.87.138.86$document
 ||194.87.138.88$document
 ||194.87.138.97$document
+||194.87.139.10$document
 ||194.87.139.108$document
 ||194.87.139.110$document
 ||194.87.139.113$document
@@ -268043,6 +268412,7 @@
 ||2.238.18.160$document
 ||2.238.195.223$document
 ||2.248.2.174$document
+||2.249.161.188$document
 ||2.249.161.196$document
 ||2.249.178.219$document
 ||2.25.93.113$document
@@ -268571,6 +268941,7 @@
 ||200.75.107.84$document
 ||200.79.152.109$document
 ||200.79.153.166$document
+||200.8.206.151$document
 ||200.8.206.224$document
 ||200.8.23.209$document
 ||200.8.240.149$document
@@ -268751,6 +269122,7 @@
 ||201.207.235.219$document
 ||201.208.129.111$document
 ||201.208.137.75$document
+||201.208.139.84$document
 ||201.208.153.220$document
 ||201.208.155.206$document
 ||201.208.209.28$document
@@ -269596,6 +269968,7 @@
 ||202.168.153.228$document
 ||202.169.234.10$document
 ||202.169.234.19$document
+||202.169.234.22$document
 ||202.169.234.33$document
 ||202.169.234.36$document
 ||202.169.234.37$document
@@ -270637,6 +271010,7 @@
 ||203.114.116.37$document
 ||203.115.102.243$document
 ||203.115.73.100$document
+||203.115.73.105$document
 ||203.115.73.107$document
 ||203.115.73.11$document
 ||203.115.73.111$document
@@ -270732,6 +271106,7 @@
 ||203.115.85.93$document
 ||203.115.91.129$document
 ||203.115.91.141$document
+||203.115.91.232$document
 ||203.115.91.47$document
 ||203.115.91.66$document
 ||203.123.205.195$document
@@ -273657,6 +274032,7 @@
 ||206.221.176.164$document
 ||206.248.136.50$document
 ||206.248.136.6$document
+||206.248.137.132$document
 ||206.248.139.132$document
 ||206.248.139.15$document
 ||206.248.219.15$document
@@ -273837,6 +274213,7 @@
 ||209.133.223.130$document
 ||209.14.30.121$document
 ||209.14.30.135$document
+||209.14.30.136$document
 ||209.14.30.159$document
 ||209.14.30.161$document
 ||209.14.30.166$document
@@ -273845,6 +274222,7 @@
 ||209.14.30.205$document
 ||209.14.30.30$document
 ||209.14.30.54$document
+||209.14.31.125$document
 ||209.14.31.162$document
 ||209.14.31.163$document
 ||209.14.31.175$document
@@ -274109,6 +274487,7 @@
 ||210.101.157.10$document
 ||210.101.157.199$document
 ||210.101.70.131$document
+||210.102.196.200$document
 ||210.102.58.78$document
 ||210.104.187.179$document
 ||210.104.210.133$document
@@ -276166,6 +276545,7 @@
 ||218.0.88.48$document
 ||218.101.202.186$document
 ||218.101.230.26$document
+||218.103.180.199$document
 ||218.104.175.100$document
 ||218.104.175.103$document
 ||218.104.175.109$document
@@ -278820,6 +279200,7 @@
 ||219.154.140.99$document
 ||219.154.141.138$document
 ||219.154.141.196$document
+||219.154.141.222$document
 ||219.154.141.227$document
 ||219.154.141.242$document
 ||219.154.141.53$document
@@ -279662,6 +280043,7 @@
 ||219.155.12.205$document
 ||219.155.12.215$document
 ||219.155.12.220$document
+||219.155.12.221$document
 ||219.155.12.40$document
 ||219.155.12.51$document
 ||219.155.12.55$document
@@ -279892,6 +280274,7 @@
 ||219.155.170.165$document
 ||219.155.170.185$document
 ||219.155.170.215$document
+||219.155.170.22$document
 ||219.155.170.228$document
 ||219.155.170.244$document
 ||219.155.170.250$document
@@ -280087,6 +280470,7 @@
 ||219.155.207.8$document
 ||219.155.207.96$document
 ||219.155.208.145$document
+||219.155.208.188$document
 ||219.155.208.19$document
 ||219.155.208.211$document
 ||219.155.208.212$document
@@ -280348,6 +280732,7 @@
 ||219.155.225.90$document
 ||219.155.226.130$document
 ||219.155.226.143$document
+||219.155.226.146$document
 ||219.155.226.154$document
 ||219.155.226.188$document
 ||219.155.226.194$document
@@ -280544,6 +280929,7 @@
 ||219.155.240.86$document
 ||219.155.241.11$document
 ||219.155.241.113$document
+||219.155.241.135$document
 ||219.155.241.137$document
 ||219.155.241.144$document
 ||219.155.241.155$document
@@ -281083,6 +281469,7 @@
 ||219.155.37.72$document
 ||219.155.37.87$document
 ||219.155.37.90$document
+||219.155.37.97$document
 ||219.155.38.10$document
 ||219.155.38.112$document
 ||219.155.38.113$document
@@ -281846,6 +282233,7 @@
 ||219.156.103.192$document
 ||219.156.103.225$document
 ||219.156.103.236$document
+||219.156.103.248$document
 ||219.156.103.43$document
 ||219.156.103.46$document
 ||219.156.103.84$document
@@ -282657,6 +283045,7 @@
 ||219.156.23.241$document
 ||219.156.23.245$document
 ||219.156.23.26$document
+||219.156.23.29$document
 ||219.156.23.3$document
 ||219.156.23.41$document
 ||219.156.23.50$document
@@ -282800,6 +283189,7 @@
 ||219.156.48.185$document
 ||219.156.48.50$document
 ||219.156.49.142$document
+||219.156.49.170$document
 ||219.156.49.172$document
 ||219.156.49.250$document
 ||219.156.5.233$document
@@ -282876,6 +283266,7 @@
 ||219.156.60.203$document
 ||219.156.60.208$document
 ||219.156.60.211$document
+||219.156.60.224$document
 ||219.156.60.250$document
 ||219.156.60.27$document
 ||219.156.60.39$document
@@ -283193,6 +283584,7 @@
 ||219.156.9.247$document
 ||219.156.9.254$document
 ||219.156.9.27$document
+||219.156.9.32$document
 ||219.156.9.34$document
 ||219.156.9.42$document
 ||219.156.9.48$document
@@ -284791,6 +285183,7 @@
 ||219.157.220.159$document
 ||219.157.220.163$document
 ||219.157.220.164$document
+||219.157.220.170$document
 ||219.157.220.171$document
 ||219.157.220.177$document
 ||219.157.220.18$document
@@ -284876,6 +285269,7 @@
 ||219.157.223.24$document
 ||219.157.223.241$document
 ||219.157.223.243$document
+||219.157.223.245$document
 ||219.157.223.29$document
 ||219.157.223.4$document
 ||219.157.223.42$document
@@ -284927,6 +285321,7 @@
 ||219.157.226.198$document
 ||219.157.226.4$document
 ||219.157.226.47$document
+||219.157.226.79$document
 ||219.157.227.124$document
 ||219.157.227.170$document
 ||219.157.227.176$document
@@ -285299,6 +285694,7 @@
 ||219.157.244.233$document
 ||219.157.244.236$document
 ||219.157.244.254$document
+||219.157.244.33$document
 ||219.157.244.39$document
 ||219.157.244.43$document
 ||219.157.244.61$document
@@ -286237,6 +286633,7 @@
 ||219.157.50.203$document
 ||219.157.50.208$document
 ||219.157.50.21$document
+||219.157.50.211$document
 ||219.157.50.228$document
 ||219.157.50.233$document
 ||219.157.50.238$document
@@ -286396,6 +286793,7 @@
 ||219.157.54.150$document
 ||219.157.54.155$document
 ||219.157.54.157$document
+||219.157.54.158$document
 ||219.157.54.159$document
 ||219.157.54.177$document
 ||219.157.54.19$document
@@ -286503,6 +286901,7 @@
 ||219.157.56.251$document
 ||219.157.56.254$document
 ||219.157.56.35$document
+||219.157.56.46$document
 ||219.157.56.47$document
 ||219.157.56.50$document
 ||219.157.56.54$document
@@ -289291,6 +289690,7 @@
 ||221.14.56.67$document
 ||221.14.57.62$document
 ||221.14.58.27$document
+||221.14.58.5$document
 ||221.14.58.84$document
 ||221.14.59.255$document
 ||221.14.60.146$document
@@ -289904,6 +290304,7 @@
 ||221.15.147.210$document
 ||221.15.147.214$document
 ||221.15.147.217$document
+||221.15.147.220$document
 ||221.15.147.225$document
 ||221.15.147.227$document
 ||221.15.147.234$document
@@ -291716,6 +292117,7 @@
 ||221.15.236.92$document
 ||221.15.236.93$document
 ||221.15.236.98$document
+||221.15.237.107$document
 ||221.15.237.109$document
 ||221.15.237.11$document
 ||221.15.237.112$document
@@ -292440,6 +292842,7 @@
 ||221.15.7.198$document
 ||221.15.7.199$document
 ||221.15.7.200$document
+||221.15.7.202$document
 ||221.15.7.205$document
 ||221.15.7.207$document
 ||221.15.7.21$document
@@ -293432,6 +293835,7 @@
 ||221.215.170.109$document
 ||221.215.171.80$document
 ||221.215.172.192$document
+||221.215.172.207$document
 ||221.215.172.217$document
 ||221.215.174.4$document
 ||221.215.174.59$document
@@ -294120,6 +294524,7 @@
 ||221.5.30.10$document
 ||221.5.30.100$document
 ||221.5.30.103$document
+||221.5.30.118$document
 ||221.5.30.14$document
 ||221.5.30.140$document
 ||221.5.30.153$document
@@ -297667,6 +298072,7 @@
 ||222.137.22.42$document
 ||222.137.22.59$document
 ||222.137.22.66$document
+||222.137.22.79$document
 ||222.137.220.10$document
 ||222.137.220.123$document
 ||222.137.220.125$document
@@ -297695,6 +298101,7 @@
 ||222.137.220.60$document
 ||222.137.220.63$document
 ||222.137.220.82$document
+||222.137.220.94$document
 ||222.137.220.99$document
 ||222.137.221.101$document
 ||222.137.221.107$document
@@ -298306,6 +298713,7 @@
 ||222.137.49.170$document
 ||222.137.49.29$document
 ||222.137.49.30$document
+||222.137.49.4$document
 ||222.137.49.75$document
 ||222.137.49.99$document
 ||222.137.5.102$document
@@ -298705,6 +299113,7 @@
 ||222.137.83.230$document
 ||222.137.83.39$document
 ||222.137.83.5$document
+||222.137.83.53$document
 ||222.137.84.2$document
 ||222.137.84.240$document
 ||222.137.84.33$document
@@ -300247,6 +300656,7 @@
 ||222.138.189.219$document
 ||222.138.189.223$document
 ||222.138.189.243$document
+||222.138.189.88$document
 ||222.138.19.110$document
 ||222.138.19.135$document
 ||222.138.19.144$document
@@ -300573,6 +300983,7 @@
 ||222.138.215.134$document
 ||222.138.215.146$document
 ||222.138.215.16$document
+||222.138.215.161$document
 ||222.138.215.183$document
 ||222.138.215.215$document
 ||222.138.215.222$document
@@ -300683,6 +301094,7 @@
 ||222.138.224.148$document
 ||222.138.224.15$document
 ||222.138.224.163$document
+||222.138.224.164$document
 ||222.138.224.173$document
 ||222.138.224.2$document
 ||222.138.224.228$document
@@ -301149,6 +301561,7 @@
 ||222.138.49.58$document
 ||222.138.49.67$document
 ||222.138.49.79$document
+||222.138.49.93$document
 ||222.138.50.106$document
 ||222.138.50.237$document
 ||222.138.50.32$document
@@ -301571,6 +301984,7 @@
 ||222.139.16.143$document
 ||222.139.16.173$document
 ||222.139.16.195$document
+||222.139.16.229$document
 ||222.139.16.236$document
 ||222.139.16.32$document
 ||222.139.16.84$document
@@ -302339,6 +302753,7 @@
 ||222.140.111.116$document
 ||222.140.111.192$document
 ||222.140.111.205$document
+||222.140.112.150$document
 ||222.140.112.171$document
 ||222.140.112.224$document
 ||222.140.113.197$document
@@ -304012,6 +304427,7 @@
 ||222.141.164.67$document
 ||222.141.164.88$document
 ||222.141.165.116$document
+||222.141.165.180$document
 ||222.141.165.189$document
 ||222.141.165.2$document
 ||222.141.165.214$document
@@ -304327,6 +304743,7 @@
 ||222.141.244.110$document
 ||222.141.244.147$document
 ||222.141.244.20$document
+||222.141.244.231$document
 ||222.141.244.80$document
 ||222.141.245.10$document
 ||222.141.245.134$document
@@ -304991,6 +305408,7 @@
 ||222.141.73.184$document
 ||222.141.73.219$document
 ||222.141.73.245$document
+||222.141.73.249$document
 ||222.141.73.38$document
 ||222.141.73.55$document
 ||222.141.73.61$document
@@ -306501,6 +306919,7 @@
 ||222.214.53.254$document
 ||222.214.53.62$document
 ||222.214.54.162$document
+||222.214.54.208$document
 ||222.214.54.238$document
 ||222.214.55.138$document
 ||222.214.55.18$document
@@ -308154,6 +308573,7 @@
 ||27.12.232.176$document
 ||27.12.233.205$document
 ||27.12.233.96$document
+||27.12.234.4$document
 ||27.12.235.176$document
 ||27.12.236.127$document
 ||27.12.238.202$document
@@ -312272,6 +312692,7 @@
 ||27.208.242.223$document
 ||27.208.244.172$document
 ||27.208.247.130$document
+||27.208.25.59$document
 ||27.208.30.1$document
 ||27.208.30.87$document
 ||27.208.31.92$document
@@ -312559,6 +312980,7 @@
 ||27.210.146.49$document
 ||27.210.146.54$document
 ||27.210.146.6$document
+||27.210.146.61$document
 ||27.210.146.89$document
 ||27.210.147.172$document
 ||27.210.147.228$document
@@ -313300,6 +313722,7 @@
 ||27.213.145.138$document
 ||27.213.145.143$document
 ||27.213.145.161$document
+||27.213.145.221$document
 ||27.213.146.231$document
 ||27.213.147.121$document
 ||27.213.148.104$document
@@ -313346,6 +313769,7 @@
 ||27.213.166.136$document
 ||27.213.166.174$document
 ||27.213.167.154$document
+||27.213.167.175$document
 ||27.213.167.180$document
 ||27.213.167.210$document
 ||27.213.168.16$document
@@ -314310,6 +314734,7 @@
 ||27.216.130.132$document
 ||27.216.130.185$document
 ||27.216.131.63$document
+||27.216.131.66$document
 ||27.216.132.194$document
 ||27.216.132.221$document
 ||27.216.132.237$document
@@ -318204,6 +318629,7 @@
 ||27.41.146.252$document
 ||27.41.146.27$document
 ||27.41.146.3$document
+||27.41.146.59$document
 ||27.41.146.63$document
 ||27.41.146.73$document
 ||27.41.146.80$document
@@ -318324,6 +318750,7 @@
 ||27.41.153.41$document
 ||27.41.153.54$document
 ||27.41.153.65$document
+||27.41.153.66$document
 ||27.41.153.89$document
 ||27.41.153.91$document
 ||27.41.154.102$document
@@ -319450,6 +319877,7 @@
 ||27.43.151.68$document
 ||27.43.151.86$document
 ||27.43.66.61$document
+||27.43.82.210$document
 ||27.43.92.65$document
 ||27.44.100.126$document
 ||27.44.100.242$document
@@ -319732,6 +320160,7 @@
 ||27.46.47.61$document
 ||27.46.47.69$document
 ||27.46.47.72$document
+||27.46.47.74$document
 ||27.46.47.75$document
 ||27.46.47.76$document
 ||27.46.47.77$document
@@ -319821,6 +320250,7 @@
 ||27.5.16.236$document
 ||27.5.16.237$document
 ||27.5.16.242$document
+||27.5.16.243$document
 ||27.5.16.244$document
 ||27.5.16.245$document
 ||27.5.16.246$document
@@ -320298,6 +320728,7 @@
 ||27.5.21.38$document
 ||27.5.21.4$document
 ||27.5.21.5$document
+||27.5.21.53$document
 ||27.5.21.56$document
 ||27.5.21.57$document
 ||27.5.21.63$document
@@ -320722,6 +321153,7 @@
 ||27.5.26.32$document
 ||27.5.26.33$document
 ||27.5.26.37$document
+||27.5.26.4$document
 ||27.5.26.43$document
 ||27.5.26.44$document
 ||27.5.26.47$document
@@ -321034,6 +321466,7 @@
 ||27.5.30.197$document
 ||27.5.30.20$document
 ||27.5.30.203$document
+||27.5.30.207$document
 ||27.5.30.210$document
 ||27.5.30.212$document
 ||27.5.30.215$document
@@ -321340,6 +321773,7 @@
 ||27.5.34.169$document
 ||27.5.34.171$document
 ||27.5.34.176$document
+||27.5.34.177$document
 ||27.5.34.182$document
 ||27.5.34.183$document
 ||27.5.34.186$document
@@ -321404,6 +321838,7 @@
 ||27.5.35.117$document
 ||27.5.35.12$document
 ||27.5.35.125$document
+||27.5.35.127$document
 ||27.5.35.130$document
 ||27.5.35.131$document
 ||27.5.35.132$document
@@ -342166,6 +342601,7 @@
 ||31.163.189.192$document
 ||31.163.189.220$document
 ||31.163.189.254$document
+||31.163.191.11$document
 ||31.163.57.231$document
 ||31.163.65.250$document
 ||31.164.47.38$document
@@ -342392,6 +342828,7 @@
 ||31.6.70.84$document
 ||31.6.98.137$document
 ||31.62.130.208$document
+||31.62.255.3$document
 ||31.62.91.175$document
 ||31.63.183.192$document
 ||31.63.189.195$document
@@ -344439,6 +344876,7 @@
 ||37.187.73.85$document
 ||37.189.109.110$document
 ||37.19.48.73$document
+||37.19.49.202$document
 ||37.19.49.206$document
 ||37.19.51.174$document
 ||37.19.52.247$document
@@ -346380,6 +346818,7 @@
 ||39.73.44.149$document
 ||39.73.44.155$document
 ||39.73.44.165$document
+||39.73.44.17$document
 ||39.73.44.176$document
 ||39.73.44.185$document
 ||39.73.44.198$document
@@ -349052,6 +349491,7 @@
 ||39.86.150.176$document
 ||39.86.150.37$document
 ||39.86.151.106$document
+||39.86.151.49$document
 ||39.86.151.96$document
 ||39.86.152.128$document
 ||39.86.152.130$document
@@ -349815,6 +350255,7 @@
 ||39.87.84.239$document
 ||39.87.87.117$document
 ||39.87.87.99$document
+||39.87.90.210$document
 ||39.87.93.109$document
 ||39.87.93.54$document
 ||39.87.98.115$document
@@ -352199,6 +352640,7 @@
 ||42.224.122.3$document
 ||42.224.122.30$document
 ||42.224.122.37$document
+||42.224.122.39$document
 ||42.224.122.41$document
 ||42.224.122.43$document
 ||42.224.122.52$document
@@ -353521,6 +353963,7 @@
 ||42.224.176.199$document
 ||42.224.176.202$document
 ||42.224.176.205$document
+||42.224.176.214$document
 ||42.224.176.216$document
 ||42.224.176.217$document
 ||42.224.176.221$document
@@ -354858,6 +355301,7 @@
 ||42.224.249.57$document
 ||42.224.249.73$document
 ||42.224.249.76$document
+||42.224.249.8$document
 ||42.224.249.87$document
 ||42.224.249.88$document
 ||42.224.249.92$document
@@ -357019,6 +357463,7 @@
 ||42.224.90.133$document
 ||42.224.90.151$document
 ||42.224.90.158$document
+||42.224.90.17$document
 ||42.224.90.196$document
 ||42.224.90.240$document
 ||42.224.90.28$document
@@ -358220,6 +358665,7 @@
 ||42.225.33.162$document
 ||42.225.33.199$document
 ||42.225.33.20$document
+||42.225.33.31$document
 ||42.225.34.174$document
 ||42.225.34.18$document
 ||42.225.34.184$document
@@ -358793,6 +359239,7 @@
 ||42.226.89.147$document
 ||42.226.89.157$document
 ||42.226.89.235$document
+||42.226.89.25$document
 ||42.226.89.82$document
 ||42.226.90.0$document
 ||42.226.90.102$document
@@ -359334,6 +359781,7 @@
 ||42.227.176.230$document
 ||42.227.176.239$document
 ||42.227.176.90$document
+||42.227.177.142$document
 ||42.227.177.250$document
 ||42.227.177.84$document
 ||42.227.178.10$document
@@ -361928,6 +362376,7 @@
 ||42.228.75.59$document
 ||42.228.75.63$document
 ||42.228.75.65$document
+||42.228.75.7$document
 ||42.228.75.74$document
 ||42.228.75.79$document
 ||42.228.75.80$document
@@ -363838,6 +364287,7 @@
 ||42.230.173.51$document
 ||42.230.173.66$document
 ||42.230.174.117$document
+||42.230.174.125$document
 ||42.230.174.161$document
 ||42.230.174.171$document
 ||42.230.174.216$document
@@ -364564,6 +365014,7 @@
 ||42.230.219.225$document
 ||42.230.219.231$document
 ||42.230.219.239$document
+||42.230.219.243$document
 ||42.230.219.254$document
 ||42.230.219.37$document
 ||42.230.219.4$document
@@ -367039,6 +367490,7 @@
 ||42.231.223.17$document
 ||42.231.223.191$document
 ||42.231.223.209$document
+||42.231.223.215$document
 ||42.231.223.59$document
 ||42.231.223.95$document
 ||42.231.224.122$document
@@ -367192,6 +367644,7 @@
 ||42.231.244.187$document
 ||42.231.244.189$document
 ||42.231.244.222$document
+||42.231.244.80$document
 ||42.231.244.83$document
 ||42.231.245.111$document
 ||42.231.245.142$document
@@ -367610,6 +368063,7 @@
 ||42.231.95.136$document
 ||42.231.95.154$document
 ||42.231.95.17$document
+||42.231.95.195$document
 ||42.231.95.210$document
 ||42.231.95.230$document
 ||42.231.95.99$document
@@ -369509,6 +369963,7 @@
 ||42.233.90.116$document
 ||42.233.90.138$document
 ||42.233.90.167$document
+||42.233.90.183$document
 ||42.233.90.187$document
 ||42.233.90.52$document
 ||42.233.91.0$document
@@ -369629,6 +370084,7 @@
 ||42.234.105.253$document
 ||42.234.105.3$document
 ||42.234.105.33$document
+||42.234.105.6$document
 ||42.234.105.68$document
 ||42.234.105.93$document
 ||42.234.106.110$document
@@ -369923,6 +370379,7 @@
 ||42.234.162.214$document
 ||42.234.162.4$document
 ||42.234.162.42$document
+||42.234.162.44$document
 ||42.234.162.76$document
 ||42.234.163.119$document
 ||42.234.163.16$document
@@ -374477,6 +374934,7 @@
 ||42.235.90.245$document
 ||42.235.90.29$document
 ||42.235.90.3$document
+||42.235.90.32$document
 ||42.235.90.46$document
 ||42.235.90.50$document
 ||42.235.90.53$document
@@ -375640,6 +376098,7 @@
 ||42.237.44.45$document
 ||42.237.44.47$document
 ||42.237.45.107$document
+||42.237.45.223$document
 ||42.237.45.25$document
 ||42.237.45.90$document
 ||42.237.46.104$document
@@ -375956,6 +376415,7 @@
 ||42.238.109.115$document
 ||42.238.11.212$document
 ||42.238.111.149$document
+||42.238.112.100$document
 ||42.238.112.125$document
 ||42.238.112.132$document
 ||42.238.112.32$document
@@ -376223,6 +376683,7 @@
 ||42.238.175.124$document
 ||42.238.175.14$document
 ||42.238.175.229$document
+||42.238.175.32$document
 ||42.238.175.35$document
 ||42.238.175.61$document
 ||42.238.175.96$document
@@ -379108,6 +379569,7 @@
 ||45.144.225.118$document
 ||45.144.225.142$document
 ||45.144.225.151$document
+||45.144.225.213$document
 ||45.144.225.65$document
 ||45.144.225.96$document
 ||45.144.29.133$document
@@ -385518,6 +385980,7 @@
 ||54.179.174.132$document
 ||54.179.179.37$document
 ||54.179.9.186$document
+||54.180.158.181$document
 ||54.186.24.183$document
 ||54.187.210.136$document
 ||54.197.30.41$document
@@ -385694,6 +386157,7 @@
 ||58.19.163.45$document
 ||58.19.163.92$document
 ||58.19.249.100$document
+||58.19.249.50$document
 ||58.19.250.18$document
 ||58.19.250.190$document
 ||58.19.251.10$document
@@ -386526,6 +386990,7 @@
 ||58.248.143.158$document
 ||58.248.143.164$document
 ||58.248.143.168$document
+||58.248.143.173$document
 ||58.248.143.174$document
 ||58.248.143.176$document
 ||58.248.143.18$document
@@ -386554,6 +387019,7 @@
 ||58.248.144.180$document
 ||58.248.144.186$document
 ||58.248.144.190$document
+||58.248.144.21$document
 ||58.248.144.216$document
 ||58.248.144.217$document
 ||58.248.144.39$document
@@ -386561,6 +387027,7 @@
 ||58.248.144.89$document
 ||58.248.144.94$document
 ||58.248.144.95$document
+||58.248.144.97$document
 ||58.248.145.113$document
 ||58.248.145.129$document
 ||58.248.145.13$document
@@ -386687,6 +387154,7 @@
 ||58.248.149.186$document
 ||58.248.149.207$document
 ||58.248.149.214$document
+||58.248.149.226$document
 ||58.248.149.230$document
 ||58.248.149.231$document
 ||58.248.149.240$document
@@ -387529,6 +387997,7 @@
 ||58.249.73.74$document
 ||58.249.73.90$document
 ||58.249.74.103$document
+||58.249.74.104$document
 ||58.249.74.11$document
 ||58.249.74.118$document
 ||58.249.74.120$document
@@ -387555,6 +388024,7 @@
 ||58.249.74.9$document
 ||58.249.75.101$document
 ||58.249.75.109$document
+||58.249.75.112$document
 ||58.249.75.125$document
 ||58.249.75.126$document
 ||58.249.75.13$document
@@ -387638,6 +388108,7 @@
 ||58.249.78.116$document
 ||58.249.78.128$document
 ||58.249.78.132$document
+||58.249.78.155$document
 ||58.249.78.168$document
 ||58.249.78.174$document
 ||58.249.78.176$document
@@ -387739,6 +388210,7 @@
 ||58.249.80.246$document
 ||58.249.80.37$document
 ||58.249.80.38$document
+||58.249.80.46$document
 ||58.249.80.56$document
 ||58.249.80.61$document
 ||58.249.80.63$document
@@ -387953,6 +388425,7 @@
 ||58.249.87.211$document
 ||58.249.87.222$document
 ||58.249.87.247$document
+||58.249.87.248$document
 ||58.249.87.250$document
 ||58.249.87.253$document
 ||58.249.87.33$document
@@ -388017,6 +388490,7 @@
 ||58.249.89.169$document
 ||58.249.89.178$document
 ||58.249.89.190$document
+||58.249.89.210$document
 ||58.249.89.213$document
 ||58.249.89.218$document
 ||58.249.89.223$document
@@ -388081,6 +388555,7 @@
 ||58.249.90.180$document
 ||58.249.90.19$document
 ||58.249.90.20$document
+||58.249.90.206$document
 ||58.249.90.216$document
 ||58.249.90.220$document
 ||58.249.90.233$document
@@ -388091,6 +388566,7 @@
 ||58.249.90.80$document
 ||58.249.90.82$document
 ||58.249.90.84$document
+||58.249.90.86$document
 ||58.249.90.94$document
 ||58.249.91.102$document
 ||58.249.91.11$document
@@ -388125,6 +388601,7 @@
 ||58.249.91.77$document
 ||58.249.91.98$document
 ||58.252.175.220$document
+||58.252.176.107$document
 ||58.252.176.117$document
 ||58.252.176.12$document
 ||58.252.176.120$document
@@ -388393,6 +388870,7 @@
 ||58.255.135.21$document
 ||58.255.135.228$document
 ||58.255.135.253$document
+||58.255.135.41$document
 ||58.255.135.48$document
 ||58.255.135.56$document
 ||58.255.135.61$document
@@ -388569,6 +389047,7 @@
 ||58.42.195.227$document
 ||58.42.198.13$document
 ||58.42.220.111$document
+||58.46.169.21$document
 ||58.46.248.182$document
 ||58.46.248.4$document
 ||58.46.249.10$document
@@ -388731,6 +389210,7 @@
 ||58.61.51.61$document
 ||58.61.51.73$document
 ||58.61.51.97$document
+||58.62.31.25$document
 ||58.62.80.50$document
 ||58.62.80.54$document
 ||58.62.83.182$document
@@ -392796,6 +393276,7 @@
 ||59.32.97.159$document
 ||59.32.97.187$document
 ||59.32.97.188$document
+||59.32.97.190$document
 ||59.32.97.208$document
 ||59.32.97.217$document
 ||59.32.97.218$document
@@ -394669,6 +395150,7 @@
 ||59.92.182.7$document
 ||59.92.182.70$document
 ||59.92.182.71$document
+||59.92.182.72$document
 ||59.92.182.74$document
 ||59.92.182.75$document
 ||59.92.182.76$document
@@ -395375,6 +395857,7 @@
 ||59.92.218.72$document
 ||59.92.218.73$document
 ||59.92.218.75$document
+||59.92.218.77$document
 ||59.92.218.79$document
 ||59.92.218.8$document
 ||59.92.218.80$document
@@ -395495,6 +395978,7 @@
 ||59.92.219.252$document
 ||59.92.219.254$document
 ||59.92.219.26$document
+||59.92.219.28$document
 ||59.92.219.29$document
 ||59.92.219.30$document
 ||59.92.219.31$document
@@ -396125,6 +396609,7 @@
 ||59.93.19.187$document
 ||59.93.19.189$document
 ||59.93.19.190$document
+||59.93.19.191$document
 ||59.93.19.193$document
 ||59.93.19.194$document
 ||59.93.19.195$document
@@ -396299,6 +396784,7 @@
 ||59.93.21.110$document
 ||59.93.21.111$document
 ||59.93.21.115$document
+||59.93.21.117$document
 ||59.93.21.121$document
 ||59.93.21.126$document
 ||59.93.21.127$document
@@ -397598,6 +398084,7 @@
 ||59.94.182.241$document
 ||59.94.182.242$document
 ||59.94.182.243$document
+||59.94.182.244$document
 ||59.94.182.246$document
 ||59.94.182.247$document
 ||59.94.182.248$document
@@ -400147,6 +400634,7 @@
 ||59.97.169.111$document
 ||59.97.169.112$document
 ||59.97.169.113$document
+||59.97.169.114$document
 ||59.97.169.115$document
 ||59.97.169.116$document
 ||59.97.169.117$document
@@ -401375,6 +401863,7 @@
 ||59.97.174.82$document
 ||59.97.174.83$document
 ||59.97.174.84$document
+||59.97.174.85$document
 ||59.97.174.87$document
 ||59.97.174.89$document
 ||59.97.174.9$document
@@ -403786,6 +404275,7 @@
 ||59.99.44.249$document
 ||59.99.44.253$document
 ||59.99.44.254$document
+||59.99.44.28$document
 ||59.99.44.29$document
 ||59.99.44.30$document
 ||59.99.44.31$document
@@ -404694,6 +405184,7 @@
 ||59.99.93.244$document
 ||59.99.93.245$document
 ||59.99.93.246$document
+||59.99.93.248$document
 ||59.99.93.250$document
 ||59.99.93.251$document
 ||59.99.93.252$document
@@ -404750,6 +405241,7 @@
 ||59.99.93.79$document
 ||59.99.93.8$document
 ||59.99.93.80$document
+||59.99.93.82$document
 ||59.99.93.83$document
 ||59.99.93.84$document
 ||59.99.93.85$document
@@ -404990,6 +405482,7 @@
 ||59.99.95.134$document
 ||59.99.95.135$document
 ||59.99.95.136$document
+||59.99.95.137$document
 ||59.99.95.139$document
 ||59.99.95.14$document
 ||59.99.95.140$document
@@ -404999,6 +405492,7 @@
 ||59.99.95.146$document
 ||59.99.95.147$document
 ||59.99.95.148$document
+||59.99.95.149$document
 ||59.99.95.15$document
 ||59.99.95.151$document
 ||59.99.95.152$document
@@ -407230,6 +407724,7 @@
 ||60.215.4.239$document
 ||60.215.4.89$document
 ||60.215.42.16$document
+||60.215.59.108$document
 ||60.215.61.56$document
 ||60.215.63.173$document
 ||60.216.122.109$document
@@ -416089,6 +416584,7 @@
 ||60.254.49.198$document
 ||60.254.49.201$document
 ||60.254.49.215$document
+||60.254.49.59$document
 ||60.254.49.68$document
 ||60.254.49.94$document
 ||60.254.50.240$document
@@ -416895,6 +417391,7 @@
 ||60.7.64.208$document
 ||60.7.64.243$document
 ||60.7.65.79$document
+||60.7.8.43$document
 ||60.7.94.111$document
 ||60.7.99.254$document
 ||60.9.155.86$document
@@ -419107,11 +419604,13 @@
 ||61.3.124.244$document
 ||61.3.124.25$document
 ||61.3.124.251$document
+||61.3.124.3$document
 ||61.3.124.33$document
 ||61.3.124.34$document
 ||61.3.124.39$document
 ||61.3.124.41$document
 ||61.3.124.46$document
+||61.3.124.51$document
 ||61.3.124.60$document
 ||61.3.124.65$document
 ||61.3.124.71$document
@@ -419123,6 +419622,7 @@
 ||61.3.124.95$document
 ||61.3.125.102$document
 ||61.3.125.107$document
+||61.3.125.112$document
 ||61.3.125.114$document
 ||61.3.125.119$document
 ||61.3.125.12$document
@@ -419218,6 +419718,7 @@
 ||61.3.127.124$document
 ||61.3.127.125$document
 ||61.3.127.135$document
+||61.3.127.138$document
 ||61.3.127.149$document
 ||61.3.127.158$document
 ||61.3.127.178$document
@@ -419913,6 +420414,7 @@
 ||61.52.135.117$document
 ||61.52.135.125$document
 ||61.52.135.144$document
+||61.52.135.192$document
 ||61.52.135.234$document
 ||61.52.135.235$document
 ||61.52.135.253$document
@@ -420989,6 +421491,7 @@
 ||61.52.212.233$document
 ||61.52.212.239$document
 ||61.52.212.244$document
+||61.52.212.250$document
 ||61.52.212.251$document
 ||61.52.212.27$document
 ||61.52.212.30$document
@@ -421825,6 +422328,7 @@
 ||61.52.39.101$document
 ||61.52.39.109$document
 ||61.52.39.110$document
+||61.52.39.119$document
 ||61.52.39.122$document
 ||61.52.39.132$document
 ||61.52.39.144$document
@@ -422132,6 +422636,7 @@
 ||61.52.5.192$document
 ||61.52.5.195$document
 ||61.52.5.198$document
+||61.52.5.217$document
 ||61.52.5.226$document
 ||61.52.5.60$document
 ||61.52.50.109$document
@@ -422705,6 +423210,7 @@
 ||61.52.62.97$document
 ||61.52.63.11$document
 ||61.52.63.110$document
+||61.52.63.119$document
 ||61.52.63.121$document
 ||61.52.63.125$document
 ||61.52.63.127$document
@@ -422868,6 +423374,7 @@
 ||61.52.76.53$document
 ||61.52.76.58$document
 ||61.52.76.59$document
+||61.52.76.72$document
 ||61.52.76.73$document
 ||61.52.76.74$document
 ||61.52.76.87$document
@@ -424066,6 +424573,7 @@
 ||61.53.123.149$document
 ||61.53.123.154$document
 ||61.53.123.161$document
+||61.53.123.162$document
 ||61.53.123.163$document
 ||61.53.123.168$document
 ||61.53.123.169$document
@@ -424152,6 +424660,7 @@
 ||61.53.124.215$document
 ||61.53.124.219$document
 ||61.53.124.223$document
+||61.53.124.225$document
 ||61.53.124.227$document
 ||61.53.124.23$document
 ||61.53.124.230$document
@@ -426707,6 +427216,7 @@
 ||61.54.240.166$document
 ||61.54.240.19$document
 ||61.54.240.198$document
+||61.54.240.20$document
 ||61.54.240.213$document
 ||61.54.240.220$document
 ||61.54.240.44$document
@@ -427065,10 +427575,12 @@
 ||61.54.58.164$document
 ||61.54.58.166$document
 ||61.54.58.172$document
+||61.54.58.190$document
 ||61.54.58.192$document
 ||61.54.58.193$document
 ||61.54.58.197$document
 ||61.54.58.198$document
+||61.54.58.20$document
 ||61.54.58.202$document
 ||61.54.58.211$document
 ||61.54.58.22$document
@@ -427127,6 +427639,7 @@
 ||61.54.60.242$document
 ||61.54.60.255$document
 ||61.54.60.29$document
+||61.54.60.4$document
 ||61.54.60.43$document
 ||61.54.60.55$document
 ||61.54.60.68$document
@@ -427149,6 +427662,7 @@
 ||61.54.61.163$document
 ||61.54.61.168$document
 ||61.54.61.172$document
+||61.54.61.18$document
 ||61.54.61.191$document
 ||61.54.61.199$document
 ||61.54.61.208$document
@@ -427857,6 +428371,7 @@
 ||62.219.131.205$document
 ||62.219.138.44$document
 ||62.219.143.46$document
+||62.219.155.61$document
 ||62.219.163.162$document
 ||62.219.164.224$document
 ||62.219.194.210$document
@@ -429060,6 +429575,7 @@
 ||71.183.150.34$document
 ||71.187.60.8$document
 ||71.19.144.47$document
+||71.19.150.93$document
 ||71.190.64.120$document
 ||71.190.64.189$document
 ||71.190.64.214$document
@@ -429968,6 +430484,7 @@
 ||77.45.182.113$document
 ||77.45.182.196$document
 ||77.45.183.124$document
+||77.45.183.39$document
 ||77.45.184.77$document
 ||77.45.185.57$document
 ||77.45.185.89$document
@@ -432192,6 +432709,7 @@
 ||84.22.38.175$document
 ||84.221.143.108$document
 ||84.224.144.27$document
+||84.224.162.170$document
 ||84.224.177.80$document
 ||84.224.213.50$document
 ||84.228.102.152$document
@@ -432405,6 +432923,7 @@
 ||85.105.77.54$document
 ||85.105.82.225$document
 ||85.105.82.94$document
+||85.105.9.152$document
 ||85.105.98.84$document
 ||85.106.129.231$document
 ||85.106.161.174$document
@@ -435589,6 +436108,7 @@
 ||95.152.49.54$document
 ||95.152.5.232$document
 ||95.152.9.183$document
+||95.153.241.63$document
 ||95.153.94.241$document
 ||95.154.20.231$document
 ||95.154.244.200$document
@@ -437114,8 +437634,7 @@
 ||access-24.jp$document
 ||access-cash.ae.org$document
 ||access-om.neomeric.us$document
-||access-one.us/aym3vh.php$document
-||access-one.us/wp-content/qvrajpy4kvx3pkg4aiuljg98c34dw1yaweefdv7gnbvxygdyki6jqug61dmqb44w7cvth/$document
+||access-one.us$document
 ||access-to-web.com$document
 ||accessclub.jp$document
 ||accessdig.com$document
@@ -437298,6 +437817,7 @@
 ||achutamanasa.com/media/jkslhiclhpj4d8q64fqmm7j/$document
 ||achutamanasa.com/media/te/$document
 ||aci.serabd.com$document
+||aciabogados.com$document
 ||aciitaly.com$document
 ||acilevarkadasi.com$document
 ||acilisbalon.com$document
@@ -437738,6 +438258,7 @@
 ||admin.greenlightcr.com$document
 ||admin.hopehorseback.org$document
 ||admin.jpcar.mystand.pt$document
+||admin.mobilezenie.com$document
 ||admin.searchlowestprice.com$document
 ||admin.solissol.com$document
 ||admin.staging.buildsmart.io$document
@@ -437926,7 +438447,7 @@
 ||adventureexplorer.in$document
 ||adventurehr.com$document
 ||adventureitdate.com$document
-||adventureits.com$document
+||adventureits.com/wp-content/6399952952/q54d7zyhe/$document
 ||adventuremania.com$document
 ||adventureracen.nl/cgi-bin/parts_service/$document
 ||adventurersafaris.com$document
@@ -438353,6 +438874,7 @@
 ||agengarcinia5000.com$document
 ||agenity.com$document
 ||agenlama.com$document
+||agenmovie.xyz$document
 ||agent-14.s3.us-east-2.amazonaws.com/agent_140020000.exe$document
 ||agent-seo.jp$document
 ||agent.ken.by$document
@@ -445605,6 +446127,7 @@
 ||barcelonaevent.es$document
 ||barcelonakartingcenter.com$document
 ||barchaklem.com$document
+||barcionstw.eastus.cloudapp.azure.com$document
 ||barcla.ug$document
 ||barclaysdownloads.com$document
 ||barcoofoods.ir$document
@@ -448491,7 +449014,7 @@
 ||bj5800.com$document
 ||bjarndahl.dk$document
 ||bjbus.net$document
-||bjconstructions.in/6382329/mlrcedkan/$document
+||bjconstructions.in$document
 ||bjdd.org$document
 ||bjenkins.webview.consulting$document
 ||bjenzer.com$document
@@ -449586,6 +450109,7 @@
 ||bnpartnersweb.com$document
 ||bnpgrup.com$document
 ||bnqzjy.cn$document
+||bnrbook.com$document
 ||bnrnews.id$document
 ||bnsddfhjdfgvbxc.ru$document
 ||bnsgroupbd.com$document
@@ -450350,6 +450874,7 @@
 ||braner.com.ua$document
 ||branfinancial.com$document
 ||branner-chile.com$document
+||brannon-powlowski25d.xyz$document
 ||brannudd.com$document
 ||brantech.com$document
 ||brany-profimar.sk/g/8plrj6ossbkavyt3ppmhxo32wnw2g9gmno/$document
@@ -451362,6 +451887,7 @@
 ||buysellfx24.ru$document
 ||buysmart365.net$document
 ||buysmartwebmall.com$document
+||buythebest.pk$document
 ||buytotake.online$document
 ||buytwitterlike.com$document
 ||buyuksigorta.com$document
@@ -452735,6 +453261,7 @@
 ||cashpickup.slmicrocredit.com$document
 ||cashslip.info$document
 ||cashstreamfinancial.com/wp-admin/23/$document
+||cashtunel.com$document
 ||cashyinvestment.org$document
 ||casimiroartes.es$document
 ||casinarium.com$document
@@ -456223,6 +456750,7 @@
 ||clubzone.ca$document
 ||cluebazar.com$document
 ||clukva.ru$document
+||clurbgolf.com$document
 ||clurit.com$document
 ||clusdirectory.xyz$document
 ||cluster-mixture.gq$document
@@ -456442,7 +456970,7 @@
 ||coastmedicalservice.com$document
 ||coastmotorsupply.com$document
 ||coastsignworks.com$document
-||coastwidewaterproofing.com.au/l4s6cpeyo.rar$document
+||coastwidewaterproofing.com.au$document
 ||coatforwinter.com$document
 ||coavce.com$document
 ||cobam.xyz$document
@@ -458536,6 +459064,7 @@
 ||cronolux.com.br$document
 ||croodly.com$document
 ||crookedchristicraddick.com$document
+||crooks-cooper24g.xyz$document
 ||crooks-taylor.com/1676470973/1/$document
 ||croos.org$document
 ||crope.shop$document
@@ -459840,7 +460369,7 @@
 ||dar-sana.com$document
 ||darajelita.com$document
 ||daralsalam-mall.com$document
-||daralsaqi.com$document
+||daralsaqi.com/preview.exe$document
 ||darapartment.com$document
 ||darasrszs.online$document
 ||darassalam.ch$document
@@ -459949,7 +460478,7 @@
 ||dasheriemagazine.com$document
 ||dashfiles.tk$document
 ||dashkevichseo.ru$document
-||dashonweb.com$document
+||dashonweb.com/wp-content/tscyjo/$document
 ||dashudance.com$document
 ||dashvaanjil.mn$document
 ||dasin-obchudek.cz$document
@@ -460280,7 +460809,7 @@
 ||dbravo.pro$document
 ||dbs-ebank.com$document
 ||dbsa-dream.com$document
-||dbsandbox.ca/cgi-bin/wgv9dtltdn9ebgnqzd7fy1me1ltgjuimrk2/$document
+||dbsandbox.ca$document
 ||dbsenvironmental.co.uk$document
 ||dbsgear.com$document
 ||dbsktoporder.yolasite.com$document
@@ -461270,6 +461799,7 @@
 ||denmaar.hplbusiness.com$document
 ||denmarkheating.net$document
 ||denmaytre.vn$document
+||dennis-hill25lw.xyz$document
 ||dennis-roth.de$document
 ||dennishester.com$document
 ||dennisisasshole.com$document
@@ -465771,6 +466301,9 @@
 ||down.posti-fi-fsa.top$document
 ||down.posti-fi-fsaq.top$document
 ||down.posti-fi-fwa.top$document
+||down.posti-fi-ij.top$document
+||down.posti-fi-in.top$document
+||down.posti-fi-iz.top$document
 ||down.pzchao.com$document
 ||down.qm188.com$document
 ||down.qqfarmer.com.cn$document
@@ -482550,7 +483083,7 @@
 ||egyptmotours.com$document
 ||egyptpharaohstours.com$document
 ||egyshadowmen.com$document
-||egyutthato.eu/5341zqvpdr/pay/smallbusiness$document
+||egyutthato.eu$document
 ||egyuttkonnyebb.zolitoth.com$document
 ||egyvision.medicahealthy.net$document
 ||egywebtest.ml$document
@@ -483784,7 +484317,7 @@
 ||ennessehospitality.id$document
 ||ennovate.elin.co.za$document
 ||eno.si$document
-||enolil-loo.com/agillawood/czafm/$document
+||enolil-loo.com$document
 ||enorichie.net$document
 ||enorka.info$document
 ||enosburgreading.pbworks.com$document
@@ -485832,7 +486365,7 @@
 ||faithcompassion.com$document
 ||faithconstructionltd.co.uk$document
 ||faithfight.my.id$document
-||faithmethodistcheras.org/wp-admin/vttrtc-133-57930/$document
+||faithmethodistcheras.org$document
 ||faithmontessorischools.com$document
 ||faithoasis.000webhostapp.com$document
 ||faithworkx.com$document
@@ -487227,6 +487760,7 @@
 ||findyourvoice.ca$document
 ||fine-art-line.de$document
 ||fine.black$document
+||fineartgallerym.com$document
 ||fineconera.com$document
 ||finefeather.info$document
 ||finefoodsfrozen.com$document
@@ -491064,6 +491598,7 @@
 ||girltalkza.co.za$document
 ||girlydesignart.com$document
 ||gironynavarro.com$document
+||girotexuniformes.com$document
 ||girraj2016.gtranzit.com$document
 ||girrajwadi.com$document
 ||gisa.company$document
@@ -491251,6 +491786,7 @@
 ||glafka.com$document
 ||glambooth.nl$document
 ||glamoroushairextension.com$document
+||glamorouspk.com$document
 ||glamour.rosolutions.com.mx$document
 ||glamourequipamiento.com/cxqsm/qt0q8224ftc5ln6/dp3ckgd2wk/$document
 ||glamourgarden-lb.com$document
@@ -492029,6 +492565,7 @@
 ||gordonmilktransport.com$document
 ||gordonruss.com$document
 ||gordyssensors.com$document
+||gorecycle.fahadjutt.com$document
 ||gorenotoservisi.net$document
 ||gorestruly.com$document
 ||goretimmo.lu$document
@@ -493244,7 +493781,7 @@
 ||guneyaski.com$document
 ||gungazcomputer.co.ke$document
 ||gunk.insol.be$document
-||gunma2u.com/ovp50ku/1pjj2peebf/$document
+||gunma2u.com$document
 ||gunmak-com.tk$document
 ||gunnarasgeir.com$document
 ||gunnersexcavating.com$document
@@ -495676,6 +496213,7 @@
 ||hollywoodsmileeg.com$document
 ||holmdalehouse.co.uk$document
 ||holmesgroup-com.azurewebsites.net$document
+||holmesprpmgmt.com$document
 ||holmnkolbas.com$document
 ||holmsater.se$document
 ||holod24.by$document
@@ -496412,6 +496950,7 @@
 ||hpmaytinhtaophongcach.com$document
 ||hpmwqjub.com$document
 ||hpq8fa.db.files.1drv.com$document
+||hprosacco25i.xyz$document
 ||hprpc.cn$document
 ||hps-sk.sk$document
 ||hps.nz$document
@@ -499135,6 +499674,7 @@
 ||instantbonheur.fr$document
 ||instantcashflowtoday.com.ng$document
 ||instantclients.network$document
+||instantindialoan.com$document
 ||instanttaxsolutions.mobi$document
 ||instanttechnology.com.au$document
 ||instantworldpay.com$document
@@ -499995,6 +500535,7 @@
 ||isciyizbiz.com$document
 ||iscleanone.com$document
 ||isclimatechangeahoax.com$document
+||iscoegypt.com$document
 ||iscoming.ir$document
 ||iscon.com.br$document
 ||iscondisth.com$document
@@ -500051,7 +500592,9 @@
 ||iskro.textronic.info$document
 ||iskyservice.ru$document
 ||islaholics.com$document
-||islamabadtrafficpolice.gov.pk$document
+||islamabadtrafficpolice.gov.pk/browse/w6nsp2/fv54115180147v7ko46qxn3bvlmfq1/$document
+||islamabadtrafficpolice.gov.pk/esp/94406698/cppdv/$document
+||islamabadtrafficpolice.gov.pk/i/$document
 ||islamabout.com$document
 ||islamappen.se$document
 ||islamforall.tv$document
@@ -501919,6 +502462,7 @@
 ||jollycharm.com$document
 ||jollyemma.com$document
 ||jolyscortinas.com.br$document
+||jomansea.com$document
 ||jomar2020.com.br$document
 ||jomblo.com$document
 ||jomhermonex.com$document
@@ -502649,6 +503193,7 @@
 ||justkp.com$document
 ||justlficante.mediafire.com/file/4t8lltc9x35wzus/justt1.tgz/file$document
 ||justlficante.mediafire.com/file/g3y3o84bbgkhu4o/jusf1c.tgz/file$document
+||justlficante.mediafire.com/file/jl01o54yy09qrzg/fac215.tgz/file$document
 ||justmaha.com$document
 ||justmail24.com$document
 ||justmyblog.info$document
@@ -503333,6 +503878,7 @@
 ||kasperskysecurity.club$document
 ||kasrasanatsepahan.com$document
 ||kassa.hostsites.ru$document
+||kassandra5024d.xyz$document
 ||kassconnect.ru$document
 ||kasshmira.com$document
 ||kassohome.com.tr$document
@@ -503994,7 +504540,8 @@
 ||khannen.com.vn$document
 ||khannen.vn$document
 ||khanqahebrahimi.com$document
-||khantil.com$document
+||khantil.com/us/payments/122018$document
+||khantil.com/us/payments/122018/$document
 ||khantipong.com$document
 ||khaochills.com$document
 ||khaoden.tech$document
@@ -505910,6 +506457,7 @@
 ||lab.valvolari.it$document
 ||lab.ydigital.asia$document
 ||lab1.ozaki-kyousei.com$document
+||lab18.it$document
 ||lab2.e-century.pl$document
 ||lab5.hu$document
 ||lab6.com.br$document
@@ -511143,6 +511691,7 @@
 ||manageitrisks.com$document
 ||management.vkims.com$document
 ||managementtop.id$document
+||managemysalon.in$document
 ||managemyshoes.tools$document
 ||manageone.co.th$document
 ||manageprint.in$document
@@ -511611,7 +512160,7 @@
 ||marek-paysage-concept.fr$document
 ||marek.in$document
 ||marekvoprsal.cz$document
-||marel.com.br/wp-content/uploads/2020/10/bn8qvr2l/$document
+||marel.com.br$document
 ||marellengifts.com$document
 ||maremarius.pt$document
 ||marematto.it$document
@@ -513050,6 +513599,7 @@
 ||meditec.ma$document
 ||mediterraneavacanze.com$document
 ||meditheraphy.com$document
+||meditreat.itwebservice.in$document
 ||meditsinanarodnaya.ru$document
 ||medius.ge$document
 ||mediusvp.com$document
@@ -515292,7 +515842,7 @@
 ||mojang.com.br$document
 ||mojehaftom.com$document
 ||mojewnetrza.pl$document
-||mojno--vse.ru/content/6tqjfutopvigfknidf0sfae6guwnsxjjicomwynq0qmfksrit2be2/$document
+||mojno--vse.ru$document
 ||mojo-studios.co.uk$document
 ||mojorockstar.com$document
 ||mojstudent.net$document
@@ -516063,7 +516613,7 @@
 ||mrpower.ir$document
 ||mrprintoke.com$document
 ||mrquick.co.il$document
-||mrsambarbershop.nl/wp-content/axm4it/$document
+||mrsambarbershop.nl$document
 ||mrsbow.com$document
 ||mrsconnect.org$document
 ||mrsdiggs.com$document
@@ -516686,7 +517236,7 @@
 ||mvid.com$document
 ||mvidl.site$document
 ||mvisionproperties.com$document
-||mvldesign.ca/durani/2lzs/$document
+||mvldesign.ca$document
 ||mvm368.com$document
 ||mvmskpd.com$document
 ||mvns.railfan.net$document
@@ -518096,7 +518646,7 @@
 ||nelsonhelps.com$document
 ||nelsonhostingcom.000webhostapp.com$document
 ||nelsonpto.org$document
-||nelsonsbutchers.co.uk/cgi-bin/4vlaf1vqrwyfgwgxp33pcd1uydauib40dllquefurt5547d0xsmo/$document
+||nelsonsbutchers.co.uk$document
 ||nelsonsilveti.com$document
 ||neltac.com$document
 ||nelyvos.nl$document
@@ -519486,7 +520036,7 @@
 ||no1angelsescort.com$document
 ||no1spinningfields.90degrees.digital$document
 ||no1websitedesigner.com$document
-||no2politics.com$document
+||no2politics.com/files/us_us/doc/invoice-069345/$document
 ||no70.fun$document
 ||noabuseshere.top$document
 ||noach.nl$document
@@ -520863,6 +521413,7 @@
 ||ohako.com.my$document
 ||ohamburguer.com.br$document
 ||ohanadev.com$document
+||ohatsbd.com$document
 ||ohdratdigital.com$document
 ||ohe.ie$document
 ||ohelloguyzzqq.com$document
@@ -521175,6 +521726,7 @@
 ||omagroup.ru$document
 ||omaharefugees.com$document
 ||omahduwur.com$document
+||omaia.org$document
 ||omaint.ml$document
 ||omalleyco-my.sharepoint.com$document
 ||omalll.com$document
@@ -523361,6 +523913,7 @@
 ||onedrive.live.com/download?cid=d7a53f4e448c59af&resid=d7a53f4e448c59af%21930&authkey=ae8aykwfbemxegw$document
 ||onedrive.live.com/download?cid=d86391352444eeed&resid=d86391352444eeed!107&authkey=ajitiybfqf5qcpw$document
 ||onedrive.live.com/download?cid=d86391352444eeed&resid=d86391352444eeed%21107&authkey=ajitiybfqf5qcpw$document
+||onedrive.live.com/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21107&authkey=alo4lep7wht05na$document
 ||onedrive.live.com/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21109&authkey=adnbm6mekgzvvh8$document
 ||onedrive.live.com/download?cid=d88d6079d4b91bdb&resid=d88d6079d4b91bdb!391&authkey=afgbzttalahmq9a$document
 ||onedrive.live.com/download?cid=d8a7da7154194e40&resid=d8a7da7154194e40!970&authkey=!alf9m4lwilj_jre$document
@@ -529915,6 +530468,7 @@
 ||pastebin.com/raw/qmhtgbwv$document
 ||pastebin.com/raw/qmq7ggtb$document
 ||pastebin.com/raw/qmsdyt9z$document
+||pastebin.com/raw/qmue83xz$document
 ||pastebin.com/raw/qmxvzneq$document
 ||pastebin.com/raw/qn1aczmi$document
 ||pastebin.com/raw/qndvdcqj$document
@@ -535382,6 +535936,7 @@
 ||promodont.com$document
 ||promokonyara.ru$document
 ||promolatinconferences.com$document
+||promolyko.com$document
 ||promomitsubishitermurah.net$document
 ||promonoble.com$document
 ||promootzie.nl$document
@@ -536853,7 +537408,7 @@
 ||quickpickapp.co$document
 ||quickreachmedia.com$document
 ||quicksaleecuador.com$document
-||quickshine.co.ke/categoryl/eyoerdilcvrt0wf2zcac6633eytah/$document
+||quickshine.co.ke$document
 ||quickstorevn.com$document
 ||quicktechsupport247.com$document
 ||quicktowtowing.com$document
@@ -539141,6 +539696,7 @@
 ||rgfloors.com.au$document
 ||rgho.st/download/6nnmwrj65/e2fd966cb90832c49db58889a5bce7fa7eb6f67c/e2fd966cb90832c49db58889a5bce7fa7eb6f67c/fornite%20hack%202018.exe$document
 ||rgitabit.in$document
+||rgleason25s.xyz$document
 ||rglgrupomedico.com.mx$document
 ||rgmobilegossip.com$document
 ||rgmvanijya.com$document
@@ -539998,6 +540554,7 @@
 ||rosemaryromero.com.br$document
 ||rosemiracle.com$document
 ||rosemurphy.co.uk$document
+||rosenbaum-jaida24nz.xyz$document
 ||rosenfeldcapital.com$document
 ||rosenlaw.cratima.com$document
 ||roseperfeito.com.br$document
@@ -544283,6 +544840,7 @@
 ||shataikok.com$document
 ||shatelnews.ir$document
 ||shatki.info/templates/ld_benew/images/blue/messg.jpg$document
+||shatteredglass.io$document
 ||shaukya.com$document
 ||shaulla.store$document
 ||shaunodonnell.com$document
@@ -546218,7 +546776,7 @@
 ||smartlync.pk$document
 ||smartmadira.com$document
 ||smartmassive.ru$document
-||smartmatrixs.com/beta/llc/2af68g7w0ysysv95nutlsp_0bunhkbg-9466852086487/$document
+||smartmatrixs.com$document
 ||smartmobilelearning.co.za$document
 ||smartmoneylife.com$document
 ||smartmovie.com.ua$document
@@ -547211,6 +547769,7 @@
 ||sosenfantsburkinafaso.fr$document
 ||sosexymagazine.com$document
 ||sosflam.com$document
+||sosgsm.fr$document
 ||sosh47.citycheb.ru$document
 ||sosoab.com$document
 ||sosofoto.cz$document
@@ -553613,6 +554172,7 @@
 ||tecnologiatech.com$document
 ||tecnologiaz.com$document
 ||tecnologicainformatica.com.br$document
+||tecnologyschool.com$document
 ||tecnolora.com$document
 ||tecnoloxia.com$document
 ||tecnopc.info$document
@@ -556492,7 +557052,7 @@
 ||toby-warren.com$document
 ||tobyetc.com$document
 ||tobysherman.com$document
-||tocaima.co/wp-includes/dj5aol1nnnzjdyzvqurfh2lopouzceyok8ndyuoew/$document
+||tocaima.co$document
 ||tocakids.resultaweb.com.br$document
 ||tocchientv.com/cgi-bin/gegesa/$document
 ||tocgiajojo.com$document
@@ -557667,6 +558227,7 @@
 ||tresnexus.com$document
 ||treterhef.download$document
 ||tretthing-bg.site$document
+||treutel-jamir25ju.xyz$document
 ||trevellinglove.com$document
 ||trevinos.net$document
 ||trevorchristensen.com$document
@@ -561191,6 +561752,7 @@
 ||vastraindia.com$document
 ||vastralaya.shop$document
 ||vastuanalyst.com$document
+||vastubless.com$document
 ||vastuvidyaarchitects.com$document
 ||vasudhagoodharvest.com$document
 ||vasumadhi.com$document
@@ -562559,6 +563121,7 @@
 ||vladetel.org$document
 ||vladimirfilin.com$document
 ||vladimirfilin.ru$document
+||vladimirinternational.com$document
 ||vladneta.lt$document
 ||vladsever.ru$document
 ||vladsp.ru$document
@@ -563594,6 +564157,7 @@
 ||web.emergingsun.com$document
 ||web.emsfabrik.de$document
 ||web.eng.ubu.ac.th$document
+||web.geetle.ga$document
 ||web.geomegasoft.net$document
 ||web.golden-goblin.com$document
 ||web.gotham.com.au$document
@@ -564446,6 +565010,7 @@
 ||whyasksolution.com$document
 ||whybowl.thebotogs.com$document
 ||whyepicshop.com$document
+||whynt.xyz$document
 ||whysquare.co.nz$document
 ||whystudio.cn$document
 ||whytech.info$document
@@ -565546,7 +566111,7 @@
 ||wrrodrigo.com$document
 ||wrtech.com.pl$document
 ||wrusnollet.com$document
-||wrzucacz.pl/download/1211536055165$document
+||wrzucacz.pl$document
 ||wrzutka.co$document
 ||ws-ebavisapia01-dll.ir$document
 ||ws3lfkm.com$document
@@ -566015,6 +566580,7 @@
 ||xhcmnews.com$document
 ||xhd.qhv.mybluehost.me$document
 ||xhencheng.tk$document
+||xherzog24pv.xyz$document
 ||xhjclq.ch.files.1drv.com$document
 ||xhs9a81.com$document
 ||xhsdxm.com$document
@@ -567946,7 +568512,7 @@
 ||zafirotiendas.com$document
 ||zagnet.pl$document
 ||zagogulina.com$document
-||zagoradesertcamp.com/templates/u/$document
+||zagoradesertcamp.com$document
 ||zagrodazbyszka.pl$document
 ||zagros-shahrekord.ir$document
 ||zagrosenergygroup.com$document
@@ -568002,6 +568568,7 @@
 ||zakopane.utazas.hu$document
 ||zakopanedomki.com.pl$document
 ||zakosciele66.cba.pl$document
+||zakra.tecnasulstore.com.br$document
 ||zakrahgroup.com$document
 ||zakriasons.co$document
 ||zakromanoff.com$document
diff --git a/urlhaus-filter.tpl b/urlhaus-filter.tpl
index 90b50105..b1c73ae1 100644
--- a/urlhaus-filter.tpl
+++ b/urlhaus-filter.tpl
@@ -1,6 +1,6 @@
 msFilterList
 # Title: Malicious Hosts Blocklist (IE)
-# Updated: Thu, 25 Mar 2021 12:12:40 UTC
+# Updated: Fri, 26 Mar 2021 00:12:29 UTC
 # Expires: 1 day (update frequency)
 # Homepage: https://gitlab.com/curben/urlhaus-filter
 # License: https://gitlab.com/curben/urlhaus-filter#license
@@ -2499,6 +2499,7 @@ msFilterList
 -d access-24.jp
 -d access-cash.ae.org
 -d access-om.neomeric.us
+-d access-one.us
 -d access-to-web.com
 -d accessclub.jp
 -d accessdig.com
@@ -2676,6 +2677,7 @@ msFilterList
 -d acht-stuecken.de
 -d achuanchaolihai.cn
 -d aci.serabd.com
+-d aciabogados.com
 -d aciitaly.com
 -d acilevarkadasi.com
 -d acilisbalon.com
@@ -3092,6 +3094,7 @@ msFilterList
 -d admin.greenlightcr.com
 -d admin.hopehorseback.org
 -d admin.jpcar.mystand.pt
+-d admin.mobilezenie.com
 -d admin.searchlowestprice.com
 -d admin.solissol.com
 -d admin.staging.buildsmart.io
@@ -3271,7 +3274,6 @@ msFilterList
 -d adventureexplorer.in
 -d adventurehr.com
 -d adventureitdate.com
--d adventureits.com
 -d adventuremania.com
 -d adventurersafaris.com
 -d adventuresofarchibald.com
@@ -3691,6 +3693,7 @@ msFilterList
 -d agengarcinia5000.com
 -d agenity.com
 -d agenlama.com
+-d agenmovie.xyz
 -d agent-seo.jp
 -d agent.ken.by
 -d agent2.icu
@@ -10707,6 +10710,7 @@ msFilterList
 -d barcelonaevent.es
 -d barcelonakartingcenter.com
 -d barchaklem.com
+-d barcionstw.eastus.cloudapp.azure.com
 -d barcla.ug
 -d barclaysdownloads.com
 -d barcoofoods.ir
@@ -12992,6 +12996,7 @@ msFilterList
 -d bj5800.com
 -d bjarndahl.dk
 -d bjbus.net
+-d bjconstructions.in
 -d bjdd.org
 -d bjenkins.webview.consulting
 -d bjenzer.com
@@ -14031,6 +14036,7 @@ msFilterList
 -d bnpartnersweb.com
 -d bnpgrup.com
 -d bnqzjy.cn
+-d bnrbook.com
 -d bnrnews.id
 -d bnsddfhjdfgvbxc.ru
 -d bnsgroupbd.com
@@ -14781,6 +14787,7 @@ msFilterList
 -d braner.com.ua
 -d branfinancial.com
 -d branner-chile.com
+-d brannon-powlowski25d.xyz
 -d brannudd.com
 -d brantech.com
 -d brar.aminfortgreene.com
@@ -15781,6 +15788,7 @@ msFilterList
 -d buysellfx24.ru
 -d buysmart365.net
 -d buysmartwebmall.com
+-d buythebest.pk
 -d buytotake.online
 -d buytwitterlike.com
 -d buyuksigorta.com
@@ -17101,6 +17109,7 @@ msFilterList
 -d cashoutrefitips.com
 -d cashpickup.slmicrocredit.com
 -d cashslip.info
+-d cashtunel.com
 -d cashyinvestment.org
 -d casimiroartes.es
 -d casinarium.com
@@ -19673,6 +19682,7 @@ msFilterList
 -d clubzone.ca
 -d cluebazar.com
 -d clukva.ru
+-d clurbgolf.com
 -d clurit.com
 -d clusdirectory.xyz
 -d cluster-mixture.gq
@@ -19889,6 +19899,7 @@ msFilterList
 -d coastmedicalservice.com
 -d coastmotorsupply.com
 -d coastsignworks.com
+-d coastwidewaterproofing.com.au
 -d coatforwinter.com
 -d coavce.com
 -d cobam.xyz
@@ -21912,6 +21923,7 @@ msFilterList
 -d cronolux.com.br
 -d croodly.com
 -d crookedchristicraddick.com
+-d crooks-cooper24g.xyz
 -d croos.org
 -d crope.shop
 -d cropfoods.com
@@ -23166,7 +23178,6 @@ msFilterList
 -d dar-sana.com
 -d darajelita.com
 -d daralsalam-mall.com
--d daralsaqi.com
 -d darapartment.com
 -d darasrszs.online
 -d darassalam.ch
@@ -23275,7 +23286,6 @@ msFilterList
 -d dasheriemagazine.com
 -d dashfiles.tk
 -d dashkevichseo.ru
--d dashonweb.com
 -d dashudance.com
 -d dashvaanjil.mn
 -d dasin-obchudek.cz
@@ -23603,6 +23613,7 @@ msFilterList
 -d dbravo.pro
 -d dbs-ebank.com
 -d dbsa-dream.com
+-d dbsandbox.ca
 -d dbsenvironmental.co.uk
 -d dbsgear.com
 -d dbsktoporder.yolasite.com
@@ -24511,6 +24522,7 @@ msFilterList
 -d denmaar.hplbusiness.com
 -d denmarkheating.net
 -d denmaytre.vn
+-d dennis-hill25lw.xyz
 -d dennis-roth.de
 -d dennishester.com
 -d dennisisasshole.com
@@ -27187,6 +27199,9 @@ msFilterList
 -d down.posti-fi-fsa.top
 -d down.posti-fi-fsaq.top
 -d down.posti-fi-fwa.top
+-d down.posti-fi-ij.top
+-d down.posti-fi-in.top
+-d down.posti-fi-iz.top
 -d down.pzchao.com
 -d down.qm188.com
 -d down.qqfarmer.com.cn
@@ -29398,6 +29413,7 @@ msFilterList
 -d egyptmotours.com
 -d egyptpharaohstours.com
 -d egyshadowmen.com
+-d egyutthato.eu
 -d egyuttkonnyebb.zolitoth.com
 -d egyvision.medicahealthy.net
 -d egywebtest.ml
@@ -30579,6 +30595,7 @@ msFilterList
 -d ennessehospitality.id
 -d ennovate.elin.co.za
 -d eno.si
+-d enolil-loo.com
 -d enorichie.net
 -d enorka.info
 -d enosburgreading.pbworks.com
@@ -32552,6 +32569,7 @@ msFilterList
 -d faithcompassion.com
 -d faithconstructionltd.co.uk
 -d faithfight.my.id
+-d faithmethodistcheras.org
 -d faithmontessorischools.com
 -d faithoasis.000webhostapp.com
 -d faithworkx.com
@@ -33822,6 +33840,7 @@ msFilterList
 -d findyourvoice.ca
 -d fine-art-line.de
 -d fine.black
+-d fineartgallerym.com
 -d fineconera.com
 -d finefeather.info
 -d finefoodsfrozen.com
@@ -37450,6 +37469,7 @@ msFilterList
 -d girltalkza.co.za
 -d girlydesignart.com
 -d gironynavarro.com
+-d girotexuniformes.com
 -d girraj2016.gtranzit.com
 -d girrajwadi.com
 -d gisa.company
@@ -37539,6 +37559,7 @@ msFilterList
 -d glafka.com
 -d glambooth.nl
 -d glamoroushairextension.com
+-d glamorouspk.com
 -d glamour.rosolutions.com.mx
 -d glamourgarden-lb.com
 -d glamourlounge.org
@@ -38295,6 +38316,7 @@ msFilterList
 -d gordonmilktransport.com
 -d gordonruss.com
 -d gordyssensors.com
+-d gorecycle.fahadjutt.com
 -d gorenotoservisi.net
 -d gorestruly.com
 -d goretimmo.lu
@@ -39451,6 +39473,7 @@ msFilterList
 -d guneyaski.com
 -d gungazcomputer.co.ke
 -d gunk.insol.be
+-d gunma2u.com
 -d gunmak-com.tk
 -d gunnarasgeir.com
 -d gunnersexcavating.com
@@ -41802,6 +41825,7 @@ msFilterList
 -d hollywoodsmileeg.com
 -d holmdalehouse.co.uk
 -d holmesgroup-com.azurewebsites.net
+-d holmesprpmgmt.com
 -d holmnkolbas.com
 -d holmsater.se
 -d holod24.by
@@ -42495,6 +42519,7 @@ msFilterList
 -d hpmaytinhtaophongcach.com
 -d hpmwqjub.com
 -d hpq8fa.db.files.1drv.com
+-d hprosacco25i.xyz
 -d hprpc.cn
 -d hps-sk.sk
 -d hps.nz
@@ -45071,6 +45096,7 @@ msFilterList
 -d instantbonheur.fr
 -d instantcashflowtoday.com.ng
 -d instantclients.network
+-d instantindialoan.com
 -d instanttaxsolutions.mobi
 -d instanttechnology.com.au
 -d instantworldpay.com
@@ -45895,6 +45921,7 @@ msFilterList
 -d isciyizbiz.com
 -d iscleanone.com
 -d isclimatechangeahoax.com
+-d iscoegypt.com
 -d iscoming.ir
 -d iscon.com.br
 -d iscondisth.com
@@ -45950,7 +45977,6 @@ msFilterList
 -d iskro.textronic.info
 -d iskyservice.ru
 -d islaholics.com
--d islamabadtrafficpolice.gov.pk
 -d islamabout.com
 -d islamappen.se
 -d islamforall.tv
@@ -47763,6 +47789,7 @@ msFilterList
 -d jollycharm.com
 -d jollyemma.com
 -d jolyscortinas.com.br
+-d jomansea.com
 -d jomar2020.com.br
 -d jomblo.com
 -d jomhermonex.com
@@ -49142,6 +49169,7 @@ msFilterList
 -d kasperskysecurity.club
 -d kasrasanatsepahan.com
 -d kassa.hostsites.ru
+-d kassandra5024d.xyz
 -d kassconnect.ru
 -d kasshmira.com
 -d kassohome.com.tr
@@ -49786,7 +49814,6 @@ msFilterList
 -d khannen.com.vn
 -d khannen.vn
 -d khanqahebrahimi.com
--d khantil.com
 -d khantipong.com
 -d khaochills.com
 -d khaoden.tech
@@ -51648,6 +51675,7 @@ msFilterList
 -d lab.valvolari.it
 -d lab.ydigital.asia
 -d lab1.ozaki-kyousei.com
+-d lab18.it
 -d lab2.e-century.pl
 -d lab5.hu
 -d lab6.com.br
@@ -56686,6 +56714,7 @@ msFilterList
 -d manageitrisks.com
 -d management.vkims.com
 -d managementtop.id
+-d managemysalon.in
 -d managemyshoes.tools
 -d manageone.co.th
 -d manageprint.in
@@ -57067,6 +57096,7 @@ msFilterList
 -d marek-paysage-concept.fr
 -d marek.in
 -d marekvoprsal.cz
+-d marel.com.br
 -d marellengifts.com
 -d maremarius.pt
 -d marematto.it
@@ -58347,6 +58377,7 @@ msFilterList
 -d meditec.ma
 -d mediterraneavacanze.com
 -d meditheraphy.com
+-d meditreat.itwebservice.in
 -d meditsinanarodnaya.ru
 -d medius.ge
 -d mediusvp.com
@@ -60523,6 +60554,7 @@ msFilterList
 -d mojang.com.br
 -d mojehaftom.com
 -d mojewnetrza.pl
+-d mojno--vse.ru
 -d mojo-studios.co.uk
 -d mojorockstar.com
 -d mojstudent.net
@@ -61277,6 +61309,7 @@ msFilterList
 -d mrpower.ir
 -d mrprintoke.com
 -d mrquick.co.il
+-d mrsambarbershop.nl
 -d mrsbow.com
 -d mrsconnect.org
 -d mrsdiggs.com
@@ -61877,6 +61910,7 @@ msFilterList
 -d mvid.com
 -d mvidl.site
 -d mvisionproperties.com
+-d mvldesign.ca
 -d mvm368.com
 -d mvmskpd.com
 -d mvns.railfan.net
@@ -63211,6 +63245,7 @@ msFilterList
 -d nelsonhelps.com
 -d nelsonhostingcom.000webhostapp.com
 -d nelsonpto.org
+-d nelsonsbutchers.co.uk
 -d nelsonsilveti.com
 -d neltac.com
 -d nelyvos.nl
@@ -64545,7 +64580,6 @@ msFilterList
 -d no1angelsescort.com
 -d no1spinningfields.90degrees.digital
 -d no1websitedesigner.com
--d no2politics.com
 -d no70.fun
 -d noabuseshere.top
 -d noach.nl
@@ -65835,6 +65869,7 @@ msFilterList
 -d ohako.com.my
 -d ohamburguer.com.br
 -d ohanadev.com
+-d ohatsbd.com
 -d ohdratdigital.com
 -d ohe.ie
 -d ohelloguyzzqq.com
@@ -66139,6 +66174,7 @@ msFilterList
 -d omagroup.ru
 -d omaharefugees.com
 -d omahduwur.com
+-d omaia.org
 -d omaint.ml
 -d omalleyco-my.sharepoint.com
 -d omalll.com
@@ -71769,6 +71805,7 @@ msFilterList
 -d promodont.com
 -d promokonyara.ru
 -d promolatinconferences.com
+-d promolyko.com
 -d promomitsubishitermurah.net
 -d promonoble.com
 -d promootzie.nl
@@ -73184,6 +73221,7 @@ msFilterList
 -d quickpickapp.co
 -d quickreachmedia.com
 -d quicksaleecuador.com
+-d quickshine.co.ke
 -d quickstorevn.com
 -d quicktechsupport247.com
 -d quicktowtowing.com
@@ -75285,6 +75323,7 @@ msFilterList
 -d rgdecor.org
 -d rgfloors.com.au
 -d rgitabit.in
+-d rgleason25s.xyz
 -d rglgrupomedico.com.mx
 -d rgmobilegossip.com
 -d rgmvanijya.com
@@ -76129,6 +76168,7 @@ msFilterList
 -d rosemaryromero.com.br
 -d rosemiracle.com
 -d rosemurphy.co.uk
+-d rosenbaum-jaida24nz.xyz
 -d rosenfeldcapital.com
 -d rosenlaw.cratima.com
 -d roseperfeito.com.br
@@ -80047,6 +80087,7 @@ msFilterList
 -d shatabbytek.com
 -d shataikok.com
 -d shatelnews.ir
+-d shatteredglass.io
 -d shaukya.com
 -d shaulla.store
 -d shaunodonnell.com
@@ -81908,6 +81949,7 @@ msFilterList
 -d smartlync.pk
 -d smartmadira.com
 -d smartmassive.ru
+-d smartmatrixs.com
 -d smartmobilelearning.co.za
 -d smartmoneylife.com
 -d smartmovie.com.ua
@@ -82870,6 +82912,7 @@ msFilterList
 -d sosenfantsburkinafaso.fr
 -d sosexymagazine.com
 -d sosflam.com
+-d sosgsm.fr
 -d sosh47.citycheb.ru
 -d sosoab.com
 -d sosofoto.cz
@@ -87506,6 +87549,7 @@ msFilterList
 -d tecnologiatech.com
 -d tecnologiaz.com
 -d tecnologicainformatica.com.br
+-d tecnologyschool.com
 -d tecnolora.com
 -d tecnoloxia.com
 -d tecnopc.info
@@ -90270,6 +90314,7 @@ msFilterList
 -d toby-warren.com
 -d tobyetc.com
 -d tobysherman.com
+-d tocaima.co
 -d tocakids.resultaweb.com.br
 -d tocgiajojo.com
 -d tochkae.ru
@@ -91397,6 +91442,7 @@ msFilterList
 -d tresnexus.com
 -d treterhef.download
 -d tretthing-bg.site
+-d treutel-jamir25ju.xyz
 -d trevellinglove.com
 -d trevinos.net
 -d trevorchristensen.com
@@ -94099,6 +94145,7 @@ msFilterList
 -d vastraindia.com
 -d vastralaya.shop
 -d vastuanalyst.com
+-d vastubless.com
 -d vastuvidyaarchitects.com
 -d vasudhagoodharvest.com
 -d vasumadhi.com
@@ -95444,6 +95491,7 @@ msFilterList
 -d vladetel.org
 -d vladimirfilin.com
 -d vladimirfilin.ru
+-d vladimirinternational.com
 -d vladneta.lt
 -d vladsever.ru
 -d vladsp.ru
@@ -96442,6 +96490,7 @@ msFilterList
 -d web.emergingsun.com
 -d web.emsfabrik.de
 -d web.eng.ubu.ac.th
+-d web.geetle.ga
 -d web.geomegasoft.net
 -d web.golden-goblin.com
 -d web.gotham.com.au
@@ -97256,6 +97305,7 @@ msFilterList
 -d whyasksolution.com
 -d whybowl.thebotogs.com
 -d whyepicshop.com
+-d whynt.xyz
 -d whysquare.co.nz
 -d whystudio.cn
 -d whytech.info
@@ -98323,6 +98373,7 @@ msFilterList
 -d wrrodrigo.com
 -d wrtech.com.pl
 -d wrusnollet.com
+-d wrzucacz.pl
 -d wrzutka.co
 -d ws-ebavisapia01-dll.ir
 -d ws3lfkm.com
@@ -98770,6 +98821,7 @@ msFilterList
 -d xhcmnews.com
 -d xhd.qhv.mybluehost.me
 -d xhencheng.tk
+-d xherzog24pv.xyz
 -d xhjclq.ch.files.1drv.com
 -d xhs9a81.com
 -d xhsdxm.com
@@ -100629,6 +100681,7 @@ msFilterList
 -d zafirotiendas.com
 -d zagnet.pl
 -d zagogulina.com
+-d zagoradesertcamp.com
 -d zagrodazbyszka.pl
 -d zagros-shahrekord.ir
 -d zagrosenergygroup.com
@@ -100684,6 +100737,7 @@ msFilterList
 -d zakopane.utazas.hu
 -d zakopanedomki.com.pl
 -d zakosciele66.cba.pl
+-d zakra.tecnasulstore.com.br
 -d zakrahgroup.com
 -d zakriasons.co
 -d zakromanoff.com
diff --git a/urlhaus-filter.txt b/urlhaus-filter.txt
index 5e0633ae..d1b0a375 100644
--- a/urlhaus-filter.txt
+++ b/urlhaus-filter.txt
@@ -1,5 +1,5 @@
 ! Title: Malicious URL Blocklist
-! Updated: Thu, 25 Mar 2021 12:12:40 UTC
+! Updated: Fri, 26 Mar 2021 00:12:29 UTC
 ! Expires: 1 day (update frequency)
 ! Homepage: https://gitlab.com/curben/urlhaus-filter
 ! License: https://gitlab.com/curben/urlhaus-filter#license
@@ -1024,6 +1024,7 @@
 1.58.206.122
 1.58.206.199
 1.58.220.198
+1.58.223.96
 1.58.50.67
 1.59.181.177
 1.59.249.83
@@ -3600,6 +3601,7 @@
 103.217.116.166
 103.217.116.245
 103.217.117.108
+103.217.117.134
 103.217.119.74
 103.217.119.75
 103.217.119.76
@@ -3670,6 +3672,7 @@
 103.217.121.228
 103.217.121.23
 103.217.121.231
+103.217.121.234
 103.217.121.237
 103.217.121.238
 103.217.121.239
@@ -3735,6 +3738,7 @@
 103.217.123.2
 103.217.123.200
 103.217.123.204
+103.217.123.210
 103.217.123.213
 103.217.123.216
 103.217.123.218
@@ -5207,6 +5211,7 @@
 103.78.183.4
 103.78.183.40
 103.78.21.238
+103.78.22.157
 103.78.22.177
 103.78.22.207
 103.78.22.219
@@ -6684,6 +6689,7 @@
 104.168.151.198
 104.168.152.230
 104.168.157.45
+104.168.158.127
 104.168.158.148
 104.168.158.248
 104.168.158.38
@@ -6778,6 +6784,7 @@
 104.168.96.11
 104.168.96.168
 104.168.96.194
+104.168.98.105
 104.168.98.206
 104.168.99.220
 104.168.99.30
@@ -8390,6 +8397,7 @@
 106.36.159.125
 106.36.4.112
 106.37.121.250
+106.4.138.95
 106.4.140.29
 106.4.209.123
 106.4.241.59
@@ -10193,6 +10201,7 @@
 110.244.46.196
 110.244.48.104
 110.244.51.22
+110.247.151.4
 110.247.16.153
 110.247.16.64
 110.247.180.69
@@ -10817,6 +10826,7 @@
 111.165.186.127
 111.165.202.37
 111.165.207.179
+111.165.21.195
 111.165.210.227
 111.165.210.249
 111.165.214.179
@@ -10849,6 +10859,7 @@
 111.165.255.240
 111.165.26.73
 111.165.27.112
+111.165.28.234
 111.165.31.62
 111.165.33.132
 111.165.33.210
@@ -16984,6 +16995,7 @@
 112.246.18.70
 112.246.18.84
 112.246.18.99
+112.246.180.49
 112.246.181.139
 112.246.184.252
 112.246.184.97
@@ -17234,6 +17246,7 @@
 112.247.247.234
 112.247.248.114
 112.247.248.14
+112.247.248.76
 112.247.249.198
 112.247.249.82
 112.247.250.193
@@ -17921,6 +17934,7 @@
 112.249.205.67
 112.249.206.105
 112.249.206.52
+112.249.206.69
 112.249.206.8
 112.249.207.154
 112.249.207.198
@@ -18284,6 +18298,7 @@
 112.249.78.69
 112.249.79.230
 112.249.79.88
+112.249.79.98
 112.249.80.217
 112.249.80.53
 112.249.80.69
@@ -18566,6 +18581,7 @@
 112.252.41.80
 112.252.42.128
 112.252.43.218
+112.252.46.212
 112.252.59.78
 112.252.66.17
 112.252.66.55
@@ -20163,6 +20179,7 @@
 112.93.7.60
 112.93.89.37
 112.94.188.182
+112.94.188.230
 112.94.189.107
 112.95.12.157
 112.95.13.15
@@ -20528,6 +20545,7 @@
 113.104.237.236
 113.104.237.34
 113.104.237.36
+113.104.237.52
 113.104.237.72
 113.104.237.74
 113.104.237.83
@@ -21249,6 +21267,7 @@
 113.116.150.101
 113.116.150.110
 113.116.150.144
+113.116.150.147
 113.116.150.161
 113.116.150.176
 113.116.150.180
@@ -22454,6 +22473,7 @@
 113.118.13.222
 113.118.13.226
 113.118.13.26
+113.118.13.29
 113.118.13.44
 113.118.13.47
 113.118.13.50
@@ -23960,6 +23980,7 @@
 113.201.24.202
 113.201.24.206
 113.201.24.24
+113.201.24.26
 113.201.24.30
 113.201.24.4
 113.201.24.5
@@ -24401,6 +24422,7 @@
 113.234.185.255
 113.234.195.226
 113.234.197.125
+113.234.224.130
 113.234.224.160
 113.234.231.172
 113.234.231.202
@@ -25300,6 +25322,7 @@
 113.81.112.13
 113.81.112.159
 113.81.112.228
+113.81.112.35
 113.81.112.66
 113.81.112.72
 113.81.113.119
@@ -25821,6 +25844,7 @@
 113.87.248.159
 113.87.248.162
 113.87.248.163
+113.87.248.177
 113.87.248.181
 113.87.248.206
 113.87.248.28
@@ -26007,6 +26031,7 @@
 113.88.1.69
 113.88.100.105
 113.88.100.117
+113.88.100.120
 113.88.100.130
 113.88.100.160
 113.88.100.172
@@ -26632,6 +26657,7 @@
 113.88.241.9
 113.88.241.92
 113.88.241.98
+113.88.242.0
 113.88.242.1
 113.88.242.10
 113.88.242.116
@@ -26960,6 +26986,7 @@
 113.89.244.91
 113.89.244.93
 113.89.245.118
+113.89.245.13
 113.89.245.132
 113.89.245.144
 113.89.245.174
@@ -29688,6 +29715,7 @@
 115.171.238.92
 115.171.239.20
 115.171.239.25
+115.171.239.28
 115.171.90.159
 115.171.91.155
 115.171.91.195
@@ -29859,6 +29887,7 @@
 115.201.37.74
 115.201.37.84
 115.201.37.88
+115.201.38.185
 115.201.40.156
 115.201.40.65
 115.201.40.66
@@ -29932,6 +29961,7 @@
 115.202.187.124
 115.202.187.242
 115.202.187.61
+115.202.188.84
 115.202.210.224
 115.202.210.228
 115.202.214.217
@@ -30260,6 +30290,7 @@
 115.213.176.80
 115.213.186.121
 115.213.186.152
+115.213.187.251
 115.213.188.167
 115.213.198.25
 115.213.199.79
@@ -30753,6 +30784,7 @@
 115.48.130.177
 115.48.130.181
 115.48.130.184
+115.48.130.187
 115.48.130.193
 115.48.130.196
 115.48.130.197
@@ -30916,6 +30948,7 @@
 115.48.135.123
 115.48.135.126
 115.48.135.150
+115.48.135.151
 115.48.135.152
 115.48.135.154
 115.48.135.155
@@ -32470,6 +32503,7 @@
 115.48.200.103
 115.48.200.104
 115.48.200.114
+115.48.200.115
 115.48.200.124
 115.48.200.126
 115.48.200.134
@@ -33717,6 +33751,7 @@
 115.49.113.126
 115.49.113.59
 115.49.116.148
+115.49.116.237
 115.49.118.13
 115.49.12.164
 115.49.12.26
@@ -33834,6 +33869,7 @@
 115.49.150.203
 115.49.150.86
 115.49.151.207
+115.49.152.10
 115.49.152.116
 115.49.152.140
 115.49.152.89
@@ -34328,6 +34364,7 @@
 115.49.241.61
 115.49.241.87
 115.49.241.94
+115.49.242.100
 115.49.242.17
 115.49.242.79
 115.49.242.91
@@ -35160,6 +35197,7 @@
 115.49.79.87
 115.49.79.98
 115.49.8.244
+115.49.80.117
 115.49.80.149
 115.49.80.161
 115.49.80.74
@@ -37025,6 +37063,7 @@
 115.50.201.85
 115.50.201.87
 115.50.201.91
+115.50.202.11
 115.50.202.13
 115.50.202.131
 115.50.202.157
@@ -38459,6 +38498,7 @@
 115.50.240.216
 115.50.240.220
 115.50.240.228
+115.50.240.230
 115.50.240.237
 115.50.240.252
 115.50.240.27
@@ -39875,6 +39915,7 @@
 115.50.61.228
 115.50.61.23
 115.50.61.233
+115.50.61.247
 115.50.61.25
 115.50.61.252
 115.50.61.254
@@ -40007,6 +40048,7 @@
 115.50.64.177
 115.50.64.178
 115.50.64.179
+115.50.64.182
 115.50.64.189
 115.50.64.212
 115.50.64.229
@@ -41126,6 +41168,7 @@
 115.51.107.156
 115.51.107.163
 115.51.107.164
+115.51.107.18
 115.51.107.183
 115.51.107.193
 115.51.107.195
@@ -42443,6 +42486,7 @@
 115.52.20.97
 115.52.200.245
 115.52.201.220
+115.52.201.231
 115.52.201.254
 115.52.202.73
 115.52.204.80
@@ -42486,6 +42530,7 @@
 115.52.22.140
 115.52.22.145
 115.52.22.149
+115.52.22.162
 115.52.22.166
 115.52.22.177
 115.52.22.19
@@ -42742,6 +42787,7 @@
 115.52.35.151
 115.52.35.6
 115.52.36.27
+115.52.37.164
 115.52.38.110
 115.52.38.132
 115.52.38.182
@@ -43946,6 +43992,7 @@
 115.54.159.16
 115.54.159.206
 115.54.159.33
+115.54.160.25
 115.54.168.18
 115.54.168.190
 115.54.168.237
@@ -44732,6 +44779,7 @@
 115.54.212.205
 115.54.212.207
 115.54.212.22
+115.54.212.227
 115.54.212.233
 115.54.212.239
 115.54.212.249
@@ -45045,6 +45093,7 @@
 115.54.240.128
 115.54.240.166
 115.54.240.170
+115.54.240.173
 115.54.240.195
 115.54.240.197
 115.54.240.198
@@ -45220,6 +45269,7 @@
 115.54.69.60
 115.54.69.89
 115.54.69.9
+115.54.70.108
 115.54.70.139
 115.54.70.150
 115.54.70.161
@@ -45266,6 +45316,7 @@
 115.54.73.254
 115.54.73.37
 115.54.73.42
+115.54.73.50
 115.54.73.51
 115.54.74.109
 115.54.74.142
@@ -48107,6 +48158,7 @@
 115.55.211.247
 115.55.211.251
 115.55.211.4
+115.55.211.41
 115.55.211.48
 115.55.211.54
 115.55.211.75
@@ -48509,6 +48561,7 @@
 115.55.3.155
 115.55.3.20
 115.55.3.204
+115.55.3.36
 115.55.3.54
 115.55.30.105
 115.55.30.138
@@ -49825,6 +49878,7 @@
 115.56.136.124
 115.56.136.127
 115.56.136.141
+115.56.136.144
 115.56.136.145
 115.56.136.146
 115.56.136.154
@@ -50715,6 +50769,7 @@
 115.56.154.14
 115.56.154.142
 115.56.154.145
+115.56.154.147
 115.56.154.164
 115.56.154.17
 115.56.154.173
@@ -50832,6 +50887,7 @@
 115.56.156.30
 115.56.156.39
 115.56.156.53
+115.56.156.54
 115.56.156.55
 115.56.156.6
 115.56.156.62
@@ -51162,6 +51218,7 @@
 115.56.177.192
 115.56.177.198
 115.56.177.2
+115.56.177.202
 115.56.177.205
 115.56.177.214
 115.56.177.220
@@ -52962,6 +53019,7 @@
 115.58.132.194
 115.58.132.196
 115.58.132.197
+115.58.132.199
 115.58.132.2
 115.58.132.205
 115.58.132.211
@@ -53607,6 +53665,7 @@
 115.58.167.23
 115.58.167.50
 115.58.167.78
+115.58.167.90
 115.58.168.104
 115.58.168.117
 115.58.168.14
@@ -53746,6 +53805,7 @@
 115.58.20.147
 115.58.20.152
 115.58.20.180
+115.58.20.186
 115.58.20.193
 115.58.20.197
 115.58.20.199
@@ -55039,6 +55099,7 @@
 115.59.198.181
 115.59.198.184
 115.59.198.194
+115.59.198.200
 115.59.198.211
 115.59.198.215
 115.59.198.218
@@ -55590,6 +55651,7 @@
 115.59.215.74
 115.59.215.8
 115.59.215.95
+115.59.215.96
 115.59.215.99
 115.59.216.103
 115.59.216.106
@@ -57072,6 +57134,7 @@
 115.59.90.149
 115.59.90.155
 115.59.90.182
+115.59.90.197
 115.59.90.204
 115.59.90.22
 115.59.90.236
@@ -57194,6 +57257,7 @@
 115.60.201.105
 115.60.201.142
 115.60.201.144
+115.60.201.176
 115.60.201.181
 115.60.201.186
 115.60.201.21
@@ -57841,6 +57905,7 @@
 115.61.118.182
 115.61.118.185
 115.61.118.189
+115.61.118.201
 115.61.118.210
 115.61.118.226
 115.61.118.245
@@ -59520,6 +59585,7 @@
 115.61.97.250
 115.61.97.39
 115.61.97.46
+115.61.97.55
 115.61.97.63
 115.61.97.65
 115.61.97.70
@@ -59752,6 +59818,7 @@
 115.62.152.143
 115.62.152.144
 115.62.152.206
+115.62.152.207
 115.62.152.37
 115.62.152.55
 115.62.152.70
@@ -60266,6 +60333,7 @@
 115.63.130.140
 115.63.130.150
 115.63.130.161
+115.63.130.162
 115.63.130.169
 115.63.130.170
 115.63.130.173
@@ -60566,6 +60634,7 @@
 115.63.140.216
 115.63.140.218
 115.63.140.236
+115.63.140.242
 115.63.140.27
 115.63.140.32
 115.63.140.39
@@ -66909,6 +66978,7 @@
 115.96.87.95
 115.96.88.171
 115.96.90.226
+115.96.92.151
 115.96.94.114
 115.97.102.100
 115.97.102.102
@@ -68385,6 +68455,7 @@
 115.97.142.175
 115.97.142.176
 115.97.142.178
+115.97.142.18
 115.97.142.180
 115.97.142.182
 115.97.142.188
@@ -91410,6 +91481,7 @@
 116.24.152.157
 116.24.152.158
 116.24.152.164
+116.24.152.217
 116.24.152.245
 116.24.152.34
 116.24.152.80
@@ -94036,6 +94108,7 @@
 116.72.202.80
 116.72.202.81
 116.72.202.83
+116.72.202.87
 116.72.202.89
 116.72.202.90
 116.72.202.92
@@ -94077,6 +94150,7 @@
 116.72.203.14
 116.72.203.141
 116.72.203.142
+116.72.203.143
 116.72.203.145
 116.72.203.146
 116.72.203.148
@@ -102333,6 +102407,7 @@
 116.74.83.90
 116.74.83.94
 116.74.83.98
+116.74.84.65
 116.74.85.1
 116.74.85.131
 116.74.87.107
@@ -105657,6 +105732,7 @@
 116.75.194.137
 116.75.194.138
 116.75.194.139
+116.75.194.14
 116.75.194.140
 116.75.194.141
 116.75.194.143
@@ -107851,6 +107927,7 @@
 116.75.214.51
 116.75.214.52
 116.75.214.53
+116.75.214.56
 116.75.214.58
 116.75.214.59
 116.75.214.6
@@ -107880,6 +107957,7 @@
 116.75.214.96
 116.75.214.97
 116.75.214.98
+116.75.214.99
 116.75.215.0
 116.75.215.1
 116.75.215.100
@@ -112646,6 +112724,7 @@
 117.194.149.247
 117.194.149.250
 117.194.149.252
+117.194.149.26
 117.194.149.28
 117.194.149.33
 117.194.149.37
@@ -112990,6 +113069,7 @@
 117.194.160.8
 117.194.160.81
 117.194.160.83
+117.194.160.84
 117.194.160.85
 117.194.160.87
 117.194.160.88
@@ -116423,6 +116503,7 @@
 117.202.70.224
 117.202.70.225
 117.202.70.226
+117.202.70.227
 117.202.70.228
 117.202.70.229
 117.202.70.23
@@ -118621,6 +118702,7 @@
 117.213.11.106
 117.213.11.136
 117.213.11.205
+117.213.11.225
 117.213.11.47
 117.213.11.50
 117.213.11.8
@@ -119040,6 +119122,7 @@
 117.213.42.153
 117.213.42.154
 117.213.42.157
+117.213.42.158
 117.213.42.159
 117.213.42.16
 117.213.42.160
@@ -120079,6 +120162,7 @@
 117.213.9.58
 117.213.9.71
 117.213.9.77
+117.213.9.78
 117.214.11.249
 117.214.11.8
 117.214.242.73
@@ -120376,6 +120460,7 @@
 117.215.248.208
 117.215.248.214
 117.215.248.217
+117.215.248.223
 117.215.248.23
 117.215.248.237
 117.215.248.242
@@ -120414,6 +120499,7 @@
 117.215.249.20
 117.215.249.22
 117.215.249.221
+117.215.249.23
 117.215.249.230
 117.215.249.240
 117.215.249.241
@@ -121001,6 +121087,7 @@
 117.222.161.65
 117.222.161.66
 117.222.161.67
+117.222.161.68
 117.222.161.7
 117.222.161.70
 117.222.161.74
@@ -121269,6 +121356,7 @@
 117.222.163.148
 117.222.163.149
 117.222.163.15
+117.222.163.150
 117.222.163.151
 117.222.163.153
 117.222.163.154
@@ -121395,6 +121483,7 @@
 117.222.163.59
 117.222.163.6
 117.222.163.60
+117.222.163.61
 117.222.163.62
 117.222.163.63
 117.222.163.65
@@ -121406,6 +121495,7 @@
 117.222.163.70
 117.222.163.71
 117.222.163.72
+117.222.163.73
 117.222.163.74
 117.222.163.77
 117.222.163.78
@@ -121773,6 +121863,7 @@
 117.222.165.28
 117.222.165.29
 117.222.165.3
+117.222.165.31
 117.222.165.32
 117.222.165.33
 117.222.165.34
@@ -122220,6 +122311,7 @@
 117.222.168.114
 117.222.168.115
 117.222.168.116
+117.222.168.119
 117.222.168.122
 117.222.168.123
 117.222.168.124
@@ -122240,6 +122332,7 @@
 117.222.168.181
 117.222.168.183
 117.222.168.185
+117.222.168.186
 117.222.168.191
 117.222.168.194
 117.222.168.195
@@ -122306,6 +122399,7 @@
 117.222.169.112
 117.222.169.113
 117.222.169.114
+117.222.169.115
 117.222.169.117
 117.222.169.12
 117.222.169.124
@@ -122521,6 +122615,7 @@
 117.222.171.192
 117.222.171.202
 117.222.171.203
+117.222.171.205
 117.222.171.209
 117.222.171.217
 117.222.171.218
@@ -122669,6 +122764,7 @@
 117.222.172.9
 117.222.172.92
 117.222.172.94
+117.222.172.97
 117.222.172.98
 117.222.173.10
 117.222.173.100
@@ -124123,6 +124219,7 @@
 117.242.210.65
 117.242.210.67
 117.242.210.68
+117.242.210.69
 117.242.210.7
 117.242.210.70
 117.242.210.71
@@ -124671,6 +124768,7 @@
 117.247.200.169
 117.247.200.170
 117.247.200.172
+117.247.200.179
 117.247.200.181
 117.247.200.182
 117.247.200.185
@@ -124749,6 +124847,7 @@
 117.247.201.156
 117.247.201.158
 117.247.201.161
+117.247.201.163
 117.247.201.172
 117.247.201.175
 117.247.201.179
@@ -124870,6 +124969,7 @@
 117.247.202.31
 117.247.202.32
 117.247.202.37
+117.247.202.4
 117.247.202.46
 117.247.202.48
 117.247.202.50
@@ -124971,6 +125071,7 @@
 117.247.203.3
 117.247.203.31
 117.247.203.33
+117.247.203.38
 117.247.203.39
 117.247.203.40
 117.247.203.45
@@ -126644,6 +126745,7 @@
 117.251.59.232
 117.251.59.237
 117.251.59.24
+117.251.59.242
 117.251.59.243
 117.251.59.244
 117.251.59.246
@@ -127506,6 +127608,7 @@
 117.63.51.128
 117.63.53.15
 117.63.53.172
+117.63.56.81
 117.63.69.253
 117.63.7.177
 117.63.7.192
@@ -127569,6 +127672,7 @@
 117.85.89.213
 117.85.95.220
 117.86.1.7
+117.86.105.110
 117.86.110.91
 117.86.148.199
 117.86.155.77
@@ -127807,6 +127911,7 @@
 117.91.156.66
 117.91.172.11
 117.91.172.49
+117.91.240.50
 117.91.241.17
 117.92.177.76
 117.92.196.126
@@ -129135,6 +129240,7 @@
 118.75.114.227
 118.75.115.154
 118.75.119.214
+118.75.120.136
 118.75.120.209
 118.75.120.229
 118.75.120.98
@@ -129263,6 +129369,7 @@
 118.75.236.238
 118.75.239.142
 118.75.240.141
+118.75.240.239
 118.75.240.9
 118.75.241.204
 118.75.241.26
@@ -129574,6 +129681,7 @@
 118.79.163.61
 118.79.163.86
 118.79.163.91
+118.79.164.102
 118.79.164.108
 118.79.167.240
 118.79.167.41
@@ -130606,6 +130714,7 @@
 119.123.175.124
 119.123.175.126
 119.123.175.128
+119.123.175.133
 119.123.175.139
 119.123.175.144
 119.123.175.145
@@ -131796,6 +131905,7 @@
 119.165.207.118
 119.165.208.188
 119.165.208.216
+119.165.208.73
 119.165.209.0
 119.165.209.121
 119.165.209.127
@@ -132946,6 +133056,7 @@
 119.179.42.247
 119.179.43.1
 119.179.43.27
+119.179.44.141
 119.179.44.157
 119.179.44.192
 119.179.45.108
@@ -133421,6 +133532,7 @@
 119.180.9.183
 119.180.9.209
 119.180.9.241
+119.180.9.35
 119.180.90.121
 119.180.92.176
 119.180.92.224
@@ -135245,6 +135357,7 @@
 119.250.10.222
 119.250.117.131
 119.250.119.227
+119.250.129.231
 119.250.132.83
 119.250.166.153
 119.250.218.177
@@ -135771,6 +135884,7 @@
 120.12.211.237
 120.12.212.231
 120.12.212.234
+120.12.212.5
 120.12.213.82
 120.12.217.158
 120.12.217.9
@@ -136956,6 +137070,7 @@
 120.57.102.243
 120.57.102.246
 120.57.102.254
+120.57.102.32
 120.57.102.46
 120.57.102.5
 120.57.102.58
@@ -139438,6 +139553,7 @@
 120.82.169.73
 120.82.170.40
 120.82.170.75
+120.82.217.176
 120.82.217.197
 120.82.228.185
 120.82.38.219
@@ -139761,6 +139877,7 @@
 120.85.173.121
 120.85.173.126
 120.85.173.135
+120.85.173.137
 120.85.173.143
 120.85.173.145
 120.85.173.149
@@ -139806,6 +139923,7 @@
 120.85.174.24
 120.85.174.30
 120.85.174.38
+120.85.174.39
 120.85.174.41
 120.85.174.42
 120.85.174.45
@@ -140062,6 +140180,7 @@
 120.85.199.184
 120.85.199.19
 120.85.199.195
+120.85.199.222
 120.85.199.242
 120.85.199.247
 120.85.199.253
@@ -140183,6 +140302,7 @@
 120.85.211.82
 120.85.211.84
 120.85.211.85
+120.85.212.45
 120.85.232.107
 120.85.232.64
 120.85.234.15
@@ -140282,6 +140402,7 @@
 120.85.238.80
 120.85.238.87
 120.85.238.89
+120.85.238.97
 120.85.239.100
 120.85.239.11
 120.85.239.113
@@ -140698,6 +140819,7 @@
 121.154.163.88
 121.154.190.19
 121.154.190.232
+121.154.190.73
 121.154.226.39
 121.154.37.14
 121.154.39.26
@@ -141693,6 +141815,7 @@
 121.34.150.234
 121.34.150.251
 121.34.150.27
+121.34.150.32
 121.34.150.36
 121.34.150.43
 121.34.150.45
@@ -142486,6 +142609,7 @@
 122.188.61.157
 122.188.61.231
 122.188.61.239
+122.188.86.225
 122.189.101.23
 122.189.105.132
 122.189.105.250
@@ -142495,6 +142619,7 @@
 122.189.7.14
 122.190.115.86
 122.190.19.131
+122.190.19.204
 122.190.192.182
 122.190.192.92
 122.190.244.85
@@ -143088,6 +143213,7 @@
 123.10.131.179
 123.10.131.204
 123.10.131.223
+123.10.131.225
 123.10.131.245
 123.10.131.251
 123.10.131.47
@@ -143750,6 +143876,7 @@
 123.10.209.61
 123.10.209.65
 123.10.209.87
+123.10.209.95
 123.10.21.116
 123.10.21.172
 123.10.21.184
@@ -143794,6 +143921,7 @@
 123.10.214.114
 123.10.214.129
 123.10.214.174
+123.10.214.193
 123.10.214.25
 123.10.214.60
 123.10.214.75
@@ -144547,6 +144675,7 @@
 123.10.82.119
 123.10.82.192
 123.10.82.228
+123.10.83.136
 123.10.84.166
 123.10.84.18
 123.10.84.187
@@ -145331,6 +145460,7 @@
 123.11.174.47
 123.11.174.61
 123.11.175.108
+123.11.175.136
 123.11.175.190
 123.11.175.197
 123.11.175.227
@@ -147111,6 +147241,7 @@
 123.12.229.211
 123.12.229.232
 123.12.229.24
+123.12.229.243
 123.12.229.25
 123.12.229.252
 123.12.229.253
@@ -147528,6 +147659,7 @@
 123.12.35.198
 123.12.35.29
 123.12.36.167
+123.12.36.185
 123.12.36.193
 123.12.36.3
 123.12.36.54
@@ -148136,6 +148268,7 @@
 123.13.100.254
 123.13.101.202
 123.13.101.30
+123.13.101.56
 123.13.102.179
 123.13.102.204
 123.13.102.205
@@ -148442,6 +148575,7 @@
 123.13.30.167
 123.13.30.2
 123.13.30.219
+123.13.30.75
 123.13.31.104
 123.13.31.144
 123.13.31.175
@@ -150448,6 +150582,7 @@
 123.14.205.198
 123.14.205.212
 123.14.205.223
+123.14.205.23
 123.14.205.236
 123.14.205.241
 123.14.205.246
@@ -152259,6 +152394,7 @@
 123.183.123.153
 123.183.123.187
 123.183.123.212
+123.183.123.41
 123.183.123.5
 123.183.124.131
 123.183.124.18
@@ -153690,6 +153826,7 @@
 123.4.179.75
 123.4.179.8
 123.4.179.82
+123.4.180.137
 123.4.180.152
 123.4.180.156
 123.4.180.171
@@ -153737,6 +153874,7 @@
 123.4.184.8
 123.4.185.112
 123.4.185.12
+123.4.185.137
 123.4.185.14
 123.4.185.168
 123.4.185.220
@@ -156552,6 +156690,7 @@
 123.5.145.23
 123.5.145.233
 123.5.145.242
+123.5.145.245
 123.5.145.248
 123.5.145.42
 123.5.145.55
@@ -157748,6 +157887,7 @@
 123.5.22.110
 123.5.22.175
 123.5.22.210
+123.5.22.220
 123.5.22.221
 123.5.22.238
 123.5.22.49
@@ -158426,6 +158566,7 @@
 123.8.183.124
 123.8.183.145
 123.8.183.185
+123.8.183.194
 123.8.183.207
 123.8.183.31
 123.8.183.46
@@ -159422,6 +159563,7 @@
 123.9.103.190
 123.9.103.200
 123.9.103.23
+123.9.103.252
 123.9.103.36
 123.9.103.53
 123.9.103.61
@@ -161542,6 +161684,7 @@
 124.130.31.18
 124.130.40.15
 124.130.40.162
+124.130.40.31
 124.130.56.200
 124.130.56.42
 124.130.57.12
@@ -162185,6 +162328,7 @@
 124.131.24.86
 124.131.25.69
 124.131.26.238
+124.131.26.243
 124.131.26.78
 124.131.28.172
 124.131.28.196
@@ -163597,6 +163741,7 @@
 124.94.244.153
 124.94.57.133
 124.95.16.252
+124.95.17.41
 124.95.81.24
 124.com.ua
 124.cpanel.realwebsitesite.com
@@ -164013,6 +164158,7 @@
 125.126.66.6
 125.126.67.145
 125.126.69.198
+125.126.69.95
 125.126.71.207
 125.126.72.174
 125.126.73.123
@@ -164143,6 +164289,7 @@
 125.160.137.80
 125.160.213.219
 125.161.14.114
+125.161.70.34
 125.161.96.233
 125.162.65.174
 125.163.199.90
@@ -164928,6 +165075,7 @@
 125.40.136.22
 125.40.136.220
 125.40.136.222
+125.40.136.25
 125.40.136.252
 125.40.136.253
 125.40.136.33
@@ -165473,6 +165621,7 @@
 125.40.234.169
 125.40.234.73
 125.40.235.80
+125.40.237.130
 125.40.24.117
 125.40.24.134
 125.40.24.143
@@ -167352,6 +167501,7 @@
 125.41.200.172
 125.41.200.181
 125.41.200.188
+125.41.200.189
 125.41.200.193
 125.41.200.203
 125.41.200.210
@@ -169353,6 +169503,7 @@
 125.42.120.98
 125.42.121.101
 125.42.121.103
+125.42.121.106
 125.42.121.108
 125.42.121.109
 125.42.121.11
@@ -169652,6 +169803,7 @@
 125.42.124.88
 125.42.124.93
 125.42.124.97
+125.42.125.103
 125.42.125.107
 125.42.125.110
 125.42.125.115
@@ -170455,6 +170607,7 @@
 125.42.97.100
 125.42.97.101
 125.42.97.102
+125.42.97.103
 125.42.97.119
 125.42.97.122
 125.42.97.123
@@ -170713,6 +170866,7 @@
 125.43.105.129
 125.43.105.135
 125.43.105.149
+125.43.105.157
 125.43.105.158
 125.43.105.168
 125.43.105.172
@@ -170997,6 +171151,7 @@
 125.43.13.92
 125.43.130.108
 125.43.130.23
+125.43.130.232
 125.43.130.24
 125.43.131.111
 125.43.131.182
@@ -171345,6 +171500,7 @@
 125.43.21.146
 125.43.21.147
 125.43.21.152
+125.43.21.157
 125.43.21.159
 125.43.21.161
 125.43.21.174
@@ -174472,6 +174628,7 @@
 125.44.211.83
 125.44.211.98
 125.44.212.105
+125.44.212.107
 125.44.212.108
 125.44.212.109
 125.44.212.114
@@ -174932,6 +175089,7 @@
 125.44.230.125
 125.44.230.164
 125.44.230.176
+125.44.230.191
 125.44.230.200
 125.44.230.226
 125.44.230.244
@@ -175394,6 +175552,7 @@
 125.44.31.61
 125.44.31.64
 125.44.31.69
+125.44.31.79
 125.44.31.8
 125.44.31.82
 125.44.31.84
@@ -176646,6 +176805,7 @@
 125.45.57.231
 125.45.57.238
 125.45.57.247
+125.45.57.249
 125.45.57.35
 125.45.57.46
 125.45.57.50
@@ -177196,6 +177356,7 @@
 125.45.90.131
 125.45.90.151
 125.45.90.153
+125.45.90.158
 125.45.90.16
 125.45.90.184
 125.45.90.189
@@ -177314,6 +177475,7 @@
 125.46.137.54
 125.46.138.0
 125.46.138.10
+125.46.138.117
 125.46.138.122
 125.46.138.149
 125.46.138.151
@@ -179992,6 +180154,7 @@
 125.47.251.96
 125.47.251.98
 125.47.252.105
+125.47.252.106
 125.47.252.107
 125.47.252.109
 125.47.252.110
@@ -180209,6 +180372,7 @@
 125.47.255.94
 125.47.255.97
 125.47.28.150
+125.47.28.217
 125.47.29.173
 125.47.29.191
 125.47.32.201
@@ -182341,10 +182505,12 @@
 125.99.207.92
 125.99.212.13
 125.99.220.105
+125.99.220.202
 125.99.222.152
 125.99.222.245
 125.99.222.76
 125.99.223.227
+125.99.223.26
 125.99.224.101
 125.99.224.102
 125.99.224.106
@@ -184210,6 +184376,7 @@
 134.209.202.202
 134.209.203.101
 134.209.203.205
+134.209.203.221
 134.209.203.223
 134.209.203.70
 134.209.204.77
@@ -184717,6 +184884,7 @@
 139.170.181.68
 139.170.200.29
 139.170.206.148
+139.170.228.166
 139.170.228.217
 139.170.228.55
 139.170.230.204
@@ -186129,6 +186297,7 @@
 140.237.255.239
 140.237.28.148
 140.237.29.28
+140.237.30.113
 140.237.30.179
 140.237.30.188
 140.237.31.197
@@ -186139,6 +186308,7 @@
 140.237.4.82
 140.237.5.254
 140.237.5.41
+140.237.5.43
 140.240.100.181
 140.240.100.94
 140.240.102.181
@@ -186927,6 +187097,8 @@
 149.255.15.121
 149.255.15.180
 149.255.15.182
+149.255.15.191
+149.255.15.235
 149.255.15.87
 149.255.36.133
 149.255.36.156
@@ -187177,6 +187349,7 @@
 151.226.2.198
 151.227.42.63
 151.232.180.152
+151.232.249.222
 151.232.56.134
 151.233.52.223
 151.233.56.139
@@ -187311,6 +187484,7 @@
 152.173.25.125
 152.231.127.54
 152.231.25.253
+152.241.13.197
 152.241.13.246
 152.241.24.181
 152.241.33.96
@@ -187543,6 +187717,7 @@
 153.34.65.168
 153.34.67.119
 153.34.86.53
+153.35.111.46
 153.35.141.25
 153.35.141.60
 153.35.141.74
@@ -187743,6 +187918,7 @@
 157.119.214.172
 157.119.214.233
 157.119.215.224
+157.122.105.142
 157.122.106.12
 157.230.0.237
 157.230.1.18
@@ -189493,6 +189669,7 @@
 163.125.181.187
 163.125.181.76
 163.125.181.87
+163.125.183.111
 163.125.183.142
 163.125.183.180
 163.125.183.75
@@ -189617,6 +189794,7 @@
 163.125.200.6
 163.125.200.64
 163.125.200.70
+163.125.200.72
 163.125.200.73
 163.125.200.75
 163.125.200.76
@@ -189674,6 +189852,7 @@
 163.125.202.158
 163.125.202.159
 163.125.202.16
+163.125.202.174
 163.125.202.183
 163.125.202.186
 163.125.202.190
@@ -189691,6 +189870,7 @@
 163.125.202.4
 163.125.202.57
 163.125.202.72
+163.125.202.74
 163.125.202.8
 163.125.202.83
 163.125.202.9
@@ -189701,6 +189881,7 @@
 163.125.203.146
 163.125.203.148
 163.125.203.154
+163.125.203.179
 163.125.203.184
 163.125.203.198
 163.125.203.200
@@ -189779,6 +189960,7 @@
 163.125.207.0
 163.125.207.102
 163.125.207.116
+163.125.207.125
 163.125.207.140
 163.125.207.143
 163.125.207.158
@@ -189863,6 +190045,7 @@
 163.125.248.230
 163.125.248.254
 163.125.250.176
+163.125.250.202
 163.125.251.214
 163.125.251.225
 163.125.251.227
@@ -189884,6 +190067,7 @@
 163.125.30.28
 163.125.31.183
 163.125.34.24
+163.125.37.201
 163.125.38.226
 163.125.4.131
 163.125.4.147
@@ -189927,6 +190111,7 @@
 163.125.68.229
 163.125.68.240
 163.125.68.243
+163.125.68.29
 163.125.68.31
 163.125.68.65
 163.125.68.7
@@ -192417,6 +192602,7 @@
 171.125.65.115
 171.125.65.193
 171.125.65.202
+171.125.65.22
 171.125.66.6
 171.125.68.45
 171.125.7.181
@@ -192668,6 +192854,7 @@
 171.34.114.167
 171.34.114.179
 171.34.114.180
+171.34.114.181
 171.34.114.215
 171.34.114.217
 171.34.114.227
@@ -192879,6 +193066,7 @@
 171.36.251.189
 171.36.251.66
 171.36.41.151
+171.36.42.154
 171.36.42.159
 171.36.42.3
 171.36.42.39
@@ -193574,6 +193762,7 @@
 172.245.5.120
 172.245.5.122
 172.245.5.185
+172.245.5.190
 172.245.52.102
 172.245.52.122
 172.245.52.160
@@ -196965,6 +197154,7 @@
 175.11.193.118
 175.11.193.122
 175.11.193.157
+175.11.193.66
 175.11.193.71
 175.11.193.82
 175.11.194.130
@@ -197125,6 +197315,7 @@
 175.145.200.51
 175.146.121.210
 175.146.16.118
+175.146.17.227
 175.146.18.195
 175.146.19.126
 175.146.20.229
@@ -200175,6 +200366,7 @@
 178.141.159.159
 178.141.16.64
 178.141.160.15
+178.141.161.129
 178.141.162.124
 178.141.162.211
 178.141.162.8
@@ -200568,8 +200760,10 @@
 178.175.0.225
 178.175.0.226
 178.175.0.229
+178.175.0.232
 178.175.0.234
 178.175.0.236
+178.175.0.239
 178.175.0.241
 178.175.0.246
 178.175.0.249
@@ -200639,6 +200833,7 @@
 178.175.1.178
 178.175.1.179
 178.175.1.186
+178.175.1.187
 178.175.1.188
 178.175.1.193
 178.175.1.194
@@ -200658,6 +200853,7 @@
 178.175.1.247
 178.175.1.25
 178.175.1.250
+178.175.1.252
 178.175.1.255
 178.175.1.26
 178.175.1.28
@@ -200733,8 +200929,10 @@
 178.175.10.255
 178.175.10.26
 178.175.10.28
+178.175.10.34
 178.175.10.37
 178.175.10.41
+178.175.10.42
 178.175.10.44
 178.175.10.46
 178.175.10.50
@@ -200881,6 +201079,7 @@
 178.175.101.203
 178.175.101.204
 178.175.101.205
+178.175.101.207
 178.175.101.208
 178.175.101.209
 178.175.101.21
@@ -200989,6 +201188,7 @@
 178.175.102.216
 178.175.102.22
 178.175.102.220
+178.175.102.221
 178.175.102.223
 178.175.102.225
 178.175.102.227
@@ -201124,6 +201324,7 @@
 178.175.104.104
 178.175.104.106
 178.175.104.11
+178.175.104.110
 178.175.104.112
 178.175.104.114
 178.175.104.116
@@ -201145,6 +201346,7 @@
 178.175.104.152
 178.175.104.153
 178.175.104.154
+178.175.104.155
 178.175.104.158
 178.175.104.16
 178.175.104.161
@@ -201200,6 +201402,7 @@
 178.175.104.54
 178.175.104.59
 178.175.104.62
+178.175.104.64
 178.175.104.66
 178.175.104.69
 178.175.104.80
@@ -201228,6 +201431,7 @@
 178.175.105.121
 178.175.105.122
 178.175.105.124
+178.175.105.125
 178.175.105.130
 178.175.105.131
 178.175.105.143
@@ -201280,6 +201484,7 @@
 178.175.105.255
 178.175.105.26
 178.175.105.27
+178.175.105.28
 178.175.105.29
 178.175.105.3
 178.175.105.30
@@ -201309,6 +201514,7 @@
 178.175.105.90
 178.175.105.91
 178.175.105.93
+178.175.105.94
 178.175.105.96
 178.175.106.100
 178.175.106.102
@@ -201365,6 +201571,7 @@
 178.175.106.219
 178.175.106.22
 178.175.106.220
+178.175.106.222
 178.175.106.224
 178.175.106.226
 178.175.106.228
@@ -201380,6 +201587,7 @@
 178.175.106.25
 178.175.106.251
 178.175.106.252
+178.175.106.253
 178.175.106.27
 178.175.106.28
 178.175.106.31
@@ -201577,6 +201785,7 @@
 178.175.108.227
 178.175.108.229
 178.175.108.23
+178.175.108.232
 178.175.108.237
 178.175.108.239
 178.175.108.24
@@ -201616,6 +201825,7 @@
 178.175.108.88
 178.175.108.90
 178.175.108.93
+178.175.108.94
 178.175.108.97
 178.175.108.98
 178.175.108.99
@@ -201631,6 +201841,7 @@
 178.175.109.121
 178.175.109.123
 178.175.109.126
+178.175.109.127
 178.175.109.132
 178.175.109.134
 178.175.109.137
@@ -201656,6 +201867,7 @@
 178.175.109.19
 178.175.109.190
 178.175.109.191
+178.175.109.193
 178.175.109.195
 178.175.109.196
 178.175.109.198
@@ -201700,6 +201912,7 @@
 178.175.109.71
 178.175.109.75
 178.175.109.77
+178.175.109.78
 178.175.109.82
 178.175.109.83
 178.175.109.86
@@ -202102,6 +202315,7 @@
 178.175.112.90
 178.175.112.97
 178.175.112.99
+178.175.113.0
 178.175.113.100
 178.175.113.106
 178.175.113.112
@@ -202265,6 +202479,7 @@
 178.175.114.242
 178.175.114.244
 178.175.114.245
+178.175.114.247
 178.175.114.250
 178.175.114.251
 178.175.114.254
@@ -202314,6 +202529,7 @@
 178.175.115.112
 178.175.115.113
 178.175.115.116
+178.175.115.12
 178.175.115.125
 178.175.115.126
 178.175.115.127
@@ -202357,6 +202573,7 @@
 178.175.115.20
 178.175.115.202
 178.175.115.205
+178.175.115.206
 178.175.115.207
 178.175.115.208
 178.175.115.209
@@ -202390,6 +202607,7 @@
 178.175.115.37
 178.175.115.39
 178.175.115.4
+178.175.115.40
 178.175.115.43
 178.175.115.45
 178.175.115.46
@@ -202438,6 +202656,7 @@
 178.175.116.143
 178.175.116.145
 178.175.116.147
+178.175.116.15
 178.175.116.150
 178.175.116.152
 178.175.116.154
@@ -202472,6 +202691,7 @@
 178.175.116.226
 178.175.116.228
 178.175.116.23
+178.175.116.236
 178.175.116.237
 178.175.116.238
 178.175.116.24
@@ -202639,6 +202859,7 @@
 178.175.118.133
 178.175.118.137
 178.175.118.138
+178.175.118.139
 178.175.118.141
 178.175.118.143
 178.175.118.144
@@ -202824,6 +203045,7 @@
 178.175.12.109
 178.175.12.11
 178.175.12.111
+178.175.12.114
 178.175.12.118
 178.175.12.12
 178.175.12.123
@@ -202944,6 +203166,7 @@
 178.175.120.189
 178.175.120.191
 178.175.120.193
+178.175.120.196
 178.175.120.197
 178.175.120.20
 178.175.120.203
@@ -203169,6 +203392,7 @@
 178.175.122.246
 178.175.122.252
 178.175.122.254
+178.175.122.26
 178.175.122.27
 178.175.122.28
 178.175.122.3
@@ -203612,6 +203836,7 @@
 178.175.126.93
 178.175.126.95
 178.175.126.99
+178.175.127.10
 178.175.127.100
 178.175.127.102
 178.175.127.106
@@ -203627,6 +203852,7 @@
 178.175.127.120
 178.175.127.122
 178.175.127.125
+178.175.127.129
 178.175.127.13
 178.175.127.130
 178.175.127.133
@@ -203656,6 +203882,7 @@
 178.175.127.185
 178.175.127.19
 178.175.127.190
+178.175.127.192
 178.175.127.195
 178.175.127.197
 178.175.127.198
@@ -203678,6 +203905,7 @@
 178.175.127.231
 178.175.127.236
 178.175.127.237
+178.175.127.238
 178.175.127.24
 178.175.127.240
 178.175.127.242
@@ -203919,6 +204147,7 @@
 178.175.15.225
 178.175.15.228
 178.175.15.229
+178.175.15.232
 178.175.15.233
 178.175.15.236
 178.175.15.238
@@ -203927,6 +204156,7 @@
 178.175.15.241
 178.175.15.244
 178.175.15.245
+178.175.15.246
 178.175.15.248
 178.175.15.25
 178.175.15.250
@@ -203941,6 +204171,7 @@
 178.175.15.35
 178.175.15.37
 178.175.15.38
+178.175.15.44
 178.175.15.45
 178.175.15.47
 178.175.15.48
@@ -203969,10 +204200,12 @@
 178.175.15.97
 178.175.15.99
 178.175.16.1
+178.175.16.10
 178.175.16.108
 178.175.16.110
 178.175.16.112
 178.175.16.113
+178.175.16.114
 178.175.16.115
 178.175.16.118
 178.175.16.12
@@ -204004,6 +204237,7 @@
 178.175.16.181
 178.175.16.186
 178.175.16.189
+178.175.16.193
 178.175.16.195
 178.175.16.196
 178.175.16.205
@@ -204175,6 +204409,7 @@
 178.175.18.249
 178.175.18.250
 178.175.18.253
+178.175.18.27
 178.175.18.32
 178.175.18.42
 178.175.18.45
@@ -204246,6 +204481,7 @@
 178.175.19.224
 178.175.19.225
 178.175.19.227
+178.175.19.229
 178.175.19.232
 178.175.19.236
 178.175.19.237
@@ -204577,6 +204813,7 @@
 178.175.22.188
 178.175.22.194
 178.175.22.203
+178.175.22.207
 178.175.22.209
 178.175.22.210
 178.175.22.211
@@ -204593,6 +204830,7 @@
 178.175.22.237
 178.175.22.241
 178.175.22.245
+178.175.22.248
 178.175.22.249
 178.175.22.255
 178.175.22.32
@@ -204690,6 +204928,7 @@
 178.175.23.55
 178.175.23.56
 178.175.23.58
+178.175.23.6
 178.175.23.61
 178.175.23.69
 178.175.23.71
@@ -204755,6 +204994,7 @@
 178.175.24.222
 178.175.24.223
 178.175.24.227
+178.175.24.230
 178.175.24.232
 178.175.24.238
 178.175.24.239
@@ -204821,6 +205061,7 @@
 178.175.25.164
 178.175.25.166
 178.175.25.168
+178.175.25.169
 178.175.25.172
 178.175.25.173
 178.175.25.177
@@ -204912,6 +205153,7 @@
 178.175.26.161
 178.175.26.162
 178.175.26.164
+178.175.26.165
 178.175.26.168
 178.175.26.169
 178.175.26.17
@@ -204936,6 +205178,7 @@
 178.175.26.207
 178.175.26.211
 178.175.26.214
+178.175.26.215
 178.175.26.217
 178.175.26.218
 178.175.26.219
@@ -204959,6 +205202,7 @@
 178.175.26.3
 178.175.26.31
 178.175.26.32
+178.175.26.34
 178.175.26.36
 178.175.26.38
 178.175.26.4
@@ -205054,12 +205298,14 @@
 178.175.27.25
 178.175.27.252
 178.175.27.30
+178.175.27.32
 178.175.27.36
 178.175.27.38
 178.175.27.39
 178.175.27.4
 178.175.27.41
 178.175.27.47
+178.175.27.48
 178.175.27.49
 178.175.27.5
 178.175.27.53
@@ -205163,6 +205409,7 @@
 178.175.28.7
 178.175.28.72
 178.175.28.74
+178.175.28.75
 178.175.28.79
 178.175.28.8
 178.175.28.81
@@ -205180,6 +205427,7 @@
 178.175.29.106
 178.175.29.111
 178.175.29.114
+178.175.29.12
 178.175.29.127
 178.175.29.128
 178.175.29.130
@@ -205291,6 +205539,7 @@
 178.175.3.190
 178.175.3.192
 178.175.3.193
+178.175.3.194
 178.175.3.196
 178.175.3.199
 178.175.3.201
@@ -205375,6 +205624,7 @@
 178.175.30.178
 178.175.30.18
 178.175.30.180
+178.175.30.181
 178.175.30.183
 178.175.30.185
 178.175.30.186
@@ -205568,6 +205818,7 @@
 178.175.32.221
 178.175.32.223
 178.175.32.227
+178.175.32.229
 178.175.32.23
 178.175.32.230
 178.175.32.233
@@ -205596,6 +205847,7 @@
 178.175.32.70
 178.175.32.72
 178.175.32.77
+178.175.32.83
 178.175.32.85
 178.175.32.87
 178.175.32.89
@@ -205632,6 +205884,7 @@
 178.175.33.165
 178.175.33.167
 178.175.33.170
+178.175.33.173
 178.175.33.174
 178.175.33.177
 178.175.33.178
@@ -205644,6 +205897,7 @@
 178.175.33.198
 178.175.33.2
 178.175.33.202
+178.175.33.205
 178.175.33.209
 178.175.33.21
 178.175.33.210
@@ -205730,6 +205984,7 @@
 178.175.34.21
 178.175.34.216
 178.175.34.217
+178.175.34.219
 178.175.34.22
 178.175.34.223
 178.175.34.224
@@ -205758,6 +206013,7 @@
 178.175.34.49
 178.175.34.5
 178.175.34.53
+178.175.34.56
 178.175.34.58
 178.175.34.60
 178.175.34.61
@@ -205904,11 +206160,13 @@
 178.175.36.172
 178.175.36.173
 178.175.36.174
+178.175.36.176
 178.175.36.177
 178.175.36.182
 178.175.36.184
 178.175.36.187
 178.175.36.189
+178.175.36.19
 178.175.36.192
 178.175.36.194
 178.175.36.198
@@ -206117,6 +206375,7 @@
 178.175.38.196
 178.175.38.2
 178.175.38.20
+178.175.38.200
 178.175.38.203
 178.175.38.204
 178.175.38.206
@@ -206193,6 +206452,7 @@
 178.175.39.17
 178.175.39.174
 178.175.39.175
+178.175.39.176
 178.175.39.181
 178.175.39.183
 178.175.39.190
@@ -206287,6 +206547,7 @@
 178.175.4.215
 178.175.4.216
 178.175.4.218
+178.175.4.219
 178.175.4.220
 178.175.4.222
 178.175.4.233
@@ -206357,6 +206618,7 @@
 178.175.40.138
 178.175.40.139
 178.175.40.14
+178.175.40.145
 178.175.40.149
 178.175.40.15
 178.175.40.151
@@ -206492,6 +206754,7 @@
 178.175.41.56
 178.175.41.57
 178.175.41.6
+178.175.41.60
 178.175.41.62
 178.175.41.65
 178.175.41.66
@@ -206610,6 +206873,7 @@
 178.175.43.154
 178.175.43.157
 178.175.43.158
+178.175.43.16
 178.175.43.162
 178.175.43.163
 178.175.43.165
@@ -206651,6 +206915,7 @@
 178.175.43.30
 178.175.43.31
 178.175.43.33
+178.175.43.34
 178.175.43.37
 178.175.43.38
 178.175.43.41
@@ -206681,6 +206946,7 @@
 178.175.43.91
 178.175.43.93
 178.175.43.94
+178.175.44.0
 178.175.44.100
 178.175.44.101
 178.175.44.102
@@ -206780,6 +207046,7 @@
 178.175.44.89
 178.175.44.9
 178.175.44.90
+178.175.44.95
 178.175.45.10
 178.175.45.102
 178.175.45.107
@@ -206892,6 +207159,7 @@
 178.175.46.110
 178.175.46.114
 178.175.46.116
+178.175.46.119
 178.175.46.120
 178.175.46.124
 178.175.46.125
@@ -206904,6 +207172,7 @@
 178.175.46.145
 178.175.46.149
 178.175.46.150
+178.175.46.151
 178.175.46.152
 178.175.46.154
 178.175.46.158
@@ -207156,6 +207425,7 @@
 178.175.48.65
 178.175.48.66
 178.175.48.71
+178.175.48.76
 178.175.48.80
 178.175.48.82
 178.175.48.85
@@ -207182,6 +207452,7 @@
 178.175.49.123
 178.175.49.126
 178.175.49.127
+178.175.49.129
 178.175.49.136
 178.175.49.137
 178.175.49.138
@@ -207195,6 +207466,7 @@
 178.175.49.18
 178.175.49.180
 178.175.49.185
+178.175.49.188
 178.175.49.189
 178.175.49.19
 178.175.49.194
@@ -207382,6 +207654,7 @@
 178.175.50.233
 178.175.50.236
 178.175.50.237
+178.175.50.239
 178.175.50.248
 178.175.50.249
 178.175.50.27
@@ -207409,6 +207682,7 @@
 178.175.50.84
 178.175.50.86
 178.175.50.87
+178.175.50.9
 178.175.50.90
 178.175.50.92
 178.175.50.95
@@ -207647,6 +207921,7 @@
 178.175.53.224
 178.175.53.225
 178.175.53.227
+178.175.53.228
 178.175.53.229
 178.175.53.231
 178.175.53.233
@@ -207808,6 +208083,7 @@
 178.175.55.165
 178.175.55.167
 178.175.55.169
+178.175.55.170
 178.175.55.191
 178.175.55.192
 178.175.55.194
@@ -207855,6 +208131,7 @@
 178.175.55.70
 178.175.55.72
 178.175.55.77
+178.175.55.85
 178.175.55.86
 178.175.55.88
 178.175.55.91
@@ -208122,6 +208399,7 @@
 178.175.58.35
 178.175.58.39
 178.175.58.40
+178.175.58.42
 178.175.58.43
 178.175.58.48
 178.175.58.49
@@ -208378,6 +208656,7 @@
 178.175.60.32
 178.175.60.34
 178.175.60.36
+178.175.60.37
 178.175.60.41
 178.175.60.42
 178.175.60.46
@@ -208458,6 +208737,7 @@
 178.175.61.36
 178.175.61.37
 178.175.61.40
+178.175.61.42
 178.175.61.43
 178.175.61.45
 178.175.61.52
@@ -208515,6 +208795,7 @@
 178.175.62.209
 178.175.62.211
 178.175.62.213
+178.175.62.216
 178.175.62.219
 178.175.62.220
 178.175.62.222
@@ -208540,11 +208821,13 @@
 178.175.62.39
 178.175.62.42
 178.175.62.43
+178.175.62.44
 178.175.62.45
 178.175.62.46
 178.175.62.50
 178.175.62.51
 178.175.62.56
+178.175.62.70
 178.175.62.72
 178.175.62.74
 178.175.62.76
@@ -209041,6 +209324,7 @@
 178.175.67.78
 178.175.67.8
 178.175.67.82
+178.175.67.83
 178.175.67.84
 178.175.67.86
 178.175.67.88
@@ -209165,6 +209449,7 @@
 178.175.69.140
 178.175.69.141
 178.175.69.143
+178.175.69.148
 178.175.69.149
 178.175.69.153
 178.175.69.154
@@ -209177,6 +209462,7 @@
 178.175.69.166
 178.175.69.169
 178.175.69.171
+178.175.69.173
 178.175.69.174
 178.175.69.175
 178.175.69.182
@@ -209424,6 +209710,7 @@
 178.175.70.92
 178.175.70.93
 178.175.70.94
+178.175.71.1
 178.175.71.102
 178.175.71.103
 178.175.71.104
@@ -209517,6 +209804,7 @@
 178.175.71.59
 178.175.71.60
 178.175.71.63
+178.175.71.64
 178.175.71.65
 178.175.71.68
 178.175.71.69
@@ -209540,6 +209828,7 @@
 178.175.72.101
 178.175.72.102
 178.175.72.108
+178.175.72.109
 178.175.72.110
 178.175.72.111
 178.175.72.113
@@ -209667,6 +209956,7 @@
 178.175.73.199
 178.175.73.2
 178.175.73.21
+178.175.73.211
 178.175.73.214
 178.175.73.216
 178.175.73.219
@@ -209700,6 +209990,7 @@
 178.175.73.6
 178.175.73.68
 178.175.73.7
+178.175.73.71
 178.175.73.72
 178.175.73.76
 178.175.73.86
@@ -209904,6 +210195,7 @@
 178.175.76.11
 178.175.76.113
 178.175.76.119
+178.175.76.121
 178.175.76.124
 178.175.76.125
 178.175.76.129
@@ -210161,6 +210453,7 @@
 178.175.78.92
 178.175.78.93
 178.175.78.94
+178.175.78.97
 178.175.79.101
 178.175.79.105
 178.175.79.106
@@ -210320,7 +210613,9 @@
 178.175.8.9
 178.175.8.93
 178.175.8.94
+178.175.8.97
 178.175.80.10
+178.175.80.100
 178.175.80.103
 178.175.80.11
 178.175.80.110
@@ -210399,6 +210694,7 @@
 178.175.80.37
 178.175.80.4
 178.175.80.40
+178.175.80.41
 178.175.80.43
 178.175.80.44
 178.175.80.46
@@ -210491,6 +210787,7 @@
 178.175.81.251
 178.175.81.252
 178.175.81.30
+178.175.81.32
 178.175.81.44
 178.175.81.45
 178.175.81.49
@@ -210505,6 +210802,7 @@
 178.175.81.7
 178.175.81.70
 178.175.81.79
+178.175.81.8
 178.175.81.80
 178.175.81.82
 178.175.81.83
@@ -210525,6 +210823,7 @@
 178.175.82.115
 178.175.82.117
 178.175.82.12
+178.175.82.120
 178.175.82.122
 178.175.82.123
 178.175.82.126
@@ -210878,6 +211177,7 @@
 178.175.85.171
 178.175.85.172
 178.175.85.183
+178.175.85.184
 178.175.85.185
 178.175.85.190
 178.175.85.192
@@ -210894,6 +211194,7 @@
 178.175.85.227
 178.175.85.228
 178.175.85.229
+178.175.85.23
 178.175.85.230
 178.175.85.242
 178.175.85.243
@@ -210933,6 +211234,7 @@
 178.175.85.79
 178.175.85.8
 178.175.85.80
+178.175.85.81
 178.175.85.83
 178.175.85.87
 178.175.85.89
@@ -210960,9 +211262,11 @@
 178.175.86.146
 178.175.86.15
 178.175.86.157
+178.175.86.159
 178.175.86.160
 178.175.86.164
 178.175.86.165
+178.175.86.166
 178.175.86.167
 178.175.86.169
 178.175.86.174
@@ -211027,6 +211331,7 @@
 178.175.86.81
 178.175.86.86
 178.175.86.90
+178.175.86.92
 178.175.86.93
 178.175.86.96
 178.175.86.97
@@ -211035,6 +211340,7 @@
 178.175.87.101
 178.175.87.106
 178.175.87.107
+178.175.87.108
 178.175.87.110
 178.175.87.113
 178.175.87.115
@@ -211208,6 +211514,7 @@
 178.175.88.51
 178.175.88.52
 178.175.88.53
+178.175.88.57
 178.175.88.60
 178.175.88.64
 178.175.88.78
@@ -211244,8 +211551,11 @@
 178.175.89.150
 178.175.89.151
 178.175.89.153
+178.175.89.157
 178.175.89.159
+178.175.89.160
 178.175.89.168
+178.175.89.169
 178.175.89.171
 178.175.89.173
 178.175.89.177
@@ -211322,6 +211632,7 @@
 178.175.9.132
 178.175.9.135
 178.175.9.138
+178.175.9.139
 178.175.9.140
 178.175.9.153
 178.175.9.155
@@ -211345,6 +211656,7 @@
 178.175.9.196
 178.175.9.200
 178.175.9.21
+178.175.9.210
 178.175.9.215
 178.175.9.217
 178.175.9.220
@@ -211385,12 +211697,14 @@
 178.175.9.92
 178.175.9.95
 178.175.9.98
+178.175.90.104
 178.175.90.109
 178.175.90.11
 178.175.90.114
 178.175.90.115
 178.175.90.116
 178.175.90.119
+178.175.90.122
 178.175.90.124
 178.175.90.127
 178.175.90.128
@@ -211525,8 +211839,10 @@
 178.175.91.219
 178.175.91.22
 178.175.91.221
+178.175.91.223
 178.175.91.224
 178.175.91.23
+178.175.91.230
 178.175.91.232
 178.175.91.236
 178.175.91.237
@@ -211689,6 +212005,7 @@
 178.175.93.144
 178.175.93.145
 178.175.93.147
+178.175.93.148
 178.175.93.149
 178.175.93.15
 178.175.93.150
@@ -211717,6 +212034,7 @@
 178.175.93.219
 178.175.93.220
 178.175.93.223
+178.175.93.224
 178.175.93.225
 178.175.93.226
 178.175.93.23
@@ -211734,6 +212052,7 @@
 178.175.93.30
 178.175.93.31
 178.175.93.33
+178.175.93.34
 178.175.93.36
 178.175.93.38
 178.175.93.4
@@ -211757,6 +212076,7 @@
 178.175.93.8
 178.175.93.82
 178.175.93.89
+178.175.93.90
 178.175.93.93
 178.175.93.95
 178.175.93.96
@@ -211881,6 +212201,7 @@
 178.175.95.119
 178.175.95.122
 178.175.95.126
+178.175.95.132
 178.175.95.135
 178.175.95.136
 178.175.95.137
@@ -211922,6 +212243,7 @@
 178.175.95.228
 178.175.95.230
 178.175.95.236
+178.175.95.237
 178.175.95.238
 178.175.95.24
 178.175.95.241
@@ -212043,6 +212365,7 @@
 178.175.96.97
 178.175.96.98
 178.175.96.99
+178.175.97.1
 178.175.97.100
 178.175.97.101
 178.175.97.103
@@ -212061,6 +212384,7 @@
 178.175.97.129
 178.175.97.130
 178.175.97.132
+178.175.97.135
 178.175.97.139
 178.175.97.140
 178.175.97.141
@@ -212074,6 +212398,7 @@
 178.175.97.163
 178.175.97.167
 178.175.97.168
+178.175.97.17
 178.175.97.173
 178.175.97.175
 178.175.97.177
@@ -212258,6 +212583,7 @@
 178.175.99.222
 178.175.99.223
 178.175.99.225
+178.175.99.226
 178.175.99.230
 178.175.99.233
 178.175.99.237
@@ -214544,6 +214870,7 @@
 180.188.241.79
 180.188.241.86
 180.188.241.91
+180.188.247.140
 180.188.252.185
 180.188.252.37
 180.188.253.153
@@ -218313,6 +218640,7 @@
 182.113.232.248
 182.113.232.81
 182.113.233.120
+182.113.233.129
 182.113.233.13
 182.113.233.20
 182.113.233.3
@@ -221859,6 +222187,7 @@
 182.116.103.68
 182.116.103.76
 182.116.103.77
+182.116.103.81
 182.116.103.85
 182.116.103.90
 182.116.103.91
@@ -222127,6 +222456,7 @@
 182.116.108.177
 182.116.108.178
 182.116.108.179
+182.116.108.180
 182.116.108.182
 182.116.108.183
 182.116.108.185
@@ -222719,6 +223049,7 @@
 182.116.119.110
 182.116.119.111
 182.116.119.122
+182.116.119.129
 182.116.119.134
 182.116.119.139
 182.116.119.140
@@ -224402,6 +224733,7 @@
 182.116.99.132
 182.116.99.141
 182.116.99.142
+182.116.99.150
 182.116.99.153
 182.116.99.160
 182.116.99.17
@@ -225990,6 +226322,7 @@
 182.117.29.202
 182.117.29.212
 182.117.29.216
+182.117.29.220
 182.117.29.227
 182.117.29.228
 182.117.29.229
@@ -229116,6 +229449,7 @@
 182.119.13.107
 182.119.13.109
 182.119.13.119
+182.119.13.141
 182.119.13.148
 182.119.13.159
 182.119.13.160
@@ -230149,6 +230483,7 @@
 182.119.191.87
 182.119.191.92
 182.119.196.160
+182.119.196.182
 182.119.196.190
 182.119.199.158
 182.119.199.85
@@ -230822,6 +231157,7 @@
 182.119.227.188
 182.119.227.194
 182.119.227.199
+182.119.227.20
 182.119.227.207
 182.119.227.21
 182.119.227.245
@@ -231408,6 +231744,7 @@
 182.119.49.148
 182.119.49.162
 182.119.49.168
+182.119.49.17
 182.119.49.185
 182.119.49.207
 182.119.49.220
@@ -231915,6 +232252,7 @@
 182.119.7.3
 182.119.7.41
 182.119.7.47
+182.119.7.54
 182.119.7.73
 182.119.7.75
 182.119.7.88
@@ -233579,6 +233917,7 @@
 182.120.85.9
 182.120.86.203
 182.120.86.234
+182.120.86.248
 182.120.86.46
 182.120.87.160
 182.120.87.227
@@ -234666,6 +235005,7 @@
 182.121.133.32
 182.121.133.37
 182.121.133.41
+182.121.133.46
 182.121.133.50
 182.121.133.58
 182.121.133.72
@@ -235445,6 +235785,7 @@
 182.121.164.75
 182.121.164.85
 182.121.165.184
+182.121.165.217
 182.121.166.105
 182.121.166.123
 182.121.166.85
@@ -235833,6 +236174,7 @@
 182.121.204.99
 182.121.205.100
 182.121.205.114
+182.121.205.118
 182.121.205.124
 182.121.205.131
 182.121.205.137
@@ -237628,6 +237970,7 @@
 182.121.49.92
 182.121.49.94
 182.121.49.97
+182.121.50.111
 182.121.50.112
 182.121.50.119
 182.121.50.121
@@ -238106,6 +238449,7 @@
 182.121.78.201
 182.121.78.220
 182.121.78.27
+182.121.78.29
 182.121.78.3
 182.121.78.36
 182.121.78.42
@@ -239343,6 +239687,7 @@
 182.122.202.219
 182.122.202.229
 182.122.202.246
+182.122.202.37
 182.122.202.59
 182.122.202.62
 182.122.202.82
@@ -239745,6 +240090,7 @@
 182.122.246.167
 182.122.246.170
 182.122.246.181
+182.122.246.187
 182.122.246.190
 182.122.246.197
 182.122.246.199
@@ -239884,6 +240230,7 @@
 182.122.251.122
 182.122.251.124
 182.122.251.133
+182.122.251.141
 182.122.251.143
 182.122.251.145
 182.122.251.150
@@ -240993,6 +241340,7 @@
 182.124.134.216
 182.124.134.235
 182.124.134.75
+182.124.134.80
 182.124.134.9
 182.124.134.90
 182.124.134.96
@@ -241096,6 +241444,7 @@
 182.124.149.52
 182.124.149.67
 182.124.15.106
+182.124.15.108
 182.124.15.109
 182.124.15.111
 182.124.15.13
@@ -241201,6 +241550,7 @@
 182.124.166.2
 182.124.166.228
 182.124.166.38
+182.124.166.57
 182.124.166.6
 182.124.166.7
 182.124.167.11
@@ -243271,6 +243621,7 @@
 182.126.180.65
 182.126.180.72
 182.126.181.115
+182.126.181.121
 182.126.181.149
 182.126.181.204
 182.126.181.214
@@ -243840,6 +244191,7 @@
 182.126.241.244
 182.126.241.30
 182.126.241.42
+182.126.241.7
 182.126.241.71
 182.126.241.92
 182.126.242.10
@@ -243917,6 +244269,7 @@
 182.126.52.202
 182.126.52.214
 182.126.52.229
+182.126.52.233
 182.126.52.252
 182.126.52.47
 182.126.52.70
@@ -244509,6 +244862,7 @@
 182.126.87.20
 182.126.87.201
 182.126.87.205
+182.126.87.207
 182.126.87.209
 182.126.87.217
 182.126.87.22
@@ -248008,6 +248362,7 @@
 182.127.70.172
 182.127.70.185
 182.127.70.194
+182.127.70.195
 182.127.70.213
 182.127.70.216
 182.127.70.218
@@ -249306,6 +249661,7 @@
 182.56.115.187
 182.56.115.191
 182.56.116.121
+182.56.116.135
 182.56.116.178
 182.56.116.56
 182.56.117.14
@@ -251855,6 +252211,7 @@
 182.58.137.168
 182.58.137.66
 182.58.137.94
+182.58.160.0
 182.58.160.122
 182.58.160.252
 182.58.160.89
@@ -254352,6 +254709,7 @@
 182.59.226.71
 182.59.227.10
 182.59.227.123
+182.59.227.125
 182.59.227.130
 182.59.227.151
 182.59.227.175
@@ -257013,6 +257371,7 @@
 183.188.184.94
 183.188.186.52
 183.188.187.52
+183.188.188.186
 183.188.194.119
 183.188.194.231
 183.188.195.189
@@ -257249,6 +257608,7 @@
 183.190.24.165
 183.190.26.125
 183.190.55.62
+183.191.162.120
 183.191.204.241
 183.191.217.113
 183.191.65.166
@@ -257305,6 +257665,7 @@
 183.27.195.242
 183.28.50.158
 183.28.61.52
+183.30.202.230
 183.30.202.247
 183.30.202.59
 183.30.202.67
@@ -257434,6 +257795,7 @@
 183.83.104.44
 183.83.104.68
 183.83.105.181
+183.83.105.21
 183.83.105.228
 183.83.105.252
 183.83.105.253
@@ -258125,6 +258487,7 @@
 185.132.53.88
 185.132.53.9
 185.132.53.98
+185.133.42.86
 185.134.122.209
 185.134.123.140
 185.134.21.75
@@ -258529,6 +258892,7 @@
 185.184.221.44
 185.184.54.15
 185.185.126.123
+185.185.126.82
 185.186.142.100
 185.186.198.120
 185.186.244.186
@@ -262064,6 +262428,7 @@
 188.10.21.14
 188.10.231.246
 188.112.169.59
+188.113.102.18
 188.113.107.75
 188.113.116.133
 188.113.81.17
@@ -262217,6 +262582,7 @@
 188.166.179.28
 188.166.18.52
 188.166.19.196
+188.166.19.45
 188.166.207.182
 188.166.21.10
 188.166.21.86
@@ -264949,6 +265315,7 @@
 192.119.106.235
 192.119.106.9
 192.119.107.81
+192.119.110.168
 192.119.110.222
 192.119.110.44
 192.119.110.49
@@ -265731,6 +266098,7 @@
 194.15.36.193
 194.15.36.194
 194.15.36.196
+194.15.36.202
 194.15.36.204
 194.15.36.207
 194.15.36.208
@@ -265988,6 +266356,7 @@
 194.87.138.86
 194.87.138.88
 194.87.138.97
+194.87.139.10
 194.87.139.108
 194.87.139.110
 194.87.139.113
@@ -267653,6 +268022,7 @@
 2.238.18.160
 2.238.195.223
 2.248.2.174
+2.249.161.188
 2.249.161.196
 2.249.178.219
 2.25.93.113
@@ -268173,6 +268543,7 @@
 200.75.107.84
 200.79.152.109
 200.79.153.166
+200.8.206.151
 200.8.206.224
 200.8.23.209
 200.8.240.149
@@ -268353,6 +268724,7 @@
 201.207.235.219
 201.208.129.111
 201.208.137.75
+201.208.139.84
 201.208.153.220
 201.208.155.206
 201.208.209.28
@@ -269194,6 +269566,7 @@
 202.168.153.228
 202.169.234.10
 202.169.234.19
+202.169.234.22
 202.169.234.33
 202.169.234.36
 202.169.234.37
@@ -270235,6 +270608,7 @@
 203.114.116.37
 203.115.102.243
 203.115.73.100
+203.115.73.105
 203.115.73.107
 203.115.73.11
 203.115.73.111
@@ -270330,6 +270704,7 @@
 203.115.85.93
 203.115.91.129
 203.115.91.141
+203.115.91.232
 203.115.91.47
 203.115.91.66
 203.123.205.195
@@ -273255,6 +273630,7 @@
 206.221.176.164
 206.248.136.50
 206.248.136.6
+206.248.137.132
 206.248.139.132
 206.248.139.15
 206.248.219.15
@@ -273435,6 +273811,7 @@
 209.133.223.130
 209.14.30.121
 209.14.30.135
+209.14.30.136
 209.14.30.159
 209.14.30.161
 209.14.30.166
@@ -273443,6 +273820,7 @@
 209.14.30.205
 209.14.30.30
 209.14.30.54
+209.14.31.125
 209.14.31.162
 209.14.31.163
 209.14.31.175
@@ -273707,6 +274085,7 @@
 210.101.157.10
 210.101.157.199
 210.101.70.131
+210.102.196.200
 210.102.58.78
 210.104.187.179
 210.104.210.133
@@ -275764,6 +276143,7 @@
 218.0.88.48
 218.101.202.186
 218.101.230.26
+218.103.180.199
 218.104.175.100
 218.104.175.103
 218.104.175.109
@@ -278418,6 +278798,7 @@
 219.154.140.99
 219.154.141.138
 219.154.141.196
+219.154.141.222
 219.154.141.227
 219.154.141.242
 219.154.141.53
@@ -279260,6 +279641,7 @@
 219.155.12.205
 219.155.12.215
 219.155.12.220
+219.155.12.221
 219.155.12.40
 219.155.12.51
 219.155.12.55
@@ -279490,6 +279872,7 @@
 219.155.170.165
 219.155.170.185
 219.155.170.215
+219.155.170.22
 219.155.170.228
 219.155.170.244
 219.155.170.250
@@ -279685,6 +280068,7 @@
 219.155.207.8
 219.155.207.96
 219.155.208.145
+219.155.208.188
 219.155.208.19
 219.155.208.211
 219.155.208.212
@@ -279946,6 +280330,7 @@
 219.155.225.90
 219.155.226.130
 219.155.226.143
+219.155.226.146
 219.155.226.154
 219.155.226.188
 219.155.226.194
@@ -280142,6 +280527,7 @@
 219.155.240.86
 219.155.241.11
 219.155.241.113
+219.155.241.135
 219.155.241.137
 219.155.241.144
 219.155.241.155
@@ -280681,6 +281067,7 @@
 219.155.37.72
 219.155.37.87
 219.155.37.90
+219.155.37.97
 219.155.38.10
 219.155.38.112
 219.155.38.113
@@ -281444,6 +281831,7 @@
 219.156.103.192
 219.156.103.225
 219.156.103.236
+219.156.103.248
 219.156.103.43
 219.156.103.46
 219.156.103.84
@@ -282255,6 +282643,7 @@
 219.156.23.241
 219.156.23.245
 219.156.23.26
+219.156.23.29
 219.156.23.3
 219.156.23.41
 219.156.23.50
@@ -282398,6 +282787,7 @@
 219.156.48.185
 219.156.48.50
 219.156.49.142
+219.156.49.170
 219.156.49.172
 219.156.49.250
 219.156.5.233
@@ -282474,6 +282864,7 @@
 219.156.60.203
 219.156.60.208
 219.156.60.211
+219.156.60.224
 219.156.60.250
 219.156.60.27
 219.156.60.39
@@ -282791,6 +283182,7 @@
 219.156.9.247
 219.156.9.254
 219.156.9.27
+219.156.9.32
 219.156.9.34
 219.156.9.42
 219.156.9.48
@@ -284389,6 +284781,7 @@
 219.157.220.159
 219.157.220.163
 219.157.220.164
+219.157.220.170
 219.157.220.171
 219.157.220.177
 219.157.220.18
@@ -284474,6 +284867,7 @@
 219.157.223.24
 219.157.223.241
 219.157.223.243
+219.157.223.245
 219.157.223.29
 219.157.223.4
 219.157.223.42
@@ -284525,6 +284919,7 @@
 219.157.226.198
 219.157.226.4
 219.157.226.47
+219.157.226.79
 219.157.227.124
 219.157.227.170
 219.157.227.176
@@ -284897,6 +285292,7 @@
 219.157.244.233
 219.157.244.236
 219.157.244.254
+219.157.244.33
 219.157.244.39
 219.157.244.43
 219.157.244.61
@@ -285835,6 +286231,7 @@
 219.157.50.203
 219.157.50.208
 219.157.50.21
+219.157.50.211
 219.157.50.228
 219.157.50.233
 219.157.50.238
@@ -285994,6 +286391,7 @@
 219.157.54.150
 219.157.54.155
 219.157.54.157
+219.157.54.158
 219.157.54.159
 219.157.54.177
 219.157.54.19
@@ -286101,6 +286499,7 @@
 219.157.56.251
 219.157.56.254
 219.157.56.35
+219.157.56.46
 219.157.56.47
 219.157.56.50
 219.157.56.54
@@ -288884,6 +289283,7 @@
 221.14.56.67
 221.14.57.62
 221.14.58.27
+221.14.58.5
 221.14.58.84
 221.14.59.255
 221.14.60.146
@@ -289497,6 +289897,7 @@
 221.15.147.210
 221.15.147.214
 221.15.147.217
+221.15.147.220
 221.15.147.225
 221.15.147.227
 221.15.147.234
@@ -291309,6 +291710,7 @@
 221.15.236.92
 221.15.236.93
 221.15.236.98
+221.15.237.107
 221.15.237.109
 221.15.237.11
 221.15.237.112
@@ -292033,6 +292435,7 @@
 221.15.7.198
 221.15.7.199
 221.15.7.200
+221.15.7.202
 221.15.7.205
 221.15.7.207
 221.15.7.21
@@ -293025,6 +293428,7 @@
 221.215.170.109
 221.215.171.80
 221.215.172.192
+221.215.172.207
 221.215.172.217
 221.215.174.4
 221.215.174.59
@@ -293713,6 +294117,7 @@
 221.5.30.10
 221.5.30.100
 221.5.30.103
+221.5.30.118
 221.5.30.14
 221.5.30.140
 221.5.30.153
@@ -297260,6 +297665,7 @@
 222.137.22.42
 222.137.22.59
 222.137.22.66
+222.137.22.79
 222.137.220.10
 222.137.220.123
 222.137.220.125
@@ -297288,6 +297694,7 @@
 222.137.220.60
 222.137.220.63
 222.137.220.82
+222.137.220.94
 222.137.220.99
 222.137.221.101
 222.137.221.107
@@ -297899,6 +298306,7 @@
 222.137.49.170
 222.137.49.29
 222.137.49.30
+222.137.49.4
 222.137.49.75
 222.137.49.99
 222.137.5.102
@@ -298298,6 +298706,7 @@
 222.137.83.230
 222.137.83.39
 222.137.83.5
+222.137.83.53
 222.137.84.2
 222.137.84.240
 222.137.84.33
@@ -299840,6 +300249,7 @@
 222.138.189.219
 222.138.189.223
 222.138.189.243
+222.138.189.88
 222.138.19.110
 222.138.19.135
 222.138.19.144
@@ -300166,6 +300576,7 @@
 222.138.215.134
 222.138.215.146
 222.138.215.16
+222.138.215.161
 222.138.215.183
 222.138.215.215
 222.138.215.222
@@ -300276,6 +300687,7 @@
 222.138.224.148
 222.138.224.15
 222.138.224.163
+222.138.224.164
 222.138.224.173
 222.138.224.2
 222.138.224.228
@@ -300742,6 +301154,7 @@
 222.138.49.58
 222.138.49.67
 222.138.49.79
+222.138.49.93
 222.138.50.106
 222.138.50.237
 222.138.50.32
@@ -301164,6 +301577,7 @@
 222.139.16.143
 222.139.16.173
 222.139.16.195
+222.139.16.229
 222.139.16.236
 222.139.16.32
 222.139.16.84
@@ -301932,6 +302346,7 @@
 222.140.111.116
 222.140.111.192
 222.140.111.205
+222.140.112.150
 222.140.112.171
 222.140.112.224
 222.140.113.197
@@ -303605,6 +304020,7 @@
 222.141.164.67
 222.141.164.88
 222.141.165.116
+222.141.165.180
 222.141.165.189
 222.141.165.2
 222.141.165.214
@@ -303920,6 +304336,7 @@
 222.141.244.110
 222.141.244.147
 222.141.244.20
+222.141.244.231
 222.141.244.80
 222.141.245.10
 222.141.245.134
@@ -304584,6 +305001,7 @@
 222.141.73.184
 222.141.73.219
 222.141.73.245
+222.141.73.249
 222.141.73.38
 222.141.73.55
 222.141.73.61
@@ -306094,6 +306512,7 @@
 222.214.53.254
 222.214.53.62
 222.214.54.162
+222.214.54.208
 222.214.54.238
 222.214.55.138
 222.214.55.18
@@ -307746,6 +308165,7 @@
 27.12.232.176
 27.12.233.205
 27.12.233.96
+27.12.234.4
 27.12.235.176
 27.12.236.127
 27.12.238.202
@@ -311864,6 +312284,7 @@
 27.208.242.223
 27.208.244.172
 27.208.247.130
+27.208.25.59
 27.208.30.1
 27.208.30.87
 27.208.31.92
@@ -312151,6 +312572,7 @@
 27.210.146.49
 27.210.146.54
 27.210.146.6
+27.210.146.61
 27.210.146.89
 27.210.147.172
 27.210.147.228
@@ -312892,6 +313314,7 @@
 27.213.145.138
 27.213.145.143
 27.213.145.161
+27.213.145.221
 27.213.146.231
 27.213.147.121
 27.213.148.104
@@ -312938,6 +313361,7 @@
 27.213.166.136
 27.213.166.174
 27.213.167.154
+27.213.167.175
 27.213.167.180
 27.213.167.210
 27.213.168.16
@@ -313902,6 +314326,7 @@
 27.216.130.132
 27.216.130.185
 27.216.131.63
+27.216.131.66
 27.216.132.194
 27.216.132.221
 27.216.132.237
@@ -317796,6 +318221,7 @@
 27.41.146.252
 27.41.146.27
 27.41.146.3
+27.41.146.59
 27.41.146.63
 27.41.146.73
 27.41.146.80
@@ -317916,6 +318342,7 @@
 27.41.153.41
 27.41.153.54
 27.41.153.65
+27.41.153.66
 27.41.153.89
 27.41.153.91
 27.41.154.102
@@ -319042,6 +319469,7 @@
 27.43.151.68
 27.43.151.86
 27.43.66.61
+27.43.82.210
 27.43.92.65
 27.44.100.126
 27.44.100.242
@@ -319324,6 +319752,7 @@
 27.46.47.61
 27.46.47.69
 27.46.47.72
+27.46.47.74
 27.46.47.75
 27.46.47.76
 27.46.47.77
@@ -319413,6 +319842,7 @@
 27.5.16.236
 27.5.16.237
 27.5.16.242
+27.5.16.243
 27.5.16.244
 27.5.16.245
 27.5.16.246
@@ -319890,6 +320320,7 @@
 27.5.21.38
 27.5.21.4
 27.5.21.5
+27.5.21.53
 27.5.21.56
 27.5.21.57
 27.5.21.63
@@ -320314,6 +320745,7 @@
 27.5.26.32
 27.5.26.33
 27.5.26.37
+27.5.26.4
 27.5.26.43
 27.5.26.44
 27.5.26.47
@@ -320626,6 +321058,7 @@
 27.5.30.197
 27.5.30.20
 27.5.30.203
+27.5.30.207
 27.5.30.210
 27.5.30.212
 27.5.30.215
@@ -320932,6 +321365,7 @@
 27.5.34.169
 27.5.34.171
 27.5.34.176
+27.5.34.177
 27.5.34.182
 27.5.34.183
 27.5.34.186
@@ -320996,6 +321430,7 @@
 27.5.35.117
 27.5.35.12
 27.5.35.125
+27.5.35.127
 27.5.35.130
 27.5.35.131
 27.5.35.132
@@ -341750,6 +342185,7 @@
 31.163.189.192
 31.163.189.220
 31.163.189.254
+31.163.191.11
 31.163.57.231
 31.163.65.250
 31.164.47.38
@@ -341976,6 +342412,7 @@
 31.6.70.84
 31.6.98.137
 31.62.130.208
+31.62.255.3
 31.62.91.175
 31.63.183.192
 31.63.189.195
@@ -344023,6 +344460,7 @@
 37.187.73.85
 37.189.109.110
 37.19.48.73
+37.19.49.202
 37.19.49.206
 37.19.51.174
 37.19.52.247
@@ -345964,6 +346402,7 @@
 39.73.44.149
 39.73.44.155
 39.73.44.165
+39.73.44.17
 39.73.44.176
 39.73.44.185
 39.73.44.198
@@ -348636,6 +349075,7 @@
 39.86.150.176
 39.86.150.37
 39.86.151.106
+39.86.151.49
 39.86.151.96
 39.86.152.128
 39.86.152.130
@@ -349399,6 +349839,7 @@
 39.87.84.239
 39.87.87.117
 39.87.87.99
+39.87.90.210
 39.87.93.109
 39.87.93.54
 39.87.98.115
@@ -351781,6 +352222,7 @@
 42.224.122.3
 42.224.122.30
 42.224.122.37
+42.224.122.39
 42.224.122.41
 42.224.122.43
 42.224.122.52
@@ -353103,6 +353545,7 @@
 42.224.176.199
 42.224.176.202
 42.224.176.205
+42.224.176.214
 42.224.176.216
 42.224.176.217
 42.224.176.221
@@ -354440,6 +354883,7 @@
 42.224.249.57
 42.224.249.73
 42.224.249.76
+42.224.249.8
 42.224.249.87
 42.224.249.88
 42.224.249.92
@@ -356601,6 +357045,7 @@
 42.224.90.133
 42.224.90.151
 42.224.90.158
+42.224.90.17
 42.224.90.196
 42.224.90.240
 42.224.90.28
@@ -357802,6 +358247,7 @@
 42.225.33.162
 42.225.33.199
 42.225.33.20
+42.225.33.31
 42.225.34.174
 42.225.34.18
 42.225.34.184
@@ -358375,6 +358821,7 @@
 42.226.89.147
 42.226.89.157
 42.226.89.235
+42.226.89.25
 42.226.89.82
 42.226.90.0
 42.226.90.102
@@ -358916,6 +359363,7 @@
 42.227.176.230
 42.227.176.239
 42.227.176.90
+42.227.177.142
 42.227.177.250
 42.227.177.84
 42.227.178.10
@@ -361510,6 +361958,7 @@
 42.228.75.59
 42.228.75.63
 42.228.75.65
+42.228.75.7
 42.228.75.74
 42.228.75.79
 42.228.75.80
@@ -363420,6 +363869,7 @@
 42.230.173.51
 42.230.173.66
 42.230.174.117
+42.230.174.125
 42.230.174.161
 42.230.174.171
 42.230.174.216
@@ -364146,6 +364596,7 @@
 42.230.219.225
 42.230.219.231
 42.230.219.239
+42.230.219.243
 42.230.219.254
 42.230.219.37
 42.230.219.4
@@ -366621,6 +367072,7 @@
 42.231.223.17
 42.231.223.191
 42.231.223.209
+42.231.223.215
 42.231.223.59
 42.231.223.95
 42.231.224.122
@@ -366774,6 +367226,7 @@
 42.231.244.187
 42.231.244.189
 42.231.244.222
+42.231.244.80
 42.231.244.83
 42.231.245.111
 42.231.245.142
@@ -367192,6 +367645,7 @@
 42.231.95.136
 42.231.95.154
 42.231.95.17
+42.231.95.195
 42.231.95.210
 42.231.95.230
 42.231.95.99
@@ -369091,6 +369545,7 @@
 42.233.90.116
 42.233.90.138
 42.233.90.167
+42.233.90.183
 42.233.90.187
 42.233.90.52
 42.233.91.0
@@ -369211,6 +369666,7 @@
 42.234.105.253
 42.234.105.3
 42.234.105.33
+42.234.105.6
 42.234.105.68
 42.234.105.93
 42.234.106.110
@@ -369505,6 +369961,7 @@
 42.234.162.214
 42.234.162.4
 42.234.162.42
+42.234.162.44
 42.234.162.76
 42.234.163.119
 42.234.163.16
@@ -374059,6 +374516,7 @@
 42.235.90.245
 42.235.90.29
 42.235.90.3
+42.235.90.32
 42.235.90.46
 42.235.90.50
 42.235.90.53
@@ -375222,6 +375680,7 @@
 42.237.44.45
 42.237.44.47
 42.237.45.107
+42.237.45.223
 42.237.45.25
 42.237.45.90
 42.237.46.104
@@ -375538,6 +375997,7 @@
 42.238.109.115
 42.238.11.212
 42.238.111.149
+42.238.112.100
 42.238.112.125
 42.238.112.132
 42.238.112.32
@@ -375805,6 +376265,7 @@
 42.238.175.124
 42.238.175.14
 42.238.175.229
+42.238.175.32
 42.238.175.35
 42.238.175.61
 42.238.175.96
@@ -378688,6 +379149,7 @@
 45.144.225.118
 45.144.225.142
 45.144.225.151
+45.144.225.213
 45.144.225.65
 45.144.225.96
 45.144.29.133
@@ -385086,6 +385548,7 @@
 54.179.174.132
 54.179.179.37
 54.179.9.186
+54.180.158.181
 54.186.24.183
 54.187.210.136
 54.197.30.41
@@ -385262,6 +385725,7 @@
 58.19.163.45
 58.19.163.92
 58.19.249.100
+58.19.249.50
 58.19.250.18
 58.19.250.190
 58.19.251.10
@@ -386094,6 +386558,7 @@
 58.248.143.158
 58.248.143.164
 58.248.143.168
+58.248.143.173
 58.248.143.174
 58.248.143.176
 58.248.143.18
@@ -386122,6 +386587,7 @@
 58.248.144.180
 58.248.144.186
 58.248.144.190
+58.248.144.21
 58.248.144.216
 58.248.144.217
 58.248.144.39
@@ -386129,6 +386595,7 @@
 58.248.144.89
 58.248.144.94
 58.248.144.95
+58.248.144.97
 58.248.145.113
 58.248.145.129
 58.248.145.13
@@ -386255,6 +386722,7 @@
 58.248.149.186
 58.248.149.207
 58.248.149.214
+58.248.149.226
 58.248.149.230
 58.248.149.231
 58.248.149.240
@@ -387097,6 +387565,7 @@
 58.249.73.74
 58.249.73.90
 58.249.74.103
+58.249.74.104
 58.249.74.11
 58.249.74.118
 58.249.74.120
@@ -387123,6 +387592,7 @@
 58.249.74.9
 58.249.75.101
 58.249.75.109
+58.249.75.112
 58.249.75.125
 58.249.75.126
 58.249.75.13
@@ -387206,6 +387676,7 @@
 58.249.78.116
 58.249.78.128
 58.249.78.132
+58.249.78.155
 58.249.78.168
 58.249.78.174
 58.249.78.176
@@ -387307,6 +387778,7 @@
 58.249.80.246
 58.249.80.37
 58.249.80.38
+58.249.80.46
 58.249.80.56
 58.249.80.61
 58.249.80.63
@@ -387521,6 +387993,7 @@
 58.249.87.211
 58.249.87.222
 58.249.87.247
+58.249.87.248
 58.249.87.250
 58.249.87.253
 58.249.87.33
@@ -387585,6 +388058,7 @@
 58.249.89.169
 58.249.89.178
 58.249.89.190
+58.249.89.210
 58.249.89.213
 58.249.89.218
 58.249.89.223
@@ -387649,6 +388123,7 @@
 58.249.90.180
 58.249.90.19
 58.249.90.20
+58.249.90.206
 58.249.90.216
 58.249.90.220
 58.249.90.233
@@ -387659,6 +388134,7 @@
 58.249.90.80
 58.249.90.82
 58.249.90.84
+58.249.90.86
 58.249.90.94
 58.249.91.102
 58.249.91.11
@@ -387693,6 +388169,7 @@
 58.249.91.77
 58.249.91.98
 58.252.175.220
+58.252.176.107
 58.252.176.117
 58.252.176.12
 58.252.176.120
@@ -387961,6 +388438,7 @@
 58.255.135.21
 58.255.135.228
 58.255.135.253
+58.255.135.41
 58.255.135.48
 58.255.135.56
 58.255.135.61
@@ -388137,6 +388615,7 @@
 58.42.195.227
 58.42.198.13
 58.42.220.111
+58.46.169.21
 58.46.248.182
 58.46.248.4
 58.46.249.10
@@ -388299,6 +388778,7 @@
 58.61.51.61
 58.61.51.73
 58.61.51.97
+58.62.31.25
 58.62.80.50
 58.62.80.54
 58.62.83.182
@@ -392364,6 +392844,7 @@
 59.32.97.159
 59.32.97.187
 59.32.97.188
+59.32.97.190
 59.32.97.208
 59.32.97.217
 59.32.97.218
@@ -394236,6 +394717,7 @@
 59.92.182.7
 59.92.182.70
 59.92.182.71
+59.92.182.72
 59.92.182.74
 59.92.182.75
 59.92.182.76
@@ -394942,6 +395424,7 @@
 59.92.218.72
 59.92.218.73
 59.92.218.75
+59.92.218.77
 59.92.218.79
 59.92.218.8
 59.92.218.80
@@ -395062,6 +395545,7 @@
 59.92.219.252
 59.92.219.254
 59.92.219.26
+59.92.219.28
 59.92.219.29
 59.92.219.30
 59.92.219.31
@@ -395692,6 +396176,7 @@
 59.93.19.187
 59.93.19.189
 59.93.19.190
+59.93.19.191
 59.93.19.193
 59.93.19.194
 59.93.19.195
@@ -395866,6 +396351,7 @@
 59.93.21.110
 59.93.21.111
 59.93.21.115
+59.93.21.117
 59.93.21.121
 59.93.21.126
 59.93.21.127
@@ -397165,6 +397651,7 @@
 59.94.182.241
 59.94.182.242
 59.94.182.243
+59.94.182.244
 59.94.182.246
 59.94.182.247
 59.94.182.248
@@ -399714,6 +400201,7 @@
 59.97.169.111
 59.97.169.112
 59.97.169.113
+59.97.169.114
 59.97.169.115
 59.97.169.116
 59.97.169.117
@@ -400942,6 +401430,7 @@
 59.97.174.82
 59.97.174.83
 59.97.174.84
+59.97.174.85
 59.97.174.87
 59.97.174.89
 59.97.174.9
@@ -403353,6 +403842,7 @@
 59.99.44.249
 59.99.44.253
 59.99.44.254
+59.99.44.28
 59.99.44.29
 59.99.44.30
 59.99.44.31
@@ -404261,6 +404751,7 @@
 59.99.93.244
 59.99.93.245
 59.99.93.246
+59.99.93.248
 59.99.93.250
 59.99.93.251
 59.99.93.252
@@ -404317,6 +404808,7 @@
 59.99.93.79
 59.99.93.8
 59.99.93.80
+59.99.93.82
 59.99.93.83
 59.99.93.84
 59.99.93.85
@@ -404557,6 +405049,7 @@
 59.99.95.134
 59.99.95.135
 59.99.95.136
+59.99.95.137
 59.99.95.139
 59.99.95.14
 59.99.95.140
@@ -404566,6 +405059,7 @@
 59.99.95.146
 59.99.95.147
 59.99.95.148
+59.99.95.149
 59.99.95.15
 59.99.95.151
 59.99.95.152
@@ -406797,6 +407291,7 @@
 60.215.4.239
 60.215.4.89
 60.215.42.16
+60.215.59.108
 60.215.61.56
 60.215.63.173
 60.216.122.109
@@ -415656,6 +416151,7 @@
 60.254.49.198
 60.254.49.201
 60.254.49.215
+60.254.49.59
 60.254.49.68
 60.254.49.94
 60.254.50.240
@@ -416462,6 +416958,7 @@
 60.7.64.208
 60.7.64.243
 60.7.65.79
+60.7.8.43
 60.7.94.111
 60.7.99.254
 60.9.155.86
@@ -418674,11 +419171,13 @@
 61.3.124.244
 61.3.124.25
 61.3.124.251
+61.3.124.3
 61.3.124.33
 61.3.124.34
 61.3.124.39
 61.3.124.41
 61.3.124.46
+61.3.124.51
 61.3.124.60
 61.3.124.65
 61.3.124.71
@@ -418690,6 +419189,7 @@
 61.3.124.95
 61.3.125.102
 61.3.125.107
+61.3.125.112
 61.3.125.114
 61.3.125.119
 61.3.125.12
@@ -418785,6 +419285,7 @@
 61.3.127.124
 61.3.127.125
 61.3.127.135
+61.3.127.138
 61.3.127.149
 61.3.127.158
 61.3.127.178
@@ -419480,6 +419981,7 @@
 61.52.135.117
 61.52.135.125
 61.52.135.144
+61.52.135.192
 61.52.135.234
 61.52.135.235
 61.52.135.253
@@ -420556,6 +421058,7 @@
 61.52.212.233
 61.52.212.239
 61.52.212.244
+61.52.212.250
 61.52.212.251
 61.52.212.27
 61.52.212.30
@@ -421392,6 +421895,7 @@
 61.52.39.101
 61.52.39.109
 61.52.39.110
+61.52.39.119
 61.52.39.122
 61.52.39.132
 61.52.39.144
@@ -421699,6 +422203,7 @@
 61.52.5.192
 61.52.5.195
 61.52.5.198
+61.52.5.217
 61.52.5.226
 61.52.5.60
 61.52.50.109
@@ -422272,6 +422777,7 @@
 61.52.62.97
 61.52.63.11
 61.52.63.110
+61.52.63.119
 61.52.63.121
 61.52.63.125
 61.52.63.127
@@ -422435,6 +422941,7 @@
 61.52.76.53
 61.52.76.58
 61.52.76.59
+61.52.76.72
 61.52.76.73
 61.52.76.74
 61.52.76.87
@@ -423633,6 +424140,7 @@
 61.53.123.149
 61.53.123.154
 61.53.123.161
+61.53.123.162
 61.53.123.163
 61.53.123.168
 61.53.123.169
@@ -423719,6 +424227,7 @@
 61.53.124.215
 61.53.124.219
 61.53.124.223
+61.53.124.225
 61.53.124.227
 61.53.124.23
 61.53.124.230
@@ -426274,6 +426783,7 @@
 61.54.240.166
 61.54.240.19
 61.54.240.198
+61.54.240.20
 61.54.240.213
 61.54.240.220
 61.54.240.44
@@ -426632,10 +427142,12 @@
 61.54.58.164
 61.54.58.166
 61.54.58.172
+61.54.58.190
 61.54.58.192
 61.54.58.193
 61.54.58.197
 61.54.58.198
+61.54.58.20
 61.54.58.202
 61.54.58.211
 61.54.58.22
@@ -426694,6 +427206,7 @@
 61.54.60.242
 61.54.60.255
 61.54.60.29
+61.54.60.4
 61.54.60.43
 61.54.60.55
 61.54.60.68
@@ -426716,6 +427229,7 @@
 61.54.61.163
 61.54.61.168
 61.54.61.172
+61.54.61.18
 61.54.61.191
 61.54.61.199
 61.54.61.208
@@ -427424,6 +427938,7 @@
 62.219.131.205
 62.219.138.44
 62.219.143.46
+62.219.155.61
 62.219.163.162
 62.219.164.224
 62.219.194.210
@@ -428624,6 +429139,7 @@
 71.183.150.34
 71.187.60.8
 71.19.144.47
+71.19.150.93
 71.190.64.120
 71.190.64.189
 71.190.64.214
@@ -429532,6 +430048,7 @@
 77.45.182.113
 77.45.182.196
 77.45.183.124
+77.45.183.39
 77.45.184.77
 77.45.185.57
 77.45.185.89
@@ -431735,6 +432252,7 @@
 84.22.38.175
 84.221.143.108
 84.224.144.27
+84.224.162.170
 84.224.177.80
 84.224.213.50
 84.228.102.152
@@ -431948,6 +432466,7 @@
 85.105.77.54
 85.105.82.225
 85.105.82.94
+85.105.9.152
 85.105.98.84
 85.106.129.231
 85.106.161.174
@@ -435128,6 +435647,7 @@
 95.152.49.54
 95.152.5.232
 95.152.9.183
+95.153.241.63
 95.153.94.241
 95.154.20.231
 95.154.244.200
@@ -436600,6 +437120,7 @@ accesointerne.theworkpc.com
 access-24.jp
 access-cash.ae.org
 access-om.neomeric.us
+access-one.us
 access-to-web.com
 accessclub.jp
 accessdig.com
@@ -436777,6 +437298,7 @@ achremittanceservices.com
 acht-stuecken.de
 achuanchaolihai.cn
 aci.serabd.com
+aciabogados.com
 aciitaly.com
 acilevarkadasi.com
 acilisbalon.com
@@ -437193,6 +437715,7 @@ admin.grapejuiceofbrazil.com
 admin.greenlightcr.com
 admin.hopehorseback.org
 admin.jpcar.mystand.pt
+admin.mobilezenie.com
 admin.searchlowestprice.com
 admin.solissol.com
 admin.staging.buildsmart.io
@@ -437372,7 +437895,6 @@ adventuredsocks.com
 adventureexplorer.in
 adventurehr.com
 adventureitdate.com
-adventureits.com
 adventuremania.com
 adventurersafaris.com
 adventuresofarchibald.com
@@ -437792,6 +438314,7 @@ agenforedi.toko-abi.net
 agengarcinia5000.com
 agenity.com
 agenlama.com
+agenmovie.xyz
 agent-seo.jp
 agent.ken.by
 agent2.icu
@@ -444808,6 +445331,7 @@ barcaacademyistanbul.com
 barcelonaevent.es
 barcelonakartingcenter.com
 barchaklem.com
+barcionstw.eastus.cloudapp.azure.com
 barcla.ug
 barclaysdownloads.com
 barcoofoods.ir
@@ -447093,6 +447617,7 @@ bizzznez.com
 bj5800.com
 bjarndahl.dk
 bjbus.net
+bjconstructions.in
 bjdd.org
 bjenkins.webview.consulting
 bjenzer.com
@@ -448132,6 +448657,7 @@ bnote.novelux.com
 bnpartnersweb.com
 bnpgrup.com
 bnqzjy.cn
+bnrbook.com
 bnrnews.id
 bnsddfhjdfgvbxc.ru
 bnsgroupbd.com
@@ -448882,6 +449408,7 @@ brandzzy.com
 braner.com.ua
 branfinancial.com
 branner-chile.com
+brannon-powlowski25d.xyz
 brannudd.com
 brantech.com
 brar.aminfortgreene.com
@@ -449882,6 +450409,7 @@ buyrigrap.com
 buysellfx24.ru
 buysmart365.net
 buysmartwebmall.com
+buythebest.pk
 buytotake.online
 buytwitterlike.com
 buyuksigorta.com
@@ -451202,6 +451730,7 @@ cashonlinestore.com
 cashoutrefitips.com
 cashpickup.slmicrocredit.com
 cashslip.info
+cashtunel.com
 cashyinvestment.org
 casimiroartes.es
 casinarium.com
@@ -453774,6 +454303,7 @@ clubyourlife.ca
 clubzone.ca
 cluebazar.com
 clukva.ru
+clurbgolf.com
 clurit.com
 clusdirectory.xyz
 cluster-mixture.gq
@@ -453990,6 +454520,7 @@ coastmediagroup.com.au
 coastmedicalservice.com
 coastmotorsupply.com
 coastsignworks.com
+coastwidewaterproofing.com.au
 coatforwinter.com
 coavce.com
 cobam.xyz
@@ -456013,6 +456544,7 @@ cronicas.com.do
 cronolux.com.br
 croodly.com
 crookedchristicraddick.com
+crooks-cooper24g.xyz
 croos.org
 crope.shop
 cropfoods.com
@@ -457267,7 +457799,6 @@ dar-ltd.uk
 dar-sana.com
 darajelita.com
 daralsalam-mall.com
-daralsaqi.com
 darapartment.com
 darasrszs.online
 darassalam.ch
@@ -457376,7 +457907,6 @@ dashcenter.info
 dasheriemagazine.com
 dashfiles.tk
 dashkevichseo.ru
-dashonweb.com
 dashudance.com
 dashvaanjil.mn
 dasin-obchudek.cz
@@ -457704,6 +458234,7 @@ dboyusa.online
 dbravo.pro
 dbs-ebank.com
 dbsa-dream.com
+dbsandbox.ca
 dbsenvironmental.co.uk
 dbsgear.com
 dbsktoporder.yolasite.com
@@ -458612,6 +459143,7 @@ denlokale.nu
 denmaar.hplbusiness.com
 denmarkheating.net
 denmaytre.vn
+dennis-hill25lw.xyz
 dennis-roth.de
 dennishester.com
 dennisisasshole.com
@@ -461288,6 +461820,9 @@ down.posti-fi-fjwa.top
 down.posti-fi-fsa.top
 down.posti-fi-fsaq.top
 down.posti-fi-fwa.top
+down.posti-fi-ij.top
+down.posti-fi-in.top
+down.posti-fi-iz.top
 down.pzchao.com
 down.qm188.com
 down.qqfarmer.com.cn
@@ -463499,6 +464034,7 @@ egyptmaint.com
 egyptmotours.com
 egyptpharaohstours.com
 egyshadowmen.com
+egyutthato.eu
 egyuttkonnyebb.zolitoth.com
 egyvision.medicahealthy.net
 egywebtest.ml
@@ -464680,6 +465216,7 @@ ennaturismo.info
 ennessehospitality.id
 ennovate.elin.co.za
 eno.si
+enolil-loo.com
 enorichie.net
 enorka.info
 enosburgreading.pbworks.com
@@ -466653,6 +467190,7 @@ faithchorale.com
 faithcompassion.com
 faithconstructionltd.co.uk
 faithfight.my.id
+faithmethodistcheras.org
 faithmontessorischools.com
 faithoasis.000webhostapp.com
 faithworkx.com
@@ -467923,6 +468461,7 @@ findyourfocusph.com
 findyourvoice.ca
 fine-art-line.de
 fine.black
+fineartgallerym.com
 fineconera.com
 finefeather.info
 finefoodsfrozen.com
@@ -471551,6 +472090,7 @@ girlsphonenumbers.online
 girltalkza.co.za
 girlydesignart.com
 gironynavarro.com
+girotexuniformes.com
 girraj2016.gtranzit.com
 girrajwadi.com
 gisa.company
@@ -471640,6 +472180,7 @@ gladwynecapital.com
 glafka.com
 glambooth.nl
 glamoroushairextension.com
+glamorouspk.com
 glamour.rosolutions.com.mx
 glamourgarden-lb.com
 glamourlounge.org
@@ -472396,6 +472937,7 @@ gordondeen.net
 gordonmilktransport.com
 gordonruss.com
 gordyssensors.com
+gorecycle.fahadjutt.com
 gorenotoservisi.net
 gorestruly.com
 goretimmo.lu
@@ -473552,6 +474094,7 @@ gunesulkesi.com
 guneyaski.com
 gungazcomputer.co.ke
 gunk.insol.be
+gunma2u.com
 gunmak-com.tk
 gunnarasgeir.com
 gunnersexcavating.com
@@ -475903,6 +476446,7 @@ hollywoodremix.com
 hollywoodsmileeg.com
 holmdalehouse.co.uk
 holmesgroup-com.azurewebsites.net
+holmesprpmgmt.com
 holmnkolbas.com
 holmsater.se
 holod24.by
@@ -476596,6 +477140,7 @@ hpmamerica.com
 hpmaytinhtaophongcach.com
 hpmwqjub.com
 hpq8fa.db.files.1drv.com
+hprosacco25i.xyz
 hprpc.cn
 hps-sk.sk
 hps.nz
@@ -479172,6 +479717,7 @@ instant-resume.com
 instantbonheur.fr
 instantcashflowtoday.com.ng
 instantclients.network
+instantindialoan.com
 instanttaxsolutions.mobi
 instanttechnology.com.au
 instantworldpay.com
@@ -479996,6 +480542,7 @@ iscidavasi.com
 isciyizbiz.com
 iscleanone.com
 isclimatechangeahoax.com
+iscoegypt.com
 iscoming.ir
 iscon.com.br
 iscondisth.com
@@ -480051,7 +480598,6 @@ iskostrip.com
 iskro.textronic.info
 iskyservice.ru
 islaholics.com
-islamabadtrafficpolice.gov.pk
 islamabout.com
 islamappen.se
 islamforall.tv
@@ -481864,6 +482410,7 @@ jolly-saito-4993.sub.jp
 jollycharm.com
 jollyemma.com
 jolyscortinas.com.br
+jomansea.com
 jomar2020.com.br
 jomblo.com
 jomhermonex.com
@@ -483243,6 +483790,7 @@ kaspersky-security.com
 kasperskysecurity.club
 kasrasanatsepahan.com
 kassa.hostsites.ru
+kassandra5024d.xyz
 kassconnect.ru
 kasshmira.com
 kassohome.com.tr
@@ -483887,7 +484435,6 @@ khannamdo.com
 khannen.com.vn
 khannen.vn
 khanqahebrahimi.com
-khantil.com
 khantipong.com
 khaochills.com
 khaoden.tech
@@ -485749,6 +486296,7 @@ lab.sjworks.net
 lab.valvolari.it
 lab.ydigital.asia
 lab1.ozaki-kyousei.com
+lab18.it
 lab2.e-century.pl
 lab5.hu
 lab6.com.br
@@ -490787,6 +491335,7 @@ managegates.com
 manageitrisks.com
 management.vkims.com
 managementtop.id
+managemysalon.in
 managemyshoes.tools
 manageone.co.th
 manageprint.in
@@ -491168,6 +491717,7 @@ marecsko.hu
 marek-paysage-concept.fr
 marek.in
 marekvoprsal.cz
+marel.com.br
 marellengifts.com
 maremarius.pt
 marematto.it
@@ -492448,6 +492998,7 @@ meditationsurmesure.com
 meditec.ma
 mediterraneavacanze.com
 meditheraphy.com
+meditreat.itwebservice.in
 meditsinanarodnaya.ru
 medius.ge
 mediusvp.com
@@ -494624,6 +495175,7 @@ moitruongtunglam.com
 mojang.com.br
 mojehaftom.com
 mojewnetrza.pl
+mojno--vse.ru
 mojo-studios.co.uk
 mojorockstar.com
 mojstudent.net
@@ -495378,6 +495930,7 @@ mrpiratz.com
 mrpower.ir
 mrprintoke.com
 mrquick.co.il
+mrsambarbershop.nl
 mrsbow.com
 mrsconnect.org
 mrsdiggs.com
@@ -495978,6 +496531,7 @@ mvicente.com.br
 mvid.com
 mvidl.site
 mvisionproperties.com
+mvldesign.ca
 mvm368.com
 mvmskpd.com
 mvns.railfan.net
@@ -497312,6 +497866,7 @@ nellyvonalven.com
 nelsonhelps.com
 nelsonhostingcom.000webhostapp.com
 nelsonpto.org
+nelsonsbutchers.co.uk
 nelsonsilveti.com
 neltac.com
 nelyvos.nl
@@ -498646,7 +499201,6 @@ no18balloonroom.co.uk
 no1angelsescort.com
 no1spinningfields.90degrees.digital
 no1websitedesigner.com
-no2politics.com
 no70.fun
 noabuseshere.top
 noach.nl
@@ -499936,6 +500490,7 @@ ogxbody.com
 ohako.com.my
 ohamburguer.com.br
 ohanadev.com
+ohatsbd.com
 ohdratdigital.com
 ohe.ie
 ohelloguyzzqq.com
@@ -500240,6 +500795,7 @@ omada.edu.gr
 omagroup.ru
 omaharefugees.com
 omahduwur.com
+omaia.org
 omaint.ml
 omalleyco-my.sharepoint.com
 omalll.com
@@ -505870,6 +506426,7 @@ promodigital.tk
 promodont.com
 promokonyara.ru
 promolatinconferences.com
+promolyko.com
 promomitsubishitermurah.net
 promonoble.com
 promootzie.nl
@@ -507285,6 +507842,7 @@ quickmusings.com
 quickpickapp.co
 quickreachmedia.com
 quicksaleecuador.com
+quickshine.co.ke
 quickstorevn.com
 quicktechsupport247.com
 quicktowtowing.com
@@ -509386,6 +509944,7 @@ rgclimatizacion.com
 rgdecor.org
 rgfloors.com.au
 rgitabit.in
+rgleason25s.xyz
 rglgrupomedico.com.mx
 rgmobilegossip.com
 rgmvanijya.com
@@ -510230,6 +510789,7 @@ roselvi.cl
 rosemaryromero.com.br
 rosemiracle.com
 rosemurphy.co.uk
+rosenbaum-jaida24nz.xyz
 rosenfeldcapital.com
 rosenlaw.cratima.com
 roseperfeito.com.br
@@ -514148,6 +514708,7 @@ shastri.com
 shatabbytek.com
 shataikok.com
 shatelnews.ir
+shatteredglass.io
 shaukya.com
 shaulla.store
 shaunodonnell.com
@@ -516009,6 +516570,7 @@ smartlogo.com.br
 smartlync.pk
 smartmadira.com
 smartmassive.ru
+smartmatrixs.com
 smartmobilelearning.co.za
 smartmoneylife.com
 smartmovie.com.ua
@@ -516971,6 +517533,7 @@ sosctb.com
 sosenfantsburkinafaso.fr
 sosexymagazine.com
 sosflam.com
+sosgsm.fr
 sosh47.citycheb.ru
 sosoab.com
 sosofoto.cz
@@ -521610,6 +522173,7 @@ tecnologiaoficial.com
 tecnologiatech.com
 tecnologiaz.com
 tecnologicainformatica.com.br
+tecnologyschool.com
 tecnolora.com
 tecnoloxia.com
 tecnopc.info
@@ -524374,6 +524938,7 @@ tobpm.kz
 toby-warren.com
 tobyetc.com
 tobysherman.com
+tocaima.co
 tocakids.resultaweb.com.br
 tocgiajojo.com
 tochkae.ru
@@ -525501,6 +526066,7 @@ tresjoliejewellery.com
 tresnexus.com
 treterhef.download
 tretthing-bg.site
+treutel-jamir25ju.xyz
 trevellinglove.com
 trevinos.net
 trevorchristensen.com
@@ -528203,6 +528769,7 @@ vastintegrated.com
 vastraindia.com
 vastralaya.shop
 vastuanalyst.com
+vastubless.com
 vastuvidyaarchitects.com
 vasudhagoodharvest.com
 vasumadhi.com
@@ -529548,6 +530115,7 @@ vlad.iset.ro
 vladetel.org
 vladimirfilin.com
 vladimirfilin.ru
+vladimirinternational.com
 vladneta.lt
 vladsever.ru
 vladsp.ru
@@ -530546,6 +531114,7 @@ web.eficiens.cl
 web.emergingsun.com
 web.emsfabrik.de
 web.eng.ubu.ac.th
+web.geetle.ga
 web.geomegasoft.net
 web.golden-goblin.com
 web.gotham.com.au
@@ -531360,6 +531929,7 @@ why-h.xyz
 whyasksolution.com
 whybowl.thebotogs.com
 whyepicshop.com
+whynt.xyz
 whysquare.co.nz
 whystudio.cn
 whytech.info
@@ -532427,6 +532997,7 @@ wroxra.by.files.1drv.com
 wrrodrigo.com
 wrtech.com.pl
 wrusnollet.com
+wrzucacz.pl
 wrzutka.co
 ws-ebavisapia01-dll.ir
 ws3lfkm.com
@@ -532874,6 +533445,7 @@ xh.hj46.cn
 xhcmnews.com
 xhd.qhv.mybluehost.me
 xhencheng.tk
+xherzog24pv.xyz
 xhjclq.ch.files.1drv.com
 xhs9a81.com
 xhsdxm.com
@@ -534733,6 +535305,7 @@ zafinternational.co.id
 zafirotiendas.com
 zagnet.pl
 zagogulina.com
+zagoradesertcamp.com
 zagrodazbyszka.pl
 zagros-shahrekord.ir
 zagrosenergygroup.com
@@ -534788,6 +535361,7 @@ zakodujbiznes.ml
 zakopane.utazas.hu
 zakopanedomki.com.pl
 zakosciele66.cba.pl
+zakra.tecnasulstore.com.br
 zakrahgroup.com
 zakriasons.co
 zakromanoff.com
@@ -536091,8 +536665,6 @@ zzznan.com
 ||academiafriedman.com/micheldomit/local/categories_projects/images/1pnw7k5nysbmks7s5xjd0qzcqmikwevuh4ssqmyuhh2snxiblod/$all
 ||acboilers.com/_/doc/kekqpw/$all
 ||acc244.com.vn/wp-content/uploads/8nkblvriceirdnnup0em/$all
-||access-one.us/aym3vh.php$all
-||access-one.us/wp-content/qvrajpy4kvx3pkg4aiuljg98c34dw1yaweefdv7gnbvxygdyki6jqug61dmqb44w7cvth/$all
 ||accoytranslingual.com/extended-metaphor-soa9a/ri5/$all
 ||achutamanasa.com/cgi-bin/bferiat1bdtdbli95gq0r3ihrys5pwnwxrotpevhj0efgow0h/$all
 ||achutamanasa.com/garmin-pro-fei8o/mw/$all
@@ -536131,6 +536703,7 @@ zzznan.com
 ||adsonpadilhacampos.weebly.com/uploads/9/7/0/3/97031710/windowsapplication1.exe$all
 ||adsudoeste.com.br/iagwfi/4398338/nerq_4398338_02062020.zip$all
 ||adsudoeste.com.br/iagwfi/nerq_09709_02062020.zip$all
+||adventureits.com/wp-content/6399952952/q54d7zyhe/$all
 ||adventureracen.nl/cgi-bin/parts_service/$all
 ||advokatryzhov.ru/images/zoelfr/$all
 ||aecotimes.com/wp-admin/44z/$all
@@ -536975,7 +537548,6 @@ zzznan.com
 ||bitly.com/loadingdocnew3$all
 ||bitly.ws/bpnp$all
 ||bizilocator.com/demo/includes/font_awesome/xzqptpjui0e/$all
-||bjconstructions.in/6382329/mlrcedkan/$all
 ||bks.tv/fedex/$all
 ||bkvvngp.org/cgi-bin/ixrh0wy4uowboaguiphtunamhsgnim1hl3wyctgeauni22ctqhxgtc/$all
 ||blackiebooks.org/zhxg/file/y8jtk0y/$all
@@ -538029,7 +538601,6 @@ zzznan.com
 ||cmnbbnshgsadrrefasderg05g.s3.us-east-2.amazonaws.com/p-5-16.dll$all
 ||cnr.org.br/validacao/sendincverif/legal/trust/en_en/201903/$all
 ||coachankit.com/cgi-bin/ebb5ixgblb2thydw64i9egmvrvx5ky1gzl4su6yy8kwfa/$all
-||coastwidewaterproofing.com.au/l4s6cpeyo.rar$all
 ||code-it-consulting.com/afrp/sbr40gfr6iddlktuef9b5xr0pgo/$all
 ||codeload.github.com/administrativox/ft-bl-novembroit/zip/master$all
 ||codeload.github.com/ahmirtim/invoice-30049798728276548687687638763897872/zip/master$all
@@ -538150,10 +538721,11 @@ zzznan.com
 ||daniuniu.ml/wp-includes/fcubdfskpp1zxq8icuu5tpaqrcisrxm9obkvdg20po/$all
 ||dansofconsultancy.com/wp-admin/4uqqzy_5utgl5-17727/$all
 ||dansofconsultancy.com/wp-admin/b/$all
+||daralsaqi.com/preview.exe$all
+||dashonweb.com/wp-content/tscyjo/$all
 ||davicapucho.com.br/avatar-the-k0yzw/5ux1xwvsbxjekq72ieffvqlzprztnovt4jkmc/$all
 ||dbestfishing.com.sg/67s/document/eyskz3/bxgi5fr6451731565347eji17khgtqmdv8brmzy/$all
 ||dbestfishing.com.sg/67s/wfe/$all
-||dbsandbox.ca/cgi-bin/wgv9dtltdn9ebgnqzd7fy1me1ltgjuimrk2/$all
 ||dbtools.com.br/mailer/0fnt-rqxt3-odxsjx/$all
 ||dbtools.com.br/mailer/ezsvr-mqo7i-zgysfrmwr/$all
 ||dc437.4sync.com/download/q2mpp4rh/fotos-30-07_whatsapp_.rar?dsid=zoc3fezc.0fb656e2033aa7dc7fd3c21022fe8a33&sbsr=9964f71c25cde34624e79b7f6155706aa1b&bip=ndyumti2lje5mc4xnq&lgfp=40$all
@@ -554628,7 +555200,6 @@ zzznan.com
 ||ecoachings.in/old/p4hyzkfvgyg3ttigdtdrtzea94vatgnxm/$all
 ||ecodetect.com.br/wp-admin/burtjklsc/$all
 ||edmedicationguide.com/wp-admin/balance/c72682830684102z3frfjy8i55xmv7/$all
-||egyutthato.eu/5341zqvpdr/pay/smallbusiness$all
 ||ehitusest.eu/marketplacel/http://oww3quopm9m95oo/ytpjiimeb24c1tpluq/$all
 ||ehitusest.eu/marketplacel/http:/oww3quopm9m95oo/ytpjiimeb24c1tpluq/$all
 ||ehitusest.eu/marketplacel/sites/r5zmfubb2b/$all
@@ -554681,7 +555252,6 @@ zzznan.com
 ||engetrate.com.br/wp-content/uploads/available-disk/external-six4h17hlyby-pio/3444483541511-vr4hhb/$all
 ||engetrate.com.br/wp-content/uploads/common_zone/special_profile/qx2gu69ar_zwt1v908t/$all
 ||engetrate.com.br/wp-content/uploads/wlrdxb/$all
-||enolil-loo.com/agillawood/czafm/$all
 ||entechco.com.vn/cgi-bin/closed-array/close-4177495-w8s0fzls1gvrwtb/256853-mb3hqona2u00a/$all
 ||entechco.com.vn/wp-includes/payment/88413395259/ylz/$all
 ||epeixao.com/vendor/inc/gefj8rs8u/w89d9hrshp/$all
@@ -554756,7 +555326,6 @@ zzznan.com
 ||fago.vn/hoqizkwj4d/673440211_udu96a9_aq6cl_vpjcpbgvdxq/verified_nkjhrlnbsz_phtzwgotreu/f2szzee7jh_0885ww2vy02x2/$all
 ||fairlinktrading.com/images/flt.pdf$all
 ||fairytalestorybook.weebly.com/uploads/1/0/2/8/102827364/%e7%8b%80%e6%85%8b%e5%9c%96.exe$all
-||faithmethodistcheras.org/wp-admin/vttrtc-133-57930/$all
 ||falconcastings.com/wp-content/n0vfh4sxudy5e9vp7/$all
 ||famitaa.com/vsijmfio/13627971/employmentverification_13627971_05052020.zip$all
 ||farago-aveyron.com/wp-content/sites/8qgvtm4fyce14/$all
@@ -555269,7 +555838,6 @@ zzznan.com
 ||gullgas.weebly.com/uploads/1/2/3/0/123060154/setup.exe$all
 ||gullgas.weebly.com/uploads/1/2/3/0/123060154/sosss00.exe$all
 ||gullgas.weebly.com/uploads/1/2/3/0/123060154/xplo_protected.exe$all
-||gunma2u.com/ovp50ku/1pjj2peebf/$all
 ||guojiazui.com/b/y0qnnwbk/$all
 ||guridosinferno.s3.us-east-2.amazonaws.com/0.zip$all
 ||gurtravel.ge/rechnungs-details/$all
@@ -555577,6 +556145,9 @@ zzznan.com
 ||is.net.sa/wp-admin/sfuqjlw/ov/8k/5bcatso4.zip$all
 ||is.net.sa/wp-admin/sfuqjlw/s/hvfcttgvy.zip$all
 ||isginsaat.com.tr/wp-admin/830sr/ach/smallbusiness$all
+||islamabadtrafficpolice.gov.pk/browse/w6nsp2/fv54115180147v7ko46qxn3bvlmfq1/$all
+||islamabadtrafficpolice.gov.pk/esp/94406698/cppdv/$all
+||islamabadtrafficpolice.gov.pk/i/$all
 ||islamiadsk.com/cgi-bin/document/8462/vqzbwir/$all
 ||isowrd-co.weebly.com/uploads/5/7/1/6/57163811/full_patch.exe$all
 ||istlain.com/userfiles/setup.zip$all
@@ -555643,6 +556214,7 @@ zzznan.com
 ||justificante-pago.mediafire.com/file/hbl9ff5idpyv2sa/justf2.tgz/file$all
 ||justlficante.mediafire.com/file/4t8lltc9x35wzus/justt1.tgz/file$all
 ||justlficante.mediafire.com/file/g3y3o84bbgkhu4o/jusf1c.tgz/file$all
+||justlficante.mediafire.com/file/jl01o54yy09qrzg/fac215.tgz/file$all
 ||jwysjt.com/wp-admin/cvzk1sxqxhoklyj9nky9zin0nxovcorzw1b688ueoox9n/$all
 ||jxwmw.cn/att/0/10/05/85/10058513_919975.exe$all
 ||jxwmw.cn/wenhuajingdian/upfiles/chm_exe/1226sanguo1gb.exe$all
@@ -555684,6 +556256,8 @@ zzznan.com
 ||keuranta.com/wp-admin/xfsb/$all
 ||keymedia.com.vn/hoosf/j08yuzrjhllej-nl3zf1jl2xp2t3ng-gcn9j-s5thniqbi0/verifiable-profile/02634724768945-fxh4bqpiv4plspgm/$all
 ||keymedia.com.vn/xgfjbnzbj/report/75zegh/$all
+||khantil.com/us/payments/122018$all
+||khantil.com/us/payments/122018/$all
 ||khjhggfgbyj67ytfg.s3.us-east-2.amazonaws.com/jhgfd.exe$all
 ||khjhggfgbyj67ytfg.s3.us-east-2.amazonaws.com/oorrg.exe$all
 ||kiet.edu/blog/wp-content/uploads/2019/05/mur187.exe$all
@@ -556020,7 +556594,6 @@ zzznan.com
 ||marbleentreprise.dk/wp-content/uploads/43-2707086267392376617210761493.php$all
 ||marcoarcieri.com/wordpress/htixsfungkxkbafrjthyboezcml/$all
 ||marcostrombetta.com.br/ds/1802.gif$all
-||marel.com.br/wp-content/uploads/2020/10/bn8qvr2l/$all
 ||marketplacecostaricapp.com/download-video-bqbcn/2wuhp2w2yabrwfzqvvx68cfynyxfirgix2it08ds/$all
 ||martinas-kunsthandwerk.at/wp-includes/0lymjh0nwlfrzxsuf1holyj4ennhexmerri/$all
 ||masterfinance.com.au/product/4myaxn/$all
@@ -556245,7 +556818,6 @@ zzznan.com
 ||mobilize.org.br/acompanhe-a-mobilidade/browse/$all
 ||mobilize.org.br/acompanhe-a-mobilidade/docs/unz0127392065-7906-8qtep00cgkpfl7wx0rh3/$all
 ||mobilize.org.br/acompanhe-a-mobilidade/qlvsgt/$all
-||mojno--vse.ru/content/6tqjfutopvigfknidf0sfae6guwnsxjjicomwynq0qmfksrit2be2/$all
 ||mommababy.vn/wp-includes/jutbya4dbu3/$all
 ||mommababy.vn/wp-includes/lgnwvunbc8/$all
 ||moneygain.work/payeerclient.exe$all
@@ -556262,7 +556834,6 @@ zzznan.com
 ||movartemusic.com/wp-content/llc/$all
 ||mpeakecreations.co.za/cgi-bin/vvk1rw/$all
 ||mrescaperoom.ca/wp-content/languages/scan/en/important-please-read/$all
-||mrsambarbershop.nl/wp-content/axm4it/$all
 ||msdecorators.in/default/us/change-of-address$all
 ||msdecorators.in/default/us/change-of-address/$all
 ||msoftwares.info/pages$all
@@ -556285,7 +556856,6 @@ zzznan.com
 ||mumbaimobilecreches.org/wp-content/uploads/browse/ao95njkbf/gd-6382-621648608-cvkh4e70-l3ago/$all
 ||mumbaimobilecreches.org/wp-content/uploads/zfbhkvjk/$all
 ||muzey.com.ua/wp-content/verif.myaccount.docs.net/$all
-||mvldesign.ca/durani/2lzs/$all
 ||mx.technolutions.net/mpss/c/bge/jm0haa/t.2me/e2sfmjjzts6masn8xxbs0w/h0/exw3hpzofskfhf9idddddtwlss3ai50r6ndwiim7gh5onf5krna5zabg7ndxzjrq-2bg2jji0uf-2f3tbbcte6aica-3d-3d$all
 ||my.cloudme.com/v1/ws2/:gianni1962/:ie6setup/ie6setup.exe$all
 ||my.mixtape.moe/ayqydr.vbs$all
@@ -556361,7 +556931,6 @@ zzznan.com
 ||nch.com.au/components/doxillionsetup.exe$all
 ||neabot.com/wp-includes/gp9c2oalybhubicfahpcor8zpo1tetl5y3jnvmagpp2satzhf6hdrefrjm2k8x1xzdgbw/$all
 ||nearlearn.com/ds/1612.gif$all
-||nelsonsbutchers.co.uk/cgi-bin/4vlaf1vqrwyfgwgxp33pcd1uydauib40dllquefurt5547d0xsmo/$all
 ||neoflash.com/download/neo2_pro_manager_1.32a_setup.exe$all
 ||neoflash.com/driver/neo2_pro_manager_1.32_setup.exe$all
 ||netedu.ir/special-offer/vyn/$all
@@ -556417,6 +556986,7 @@ zzznan.com
 ||nissanvinh.com.vn/wp-content/file/dzstsbdfmrxcrylycpikagmv/$all
 ||nltu.edu.ua/fakturierung/rechnung-0269807/$all
 ||nmsdevelopers.com/cgi-bin/isir0cvzfzzk3zjymvnmjykw/$all
+||no2politics.com/files/us_us/doc/invoice-069345/$all
 ||nobletrade.top/forced-to-ppjht/4ujxrcjziel7naqcz4okyfz9wamd4m/$all
 ||nobletrade.top/forced-to-ppjht/r8zjyoribymmst7nssspsdtkhe/$all
 ||nofile.io/f/ed4ptb5vkud/purchase+order.zip$all
@@ -558538,6 +559108,7 @@ zzznan.com
 ||onedrive.live.com/download?cid=d7a53f4e448c59af&resid=d7a53f4e448c59af%21930&authkey=ae8aykwfbemxegw$all
 ||onedrive.live.com/download?cid=d86391352444eeed&resid=d86391352444eeed!107&authkey=ajitiybfqf5qcpw$all
 ||onedrive.live.com/download?cid=d86391352444eeed&resid=d86391352444eeed%21107&authkey=ajitiybfqf5qcpw$all
+||onedrive.live.com/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21107&authkey=alo4lep7wht05na$all
 ||onedrive.live.com/download?cid=d888b8d6e7ceee72&resid=d888b8d6e7ceee72%21109&authkey=adnbm6mekgzvvh8$all
 ||onedrive.live.com/download?cid=d88d6079d4b91bdb&resid=d88d6079d4b91bdb!391&authkey=afgbzttalahmq9a$all
 ||onedrive.live.com/download?cid=d8a7da7154194e40&resid=d8a7da7154194e40!970&authkey=!alf9m4lwilj_jre$all
@@ -563131,6 +563702,7 @@ zzznan.com
 ||pastebin.com/raw/qmhtgbwv$all
 ||pastebin.com/raw/qmq7ggtb$all
 ||pastebin.com/raw/qmsdyt9z$all
+||pastebin.com/raw/qmue83xz$all
 ||pastebin.com/raw/qmxvzneq$all
 ||pastebin.com/raw/qn1aczmi$all
 ||pastebin.com/raw/qndvdcqj$all
@@ -565145,7 +565717,6 @@ zzznan.com
 ||quaxel2.net/v1/t/c/ac95f29a-4b23-8bed-a80c-19848f03d48c/outlk:97b7fdec-1450-4311-b9e5-698749862d93/irespond@financeofamerica.com/https:/laminingraphics.co.za/wp-admin/etrac/$all
 ||quen.s3.us-east-2.amazonaws.com/order+acknowledgement+bc202374++stock++20021+dem+p4.ace$all
 ||quen.s3.us-east-2.amazonaws.com/purchasing+ordersigned+contractinv-30067121.ace$all
-||quickshine.co.ke/categoryl/eyoerdilcvrt0wf2zcac6633eytah/$all
 ||quuik.com/rwc/jr42/$all
 ||quuik.com/wp-keys.php$all
 ||r20.rs6.net/tn.jsp?f=001jyht2t3omeetiei35oqstjgs_9nzk9sjylnhtbb0ao4bhans77uolbdrrwaaelcy_xfpwz_v9kt7buybu0v7bxkhuwlnsftzi2_8ddimoio4s1lnjpwd3da7cbyogtmhkf5obn3ysllinftl_gcxaufwxn0bz8fxjf4yvhjb-3gtb-da07vpp0qazekjwo7a9udmhkol3peul1z7wczztkps5tadshty&c=sda7vzhezlmymcpvzhysvdoo2nf8acki9xwyb_wfzgl7nntihduz-a==&ch=hl2va1psqpoi_ueanwygza8msuiyrkcqkgylcfuiihszmkx0z2mngg==$all
@@ -565786,7 +566357,6 @@ zzznan.com
 ||slsbearings.com.sg/en/corporation/cdiih-tcjn3_vdroc-dsx/$all
 ||smartgrocerysl.com/content/dlm/$all
 ||smartitventures.com/671295aysj/biz/smallbusiness$all
-||smartmatrixs.com/beta/llc/2af68g7w0ysysv95nutlsp_0bunhkbg-9466852086487/$all
 ||smartpresence.id/wp-includes/blocks/overview/$all
 ||smcsme.com/fedex/$all
 ||smedia.com.au/open-past-due-orders/$all
@@ -567695,7 +568265,6 @@ zzznan.com
 ||tlsac.pe/wp-touch.php$all
 ||tmpfiles.org/dl/160986/0702.exe$all
 ||tnkhanh.info/wp-admin/az0fysfnexo1qfw9si6bvfxs/$all
-||tocaima.co/wp-includes/dj5aol1nnnzjdyzvqurfh2lopouzceyok8ndyuoew/$all
 ||tocchientv.com/cgi-bin/gegesa/$all
 ||tog.org.tr/wp-content/uploads/2018/07/alta_settlement_statement.zip$all
 ||tonetdog.com/updedge$all
@@ -568696,7 +569265,6 @@ zzznan.com
 ||woweasily.com/accounts/webbrowser.php$all
 ||wowsoftware.weebly.com/uploads/6/0/1/3/60131139/spell_checker_64bit.exe$all
 ||wpengine.zendesk.com/attachments/token/qigbj5ov2vik5lcgbzkwa3wzh/?name=ly7995522-693.doc$all
-||wrzucacz.pl/download/1211536055165$all
 ||wsu.ac.za/che_audit/che_docs/5jyu-82i190-gszut.view/$all
 ||wsu.ac.za/che_audit/che_docs/sendincencrypt/service/trust/en_en/03-2019/$all
 ||ww2today.com/wp-admin/pkybkm/$all
@@ -568790,7 +569358,6 @@ zzznan.com
 ||yurdumaku.com/blogs/zqawwa/$all
 ||yushilimited.uk/content/ptclzsyp48/$all
 ||ywhmcs.com/110244.exe$all
-||zagoradesertcamp.com/templates/u/$all
 ||zardoubbeauty.com/fullcalendar-bs3-php-mysql-master/d/$all
 ||zasobygwp.pl/redirect?sig=f88a745272587f579e8ce173b9952c32f161eb9733ec249031b854898cd62375&url=ahr0cdovl2rhbmlydmlucghvdg9ncmfwahkuy29tl3dlzgrpbmcvrklmrs94ohp5nm9nni8=&platform=desktop&brand=wp/$all
 ||zawiyadevelopers.com/wp-content/plugins/so-widgets-bundle/base/inc/widgets/clnqgzvncz/o/a89khrpth.zip$all